{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/maine",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/maine.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/maine",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/maine/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/maine/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "maine",
    "frontmatter": {
      "title": "Maine Consumer Privacy Law",
      "description": "Maine has no comprehensive consumer-privacy statute — LD 1822 was placed in the Legislative Files (DEAD) on April 13, 2026 after the chambers insisted on opposing enactment positions — but it has the nation's strictest ISP privacy law (35-A M.R.S. § 9301, opt-in consent) plus a 30-day breach-notice clock under the Notice of Risk to Personal Data Act.",
      "state": "Maine",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "35-A M.R.S. § 9301 (broadband ISP opt-in privacy law, eff. July 1, 2020) plus the Notice of Risk to Personal Data Act, 10 M.R.S. §§ 1346–1350-B — Maine has no comprehensive consumer-privacy statute",
        "appliesTo": "The ISP law reaches only broadband providers serving customers physically located and billed in Maine; the breach act reaches any person maintaining computerized personal information of Maine residents — including state agencies, municipalities, and universities — with no revenue or volume threshold",
        "privacyPolicyRequired": "No general mandate — broadband providers must post a clear notice of customers' opt-in rights at the point of sale and on their website; for everyone else, policy contents are driven by FTC Act § 5 and the GLBA, HIPAA, and COPPA overlay",
        "privateRightOfAction": "None under the breach act (regulator/AG-enforced) and none stated in the ISP law; Maine UTPA § 213 gives consumer purchasers a restitution-oriented action for loss of money or property from unfair or deceptive practices",
        "regulator": "Maine Attorney General; Department of Professional and Financial Regulation regulators for licensed entities (Bureau of Insurance superintendent for insurance licensees)",
        "bottomLine": "Maine has no comprehensive consumer-privacy law — the Maine Online Data Privacy Act (LD 1822) was placed in the Legislative Files (DEAD) on April 13, 2026 after the chambers insisted on opposing enactment positions — but it does have the nation's strictest ISP privacy statute, which since July 1, 2020 has required broadband providers serving Maine customers to get opt-in consent before using, disclosing, or selling customer personal information. Every other business builds to the Notice of Risk to Personal Data Act's 30-day breach-notice clock, the Maine Unfair Trade Practices Act, and the federal overlay.",
        "lawCoverage": "sectoral",
        "policyMandate": "sectoralPolicy",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "categorySpecific",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Maine consumer privacy law",
        "Maine broadband internet privacy law 35-A 9301",
        "Maine ISP opt-in consent requirement",
        "Maine Online Data Privacy Act LD 1822",
        "Maine data breach notification Notice of Risk to Personal Data Act",
        "Maine no comprehensive privacy law",
        "Maine privacy policy requirements",
        "Maine Unfair Trade Practices Act privacy enforcement",
        "Maine Insurance Data Security Act",
        "Maine student data privacy"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Maine?",
        "heading": "Which privacy laws apply to your business in Maine?",
        "answerText": "Maine regulates privacy by sector, not across the board — there is no comprehensive consumer-privacy law. The state's headline statute is the broadband privacy law, 35-A M.R.S. § 9301, the strictest ISP privacy rule in the country: a broadband provider may not use, disclose, sell, or permit access to customer personal information without the customer's opt-in consent, but it applies only to providers serving customers that are physically located and billed for service in Maine. For every other business, the operative state statute is the Notice of Risk to Personal Data Act, Maine's breach-notification law, which reaches essentially any person or entity — including government agencies and universities — that maintains computerized personal information.",
        "sources": [
          {
            "id": "isp-ban",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(2).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "Maine's broadband privacy law prohibits a provider from using, disclosing, selling, or permitting access to customer personal information except under the statute's consent and operational exceptions.",
            "verbatimQuote": "A provider may not use, disclose, sell or permit access to customer personal information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-isp-ban"
          },
          {
            "id": "isp-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(7).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "The broadband privacy law applies only to providers operating in Maine when serving customers physically located and billed for service in Maine — it does not reach general businesses.",
            "verbatimQuote": "The requirements of this section apply to providers operating within the State when providing broadband Internet access service to customers that are physically located and billed for service received in the State.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-isp-scope"
          },
          {
            "id": "breach-person",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1347",
            "citation": "10 M.R.S. § 1347(5).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1347.html",
            "proposition": "The Notice of Risk to Personal Data Act defines a covered person broadly — individuals, business entities, state agencies, municipalities, school units, and universities — with no size or revenue threshold.",
            "verbatimQuote": "“Person” means an individual, partnership, corporation, limited liability company, trust, estate, cooperative, association or other entity, including agencies of State Government, municipalities, school administrative units, the University of Maine System, the Maine Community College System, Maine Maritime Academy and private colleges and universities.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-person"
