Maine

Maine Privacy Law

Maine has no comprehensive consumer privacy statute, and the bill that came closest did not survive the 2026 session: LD 1822, the Maine Online Data Privacy Act, died between the houses on April 13, 2026 after the chambers adopted different amendments. What Maine does have is a broadband privacy law with no real equivalent anywhere else — 35-A M.R.S. § 9301 requires express, affirmative consent before an internet service provider may use, disclose, sell or permit access to any customer personal information, with no sensitive-and-non-sensitive split and no ability to charge for the choice. That statute survived a federal preemption and vagueness challenge in 2020.

Sector-Specific Privacy Laws in Maine

Privacy of broadband Internet access service customer personal information (35-A M.R.S. § 9301)

Enacted as PL 2019, c. 216 and in force since July 1, 2020, chapter 94 of Title 35-A applies a single opt-in rule rather than the tiered structure used by the federal framework it replaced. Section 9301(2) bars a provider from using, disclosing, selling or permitting access to customer personal information except as subsections 3 and 4 allow. Subsection 3(A) permits it only where the customer gives express, affirmative consent, revocable at any time; subsection 3(B) then closes the usual workaround by barring a provider from refusing to serve a customer who withholds consent, and from charging a penalty or offering a discount based on the customer’s decision to give or withhold it. Subsection 3(C) inverts the default for everything else: information that is not customer personal information may be used or sold unless the customer gives written notice objecting. What counts as customer personal information under subsection 1(C) is broad — not only name, billing information, Social Security number and demographic data, but web browsing history, application usage history, precise geolocation, financial information, health information, information pertaining to the customer’s children, device identifiers such as a MAC address or IMEI, the content of communications, and the origin and destination IP addresses. Subsection 4 lists six exceptions covering service provision, marketing the provider’s own communications-related services, lawful court orders, billing and collection, protection against fraudulent or unlawful use, and geolocation for emergency response. Subsection 5 adds a duty to take reasonable measures to protect customer personal information from unauthorized use, disclosure or access. “Customer” under subsection 1(B) includes applicants and former subscribers, not only current ones.

Maine Unfair Trade Practices Act (5 M.R.S. §§ 205-A to 214)

Section 207 declares unfair methods of competition and unfair or deceptive acts or practices in trade or commerce unlawful, and subsection 1 directs courts construing it to be guided by the interpretations the Federal Trade Commission and the federal courts give to section 45(a)(1) of the FTC Act. Subsection 2 lets the Attorney General make rules interpreting the section, provided they are not inconsistent with FTC and federal-court interpretations, and makes evidence of a violation of such a rule prima facie evidence of an unlawful act. Section 209 supplies the public remedy and constrains it: at least 10 days before commencing an action the Attorney General notifies the person of the intended action and gives an opportunity to confer, unless an affidavit shows immediate irreparable harm to consumers; violations of an injunction carry a civil penalty of not more than $10,000 each; and for intentional violations of section 207 the Attorney General may seek a civil penalty of not more than $10,000, bearing the burden of proving that the conduct was intentional and was unfair or deceptive, “notwithstanding any other statute which declares a violation of that statute an unfair trade practice”. Section 213 supplies the private remedy, available to a person who purchases or leases goods, services or property primarily for personal, family or household purposes and thereby suffers a loss of money or property. It provides actual damages, restitution and equitable relief rather than statutory or multiplied damages, requires a written demand for relief at least 30 days before filing, and directs an award of reasonable attorney’s fees and costs to a petitioner who establishes a violation, irrespective of the amount in controversy.

Data Breach Notification in Maine

The Notice of Risk to Personal Data Act sits at 10 M.R.S. §§ 1346 through 1350-B and applies two different triggers depending on who holds the data. Under § 1348(1)(A) an information broker — defined in § 1347(3) as a person who for monetary fees or dues engages in collecting, assembling, evaluating, compiling, reporting, transmitting, transferring or communicating information about individuals for the primary purpose of furnishing it to nonaffiliated third parties — investigates the likelihood that personal information has been or will be misused and gives notice where the information was or is reasonably believed to have been acquired by an unauthorized person. Under § 1348(1)(B) any other person gives notice where misuse has occurred or it is reasonably possible that misuse will occur. Both notices are due as expediently as possible and without unreasonable delay, and where there is no law enforcement delay, no more than 30 days after the person becomes aware of the breach and identifies its scope. Section 1348(3) caps any law enforcement delay at seven business days after the agency determines that notification will not compromise a criminal investigation. Section 1348(5) routes regulator notice to the appropriate state regulators within the Department of Professional and Financial Regulation, and to the Attorney General only where the person is not regulated by that department. Section 1348(4) adds notice to the nationwide consumer reporting agencies where more than 1,000 persons are notified at a single time. Substitute notice under § 1347(4)(C) is available where the cost of notice would exceed $5,000 or the affected class exceeds 1,000. The Act’s definition of “person” in § 1347(5) expressly includes state agencies, municipalities, school administrative units, the University of Maine System, the Maine Community College System, Maine Maritime Academy and private colleges and universities.

