🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-ME · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Maine

US-ME schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 28 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fragmented sectoral framework with an active AG enforcer, but no omnibus statute currently in force.

Primary frameworkMaine Notice of Risk to Personal Data Act (Title 10 §1346 et seq.); Act to Protect the Privacy of Online Customer Information (Title 35-A §9301); FTC Act Section 5
Supervisory authorityMaine Attorney General
Traffic-light rationale — AmberFragmented sectoral framework with an active AG enforcer, but no omnibus statute currently in force.

Sub-modules (5)

Regulator And AuthorityAmber

The Maine AG is the primary state enforcer for consumer-protection and breach-notification matters; the FTC is the concurrent federal enforcer under Section 5.

Claims (1):

  • The Maine Attorney General is the primary state enforcement authority for consumer data-protection matters in Maine, including breach notification and general consumer-protection statutes.

Act And InstrumentsAmber

Instruments include the Notice of Risk to Personal Data Act, the Maine Insurance Data Security Act, the Act to Protect the Privacy of Online Customer Information, and the pending LD 1822.

Claims (4):

  • Maine has no comprehensive consumer-privacy statute; data protection is governed by a patchwork of the federal FTC Act Section 5, sectoral federal laws (HIPAA, GLBA, COPPA), and Maine's own sector-specific and breach-notification statutes.
  • The Maine Notice of Risk to Personal Data Act, found at §1346 et seq. of Chapter 210-B, Part 3 of Title 10 of the Maine Revised Statutes, establishes the state's data breach notification requirement.
  • The Maine Insurance Data Security Act (LD 51) was signed into law on 17 March 2021, establishing data-security standards and exclusive investigation/notification standards for cybersecurity events applicable to insurance licensees.
  • The Maine Online Data Privacy Act (LD 1822), a comprehensive consumer-privacy bill modeled on Maryland's framework, passed the Maine Senate 20-14 on 5 March 2026 with a proposed 1 September 2027 effective date, but had not received final House concurrence or gubernatorial signature as of the most recent reporting available.

Material ScopeAmber

Material scope is defined narrowly per-instrument (e.g., computerized personal information for breach law; broadband customer information for the ISP law) rather than by a single omnibus definition.

Claims (1):

  • Maine's breach-notification statute applies to computerized personal information of Maine residents held by entities that own, license, or maintain such data.

Territorial ScopeAmber

Territorial scope is instrument-specific; the ISP privacy law applies to providers billing Maine-located customers rather than to controllers generally.

Claims (1):

  • The Act to Protect the Privacy of Online Customer Information applies to broadband internet access service providers serving customers physically located in and billed for service in Maine, rather than to controllers generally.

Regulator Registration And FilingAmber

No general controller registration/filing regime exists outside the insurance sector, where the IDSA imposes filing obligations to the Superintendent of Insurance.

Claims (1):

  • Maine does not impose a general controller registration or filing obligation on data controllers outside the insurance sector; the Maine Insurance Data Security Act requires certain filings by insurance licensees to the Superintendent of Insurance.
Category narrative64 words

Maine has no comprehensive omnibus consumer-privacy statute. The Maine Attorney General enforces a patchwork of the state's own sector-specific statutes (broadband-ISP privacy law, insurance data-security law, general breach-notification law) plus federal sectoral laws (HIPAA, GLBA, COPPA) and the FTC's general Section 5 unfair/deceptive-practices authority. A comprehensive bill, LD 1822 (Maine Online Data Privacy Act), is advancing through the Legislature but is not yet enacted.

