#
Fragmented sectoral framework with an active AG enforcer, but no omnibus statute currently in force.
Sub-modules (5)
Regulator And AuthorityAmber
The Maine AG is the primary state enforcer for consumer-protection and breach-notification matters; the FTC is the concurrent federal enforcer under Section 5.
Claims (1):
- The Maine Attorney General is the primary state enforcement authority for consumer data-protection matters in Maine, including breach notification and general consumer-protection statutes.
Act And InstrumentsAmber
Instruments include the Notice of Risk to Personal Data Act, the Maine Insurance Data Security Act, the Act to Protect the Privacy of Online Customer Information, and the pending LD 1822.
Claims (4):
- Maine has no comprehensive consumer-privacy statute; data protection is governed by a patchwork of the federal FTC Act Section 5, sectoral federal laws (HIPAA, GLBA, COPPA), and Maine's own sector-specific and breach-notification statutes.
- The Maine Notice of Risk to Personal Data Act, found at §1346 et seq. of Chapter 210-B, Part 3 of Title 10 of the Maine Revised Statutes, establishes the state's data breach notification requirement.
- The Maine Insurance Data Security Act (LD 51) was signed into law on 17 March 2021, establishing data-security standards and exclusive investigation/notification standards for cybersecurity events applicable to insurance licensees.
- The Maine Online Data Privacy Act (LD 1822), a comprehensive consumer-privacy bill modeled on Maryland's framework, passed the Maine Senate 20-14 on 5 March 2026 with a proposed 1 September 2027 effective date, but had not received final House concurrence or gubernatorial signature as of the most recent reporting available.
Material ScopeAmber
Material scope is defined narrowly per-instrument (e.g., computerized personal information for breach law; broadband customer information for the ISP law) rather than by a single omnibus definition.
Claims (1):
- Maine's breach-notification statute applies to computerized personal information of Maine residents held by entities that own, license, or maintain such data.
Territorial ScopeAmber
Territorial scope is instrument-specific; the ISP privacy law applies to providers billing Maine-located customers rather than to controllers generally.
Claims (1):
- The Act to Protect the Privacy of Online Customer Information applies to broadband internet access service providers serving customers physically located in and billed for service in Maine, rather than to controllers generally.
Regulator Registration And FilingAmber
No general controller registration/filing regime exists outside the insurance sector, where the IDSA imposes filing obligations to the Superintendent of Insurance.
Claims (1):
- Maine does not impose a general controller registration or filing obligation on data controllers outside the insurance sector; the Maine Insurance Data Security Act requires certain filings by insurance licensees to the Superintendent of Insurance.
Sources and claims (8)
- ConfirmedNAAG Attorney General Journal — The Maine Attorney General is the primary state enforcement authority for consumer data-protection matters in Maine, including breach notification and general consumer-protection statutes.observed
- ConfirmedFederal Trade Commission — Maine has no comprehensive consumer-privacy statute; data protection is governed by a patchwork of the federal FTC Act Section 5, sectoral federal laws (HIPAA, GLBA, COPPA), and Maine's own sector-specific and breach-notification statutes.observed
- ConfirmedOneTrust DataGuidance — The Maine Notice of Risk to Personal Data Act, found at §1346 et seq. of Chapter 210-B, Part 3 of Title 10 of the Maine Revised Statutes, establishes the state's data breach notification requirement.observed
- ConfirmedOneTrust DataGuidance — The Maine Insurance Data Security Act (LD 51) was signed into law on 17 March 2021, establishing data-security standards and exclusive investigation/notification standards for cybersecurity events applicable to insurance licensees.observed
- ProbableIAPP — The Maine Online Data Privacy Act (LD 1822), a comprehensive consumer-privacy bill modeled on Maryland's framework, passed the Maine Senate 20-14 on 5 March 2026 with a proposed 1 September 2027 effective date, but had not received final House concurrence or gubernatorial signature as of the most recent reporting available.observed
- ProbableOneTrust DataGuidance — Maine's breach-notification statute applies to computerized personal information of Maine residents held by entities that own, license, or maintain such data.observed
- ConfirmedOneTrust DataGuidance — The Act to Protect the Privacy of Online Customer Information applies to broadband internet access service providers serving customers physically located in and billed for service in Maine, rather than to controllers generally.observed
- ProbableOneTrust DataGuidance — Maine does not impose a general controller registration or filing obligation on data controllers outside the insurance sector; the Maine Insurance Data Security Act requires certain filings by insurance licensees to the Superintendent of Insurance.observed