HB 264, the Maryland Data Privacy and Protection Act of 2026, sets new rules for how Maryland state government agencies collect, store, and handle personal information. It requires agencies to only collect personal data that is necessary for a legitimate government purpose, delete or remove identifying details when no longer needed, and post clear privacy notices on their websites. The bill specifically defines "sensitive data" (like racial origin, health information, biometric data, and location tracking) and mandates that agencies designate a Privacy Officer to oversee compliance. This law directly affects all Maryland state government units, including departments and agencies, by requiring them to update their data practices to protect residents' privacy.
SB 114 establishes the Maryland 3-1-1 Oversight Board to manage a statewide expansion of nonemergency 3-1-1 services. The bill requires all Maryland counties to implement AI-powered chatbots (by June 2027) and voicebots (by December 2028) that provide multilingual support, route calls accurately, and escalate complex issues to live agents. These systems must align with accessibility and equity standards, using curated government data for responses. The bill directly affects all 23 Maryland counties, residents using 3-1-1 services, and state agencies managing the program, with full statewide implementation required by July 2028.
HB 718 requires public institutions of higher education in Maryland (excluding Morgan State University, the University System of Maryland, St. Mary’s College, and Baltimore City Community College) to adopt email security policies aligned with state government standards. It mandates that all employee email systems automatically filter spam and non-state-business emails (like unsolicited marketing) while permitting minimal personal use that doesn’t impact resources or violate professional norms. The bill extends existing state IT requirements to these institutions, ensuring email systems support official work only and include specific security measures. This directly affects higher education employees and administrators responsible for managing institutional email systems.
SB 482 makes it a crime to intentionally access or interfere with computer systems supporting critical infrastructure (like emergency services, utilities, or public safety answering points) with the intent to disrupt operations. It prohibits unauthorized access, ransomware attacks, or sharing access codes to such systems, specifically targeting acts meant to impair public safety services. The law applies to individuals who disrupt or deny access to systems vital for public security, health, transportation, or utilities. It amends Maryland’s criminal code to clarify penalties for these specific cyber-related interferences.
HB 593 amends Maryland's criminal law to specifically prohibit unauthorized actions intended to disrupt critical infrastructure or public safety answering points. It makes it a crime to intentionally access, copy data from, or possess access codes for systems like power grids, emergency call centers, or transportation networks with the intent to impair their function. The bill defines "critical infrastructure" as systems vital to public security, health, safety, or utilities, and explicitly includes ransomware attacks as a prohibited act. This law directly affects individuals who interfere with these essential systems, imposing criminal penalties for intentional disruption.
HB 895 prohibits large food retailers (defined as those with at least 15,000 square feet selling tax-exempt food) from using dynamic pricing (real-time price changes based on demand or AI) or consumer surveillance data to set prices for individual shoppers. It also bans retailers from using data about protected characteristics (like race or gender) to deny discounts or services to specific customers. The bill further protects union rights by preventing retailers from weakening employee benefits under existing collective bargaining agreements without negotiation. Violations would be treated as unfair trade practices under Maryland’s Consumer Protection Act, subject to enforcement and penalties.
SB 601 requires all Maryland local school systems to designate a cybersecurity point of contact by 2027 and comply with state minimum cybersecurity standards established by the Department of Information Technology. Schools must conduct a cybersecurity maturity assessment every two years and certify compliance annually by June 30, starting in 2027. The bill repeals a previous requirement that county boards prioritize purchasing digital devices with certain funds and instead mandates annual reporting on cybersecurity expenditures. It also directs the Department of Information Technology to annually review and update the state cybersecurity standards. This bill directly affects all public school systems in Maryland, focusing on strengthening cybersecurity practices rather than device procurement.
HB 957 requires all Maryland local school systems to designate a cybersecurity point of contact, comply with state minimum cybersecurity standards set by the Department of Information Technology (DOIT), and conduct a cybersecurity maturity assessment every two years starting in 2027. It repeals a prior requirement that county boards prioritize purchasing digital devices with certain funds, shifting focus toward cybersecurity compliance. Schools must annually certify compliance with DOIT’s standards by June 30 and report cybersecurity spending details by August 15 each year. The bill also mandates DOIT to annually review and update the state cybersecurity standards. This directly affects all local school systems and their technology budgeting and reporting practices.
SB 56 authorizes Maryland's Longitudinal Data System Center to share student and workforce data with third-party data centers for multistate research and reporting, replacing its previous ability to share data with the U.S. Census Bureau. The bill requires third-party centers to meet strict security and privacy standards - including using de-identified data, avoiding individual identification, and signing written agreements - before sharing any data. This directly affects the Center (which must now follow these new rules), third-party data centers (which must comply with the requirements), and the privacy of Maryland students and workers whose data is shared.
SB 200 renames Maryland's "Council on Open Data" to the "Council for Open Data" and restructures its membership from 37 to 11 members. The Council now includes 10 state agency heads, the State Chief Data Officer (as chair), three locally appointed officials representing specific county groups, and five private-sector members appointed by the Governor. Its key duties include setting open data standards for portals, ensuring privacy/security, advising on budget needs, and promoting data-sharing partnerships. This directly affects state agencies, local governments (through appointed county representatives), and private-sector stakeholders participating in governance.