Sources and claims (8)
  1. ConfirmedNAAG Attorney General JournalThe Maine Attorney General is the primary state enforcement authority for consumer data-protection matters in Maine, including breach notification and general consumer-protection statutes.observed
  2. ConfirmedFederal Trade CommissionMaine has no comprehensive consumer-privacy statute; data protection is governed by a patchwork of the federal FTC Act Section 5, sectoral federal laws (HIPAA, GLBA, COPPA), and Maine's own sector-specific and breach-notification statutes.observed
  3. ConfirmedOneTrust DataGuidanceThe Maine Notice of Risk to Personal Data Act, found at §1346 et seq. of Chapter 210-B, Part 3 of Title 10 of the Maine Revised Statutes, establishes the state's data breach notification requirement.observed
  4. ConfirmedOneTrust DataGuidanceThe Maine Insurance Data Security Act (LD 51) was signed into law on 17 March 2021, establishing data-security standards and exclusive investigation/notification standards for cybersecurity events applicable to insurance licensees.observed
  5. ProbableIAPPThe Maine Online Data Privacy Act (LD 1822), a comprehensive consumer-privacy bill modeled on Maryland's framework, passed the Maine Senate 20-14 on 5 March 2026 with a proposed 1 September 2027 effective date, but had not received final House concurrence or gubernatorial signature as of the most recent reporting available.observed
  6. ProbableOneTrust DataGuidanceMaine's breach-notification statute applies to computerized personal information of Maine residents held by entities that own, license, or maintain such data.observed
  7. ConfirmedOneTrust DataGuidanceThe Act to Protect the Privacy of Online Customer Information applies to broadband internet access service providers serving customers physically located in and billed for service in Maine, rather than to controllers generally.observed
  8. ProbableOneTrust DataGuidanceMaine does not impose a general controller registration or filing obligation on data controllers outside the insurance sector; the Maine Insurance Data Security Act requires certain filings by insurance licensees to the Superintendent of Insurance.observed

#

No general lawful-basis, special-category, or anonymisation regime exists; only a narrow sectoral consent rule.

Primary frameworkAct to Protect the Privacy of Online Customer Information (Title 35-A §9301)
Supervisory authorityMaine Attorney General
Traffic-light rationale — RedNo general lawful-basis, special-category, or anonymisation regime exists; only a narrow sectoral consent rule.

Sub-modules (4)

Lawful BasesRed

No general enumerated lawful-basis framework exists in Maine law; processing outside the ISP-consent rule is governed only by general FTC unfairness/deception norms.

Claims (1):

  • Maine has no general statutory lawful-basis framework for personal-data processing equivalent to GDPR Article 6; processing is governed by sector-specific consent/opt-in rules and general FTC Act Section 5 unfairness/deception standards.

Special CategoriesRed

No Maine-specific sensitive/special-category data statute exists; health data is addressed federally via HIPAA.

Claims (1):

  • Maine has no standalone special-category (sensitive data) statute; sensitive health data is addressed at the federal level through HIPAA rather than a Maine-specific sensitive-data regime.

Pseudonymisation And AnonymisationRed

No Maine statutory definition or safe-harbour for pseudonymised/anonymised data was identified.

Category narrative67 words

Maine lacks a general lawful-basis or sensitive-data framework analogous to GDPR Arts 6/9. The only codified consent standard is the opt-in requirement in the broadband-ISP privacy law. Special-category and pseudonymisation/anonymisation concepts are not separately codified at state level; sensitive health data instead falls under federal HIPAA. Searches conducted: 'Maine sensitive personal data statute', 'Maine special category data law', 'Maine anonymisation pseudonymisation statute' — no Maine-specific instrument located.

Sources and claims (3)
  1. ConfirmedFederal Trade CommissionMaine has no general statutory lawful-basis framework for personal-data processing equivalent to GDPR Article 6; processing is governed by sector-specific consent/opt-in rules and general FTC Act Section 5 unfairness/deception standards.observed
  2. ConfirmedOneTrust DataGuidanceThe Act to Protect the Privacy of Online Customer Information requires broadband ISPs to obtain a customer's affirmative, opt-in consent before using, disclosing, selling, or permitting access to customer personal information, and prohibits tying consent to financial incentives or penalties.observed
  3. ProbableFederal Trade CommissionMaine has no standalone special-category (sensitive data) statute; sensitive health data is addressed at the federal level through HIPAA rather than a Maine-specific sensitive-data regime.observed

#

Only a narrow, sector-specific revocation right exists; no general DSAR/erasure/portability framework.

Primary frameworkAct to Protect the Privacy of Online Customer Information (Title 35-A §9301)
Supervisory authorityMaine Attorney General
Traffic-light rationale — RedOnly a narrow, sector-specific revocation right exists; no general DSAR/erasure/portability framework.

Sub-modules (5)

Access RightRed

No general access right exists outside the ISP-consent-revocation mechanism.