          },
          {
            "id": "insurance-infosec",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "24-A M.R.S. § 2264",
            "citation": "24-A M.R.S. § 2264(1).",
            "url": "https://legislature.maine.gov/statutes/24-A/title24-Asec2264.html",
            "proposition": "The Maine Insurance Data Security Act requires every insurance licensee to develop and maintain a comprehensive written information security program based on its risk assessment.",
            "verbatimQuote": "a licensee shall develop, implement and maintain a comprehensive, written information security program based on the licensee's risk assessment and containing administrative, technical and physical safeguards for the protection of nonpublic information and the licensee's information systems",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-insurance-infosec"
          },
          {
            "id": "student-privacy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "20-A M.R.S. § 953",
            "citation": "20-A M.R.S. § 953(1)(A)-(C).",
            "url": "https://legislature.maine.gov/statutes/20-A/title20-Asec953.html",
            "proposition": "The Student Information Privacy Act prohibits K-12 ed-tech operators from using student data for targeted advertising, amassing student profiles outside K-12 school purposes, or selling student data without explicit written or electronic consent from a parent or eligible student.",
            "verbatimQuote": "An operator may not knowingly engage in any of the following activities with respect to the operator's website, service or application without explicit written or electronic consent from a student's parent or an eligible student:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-student-privacy"
          }
        ]
      },
      {
        "slug": "broadband-opt-in-consent",
        "label": "Does Maine's broadband privacy law require opt-in consent?",
        "heading": "Does Maine's broadband privacy law require opt-in consent?",
        "answerText": "Yes — if you are a broadband provider serving Maine customers. Since July 1, 2020, a provider may use, disclose, sell, or permit access to a customer's personal information only if the customer gives express, affirmative consent, which the customer may revoke at any time. The statute also bans pay-for-privacy: a provider may not refuse to serve a customer who withholds consent, and may not charge a penalty or offer a discount based on the consent decision. This opt-in default is unusually strict for broadband privacy, and the FCC rules Congress repealed in 2017 were the model this statute revived at the state level.",
        "sources": [
          {
            "id": "optin-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(3)(A).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "A provider may use, disclose, sell, or permit access to customer personal information only on the customer's express, affirmative consent, revocable at any time — an opt-in regime.",
            "verbatimQuote": "A provider may use, disclose, sell or permit access to a customer's customer personal information if the customer gives the provider express, affirmative consent to such use, disclosure, sale or access. A customer may revoke the customer's consent under this paragraph at any time.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-optin-consent"
          },
          {
            "id": "no-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(3)(B)(2).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "A provider may not penalize or discount based on the customer's consent decision — Maine's ban on pay-for-privacy ISP pricing.",
            "verbatimQuote": "Charge a customer a penalty or offer a customer a discount based on the customer's decision to provide or not provide consent under paragraph A",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-no-penalty"
          },
          {
            "id": "noncpi-optout",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(3)(C).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "Information that is not customer personal information runs on an opt-out basis: the provider may use it unless the customer gives written notice withholding permission.",
            "verbatimQuote": "A provider may use, disclose, sell or permit access to information the provider collects pertaining to a customer that is not customer personal information, except upon written notice from the customer notifying the provider that the customer does not permit the provider to use, disclose, sell or permit access to that information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-noncpi-optout"
          },
          {
            "id": "exceptions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(4).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "The statute permits use of customer personal information without consent for listed operational purposes — providing the service, the provider's own communications marketing, billing, court orders, fraud protection, and emergency geolocation.",
            "verbatimQuote": "a provider may collect, retain, use, disclose, sell and permit access to customer personal information without customer approval",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-exceptions"
          },
          {
            "id": "security-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(5).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "Providers owe a freestanding duty to take reasonable measures to protect customer personal information, scaled to the provider's activities, data sensitivity, size, and technical feasibility.",
            "verbatimQuote": "A provider shall take reasonable measures to protect customer personal information from unauthorized use, disclosure or access.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-security-duty"
          }
        ]
      },
      {
        "slug": "privacy-policy-required",
        "label": "Does Maine require your business to post a privacy policy?",
        "heading": "Does Maine require your business to post a privacy policy?",
