Law note · Maine

Notice of Risk to Personal Data

cite 10 M.R.S. secs. 1347-1349 stage IMMINENT commencement not set reviewed 2026-08-27

A person must notify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope absent a law-enforcement delay, and must notify the appropriate state regulator within the Department of Professional and Financial Regulation, or the Attorney General if unregulated by that department.

A violation carries a fine of up to $500 per violation, up to $2,500 per day, and the chapter's "cumulative effect" clause (sec. 1349(3)) preserves rights and remedies available under other federal or state law rather than itself granting one; unlike Virginia's damages-preservation clause, it names no individual right to recover damages, so it is not read as a private right of action.

The section's own history note dates enactment to PL 2005, c. 379, sec. 1, amended by PL 2005, c. 583, PL 2009, c. 161, and PL 2019, c. 512, without printing a same-page effective date, so no effective_date is recorded here.

What it asks of an app

  • Notify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope, absent a law enforcement delay.
  • Notify the appropriate Department of Professional and Financial Regulation regulator, or the Attorney General if you are not regulated by that department.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Maine statute text, 10 M.R.S. sections 1347 to 1349, Maine Legislature website

← Back to the example  ·  Lint your app →