Claims (1):

  • Maine's Act to Protect the Privacy of Online Customer Information provides broadband customers a right to revoke previously given consent to use, disclosure or sale of their personal information, but does not establish general access, rectification, erasure or portability rights akin to GDPR/CCPA.

Rectification And ErasureRed

No general rectification or erasure right identified in Maine statute.

Restriction And ObjectionAmber

The ISP privacy law's consent-revocation right functions as a limited restriction/objection mechanism for broadband customer data only.

Claims (1):

  • Maine's Act to Protect the Privacy of Online Customer Information provides broadband customers a right to revoke previously given consent to use, disclosure or sale of their personal information, but does not establish general access, rectification, erasure or portability rights akin to GDPR/CCPA.

Data PortabilityRed

No data-portability right identified in Maine statute.

Deadlines And Response WindowsRed

No general statutory response-window regime exists for consumer rights requests in Maine.

Category narrative53 words

Maine confers no general access, rectification, erasure, restriction/objection, or portability rights. The only codified subject right is the ISP customer's right to revoke previously given consent under the broadband-privacy law. Searches conducted: 'Maine consumer right to delete data', 'Maine data subject access request law', 'Maine data portability statute' — no general-purpose statute located.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceMaine's Act to Protect the Privacy of Online Customer Information provides broadband customers a right to revoke previously given consent to use, disclosure or sale of their personal information, but does not establish general access, rectification, erasure or portability rights akin to GDPR/CCPA.observed

#

Meaningful breach-notification and sectoral security duties exist, but accountability/DPIA/DPO/ROPA concepts are entirely absent.

Primary frameworkMaine Notice of Risk to Personal Data Act (Title 10 §1346 et seq.); Maine Insurance Data Security Act
Supervisory authorityMaine Attorney General
Traffic-light rationale — AmberMeaningful breach-notification and sectoral security duties exist, but accountability/DPIA/DPO/ROPA concepts are entirely absent.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle statute identified.

Dpo RequirementsRed

No DPO appointment threshold or independence requirement identified in Maine law.

Ropa RequirementsRed

No records-of-processing requirement identified in Maine law.

Joint Controller ArrangementsRed

No joint-controller regime identified in Maine law.

Security MeasuresAmber

The ISP privacy law and the Insurance Data Security Act impose sector-specific technical/organisational security obligations.

Claims (1):

  • The Act to Protect the Privacy of Online Customer Information requires broadband ISPs to implement reasonable measures to protect customer personal information from unauthorized use, disclosure or access, calibrated to the nature and sensitivity of the data and the size of the provider.

Breach NotificationAmber

The Notice of Risk to Personal Data Act and the Insurance Data Security Act together form Maine's breach-notification regime.

Claims (2):

  • Maine's Notice of Risk to Personal Data Act (Title 10 §1346 et seq.) requires notification of security breaches involving unencrypted personal information of Maine residents, with additional sector-specific notification obligations for insurance licensees under the Maine Insurance Data Security Act.
  • The Maine Insurance Data Security Act establishes exclusive standards for investigating and notifying the Superintendent of Insurance of a cybersecurity event affecting licensees, and requires licensees to maintain a written information security program.

Retention And DisposalRed

No general retention/disposal mandate identified outside sector-specific insurance rules.

Category narrative50 words

No general accountability/DPIA, DPO, ROPA, or joint-controller framework exists in Maine. Security-of-processing and breach-notification duties exist through the general breach-notification statute and, for insurers, the Insurance Data Security Act. Searches conducted: 'Maine data protection impact assessment law', 'Maine DPO requirement statute', 'Maine records of processing activities law' — none located.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceThe Act to Protect the Privacy of Online Customer Information requires broadband ISPs to implement reasonable measures to protect customer personal information from unauthorized use, disclosure or access, calibrated to the nature and sensitivity of the data and the size of the provider.observed
  2. ConfirmedOneTrust DataGuidanceMaine's Notice of Risk to Personal Data Act (Title 10 §1346 et seq.) requires notification of security breaches involving unencrypted personal information of Maine residents, with additional sector-specific notification obligations for insurance licensees under the Maine Insurance Data Security Act.observed
  3. ConfirmedOneTrust DataGuidanceThe Maine Insurance Data Security Act establishes exclusive standards for investigating and notifying the Superintendent of Insurance of a cybersecurity event affecting licensees, and requires licensees to maintain a written information security program.observed

#

No state-level transfer or localisation regime exists; matters are governed only by general federal law and contract.