        "answerText": "For most businesses, no — no Maine statute of general application requires a consumer privacy policy or fixes its contents. The one Maine-specific posting duty falls on broadband providers, which must give every customer a clear, conspicuous, and nondeceptive notice — at the point of sale and on the provider's public website — of the provider's obligations and the customer's rights under the opt-in law. For everyone else, FTC Act § 5 supplies the general federal unfair-or-deceptive-practices hook, so whatever you publish has to match what you do.",
        "sources": [
          {
            "id": "isp-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "35-A M.R.S. § 9301",
            "citation": "35-A M.R.S. § 9301(6).",
            "url": "https://legislature.maine.gov/statutes/35-A/title35-Asec9301-3.html",
            "proposition": "A broadband provider must give each customer clear, conspicuous, nondeceptive notice of its obligations and the customer's rights under the opt-in law, at the point of sale and on its public website.",
            "verbatimQuote": "A provider shall provide to each of the provider's customers a clear, conspicuous and nondeceptive notice at the point of sale and on the provider's publicly accessible website of the provider's obligations and a customer's rights under this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-isp-notice"
          },
          {
            "id": "ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act supplies the general federal unfair-or-deceptive-practices hook by declaring unfair or deceptive acts or practices in or affecting commerce unlawful.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-ftc5-deceptive"
          },
          {
            "id": "glba-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Privacy Notice",
            "citation": "15 U.S.C. § 6802(a).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6802",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6802#:~:text=a%20financial%20institution%20may%20not%2C,section%206803%20of%20this%20title",
            "proposition": "The GLBA bars a financial institution from disclosing nonpublic personal information to nonaffiliated third parties unless it has delivered the required privacy notice to the consumer.",
            "verbatimQuote": "a financial institution may not, directly or through any affiliate, disclose to a nonaffiliated third party any nonpublic personal information, unless such financial institution provides or has provided to the consumer a notice that complies with section 6803 of this title",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-glba-notice"
          },
          {
            "id": "hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520.",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-hipaa-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say under Maine law?",
        "heading": "What must your contracts with vendors say under Maine law?",
        "answerText": "There is no Maine omnibus data-processing-agreement requirement — no statute of general application prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs. The vendor duties that do exist are sectoral. An insurance licensee must require each third-party service provider to implement appropriate administrative, technical, and physical safeguards for the nonpublic information the provider holds. No later than January 1, 2027, an insurance licensee must also require third-party service providers to notify it of certain materially harmful cybersecurity events affecting nonpublic information obtained from the licensee. A K-12 ed-tech operator disclosing student data to a service provider must contractually prohibit the provider from using the data for any purpose other than the contracted service.",
        "sources": [
          {
            "id": "insurance-vendor",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "24-A M.R.S. § 2264",
            "citation": "24-A M.R.S. § 2264(6)(B).",
            "url": "https://legislature.maine.gov/statutes/24-A/title24-Asec2264.html",
            "proposition": "The Insurance Data Security Act requires licensees to make each third-party service provider implement appropriate administrative, technical, and physical safeguards for the information systems and nonpublic information the provider holds.",
            "verbatimQuote": "Require each 3rd-party service provider to implement appropriate administrative, technical and physical safeguards to protect and secure the information systems and nonpublic information that are accessible to or held by the 3rd-party service provider",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-insurance-vendor"
          },
          {
            "id": "insurance-vendor-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "24-A M.R.S. § 2264",
            "citation": "24-A M.R.S. § 2264(6)(C).",
            "url": "https://legislature.maine.gov/statutes/24-A/title24-Asec2264.html",
            "proposition": "No later than January 1, 2027, an insurance licensee must require third-party service providers to notify it of materially harmful cybersecurity events affecting nonpublic information obtained from the licensee.",
            "verbatimQuote": "No later than January 1, 2027, require each 3rd-party service provider to notify the licensee when the 3rd-party service provider becomes aware of any cybersecurity event affecting nonpublic information obtained from the licensee that has occurred in an information system maintained by the 3rd-party service provider or by an ancillary service provider if the cybersecurity event has a reasonable likelihood of materially harming any consumer or any material part of the normal operations of the licensee.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-insurance-vendor-notice"
          },
          {
            "id": "student-vendor",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "20-A M.R.S. § 953",
            "citation": "20-A M.R.S. § 953(1)(D)(6)(a).",
            "url": "https://legislature.maine.gov/statutes/20-A/title20-Asec953.html",
            "proposition": "A K-12 ed-tech operator may disclose student data to a service provider only under a contract that bars the provider from using the data for any purpose other than the contracted service.",
            "verbatimQuote": "Prohibits the service provider from using any student data for any purpose other than providing the contracted service to, or on behalf of, the operator",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-student-vendor"
          },
