A new, powerful Citizen Portal experience is ready. Switch now

Committee presses Maryland data office on safeguards for multi-state research agreement

February 27, 2026 | Education, Energy, and the Environment Committee, SENATE, SENATE, Committees, Legislative, Maryland


This article was created by AI summarizing key points discussed. AI makes mistakes, so for full details and context, please refer to the video of the full meeting. Please report any errors so we can fix them. Report an error »

Committee presses Maryland data office on safeguards for multi-state research agreement
The Education, Energy, and the Environment Committee held an extended briefing with Ross Goldstein, executive director of the Maryland Longitudinal Data System Center, about a planned multi-state research project that would link Maryland data with partners and a third-party research center.

Senator Hester, among others, asked pointedly about scope: "where does this end? Like how many third-party data brokers get access to our kids data?" (Senator Hester). Goldstein said "the intention is only to do this to do this project with the Colidge Initiative," and described governance and technical controls intended to limit broad reuse.

Goldstein said the center has a governing board made up of data-providing agency principals and a separate research and policy advisory board that reviews project proposals and proposed data elements. He described a cybersecurity subcommittee and an internal review pathway: external researchers submit proposals, the center reviews and revises projects, the advisory board evaluates impacts and data appropriateness, and contested or novel projects go to the governing board for final approval. He said the center will "retain control over the data" for approved projects and that third parties would be restricted to approved users; project closeout would require contractual destruction and FedRAMP-style auditing.

Committee members asked whether the legislation prohibits secondary sharing, how the state would respond to a breach, and whether notification should occur before or after an agreement is signed. Goldstein confirmed the third party would not be permitted to re-disclose data beyond approved users, that breaches and liability would be addressed by contractual requirements (including insurance), and that data minimization and hashing of personally identifiable information are standard controls. On notification timing, Goldstein and members discussed language requiring the center to notify the committee within 30 days after entering an agreement and whether pre-notification would be preferable.

Nut graf: Senators expressed a mix of procedural and substantive concern — from operational questions about who signs and audits contracts to policy concerns about future administrations and the possibility of multiple agreements — and asked the center to clarify its selection criteria, the exact data elements proposed (e.g., juvenile services or child-welfare indicators), ownership and post-project destruction, and the committee notification mechanism.

Ending: The committee did not vote; members agreed to continue the conversation and to work on tighter notice and review language before advancing any statutory authorization.

Don't Miss a Word: See the Full Meeting!

Go beyond summaries. Unlock every video, transcript, and key insight with a Founder Membership.

Get instant access to full meeting videos
Search and clip any phrase from complete transcripts
Receive AI-powered summaries & custom alerts
Enjoy lifetime, unrestricted access to government data
Access Full Meeting

30-day money-back guarantee