Traffic-light rationale — RedNo state-level transfer or localisation regime exists; matters are governed only by general federal law and contract.

Sub-modules (6)

Transfer MechanismsRed

No Maine-specific transfer mechanism identified.

Adequacy ReceivedRed

Not applicable at state level; adequacy determinations are a national/federal or foreign-regime concept, not issued by Maine.

Adequacy GrantedRed

Not applicable; Maine issues no adequacy determinations.

Sccs And BcrsRed

No Maine-specific SCC/BCR framework identified.

Transfer Impact AssessmentRed

No TIA requirement identified in Maine law.

Data LocalisationRed

No data-localisation mandate identified in Maine law.

Category narrative45 words

No Maine-specific cross-border transfer mechanism, adequacy determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate was identified; this is consistent with Maine's lack of an omnibus privacy statute. Searches conducted: 'Maine data localisation law', 'Maine cross-border data transfer statute', 'Maine adequacy determination' — no results found.

#

Insurance and telecoms sectors have dedicated Maine statutes; other listed sectors rely solely on federal law.

Primary frameworkMaine Insurance Data Security Act; Act to Protect the Privacy of Online Customer Information (Title 35-A §9301)
Traffic-light rationale — AmberInsurance and telecoms sectors have dedicated Maine statutes; other listed sectors rely solely on federal law.

Sub-modules (7)

Financial Sector OverlayAmber

Financial institutions are exempted from the ISP privacy law where already subject to the federal Gramm-Leach-Bliley Act.

Claims (1):

  • Financial institutions and their affiliates subject to the federal Gramm-Leach-Bliley Act are exempted from Maine's Act to Protect the Privacy of Online Customer Information.

Health Sector OverlayAmber

Health-sector data is governed by federal HIPAA rather than a Maine-specific statute; HIPAA-regulated entities are exempted from the ISP privacy law.

Claims (1):

  • Entities subject to the federal Health Insurance Portability and Accountability Act of 1996 are exempted from Maine's Act to Protect the Privacy of Online Customer Information, reflecting reliance on HIPAA rather than a Maine-specific health-privacy statute.

Telecoms And EprivacyAmber

The ISP privacy law is Maine's primary telecoms/eprivacy-style instrument, regulating broadband providers' use of customer data.

Claims (1):

  • Maine's Act to Protect the Privacy of Online Customer Information regulates broadband internet access service providers' use and disclosure of customer personal information.

Employment DataRed

No Maine-specific employment-data privacy statute identified; federal HIPAA/ADA/GINA penumbral protections apply as elsewhere in the US.

Credit And ScoringRed

No Maine-specific credit-scoring privacy statute identified; federal FCRA applies nationally.

EducationRed

No Maine-specific K-12 student-data-privacy statute was confirmed in this research pass; federal FERPA applies as the baseline.

InsuranceAmber

The Maine Insurance Data Security Act imposes dedicated data-security and breach standards on insurance licensees.

Claims (1):

  • The Maine Insurance Data Security Act (LD 51, signed 17 March 2021) imposes data-security, investigation and notification standards on insurance licensees operating in Maine.
Category narrative68 words

Maine's most developed data-protection rules are sectoral: broadband-ISP privacy (Title 35-A §9301) and insurance data security (Maine IDSA). Health and financial data are governed primarily by federal HIPAA and GLBA respectively, with Maine's ISP law expressly carving out GLBA/HIPAA-regulated entities. No Maine-specific employment, credit-scoring, or education sectoral privacy statute was identified. Searches conducted: 'Maine employment data privacy law', 'Maine credit scoring privacy statute', 'Maine student data privacy law'.