          {
            "id": "glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Oversee%20service%20providers%2C%20by%3A%20(1),continued%20adequacy%20of%20their%20safeguards.",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-glba-safeguards"
          },
          {
            "id": "hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,with%20respect%20to%20such%20information",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted uses and disclosures of protected health information and binds the business associate to safeguard it.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity, except that: (A) The contract may permit the business associate to use and disclose protected health information for the proper management and administration of the business associate, as provided in paragraph (e)(4) of this section; and (B) The contract may permit the business associate to provide data aggregation services relating to the health care operations of the covered entity. (ii) Provide that the business associate will: (A) Not use or further disclose the information other than as permitted or required by the contract or as required by law; (B) Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract; (C) Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410; (D) In accordance with § 164.502(e)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate with respect to such information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-hipaa-baa"
          },
          {
            "id": "breach-thirdparty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1348",
            "citation": "10 M.R.S. § 1348(2).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1348.html",
            "proposition": "A third party that maintains computerized personal information on another person's behalf must notify that person immediately after discovering a breach in which the data was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "verbatimQuote": "A 3rd-party entity that maintains, on behalf of a person, computerized data that includes personal information that the 3rd-party entity does not own shall notify the person maintaining personal information of a breach of the security of the system immediately following discovery if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-thirdparty"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Maine?",
        "heading": "When must you notify people of a data breach in Maine?",
        "answerText": "Within 30 days of becoming aware of the breach and identifying its scope, if notice is required at all. The trigger is two-tiered. An ordinary business must investigate promptly and notify affected Maine residents if misuse of their personal information has occurred or is reasonably possible. An information broker — a business that compiles personal information about individuals to furnish to third parties — faces a stricter, acquisition-based trigger: it must notify residents whose personal information has been, or is reasonably believed to have been, acquired by an unauthorized person, with no misuse-likelihood screen. Whenever resident notice is required, you must also notify the appropriate state regulator — the Department of Professional and Financial Regulation for entities it licenses, otherwise the Attorney General.",
        "sources": [
          {
            "id": "breach-30-day",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1348",
            "citation": "10 M.R.S. § 1348(1).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1348.html",
            "proposition": "Absent a law-enforcement delay, breach notices must go out no more than 30 days after the covered person becomes aware of the breach and identifies its scope.",
            "verbatimQuote": "If there is no delay of notification due to law enforcement investigation pursuant to subsection 3, the notices must be made no more than 30 days after the person identified in paragraph A or B becomes aware of a breach of security and identifies its scope.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-30-day"
          },
          {
            "id": "breach-general-trigger",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1348",
            "citation": "10 M.R.S. § 1348(1)(B).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1348.html",
            "proposition": "An ordinary business must investigate promptly and notify Maine residents if misuse of their personal information has occurred or is reasonably possible — a misuse-likelihood trigger.",
            "verbatimQuote": "If any other person who maintains computerized data that includes personal information becomes aware of a breach of the security of the system, the person shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused and shall give notice of a breach of the security of the system following discovery or notification of the security breach to a resident of this State if misuse of the personal information has occurred or if it is reasonably possible that misuse will occur.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-general-trigger"
          },
          {
            "id": "breach-broker-trigger",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1348",
            "citation": "10 M.R.S. § 1348(1)(A).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1348.html",
            "proposition": "An information broker faces a stricter acquisition-based trigger: it must notify residents whose personal information has been, or is reasonably believed to have been, acquired by an unauthorized person.",
            "verbatimQuote": "If an information broker that maintains computerized data that includes personal information becomes aware of a breach of the security of the system, the information broker shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused and shall give notice of a breach of the security of the system following discovery or notification of the security breach to a resident of this State whose personal information has been, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-broker-trigger"
          },
          {
            "id": "breach-regulator-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1348",
            "citation": "10 M.R.S. § 1348(5).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1348.html",
