Effective July 1, 2026, Maryland has amended the Maryland Online Data Privacy Act to prohibit controllers from knowingly selling the personal data of a consumer to a governmental entity that, within the preceding six months, engaged in or supported civil immigration enforcement. The amendment introduces a targeted but operationally significant restriction that businesses handling Maryland consumer data must address without delay, particularly where data-sale arrangements involve public-sector purchasers or intermediaries that may transact with government buyers.

The core obligation is straightforward in principle but demanding in practice. Controllers must now evaluate whether a prospective governmental purchaser has engaged in or supported civil immigration enforcement activity during a rolling six-month lookback window. If it has, the sale of personal data to that entity is prohibited. This structure effectively imposes a due diligence requirement on controllers, who will need to develop reliable procedures for identifying governmental purchasers, assessing their recent enforcement-related conduct, and refreshing that assessment as the six-month window moves forward. Contractual representations, screening protocols, and internal escalation pathways will likely be central to demonstrating good-faith compliance with the knowingly standard embedded in the statute.

The Maryland amendment does not stand alone. It arrived as part of a broader July 1, 2026 wave of state privacy updates that also brought Arkansas online as a comprehensive privacy jurisdiction and expanded controller obligations in Connecticut, Utah, and Virginia. Taken together, these developments reinforce the continued fragmentation of the U.S. state privacy landscape and underscore the need for national businesses to maintain a coordinated, jurisdiction-aware compliance program rather than relying on a single baseline standard.

Practical next steps for controllers include mapping data flows that could result in a sale to a governmental entity, updating data-sale contracts and onboarding questionnaires to capture the required diligence, and calibrating internal policies to reflect the rolling lookback. Organizations should also confirm that their broader privacy programs remain aligned with the concurrent changes in Arkansas, Connecticut, Utah, and Virginia, since overlapping obligations can create unexpected compliance gaps when addressed in isolation.

This article is provided for general informational purposes only and does not constitute legal advice. Clients should seek tailored guidance regarding their specific circumstances and jurisdictions.