A coalition’s complaint to Maryland’s attorney general has raised a specific question for data brokers and technology companies: whether selling or sharing location and personal information with immigration enforcement can comply with the state’s privacy law. The filing is an allegation, not a finding that the named companies violated the law.
We Are CASA, represented by the Georgetown Technology Law Clinic and joined by privacy and civil-rights organizations, filed the consumer complaint on August 19, 2026. It asks Attorney General Anthony G. Brown to investigate alleged sales of geolocation data, personal data and motor vehicle records to law enforcement and federal immigration authorities, including U.S. Immigration and Customs Enforcement.
What Maryland’s law is designed to restrict
The complaint points to provisions of Maryland’s Online Data Privacy Act, also known as MODPA. According to the filing, the law bars companies from sharing a Maryland resident’s phone or vehicle location data with law enforcement without proper legal process. It also bars sharing personal data with immigration enforcement agencies without a judicial warrant.
The law separately restricts the sale of sensitive data except in narrow circumstances. The coalition argues that precise cell-phone location information and vehicle-location data collected through automated license plate readers fall within the protections that make those transactions legally significant.
That mechanism matters because the dispute is not simply about whether a person gave an app permission to collect information. The legal question is also what a company can do after collecting it, who can receive it and whether the recipient and purpose trigger stricter limits.
Who could be affected
The complaint names Penlink, Motorola, Thomson Reuters, LexisNexis, Insight LPR, Flock and ThunderCat Technology. The supplied filing says several of the companies currently hold state or federal contracts with ICE. It identifies ThunderCat Technology in connection with the complaint, but the evidence provided here does not establish the conduct of any individual company.
Maryland residents could be affected if information linked to their phones, vehicles or other personal records is transferred for purposes covered by the law. Data brokers and technology vendors face a different consequence: they may need to review data sources, customer contracts, recipient screening and the legal process attached to government requests.
A separate Baker Donelson analysis says MODPA applies to businesses that conduct business in Maryland or target Maryland residents and either processed the personal data of at least 35,000 consumers in the preceding calendar year, excluding data used only to complete payment transactions, or processed data from at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. The analysis also says the law has relatively limited entity-level exemptions.
What the complaint does—and does not—prove
The filing supplies a formal path for the attorney general to examine the alleged data flows. It does not, by itself, prove that a company sold a particular Maryland resident’s information, that a transaction lacked legally required process or that the attorney general will bring an enforcement action.
That distinction is especially important because the supplied evidence contains no response from the named companies, no finding by Maryland regulators and no court ruling. It also does not provide a verified count of Maryland residents whose data may have been involved. The scope and outcome therefore remain unresolved.
WilmerHale’s analysis describes MODPA as stricter than many state privacy laws, including stronger sensitive-data requirements and enforcement through Maryland’s Consumer Protection Act. It says potential remedies can include restitution, injunctive relief and fines. Those are statutory enforcement possibilities, not penalties announced in this complaint.
The practical decision for residents and businesses
Residents should treat the complaint as a signal about how location data can move through commercial and government systems, not as proof that every location-data service has violated Maryland law. The most useful unanswered question is whether regulators can connect a named company, a specific data set and a specific transfer to the law’s restrictions.
Businesses that handle Maryland residents’ data have a more immediate compliance decision: determine whether MODPA applies, identify sensitive and location data in their systems and verify the legal basis for government disclosures. The next meaningful signal will be an announcement, investigative action or other filing from the Maryland attorney general that addresses those links directly.
Maryland’s complaint turns a broad privacy debate into a test of data-chain accountability. The key issue is whether companies can connect the collection, sale or disclosure of location and personal data to a legally permitted purpose and process. The filing identifies potential exposure for brokers and technology vendors, but it does not establish liability, a resident count or an enforcement result. For readers, the practical takeaway is limited but clear: location data can carry different legal consequences depending on its sensitivity, recipient and use. For businesses, the next decision is to document those pathways before regulators determine whether the alleged transfers violated MODPA.
Sources and methodology
- Coalition Files Formal Request with Maryland Attorney General to ... - https://wearecasa.org/coalition-files-formal-request-with-maryland-attorney-general-to-investigate-data-brokers-for-violating-state-privacy-laws
- Practical Next Steps for Businesses as Maryland's Updated Consumer ... - https://www.bakerdonelson.com/practical-next-steps-for-businesses-as-marylands-updated-consumer-data-privacy-laws-take-effect-in-october
- Maryland and Nebraska Adopt Comprehensive Privacy Laws - https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20240521-maryland-and-nebraska-adopt-comprehensive-privacy-laws
- MODPA Fines: What We Know So Far - Measured Collective - https://measuredcollective.com/modpa-fines-what-we-know-so-far


