{"data":{"id":"us-md/md.-code-local-government-31-107","jurisdiction":"us-md","citation":"Md. Code, Local Government § 31–107","heading":"","body":"(a) (1) The manager shall promptly review any query requested by a\nprovider.\n(2) The manager may run queries for individuals or entities that are\nnot providers.\n(b) Before approving a query, the manager, with assistance from technical\nexperts identified by the executive committee, shall conduct an in–depth review of\nthe proposed query for consistency with authorized purposes, alignment with\nevidence–based standards for equitable, ethical, and methodologically appropriate\ninquiries, and assessment of the benefits for and impact on the greater Baltimore\nCity community.\n(c) Before providing any data in response to a query, the manager shall\nobtain written approval from any provider of data to confirm that there is no\nreasonable basis to believe that de–identified data provided in response to a query\ncould be used by a data recipient to successfully link de–identified data to a particular\nindividual, based on the size or uniqueness of the population under consideration in\nthe query, or otherwise.\n(d) The manager shall ensure that the data management system and\nprovided data are secure using security standards and protocols that address, at a\nminimum, data security and access, security incident and disaster recovery\nprocedures, and recording and monitoring of system activity.\n(e) The manager shall maintain appropriate administrative, physical, and\ntechnical safeguards that protect privacy, confidentiality, integrity, and availability\nof any data in compliance with the federal Family Educational Rights and Privacy\nAct and other relevant privacy laws and policies, including:\n(1) the required use of de–identified data in data research and\nreporting;\n(2) the required disposition of data that is no longer needed;\n(3) providing data security, including the capacity for audit trails;\n(4) providing for the performance of regular audits for compliance\nwith data privacy and security standards; and\n(5) implementing guidelines and policies that prevent the reporting\nof other potentially personally identifiable information.\n(f) The manager shall ensure that a query of the data management system:\n(1) results in disclosure of only aggregated de–identified data or\naggregated de–identified data reports to a data recipient; and\n(2) does not reveal personally identifiable information to a data\nrecipient.\n(g) On request, the manager may provide technical assistance to data\nrecipients regarding data received from the Baltimore City Youth Data Hub.\n(h) (1) The manager and any data recipients may not:\n(i) attempt to re–identify de–identified data; or\n(ii) disclose, release, or report data in any form that may result\nin the re–identification of de–identified data.\n(2) This subsection may not be construed to interfere with a data\nrecipient’s continued use of or reliance on personally identifiable information\nprovided to the Baltimore City Youth Data Hub.","path":["Article - Local Government"],"source_url":"https://mgaleg.maryland.gov/mgawebsite/Laws/StatuteText?article=glg\u0026section=31-107","current_through":"2026-01-01","vintage":"","retrieved_at":"2026-09-14T19:59:58Z","sha256":"420da6241ea784127aa12632db027d1dd5b9664ec4579177c6afb7ef50ca376f","source_id":"us-md","stale":false,"prev":"us-md/md.-code-local-government-31-106","next":"us-md/md.-code-local-government-31-108"},"notice":"GroundRules: Original legal text. Not legal advice."}