Sources and claims (4)
  1. ProbableIAPPFinancial institutions and their affiliates subject to the federal Gramm-Leach-Bliley Act are exempted from Maine's Act to Protect the Privacy of Online Customer Information.observed
  2. ProbableIAPPEntities subject to the federal Health Insurance Portability and Accountability Act of 1996 are exempted from Maine's Act to Protect the Privacy of Online Customer Information, reflecting reliance on HIPAA rather than a Maine-specific health-privacy statute.observed
  3. ConfirmedOneTrust DataGuidanceMaine's Act to Protect the Privacy of Online Customer Information regulates broadband internet access service providers' use and disclosure of customer personal information.observed
  4. ConfirmedOneTrust DataGuidanceThe Maine Insurance Data Security Act (LD 51, signed 17 March 2021) imposes data-security, investigation and notification standards on insurance licensees operating in Maine.observed

#

No general adtech/commercial-privacy statute exists beyond the narrow ISP consent rule.

Primary frameworkAct to Protect the Privacy of Online Customer Information (Title 35-A §9301)
Supervisory authorityMaine Attorney General
Traffic-light rationale — RedNo general adtech/commercial-privacy statute exists beyond the narrow ISP consent rule.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-specific statute identified.

Dark PatternsRed

No dark-pattern prohibition identified in Maine law.

Opt Out SignalsRed

No statutory recognition of universal opt-out signals (e.g., GPC) identified in Maine law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regulation identified.

Cross Context AdvertisingRed

No cross-context-advertising or 'sale'/'share' framework identified; the ISP consent rule is the closest analogue but is sector-limited.

Claims (1):

  • Maine has no state-level comprehensive cookie-consent, dark-pattern, or cross-context-advertising statute; the closest analogue is the sector-specific opt-in consent regime for broadband ISPs under Title 35-A §9301, which does not extend to general online advertising or cross-context data sharing.

Direct MarketingRed

No general direct-marketing consent/suppression statute identified.

Category narrative59 words

Maine has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, clean-room regulation, or cross-context-advertising ('sale'/'share') regime. The only relevant consent mechanism is the ISP opt-in rule, which does not extend to general online advertising or direct marketing. Searches conducted: 'Maine cookie consent law', 'Maine dark patterns statute', 'Maine Global Privacy Control law', 'Maine direct marketing opt-out law'.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceMaine has no state-level comprehensive cookie-consent, dark-pattern, or cross-context-advertising statute; the closest analogue is the sector-specific opt-in consent regime for broadband ISPs under Title 35-A §9301, which does not extend to general online advertising or cross-context data sharing.observed

#

A notable government-use facial-recognition ban exists, but commercial biometrics, ADM transparency, and AI-risk-assessment concepts remain unregulated.

Primary frameworkLD 1585, An Act to Increase Privacy and Security by Regulating the Use of Facial Surveillance Systems by Departments, Public Employees and Public Officials
Supervisory authorityMaine Attorney General
Traffic-light rationale — AmberA notable government-use facial-recognition ban exists, but commercial biometrics, ADM transparency, and AI-risk-assessment concepts remain unregulated.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction statute analogous to GDPR Art 22 identified.

Automated Decision Making TransparencyRed

No ADM transparency/explanation-right statute identified.

Ai Risk AssessmentsRed

No AI-specific risk-assessment statute identified at Maine state level.

Biometric RegimeAmber

LD 1585 bans government departments/officials from using or possessing facial-recognition technology, with narrow exceptions; commercial biometric use remains unregulated.

Claims (2):

  • Maine's LD 1585, An Act to Increase Privacy and Security by Regulating the Use of Facial Surveillance Systems by Departments, Public Employees and Public Officials, prohibits state, county and municipal departments, employees and officials from using or possessing facial recognition technology, with narrow statutory exceptions, and took effect 1 October 2021.
  • Maine's facial-surveillance law applies to government use only and does not regulate private-sector or commercial biometric data collection, leaving commercial biometric processing largely unregulated at the state level.

Genetic DataRed

No Maine-specific genetic-data privacy statute identified in this research pass.

State Surveillance CarveoutsAmber

LD 1585 is itself a surveillance-limiting statute rather than a carve-out; it restricts, rather than exempts, government facial-surveillance use.

Claims (1):

  • Maine's LD 1585, An Act to Increase Privacy and Security by Regulating the Use of Facial Surveillance Systems by Departments, Public Employees and Public Officials, prohibits state, county and municipal departments, employees and officials from using or possessing facial recognition technology, with narrow statutory exceptions, and took effect 1 October 2021.
Category narrative53 words

Maine has enacted one of the strongest state-level facial-recognition restrictions in the US (LD 1585), but this applies only to government use, not private/commercial biometric processing. No profiling-restriction, ADM-transparency, AI-risk-assessment, or genetic-data statute was identified at state level. Searches conducted: 'Maine automated decision-making law', 'Maine AI risk assessment statute', 'Maine genetic privacy law'.

