Maryland's HB 711 took effect July 1, 2026, and it does something no other state privacy law has done this directly: it bars businesses from knowingly selling personal data to a government unit that has supported civil immigration enforcement in the prior six months. The bill passed the House of Delegates 94-35 and the Senate 28-8, then became law without the governor's signature on May 31, 2026, under Article II, Section 17(c) of the Maryland Constitution. It is now Chapter 874 of the 2026 Regular Session.
That is a narrower target than a typical state privacy amendment, and that narrowness is exactly why it is drawing attention outside the usual privacy trade press. Most state privacy laws restrict data sales by purchaser type or consumer opt-out status. HB 711 restricts a sale by naming a specific government activity, civil immigration enforcement, as an off-limits buyer purpose, which puts the bill inside the broader national immigration policy conversation as much as the privacy law conversation.

Source: Maryland General Assembly, HB 711 bill page, captured August 3, 2026.
What the law actually prohibits
The core rule, as described in Fisher Phillips' analysis of the bill, blocks a controller from knowingly selling the personal data of a consumer to a federal, state, or local governmental unit that, within the six months immediately preceding the sale, has engaged in or supported civil immigration enforcement through personnel or material resources. The Maryland General Assembly's own bill page states the prohibition in nearly identical terms in its synopsis, describing it as barring a sale to a governmental unit that "has engaged in or supported civil immigration enforcement under certain circumstances."
The six-month lookback is the mechanic that makes this more than a one-time check. A data seller cannot simply confirm a buyer's status once and move on. Whether a prospective government buyer counts as a barred recipient can change from one sale to the next, depending on what that government unit has done in the preceding six months. There is one carve-out: a sale made to satisfy a valid, specific court warrant is exempted from the prohibition.
Who counts as a controller, and how it is enforced
Figure: HB 711's vote margins in the Maryland General Assembly, House and Senate third readings.
"Controller" carries its standard meaning under Maryland's existing online data privacy framework: any business that determines the purposes and means of processing consumers' personal data and is subject to the law's applicability thresholds. That reach extends past data brokers narrowly defined. Any controller that sells personal data, directly or through an intermediary, needs to know who is on the buying end and what that buyer has been doing for the last six months before the sale closes.
Enforcement sits with Maryland's Division of Consumer Protection under the Attorney General's office. Per Fisher Phillips' analysis, a violation is treated as an unfair, abusive, or deceptive trade practice under Maryland's Consumer Protection Act, and a business gets a 60-day cure period to fix the violation before an enforcement action can proceed. That cure window gives a controller a real chance to correct a bad sale once flagged, but it does not remove the underlying obligation to screen buyers before a sale happens in the first place.
One companion provision worth knowing about, even though it sits outside the data-sale rule itself: HB 711 also requires custodians of certain public records to monitor access to those records for immigration-law-enforcement purposes, a separate and broader obligation than the consumer-data-sale ban covered here.
What this means for your privacy policy
Most privacy policies handle government disclosure with a single generic line: something like "we may share your information with government authorities as required by law." HB 711 shows why that line is no longer sufficient for a business that sells or shares personal data with government entities, or with data brokers who might resell that data to a government entity. A generic authorities clause does not disclose whether a data sale is screened against a purpose-based restriction like Maryland's, and it gives a consumer no way to understand that a sale to a specific kind of government buyer is legally off-limits regardless of what the buyer requests.
A privacy policy's data-sharing section needs to reflect the actual conditions under which a sale can happen, not just the categories of parties who might receive data. If your business sells personal data at all, or works with a data broker who might, your policy should describe how buyer screening works and what restrictions apply, rather than leaving readers with a blanket statement that glosses over laws like this one. Our Privacy Policy Generator builds data-sharing and government-disclosure language that can reflect purpose-based restrictions like Maryland's, instead of a one-size-fits-all authorities clause that will not hold up under a law written this specifically.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.