SB 601 requires all Maryland local school systems to designate a cybersecurity point of contact by 2027 and comply with state minimum cybersecurity standards established by the Department of Information Technology. Schools must conduct a cybersecurity maturity assessment every two years and certify compliance annually by June 30, starting in 2027. The bill repeals a previous requirement that county boards prioritize purchasing digital devices with certain funds and instead mandates annual reporting on cybersecurity expenditures. It also directs the Department of Information Technology to annually review and update the state cybersecurity standards. This bill directly affects all public school systems in Maryland, focusing on strengthening cybersecurity practices rather than device procurement.
SB 56 authorizes Maryland's Longitudinal Data System Center to share student and workforce data with third-party data centers for multistate research and reporting, replacing its previous ability to share data with the U.S. Census Bureau. The bill requires third-party centers to meet strict security and privacy standards - including using de-identified data, avoiding individual identification, and signing written agreements - before sharing any data. This directly affects the Center (which must now follow these new rules), third-party data centers (which must comply with the requirements), and the privacy of Maryland students and workers whose data is shared.
SB 200 renames Maryland's "Council on Open Data" to the "Council for Open Data" and restructures its membership from 37 to 11 members. The Council now includes 10 state agency heads, the State Chief Data Officer (as chair), three locally appointed officials representing specific county groups, and five private-sector members appointed by the Governor. Its key duties include setting open data standards for portals, ensuring privacy/security, advising on budget needs, and promoting data-sharing partnerships. This directly affects state agencies, local governments (through appointed county representatives), and private-sector stakeholders participating in governance.
SB 216 updates Maryland's unemployment insurance confidentiality rules to align with federal requirements. It clarifies that claim details (including benefit amounts, address, and work refusal history), wage information, and other personal data are protected as "confidential unemployment insurance information." The bill allows limited disclosure to child support enforcement agencies when permitted under federal law, while adding penalties for unauthorized leaks by current or former Maryland Department of Labor employees. These changes directly affect unemployment claimants, employers, and child support agencies by defining how personal financial data may be shared.
SB 867 expands the Maryland Aerospace and Technology Commission's mission to specifically promote innovation in space science, space technology, and aeronautics. It restructures the Commission's membership by adding representatives from the commercial space industry (up to three) and higher education institutions, while requiring the Commission to appoint an Executive Director. The bill authorizes the Commission to provide grants to eligible entities - including aerospace businesses, nonprofits, government agencies, and universities conducting aerospace research in Maryland. These changes aim to strengthen Maryland's aerospace sector by formalizing grant programs and broadening stakeholder representation on the Commission.
SB 504 prohibits businesses from selling consumer personal data to buyers who intend to use it for immigration enforcement. It defines "sensitive data" to include immigration status, racial origin, health information, and sexual orientation, requiring businesses to handle such data more carefully. The bill also mandates public record custodians to prevent unauthorized disclosure - especially for immigration enforcement - and requires message switching systems to implement access controls. These changes aim to strengthen privacy protections for Maryland residents while modifying existing data privacy laws in the state code.
SB 247 converts Maryland's Biotechnology Investment Incentive Tax Credit into a direct grant program administered by the Department of Commerce. It replaces tax credits with cash grants for qualifying biotechnology companies engaged in research, development, or commercialization of biological technologies. The bill requires the Department to disburse grants within a specified timeframe and allows recipients to deduct these grants from their Maryland income tax for the same year. This change shifts the incentive from tax savings to immediate funding, directly affecting eligible biotech firms in Maryland.
SB 564 creates a new Division of Data Protection within Maryland’s Office of the Attorney General. This division will investigate and enforce civil actions for violations of existing data privacy laws affecting businesses and consumers. It also establishes a Maryland Data Privacy Implementation and Innovation Workgroup, composed of state officials, consumer advocates, business representatives, and industry experts, to study implementation challenges and recommend improvements. The Workgroup must report its findings to the governor and legislature by January 1, 2027, and the bill’s provisions take effect on July 1, 2026, with the Workgroup structure expiring June 30, 2027.
SB 629 requires all Maryland state government units and public higher education institutions (excluding Morgan State University, the University System of Maryland, St. Mary’s College, and Baltimore City Community College) to implement email security policies. It mandates automatic filtering of spam emails (defined as unsolicited, non-state-business emails like phishing or bulk solicitations unrelated to official duties) and prohibits using state email systems as public forums. The bill also permits minimal personal email use that has no significant impact on resources and aligns with professional business standards. These requirements must be included in institutional IT policies, plans, and standards, effective October 1, 2026.
SB 632 creates a new Office of State Elected Officials Information Privacy within Maryland’s Department of Legislative Services. It allows state elected officials (the "protected individuals") to request that their personal details - such as addresses, phone numbers, and email - be removed from public online sources like government websites, social media, or social networks. The bill also establishes criminal penalties for intentionally posting an official’s personal information online under certain circumstances. This replaces the existing Address Confidentiality Program for domestic violence survivors with a dedicated system specifically for protecting state elected officials’ privacy.