Sources and claims (2)
  1. ConfirmedIAPPMaine's LD 1585, An Act to Increase Privacy and Security by Regulating the Use of Facial Surveillance Systems by Departments, Public Employees and Public Officials, prohibits state, county and municipal departments, employees and officials from using or possessing facial recognition technology, with narrow statutory exceptions, and took effect 1 October 2021.observed
  2. ProbableIAPPMaine's facial-surveillance law applies to government use only and does not regulate private-sector or commercial biometric data collection, leaving commercial biometric processing largely unregulated at the state level.observed

#

Federal COPPA provides a baseline; state-specific enhancements remain only proposed (LD 1822).

Primary frameworkChildren's Online Privacy Protection Act (COPPA), 16 CFR Part 312 (federal)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal COPPA provides a baseline; state-specific enhancements remain only proposed (LD 1822).

Sub-modules (5)

Age VerificationAmber

No Maine-specific age-verification statute identified; COPPA's under-13 threshold applies federally.

Claims (1):

  • Children's online-privacy protection in Maine is governed by the federal COPPA framework, which requires operators of child-directed websites/services to obtain verifiable parental consent before collecting personal information from children under 13; Maine has no state-specific parental-consent or age-verification statute supplementing COPPA.

Minor Profiling BansRed

No minor-profiling ban currently in force in Maine; LD 1822 proposes enhanced children's-privacy protections if enacted.

Claims (1):

  • The pending Maine Online Data Privacy Act (LD 1822) would introduce enhanced children's-privacy protections modeled on Maryland's comprehensive framework, but has not been enacted as of the most recent reporting available.

Education SettingsRed

No Maine-specific education-sector student-data statute was confirmed in this research pass; federal FERPA applies as baseline.

Dependent AdultsRed

No dependent-adult-specific data-protection statute identified in Maine law.

Category narrative64 words

Children's online-data protection in Maine rests on the federal COPPA framework; Maine has no state-specific age-verification, parental-consent, or minor-profiling statute currently in force. The pending LD 1822 would add enhanced children's-privacy protections modeled on Maryland's framework, but is not yet enacted. No dependent-adult-specific data-protection statute was identified. Searches conducted: 'Maine children online privacy law', 'Maine minor data protection statute', 'Maine dependent adult data privacy'.

Sources and claims (2)
  1. ConfirmedFederal Trade CommissionChildren's online-privacy protection in Maine is governed by the federal COPPA framework, which requires operators of child-directed websites/services to obtain verifiable parental consent before collecting personal information from children under 13; Maine has no state-specific parental-consent or age-verification statute supplementing COPPA.observed
  2. ProbableIAPPThe pending Maine Online Data Privacy Act (LD 1822) would introduce enhanced children's-privacy protections modeled on Maryland's comprehensive framework, but has not been enacted as of the most recent reporting available.observed

#

Active AG enforcement of breach law exists, but no dedicated data-privacy penalty schedule or private right of action.

Primary frameworkMaine Notice of Risk to Personal Data Act; general Maine consumer-protection authority
Supervisory authorityMaine Attorney General
Traffic-light rationale — AmberActive AG enforcement of breach law exists, but no dedicated data-privacy penalty schedule or private right of action.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG enforces via general consumer-protection powers; the ISP privacy law lacks an explicit dedicated enforcement mechanism.

Claims (1):

  • The Maine Attorney General enforces the state's consumer-protection and data-breach laws under general state consumer-protection authority; the Act to Protect the Privacy of Online Customer Information notably lacks an explicit statutory enforcement mechanism of its own.

Enforcement Activity IndexAmber

The AG actively tracks and announces large-scale breaches under the breach-notification statute.

Claims (1):

  • The Maine Attorney General has previously announced large-scale data breaches, such as the Managed Care of North America breach affecting approximately 8.9 million individuals disclosed in May 2023, reflecting active use of the state's breach-notification reporting regime.

Regulator Funding And CapacityAmber

LD 1822 (if enacted) proposes updates to AG enforcement funding specific to comprehensive privacy enforcement; no current dedicated funding line was identified for existing sectoral statutes.

