Maine Privacy Law
Maine has no comprehensive consumer privacy statute, and the bill that came closest did not survive the 2026 session: LD 1822, the Maine Online Data Privacy Act, died between the houses on April 13, 2026 after the chambers adopted different amendments. What Maine does have is a broadband privacy law with no real equivalent anywhere else — 35-A M.R.S. § 9301 requires express, affirmative consent before an internet service provider may use, disclose, sell or permit access to any customer personal information, with no sensitive-and-non-sensitive split and no ability to charge for the choice. That statute survived a federal preemption and vagueness challenge in 2020.
Sector-Specific Privacy Laws in Maine
Privacy of broadband Internet access service customer personal information (35-A M.R.S. § 9301)
Enacted as PL 2019, c. 216 and in force since July 1, 2020, chapter 94 of Title 35-A applies a single opt-in rule rather than the tiered structure used by the federal framework it replaced. Section 9301(2) bars a provider from using, disclosing, selling or permitting access to customer personal information except as subsections 3 and 4 allow. Subsection 3(A) permits it only where the customer gives express, affirmative consent, revocable at any time; subsection 3(B) then closes the usual workaround by barring a provider from refusing to serve a customer who withholds consent, and from charging a penalty or offering a discount based on the customer’s decision to give or withhold it. Subsection 3(C) inverts the default for everything else: information that is not customer personal information may be used or sold unless the customer gives written notice objecting. What counts as customer personal information under subsection 1(C) is broad — not only name, billing information, Social Security number and demographic data, but web browsing history, application usage history, precise geolocation, financial information, health information, information pertaining to the customer’s children, device identifiers such as a MAC address or IMEI, the content of communications, and the origin and destination IP addresses. Subsection 4 lists six exceptions covering service provision, marketing the provider’s own communications-related services, lawful court orders, billing and collection, protection against fraudulent or unlawful use, and geolocation for emergency response. Subsection 5 adds a duty to take reasonable measures to protect customer personal information from unauthorized use, disclosure or access. “Customer” under subsection 1(B) includes applicants and former subscribers, not only current ones.
Maine Unfair Trade Practices Act (5 M.R.S. §§ 205-A to 214)
Section 207 declares unfair methods of competition and unfair or deceptive acts or practices in trade or commerce unlawful, and subsection 1 directs courts construing it to be guided by the interpretations the Federal Trade Commission and the federal courts give to section 45(a)(1) of the FTC Act. Subsection 2 lets the Attorney General make rules interpreting the section, provided they are not inconsistent with FTC and federal-court interpretations, and makes evidence of a violation of such a rule prima facie evidence of an unlawful act. Section 209 supplies the public remedy and constrains it: at least 10 days before commencing an action the Attorney General notifies the person of the intended action and gives an opportunity to confer, unless an affidavit shows immediate irreparable harm to consumers; violations of an injunction carry a civil penalty of not more than $10,000 each; and for intentional violations of section 207 the Attorney General may seek a civil penalty of not more than $10,000, bearing the burden of proving that the conduct was intentional and was unfair or deceptive, “notwithstanding any other statute which declares a violation of that statute an unfair trade practice”. Section 213 supplies the private remedy, available to a person who purchases or leases goods, services or property primarily for personal, family or household purposes and thereby suffers a loss of money or property. It provides actual damages, restitution and equitable relief rather than statutory or multiplied damages, requires a written demand for relief at least 30 days before filing, and directs an award of reasonable attorney’s fees and costs to a petitioner who establishes a violation, irrespective of the amount in controversy.
Data Breach Notification in Maine
The Notice of Risk to Personal Data Act sits at 10 M.R.S. §§ 1346 through 1350-B and applies two different triggers depending on who holds the data. Under § 1348(1)(A) an information broker — defined in § 1347(3) as a person who for monetary fees or dues engages in collecting, assembling, evaluating, compiling, reporting, transmitting, transferring or communicating information about individuals for the primary purpose of furnishing it to nonaffiliated third parties — investigates the likelihood that personal information has been or will be misused and gives notice where the information was or is reasonably believed to have been acquired by an unauthorized person. Under § 1348(1)(B) any other person gives notice where misuse has occurred or it is reasonably possible that misuse will occur. Both notices are due as expediently as possible and without unreasonable delay, and where there is no law enforcement delay, no more than 30 days after the person becomes aware of the breach and identifies its scope. Section 1348(3) caps any law enforcement delay at seven business days after the agency determines that notification will not compromise a criminal investigation. Section 1348(5) routes regulator notice to the appropriate state regulators within the Department of Professional and Financial Regulation, and to the Attorney General only where the person is not regulated by that department. Section 1348(4) adds notice to the nationwide consumer reporting agencies where more than 1,000 persons are notified at a single time. Substitute notice under § 1347(4)(C) is available where the cost of notice would exceed $5,000 or the affected class exceeds 1,000. The Act’s definition of “person” in § 1347(5) expressly includes state agencies, municipalities, school administrative units, the University of Maine System, the Maine Community College System, Maine Maritime Academy and private colleges and universities.
Residents must be notified as expediently as possible and without unreasonable delay, and no more than 30 days after becoming aware of the breach and identifying its scope where there is no law enforcement delay. Notice goes to the appropriate state regulators within the Department of Professional and Financial Regulation, or to the Attorney General only where the person is not regulated by that department. Complaints are taken by the Maine Attorney General, which enforces the statute.
How Maine Enforces Its Privacy Laws
Breach enforcement is split between two offices. Section 1349(1) divides the chapter’s enforcement rather than assigning it to one regulator: the appropriate state regulators within the Department of Professional and Financial Regulation enforce it for any person they license or regulate, and the Attorney General enforces it for everyone else. Section 1349(4) then supplies a compliance safe harbour: a person that complies with breach notification requirements established under federal law or the law of this State is deemed to comply with section 1348, provided those requirements are at least as protective as section 1348’s.