Residents must be notified as expediently as possible and without unreasonable delay, and no more than 30 days after becoming aware of the breach and identifying its scope where there is no law enforcement delay. Notice goes to the appropriate state regulators within the Department of Professional and Financial Regulation, or to the Attorney General only where the person is not regulated by that department. Complaints are taken by the Maine Attorney General, which enforces the statute.

How Maine Enforces Its Privacy Laws

Breach enforcement is split between two offices. Section 1349(1) divides the chapter’s enforcement rather than assigning it to one regulator: the appropriate state regulators within the Department of Professional and Financial Regulation enforce it for any person they license or regulate, and the Attorney General enforces it for everyone else. Section 1349(4) then supplies a compliance safe harbour: a person that complies with breach notification requirements established under federal law or the law of this State is deemed to comply with section 1348, provided those requirements are at least as protective as section 1348’s.

The Attorney General carries the burden on intent. Section 209 places an unusual constraint on the Attorney General’s civil penalty power under the Unfair Trade Practices Act. Penalties for violations of section 207 are available only where the violations are intentional and are unfair or deceptive, and the section states expressly that the Attorney General “has the burden of proving that the conduct was intentional and was unfair or deceptive notwithstanding any other statute which declares a violation of that statute an unfair trade practice”. Section 209 also requires at least 10 days’ notice of an intended action and an opportunity to confer, unless an affidavit shows immediate irreparable harm to consumers, and permits a court that denies a permanent injunction to order the State to pay the prevailing party’s costs on a finding that the action was frivolous.

Recent Enforcement in Maine

Experian and T-Mobile — multistate settlements over the 2012 and 2015 breaches, November 2022. The Attorney General’s office announced on November 7, 2022 that Maine had joined a coalition obtaining two multistate settlements with Experian over data breaches in 2012 and 2015, together with a separate settlement with T-Mobile in connection with the 2015 breach, for a combined total of more than $16 million, of which Maine receives $143,322.65. The office states that the 2015 breach involved consumers who had applied for T-Mobile postpaid services and device financing between September 2013 and September 2015, exposing names, addresses, dates of birth, Social Security numbers, and identification numbers such as driver’s licence and passport numbers, and that 12,068 Maine residents were affected. Under the $12.67 million Experian settlement the company agreed to strengthen its due diligence and data security practices and to offer five years of free credit monitoring plus two free annual credit reports to affected consumers; under the separate $2.43 million settlement T-Mobile agreed to detailed vendor management provisions. A further $1 million resolved a separate investigation into Experian Data Corp. over a 2012 breach in which an identity thief posing as a private investigator obtained access to sensitive personal information in commercial databases, with that company agreeing to maintain a Red Flags program.

TJX Companies — Assurance of Discontinuance over the 2007 breach, June 2009. The Attorney General’s office announced on June 23, 2009 that Attorney General Janet T. Mills and 40 other state attorneys general had reached an Assurance of Discontinuance with The TJX Companies, Inc., resolving an investigation into whether the company had implemented sufficient safeguards to protect customers’ financial information against the breach it disclosed in 2007. The office states the investigation uncovered vulnerabilities and flaws in the company’s data security systems that may have allowed both the unlawful intrusion and its ability to continue undetected. The company agreed to pay $9.75 million to the states — $5.5 million dedicated to state data protection and consumer protection efforts, $1.75 million to reimburse investigation costs and fees, and $2.5 million to fund a Data Security Trust Fund for enforcement and policy development — with Maine’s share reported as $38,675.00, and to implement and maintain a comprehensive Information Security Program with regular reporting to the attorneys general and third-party assessment.

Pending Privacy Legislation

Maine’s comprehensive privacy effort ended rather than advanced in the 132nd Legislature. LD 1822, HP 1220, “An Act to Enact the Maine Online Data Privacy Act”, sponsored by Representative Kuhn of Falmouth, was referred to the Judiciary Committee on April 29, 2025, tabled at work sessions on May 14 and May 23, voted out as a divided report on May 30 and reported out on June 13, 2025 as OTP-AM/OTP-AM/ONTP. Report A, carrying eight signatures including both chairs, and Report B, carrying four, proposed different amended versions. Committee Amendment C-A (H-716) and House Amendment H-B to C-A (H-906) were adopted by House and Senate, while Senate Amendment S-A to C-A (S-528), sponsored by Senator Carney of Cumberland, was adopted by the Senate alone. The chambers did not reconcile, and the record of final disposition is “Died Between Houses, Apr 13, 2026”. The affected-sections table shows the bill would have added new sections 9609 through 9612 and others to the statutes.