Claims (1):

  • As of March 2026, the Maine Legislature advanced LD 1822, the Maine Online Data Privacy Act, through Senate passage (20-14) with a proposed 1 September 2027 effective date and updated AG enforcement funding provisions, representing the most significant potential change to Maine's data-protection landscape, though it had not received final enactment as of this run.

Collective Redress And Class ActionsRed

No Maine-specific collective-redress mechanism for data-privacy claims was identified beyond general state consumer-class-action rules.

Private Right Of ActionRed

Maine's ISP privacy law does not create a private right of action; enforcement is limited to AG authority.

Claims (1):

  • Maine's Act to Protect the Privacy of Online Customer Information does not create a private right of action for consumers; enforcement is limited to the Attorney General's general consumer-protection authority.

Recent Developments 180DAmber

The most significant recent development is the continued advancement of LD 1822 through the Legislature (Senate passage 5 March 2026), not yet enacted.

Claims (1):

  • As of March 2026, the Maine Legislature advanced LD 1822, the Maine Online Data Privacy Act, through Senate passage (20-14) with a proposed 1 September 2027 effective date and updated AG enforcement funding provisions, representing the most significant potential change to Maine's data-protection landscape, though it had not received final enactment as of this run.
Category narrative69 words

The Maine Attorney General enforces the state's data-breach and consumer-protection statutes but lacks a defined civil-penalty schedule specific to data privacy comparable to omnibus-state laws; the ISP privacy law notably lacks its own enforcement mechanism. There is no general private right of action for data-privacy violations in Maine. LD 1822, if enacted, would add AG enforcement funding provisions. Recent development: LD 1822 advanced through Senate passage in March 2026.

Sources and claims (4)
  1. ConfirmedIAPPThe Maine Attorney General enforces the state's consumer-protection and data-breach laws under general state consumer-protection authority; the Act to Protect the Privacy of Online Customer Information notably lacks an explicit statutory enforcement mechanism of its own.observed
  2. ConfirmedOneTrust DataGuidanceThe Maine Attorney General has previously announced large-scale data breaches, such as the Managed Care of North America breach affecting approximately 8.9 million individuals disclosed in May 2023, reflecting active use of the state's breach-notification reporting regime.observed
  3. ProbableIAPPAs of March 2026, the Maine Legislature advanced LD 1822, the Maine Online Data Privacy Act, through Senate passage (20-14) with a proposed 1 September 2027 effective date and updated AG enforcement funding provisions, representing the most significant potential change to Maine's data-protection landscape, though it had not received final enactment as of this run.observed
  4. ProbableIAPPMaine's Act to Protect the Privacy of Online Customer Information does not create a private right of action for consumers; enforcement is limited to the Attorney General's general consumer-protection authority.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Maine
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressprivate right of action
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, children_and_vulnerable_groups, and algorithmic_biometric_and_surveillance_governance drew on T1 primary sources (FTC.gov, NAAG/Maine AG) for their strongest claims. lawful_processing_and_special_data, data_subject_rights, sectoral_watch, adtech_and_commercial_privacy, controller_processor_duties, and enforcement_and_redress relied predominantly on T3 secondary commentary (IAPP, OneTrust DataGuidance) because the underlying Maine statutory text (mainelegislature.gov / legislature.maine.gov) was not directly fetchable in this pass. cross_border_and_adequacy carries no claims and is supported only by absent_field_provenance, consistent with the seed's disambiguation that Maine has no comprehensive regime. The pending LD 1822 (Maine Online Data Privacy Act) was tracked as a non-binding, proposed development across regulator_and_framework, children_and_vulnerable_groups, and enforcement_and_redress.

Unresolved questions (4):

  • Has LD 1822 (Maine Online Data Privacy Act) received House concurrence and gubernatorial action since the 5 March 2026 Senate vote?
  • What are the exact statutory day-count deadlines for breach notification under Title 10 §1346 et seq. (primary text not independently fetched)?
  • Does any Maine student-data-privacy statute (FERPA-style state law) exist that was not surfaced in this research pass?
  • Is there a Maine genetic-information-privacy statute analogous to those in neighboring New England states?

Escalate to primary-source review: yes