            "proposition": "Whenever resident notice is required, the person must also notify the appropriate regulators within the Department of Professional and Financial Regulation or, if not regulated by the department, the Attorney General.",
            "verbatimQuote": "When notice of a breach of the security of the system is required under subsection 1, the person shall notify the appropriate state regulators within the Department of Professional and Financial Regulation, or if the person is not regulated by the department, the Attorney General.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-regulator-notice"
          },
          {
            "id": "breach-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1347",
            "citation": "10 M.R.S. § 1347(1).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1347.html",
            "proposition": "A security breach is the unauthorized acquisition, release, or use of computerized personal information that compromises its security, confidentiality, or integrity — with a good-faith employee-access carve-out.",
            "verbatimQuote": "“Breach of the security of the system” or “security breach” means unauthorized acquisition, release or use of an individual's computerized data that includes personal information that compromises the security, confidentiality or integrity of personal information of the individual maintained by a person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-definition"
          },
          {
            "id": "breach-personal-info",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1347",
            "citation": "10 M.R.S. § 1347(6).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1347.html",
            "proposition": "Personal information under the breach act means a first name or initial and last name combined with listed data elements only when either the name or data elements are not encrypted or redacted, plus standalone identity-assumption data elements.",
            "verbatimQuote": "\"Personal information\" means an individual's first name, or first initial, and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-personal-info"
          },
          {
            "id": "breach-cra-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1348",
            "citation": "10 M.R.S. § 1348(4).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1348.html",
            "proposition": "A breach requiring notice to more than 1,000 persons at a single time also requires notice to the nationwide consumer reporting agencies without unreasonable delay.",
            "verbatimQuote": "If a person discovers a breach of the security of the system that requires notification to more than 1,000 persons at a single time, the person shall also notify, without unreasonable delay, consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 United States Code, Section 1681a(p).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-cra-notice"
          },
          {
            "id": "insurance-3day",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "24-A M.R.S. § 2266",
            "citation": "24-A M.R.S. § 2266(1).",
            "url": "https://legislature.maine.gov/statutes/24-A/title24-Asec2266.html",
            "proposition": "An insurance licensee must notify the superintendent of a cybersecurity event as promptly as possible and no later than 3 business days after determining the event occurred if Maine is the carrier's domicile or producer's home state, or if the event involves 250 or more Maine consumers and is otherwise reportable or reasonably likely to materially harm a Maine consumer or a material part of operations.",
            "verbatimQuote": "Notwithstanding Title 10, chapter 210‑B, a licensee shall notify the superintendent as promptly as possible but in no event later than 3 business days from a determination that a cybersecurity event has occurred if:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-insurance-3day"
          },
          {
            "id": "breach-deemed-compliance",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1349",
            "citation": "10 M.R.S. § 1349(4).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1349.html",
            "proposition": "A person that complies with at-least-as-protective federal or state security-breach notification procedures is deemed compliant with Maine's resident-notice requirements.",
            "verbatimQuote": "A person that complies with the security breach notification requirements of rules, regulations, procedures or guidelines established pursuant to federal law or the law of this State is deemed to be in compliance with the requirements of section 1348 as long as the law, rules, regulations or guidelines provide for notification procedures at least as protective as the notification requirements of section 1348.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-deemed-compliance"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in Maine over privacy?",
        "heading": "Can a consumer sue your business in Maine over privacy?",
        "answerText": "Not under the breach act, and not expressly under the broadband privacy law. The Notice of Risk to Personal Data Act is enforced publicly: the Department of Professional and Financial Regulation enforces it against the entities it licenses, and the Attorney General enforces it against everyone else. A violation is a civil violation punishable by a fine of not more than $500 per violation, up to a maximum of $2,500 for each day the person is in violation, plus equitable relief and injunctions. The route a Maine consumer does have is the Unfair Trade Practices Act: a person who buys goods or services for personal, family, or household purposes and suffers a loss of money or property from an unfair or deceptive practice may sue for actual damages, restitution, and equitable relief.",
        "sources": [
          {
            "id": "breach-enforcement",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1349",
            "citation": "10 M.R.S. § 1349(1).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1349.html",
            "proposition": "The breach act is publicly enforced: Department of Professional and Financial Regulation regulators enforce it against their licensees, and the Attorney General enforces it against all other persons.",