Federal Privacy Laws That Apply in Maine

Federal privacy law applies in Maine by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Maine Unfair Trade Practices Act (5 M.R.S. §§ 205-A to 214), which the Maine Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Maine Businesses

With no comprehensive state statute, most privacy obligations on a Maine business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Maine businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Maine itself has none, and any business holding personal information about Maine residents is subject to the state’s breach-notification statute described above.

Maine Privacy Law FAQ

Does Maine have a comprehensive consumer privacy law?
Not as of the 2026 session. LD 1822, HP 1220, “An Act to Enact the Maine Online Data Privacy Act”, sponsored by Representative Kuhn of Falmouth, was referred to the Judiciary Committee on April 29, 2025 and reported out on June 13, 2025 in a divided report — eight members for Ought To Pass As Amended under Report A, four for a different Ought To Pass As Amended under Report B, and one for Ought Not To Pass. The chambers then adopted different amendments, and the bill’s final disposition on the legislative record is “Died Between Houses, Apr 13, 2026”.
What does Maine’s broadband privacy law require of internet providers?
Section 9301(2) bars a provider from using, disclosing, selling or permitting access to customer personal information except under the listed exceptions, and § 9301(3)(A) makes express, affirmative consent the only general path, revocable by the customer at any time. Section 9301(3)(B) bars the provider from refusing to serve a customer who does not consent and from charging a penalty or offering a discount based on the customer’s decision. Information that is not customer personal information runs the other way under subsection 3(C): the provider may use or sell it unless the customer gives written notice that it may not.
Has Maine’s broadband privacy law been challenged in court?
Yes. In ACA Connects — America’s Communications Association v. Frey, No. 1:20-cv-00055-LEW (D. Me.), four trade associations representing internet service providers argued that the statute violates the First and Fourteenth Amendments, is unconstitutionally void for vagueness, and is preempted by federal law. On July 7, 2020 the court denied the plaintiffs’ motion for judgment on the pleadings, granted the Attorney General’s cross motion, and dismissed Counts Three, Four and Five — the preemption claims resting on a congressional joint resolution, on the FCC’s Restoring Internet Freedom Order, and on impossibility. On the vagueness challenge the court concluded that the language complained of might support an as-applied challenge but did not make the statute unconstitutionally vague on its face.
Which Maine office receives a data breach notice?
It depends on who is regulated by whom. Section 1348(5) requires notice to the appropriate state regulators within the Department of Professional and Financial Regulation, and directs notice to the Attorney General only where the person giving notice is not regulated by that department. The enforcement provision in § 1349(1) tracks the same split: those regulators enforce the chapter for any person they license or regulate, and the Attorney General enforces it for all other persons.
What is the deadline for a Maine breach notice?
Section 1348(1) requires notice as expediently as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity, security and confidentiality of the data. Where there is no law enforcement delay, the notice is due no more than 30 days after the person becomes aware of a breach and identifies its scope — the second condition matters, because the clock does not begin on awareness alone. Section 1348(3) limits any law enforcement delay to seven business days after the agency determines notification will not compromise its investigation.
What can a Maine breach-notice failure cost?
Section 1349(2) makes a violation of the chapter a civil violation subject to one or more of three consequences: a fine of not more than $500 per violation, up to a maximum of $2,500 for each day the person is in violation; equitable relief; or enjoinment from further violations. The fine does not reach State Government, municipalities, school administrative units, the University of Maine System, the Maine Community College System or Maine Maritime Academy, though those bodies remain within the chapter’s notice duties. Subsection 3 provides that the remedies are cumulative and do not affect rights available under other federal or state law.
Can a Maine consumer sue for an unfair trade practice?
Section 213(1) allows it, within limits. The claimant must have purchased or leased goods, services or property primarily for personal, family or household purposes and suffered a loss of money or property as a result of a practice declared unlawful by section 207 or by a rule issued under section 207(2). The recovery is actual damages, restitution and equitable relief — not statutory or multiplied damages. Subsection 1-A requires a written demand for relief at least 30 days before filing, and subsection 2 directs an award of reasonable attorney’s fees and costs to a petitioner who establishes a violation, irrespective of the amount in controversy.
Does Maine treat information brokers differently from other businesses after a breach?
Yes, on the trigger for notice. Section 1348(1)(A) requires an information broker to investigate the likelihood that personal information has been or will be misused and to give notice where the information was or is reasonably believed to have been acquired by an unauthorized person. Section 1348(1)(B) requires any other person to give notice only where misuse of the information has occurred or it is reasonably possible that misuse will occur. Section 1347(3) defines an information broker by reference to furnishing personal information to nonaffiliated third parties for monetary fees or dues, and excludes government agencies whose records are maintained primarily for traffic safety, law enforcement or licensing purposes.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.