Law / Maine

Maine

age

Maine has not enacted an adult content age verification law, a social media minor-access law, an app store accountability law, or a design code law as of this date. A 2025 bill requiring age verification for online obscene matter (LD 1873) and a bill restricting social media use by minors under 16 (LD 844) both died in June 2025 when the House accepted ought not to pass committee reports, and the 132nd Legislature adjourned in April 2026 without enacting any age-gating law.

privacy

Maine has no comprehensive consumer-data-privacy statute as of this research. A marquee bill, LD 1822 (An Act to Enact the Maine Online Data Privacy Act), passed the House and the Senate in differently amended forms but died between houses on April 13, 2026 and has no current legal effect.

Maine instead layers two sectoral statutes: an unusually strict opt-in privacy regime for broadband internet access providers (35-A M.R.S. sec. 9301) that never mentions biometric data at all, and a breach-notification statute (10 M.R.S. secs. 1347-1349) enforced by the Department of Professional and Financial Regulation or the Attorney General.

No dedicated biometric-privacy provision of any kind reaches the private sector in Maine; the state's only enacted biometric statute, 25 M.R.S. sec. 6001, restricts government use of facial recognition only and is out of scope for this private-sector-duty-bearer document.

9 instruments named 3 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Notice of Risk to Personal Data

cite 10 M.R.S. secs. 1347-1349 stage IMMINENT commencement not set source official Maine statute text, 10 M.R.S. sections 1347 to 1349, Maine Legislature website

A person must notify affected Maine residents of a breach of security as expediently as possible and without unreasonable delay, no more than 30 days after becoming aware of the breach and identifying its scope absent a law-enforcement delay, and must notify the appropriate state regulator within the Department of Professional and Financial Regulation, or the Attorney General if unregulated by that department.

A violation carries a fine of up to $500 per violation, up to $2,500 per day, and the chapter's "cumulative effect" clause (sec. 1349(3)) preserves rights and remedies available under other federal or state law rather than itself granting one; unlike Virginia's damages-preservation clause, it names no individual right to recover damages, so it is not read as a private right of action.

The section's own history note dates enactment to PL 2005, c. 379, sec. 1, amended by PL 2005, c. 583, PL 2009, c. 161, and PL 2019, c. 512, without printing a same-page effective date, so no effective_date is recorded here.

What it asks of an app

Comprehensive regime

An Act to Enact the Maine Online Data Privacy Act (LD 1822)

cite 10 M.R.S. secs. 9601-9615 (proposed, LD 1822, died between houses) stage WITHDRAWN no longer proceeding source official Maine bill status page, Maine Legislature website

This bill never became law and has no current legal effect. LD 1822, 132nd Legislature, Second Regular Session, would have codified a comprehensive online data privacy act at 10 M.R.S. secs. 9601-9615 (new). It passed the House and the Senate in differently amended forms, and the two chambers failed to reconcile their versions; the bill's official disposition is "Died Between Houses, Apr 13, 2026."

A similar bill returning in a future session is a live possibility, since Maine's absence of a comprehensive regime is a result of this bill's failure to reconcile, not an absence of legislative interest.

As introduced, the bill's own sec. 9601(3) would have classified genetic or biometric data as sensitive, and would have excluded a photograph, video, or audio recording, or data generated from one, from the biometric data definition only until that data was generated to identify a specific consumer, the same clawback shape as Colorado, Maryland, Minnesota, and New Jersey; the reviewed committee amendment did not touch that definition.

What it asks of an app

Broadband internet access service, customer personal information privacy

cite 35-A M.R.S. sec. 9301 stage IMMINENT commencement not set source official Maine statute text, 35-A M.R.S. section 9301, Maine Legislature website

A provider of broadband internet access service may not use, disclose, sell, or permit access to a customer's customer personal information except with the customer's express, affirmative, opt-in consent, revocable at any time, and may not refuse service or charge a penalty or offer a discount based on the customer's consent decision.

"Customer personal information" is defined broadly (name, billing information, Social Security number, demographic data, browsing history, application usage history, precise geolocation, financial and health information, children's information, device identifiers, communications content, and origin and destination IP addresses) but never mentions biometric data.

The section's own history note dates enactment to PL 2019, c. 216, sec. 1, without printing a same-page effective date, so no effective_date is recorded here; the section carries no amendment since. No enforcement or penalty provision appears within the section itself as read.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.