Police Data Pipelines
Maryland complaint names LexisNexis and Insight LPR as sellers of residents' vehicle location data
Ten privacy and civil rights groups have asked Maryland Attorney General Anthony Brown to investigate LexisNexis, Insight LPR, Flock Safety, Motorola, Thomson Reuters, Penlink and ThunderCat Technology for violating the state's privacy law. The 29-page consumer complaint, filed August 19 by We Are CASA and drafted by Georgetown Law's Technology Law Clinic, asks the state to open enforcement actions against all seven.
The hook is the Maryland Data Privacy Act of 2026, in force since July 1. It amended the state's existing privacy law so that "precise geolocation data" now explicitly covers the location of a vehicle, bans the sale of that data outright, and bars knowingly selling any personal data to a government unit that engaged in or supported civil immigration enforcement in the previous six months. It also closed the exception that let companies hand data to police on a mere "inquiry" with no subpoena or warrant behind it.
Two of the named companies are ones we have spent the year documenting.
Insight LPR is accused directly. The complaint cites marketing for its MX Guardian product offering "millions of scans monthly" from a network the company says links more than 1,000 communities. A large share of that data comes from cameras mounted on repossession tow trucks, which is how the company can tell police where a car sleeps at night.
LexisNexis is accused of reselling that same data. The complaint quotes the company's own page offering agencies "LPR Tools" through the Accurint Public Safety Marketplace, and cites a July 2026 ICE contract document for a platform ICE plans to pay nearly $7 million for, which must integrate "license plate recognition capabilities." The complaint treats LexisNexis as a data controller in its own right. That is the question underneath our marketplace reporting: when an agency reaches Insight scans through an Accurint login, the only contract on file names LexisNexis.
The complaint also goes after Accurint itself. ICE's Baltimore field office ran 2,193 Accurint searches and generated 352 reports between February and September 2021, per records Just Futures Law obtained by FOIA. Accurint reports include driver's license numbers, which the complaint says now fall outside Maryland's narrowed motor vehicle records exception: the federal Driver's Privacy Protection Act permits that disclosure but does not require it, and Maryland now exempts only what federal law requires. We documented ICE using Accurint to find a person booked into an Illinois jail.
The vendors' standard defense is that the agency, not the vendor, owns the data. The complaint argues that a company that decides how the data is searched, stored and resold is a controller regardless of who holds title.
The attorney general's office told WJZ it received the complaint and is reviewing it. Only the attorney general can enforce the law; Maryland gave residents no private right of action. Penlink and Thomson Reuters denied the allegations. LexisNexis, Insight LPR, Flock, Motorola and ThunderCat did not respond to NPR or WJZ. Flock's press inbox sent NPR an automated reply saying its media team was "touching grass."
The full complaint is embedded below. See also the agencies feeding Accurint, by state.
Document
Primary Source
documentcloud.org
View document →
Newsletter
Findings and features, in your inbox.
New findings and monthly features from the FinePrint newsroom. Free, no spam, unsubscribe anytime.
Delivered by Substack.
Related Articles
Elk Grove, CA shares over a million local police records with data broker LexisNexis
California's sanctuary law and the LexisNexis contract, explained
LexisNexis told police departments nationwide to call the company before answering our public records requests