            "verbatimQuote": "The appropriate state regulators within the Department of Professional and Financial Regulation shall enforce this chapter for any person that is licensed or regulated by those regulators. The Attorney General shall enforce this chapter for all other persons.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-enforcement"
          },
          {
            "id": "breach-penalties",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "10 M.R.S. § 1349",
            "citation": "10 M.R.S. § 1349(2).",
            "url": "https://legislature.maine.gov/statutes/10/title10sec1349.html",
            "proposition": "A breach-act violation is a civil violation carrying fines of up to $500 per violation, capped at $2,500 per day, alongside equitable relief and injunctions.",
            "verbatimQuote": "A person that violates this chapter commits a civil violation and is subject to one or more of the following:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-breach-penalties"
          },
          {
            "id": "utpa-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "5 M.R.S. § 213",
            "citation": "5 M.R.S. § 213(1).",
            "url": "https://legislature.maine.gov/statutes/5/title5sec213.html",
            "proposition": "The UTPA gives a consumer purchaser who suffers a loss of money or property from an unlawful practice a private action for actual damages, restitution, and equitable relief.",
            "verbatimQuote": "Any person who purchases or leases goods, services or property, real or personal, primarily for personal, family or household purposes and thereby suffers any loss of money or property, real or personal, as a result of the use or employment by another person of a method, act or practice declared unlawful by section 207 or by any rule or regulation issued under section 207, subsection 2 may bring an action either in the Superior Court or District Court for actual damages, restitution and for such other equitable relief, including an injunction, as the court determines to be necessary and proper.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-utpa-pra"
          },
          {
            "id": "utpa-demand",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "5 M.R.S. § 213",
            "citation": "5 M.R.S. § 213(1-A).",
            "url": "https://legislature.maine.gov/statutes/5/title5sec213.html",
            "proposition": "A UTPA damages action requires a written pre-suit demand for relief mailed or delivered to the respondent at least 30 days before filing.",
            "verbatimQuote": "At least 30 days prior to the filing of an action for damages, a written demand for relief, identifying the claimant and reasonably describing the unfair and deceptive act or practice relied upon and the injuries suffered, must be mailed or delivered to any prospective respondent at the respondent's last known address.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-utpa-demand"
          },
          {
            "id": "utpa-fees",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "5 M.R.S. § 213",
            "citation": "5 M.R.S. § 213(2).",
            "url": "https://legislature.maine.gov/statutes/5/title5sec213.html",
            "proposition": "A petitioner who establishes a UTPA violation is awarded reasonable attorney's fees and costs irrespective of the amount in controversy.",
            "verbatimQuote": "If the court finds, in any action commenced under this section that there has been a violation of section 207, the petitioner shall, in addition to other relief provided for by this section and irrespective of the amount in controversy, be awarded reasonable attorney's fees and costs incurred in connection with said action.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-utpa-fees"
          },
          {
            "id": "utpa-207",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "5 M.R.S. § 207",
            "citation": "5 M.R.S. § 207, § 207(1).",
            "url": "https://legislature.maine.gov/statutes/5/title5sec207.html",
            "proposition": "The Maine UTPA declares unfair methods of competition and unfair or deceptive acts or practices in trade or commerce unlawful, construed in line with FTC Act interpretations.",
            "verbatimQuote": "Unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are declared unlawful",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-utpa-207"
          },
          {
            "id": "utpa-ag-remedies",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "5 M.R.S. § 209",
            "citation": "5 M.R.S. § 209.",
            "url": "https://legislature.maine.gov/statutes/5/title5sec209.html",
            "proposition": "The Attorney General may bring a UTPA action to restrain unlawful practices by temporary or permanent injunction and seek restoration of money or property acquired through the unlawful practice.",
            "verbatimQuote": "Whenever the Attorney General has reason to believe that a person is using or is about to use any method, act or practice declared by section 207 to be unlawful, and that proceedings would be in the public interest, the Attorney General may bring an action in the name of the State against the person to restrain by temporary or permanent injunction the use of the method, act or practice and the court may make such other orders or judgments as may be necessary to restore to any person who has suffered any ascertainable loss by reason of the use or employment of the unlawful method, act or practice, any moneys or property, real or personal, that may have been acquired by means of the method, act or practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-utpa-ag-remedies"
          },
          {
            "id": "utpa-ag-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "5 M.R.S. § 209",
            "citation": "5 M.R.S. § 209.",
            "url": "https://legislature.maine.gov/statutes/5/title5sec209.html",
            "proposition": "The Attorney General may recover a civil penalty of up to $10,000 for each intentional violation of the UTPA shown to be unfair or deceptive.",
            "verbatimQuote": "Each intentional violation of section 207 in which the Attorney General establishes that the conduct giving rise to the violation is either unfair or deceptive is a violation for which a civil penalty of not more than $10,000 shall be adjudged.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/maine#src-utpa-ag-penalty"
          }
        ]
      }
    ]
  }
}
