HB 487 amends Maryland law to give the Maryland Technology Development Corporation (MTDC) more flexibility regarding investments in businesses that no longer qualify under program rules. Specifically, it changes the requirement that MTDC must divest such investments to an authorization allowing it to choose whether to divest or pursue other remedies (like repayment) when a business no longer meets "qualified business" criteria. The bill also updates procedures for the MTDC's investment committee to consider these remedies. This directly affects MTDC and businesses that previously received MTDC equity investments but no longer qualify under the program.
HB 264, the Maryland Data Privacy and Protection Act of 2026, sets new rules for how Maryland state government agencies collect, store, and handle personal information. It requires agencies to only collect personal data that is necessary for a legitimate government purpose, delete or remove identifying details when no longer needed, and post clear privacy notices on their websites. The bill specifically defines "sensitive data" (like racial origin, health information, biometric data, and location tracking) and mandates that agencies designate a Privacy Officer to oversee compliance. This law directly affects all Maryland state government units, including departments and agencies, by requiring them to update their data practices to protect residents' privacy.
SB 482 makes it a crime to intentionally access or interfere with computer systems supporting critical infrastructure (like emergency services, utilities, or public safety answering points) with the intent to disrupt operations. It prohibits unauthorized access, ransomware attacks, or sharing access codes to such systems, specifically targeting acts meant to impair public safety services. The law applies to individuals who disrupt or deny access to systems vital for public security, health, transportation, or utilities. It amends Maryland’s criminal code to clarify penalties for these specific cyber-related interferences.
HB 593 amends Maryland's criminal law to specifically prohibit unauthorized actions intended to disrupt critical infrastructure or public safety answering points. It makes it a crime to intentionally access, copy data from, or possess access codes for systems like power grids, emergency call centers, or transportation networks with the intent to impair their function. The bill defines "critical infrastructure" as systems vital to public security, health, safety, or utilities, and explicitly includes ransomware attacks as a prohibited act. This law directly affects individuals who interfere with these essential systems, imposing criminal penalties for intentional disruption.
SB 601 requires all Maryland local school systems to designate a cybersecurity point of contact by 2027 and comply with state minimum cybersecurity standards established by the Department of Information Technology. Schools must conduct a cybersecurity maturity assessment every two years and certify compliance annually by June 30, starting in 2027. The bill repeals a previous requirement that county boards prioritize purchasing digital devices with certain funds and instead mandates annual reporting on cybersecurity expenditures. It also directs the Department of Information Technology to annually review and update the state cybersecurity standards. This bill directly affects all public school systems in Maryland, focusing on strengthening cybersecurity practices rather than device procurement.
HB 957 requires all Maryland local school systems to designate a cybersecurity point of contact, comply with state minimum cybersecurity standards set by the Department of Information Technology (DOIT), and conduct a cybersecurity maturity assessment every two years starting in 2027. It repeals a prior requirement that county boards prioritize purchasing digital devices with certain funds, shifting focus toward cybersecurity compliance. Schools must annually certify compliance with DOIT’s standards by June 30 and report cybersecurity spending details by August 15 each year. The bill also mandates DOIT to annually review and update the state cybersecurity standards. This directly affects all local school systems and their technology budgeting and reporting practices.
SB 216 updates Maryland's unemployment insurance confidentiality rules to align with federal requirements. It clarifies that claim details (including benefit amounts, address, and work refusal history), wage information, and other personal data are protected as "confidential unemployment insurance information." The bill allows limited disclosure to child support enforcement agencies when permitted under federal law, while adding penalties for unauthorized leaks by current or former Maryland Department of Labor employees. These changes directly affect unemployment claimants, employers, and child support agencies by defining how personal financial data may be shared.
HB 145 requires Maryland's State Administrator of Elections to act on credible reports of election misinformation (false information about voting) or disinformation (knowingly misleading information) by providing corrective information, requesting removal from online platforms, and seeking records via subpoena. It prohibits knowingly using AI-generated deepfakes (manipulated videos/audio) to mislead voters about voting rights, election results, or registration, with violations punishable as misdemeanors carrying up to $5,000 fines or 5 years in jail. The law exempts satire, news coverage (like interviews or documentaries), and media outlets that clearly label deceptive content. It directly affects voters seeking accurate election information, election officials managing reports, and content creators distributing election-related material. The bill takes effect June 1, 2026.
HB 172 allows Maryland municipalities to authorize code, parking, and traffic enforcement officers to use body-worn cameras during their duties. It expands the legal definition of "law enforcement officer" to include these municipal officers for camera use, requiring cities to adopt policies that align with state standards for body-worn camera use. The bill mandates that municipalities publishing such policies must follow guidelines similar to those for police body cameras, including notifying individuals when recording is occurring. The law takes effect October 1, 2026, and does not require municipalities to implement the policy.
HB 952 requires operators of "companion chatbots" (AI systems designed to meet social needs through human-like interactions) to establish safety protocols, including preventing harmful content like self-harm discussions and sexually explicit material for minors. Operators must publish these protocols online, display clear warnings that chatbots are AI (not human), and provide crisis resource referrals for users expressing suicidal thoughts. The bill also mandates that operators of chatbots used by minors display mandatory break reminders after 3 hours of continuous use. It excludes business customer service bots, video game features, and basic voice assistants from these requirements.