Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite 10 M.R.S. secs. 1347-1349
stage IMMINENT commencement not set
source official Maine statute text, 10 M.R.S. sections 1347 to 1349, Maine Legislature website
A person must notify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope absent a law-enforcement delay, and must notify the appropriate state regulator within the Department of Professional and Financial Regulation, or the Attorney General if unregulated by that department.
A violation carries a fine of up to $500 per violation, up to $2,500 per day, and the chapter's "cumulative effect" clause (sec. 1349(3)) preserves rights and remedies available under other federal or state law rather than itself granting one; unlike Virginia's damages-preservation clause, it names no individual right to recover damages, so it is not read as a private right of action.
The section's own history note dates enactment to PL 2005, c. 379, sec. 1, amended by PL 2005, c. 583, PL 2009, c. 161, and PL 2019, c. 512, without printing a same-page effective date, so no effective_date is recorded here.
What it asks of an app →
Comprehensive regime
This bill never became law and has no current legal effect. LD 1822, 132nd Legislature, Second Regular Session, would have codified a comprehensive online data privacy act at 10 M.R.S. secs. 9601-9615 (new). It passed the House and the Senate in differently amended forms, and the two chambers failed to reconcile their versions; the bill's official disposition is "Died Between Houses, Apr 13, 2026."
A similar bill returning in a future session is a live possibility, since Maine's absence of a comprehensive regime is a result of this bill's failure to reconcile, not an absence of legislative interest.
As introduced, the bill's own sec. 9601(3) would have classified genetic or biometric data as sensitive, and would have excluded a photograph, video, or audio recording, or data generated from one, from the biometric data definition only until that data was generated to identify a specific consumer, the same clawback shape as Colorado, Maryland, Minnesota, and New Jersey; the reviewed committee amendment did not touch that definition.
What it asks of an app →
cite 35-A M.R.S. sec. 9301
stage IMMINENT commencement not set
source official Maine statute text, 35-A M.R.S. section 9301, Maine Legislature website
A provider of broadband internet access service may not use, disclose, sell, or permit access to a customer's customer personal information except with the customer's express, affirmative, opt-in consent, revocable at any time, and may not refuse service or charge a penalty or offer a discount based on the customer's consent decision.
"Customer personal information" is defined broadly (name, billing information, Social Security number, demographic data, browsing history, application usage history, precise geolocation, financial and health information, children's information, device identifiers, communications content, and origin and destination IP addresses) but never mentions biometric data.
The section's own history note dates enactment to PL 2019, c. 216, sec. 1, without printing a same-page effective date, so no effective_date is recorded here; the section carries no amendment since. No enforcement or penalty provision appears within the section itself as read.
What it asks of an app →