The Attorney General carries the burden on intent. Section 209 places an unusual constraint on the Attorney General’s civil penalty power under the Unfair Trade Practices Act. Penalties for violations of section 207 are available only where the violations are intentional and are unfair or deceptive, and the section states expressly that the Attorney General “has the burden of proving that the conduct was intentional and was unfair or deceptive notwithstanding any other statute which declares a violation of that statute an unfair trade practice”. Section 209 also requires at least 10 days’ notice of an intended action and an opportunity to confer, unless an affidavit shows immediate irreparable harm to consumers, and permits a court that denies a permanent injunction to order the State to pay the prevailing party’s costs on a finding that the action was frivolous.
Recent Enforcement in Maine
Experian and T-Mobile — multistate settlements over the 2012 and 2015 breaches, November 2022. The Attorney General’s office announced on November 7, 2022 that Maine had joined a coalition obtaining two multistate settlements with Experian over data breaches in 2012 and 2015, together with a separate settlement with T-Mobile in connection with the 2015 breach, for a combined total of more than $16 million, of which Maine receives $143,322.65. The office states that the 2015 breach involved consumers who had applied for T-Mobile postpaid services and device financing between September 2013 and September 2015, exposing names, addresses, dates of birth, Social Security numbers, and identification numbers such as driver’s licence and passport numbers, and that 12,068 Maine residents were affected. Under the $12.67 million Experian settlement the company agreed to strengthen its due diligence and data security practices and to offer five years of free credit monitoring plus two free annual credit reports to affected consumers; under the separate $2.43 million settlement T-Mobile agreed to detailed vendor management provisions. A further $1 million resolved a separate investigation into Experian Data Corp. over a 2012 breach in which an identity thief posing as a private investigator obtained access to sensitive personal information in commercial databases, with that company agreeing to maintain a Red Flags program.
TJX Companies — Assurance of Discontinuance over the 2007 breach, June 2009. The Attorney General’s office announced on June 23, 2009 that Attorney General Janet T. Mills and 40 other state attorneys general had reached an Assurance of Discontinuance with The TJX Companies, Inc., resolving an investigation into whether the company had implemented sufficient safeguards to protect customers’ financial information against the breach it disclosed in 2007. The office states the investigation uncovered vulnerabilities and flaws in the company’s data security systems that may have allowed both the unlawful intrusion and its ability to continue undetected. The company agreed to pay $9.75 million to the states — $5.5 million dedicated to state data protection and consumer protection efforts, $1.75 million to reimburse investigation costs and fees, and $2.5 million to fund a Data Security Trust Fund for enforcement and policy development — with Maine’s share reported as $38,675.00, and to implement and maintain a comprehensive Information Security Program with regular reporting to the attorneys general and third-party assessment.
Pending Privacy Legislation
Maine’s comprehensive privacy effort ended rather than advanced in the 132nd Legislature. LD 1822, HP 1220, “An Act to Enact the Maine Online Data Privacy Act”, sponsored by Representative Kuhn of Falmouth, was referred to the Judiciary Committee on April 29, 2025, tabled at work sessions on May 14 and May 23, voted out as a divided report on May 30 and reported out on June 13, 2025 as OTP-AM/OTP-AM/ONTP. Report A, carrying eight signatures including both chairs, and Report B, carrying four, proposed different amended versions. Committee Amendment C-A (H-716) and House Amendment H-B to C-A (H-906) were adopted by House and Senate, while Senate Amendment S-A to C-A (S-528), sponsored by Senator Carney of Cumberland, was adopted by the Senate alone. The chambers did not reconcile, and the record of final disposition is “Died Between Houses, Apr 13, 2026”. The affected-sections table shows the bill would have added new sections 9609 through 9612 and others to the statutes.
Federal Privacy Laws That Apply in Maine
Federal privacy law applies in Maine by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Maine Unfair Trade Practices Act (5 M.R.S. §§ 205-A to 214), which the Maine Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Maine Businesses
With no comprehensive state statute, most privacy obligations on a Maine business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Maine businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Maine itself has none, and any business holding personal information about Maine residents is subject to the state’s breach-notification statute described above.
Maine Privacy Law FAQ
Does Maine have a comprehensive consumer privacy law?
What does Maine’s broadband privacy law require of internet providers?
Has Maine’s broadband privacy law been challenged in court?
Which Maine office receives a data breach notice?
What is the deadline for a Maine breach notice?
What can a Maine breach-notice failure cost?
Can a Maine consumer sue for an unfair trade practice?
Does Maine treat information brokers differently from other businesses after a breach?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- 35-A M.R.S. § 9301 — Privacy of broadband Internet access service customer personal information statute
- 10 M.R.S. § 1347 — Notice of Risk to Personal Data Act; definitions statute
- 10 M.R.S. § 1348 — Security breach notice requirements statute
- 10 M.R.S. § 1349 — Enforcement; penalties statute
- 5 M.R.S. § 207 — Unfair Trade Practices Act; unlawful acts and conduct statute
- 5 M.R.S. § 209 — Unfair Trade Practices Act; injunction and civil penalties statute
- 5 M.R.S. § 213 — Unfair Trade Practices Act; private remedies statute
- LD 1822 (132nd Legislature) — Maine Online Data Privacy Act, text and disposition legislation
- ACA Connects v. Frey, No. 1:20-cv-00055-LEW (D. Me. July 7, 2020) case
- Maine Attorney General — Experian and T-Mobile multistate breach settlements agency
- Maine Attorney General — TJX Companies multistate data breach settlement agency
- Maine Attorney General — Data Security Breaches agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.