Maine
Maine Data Privacy Laws: ISP Privacy & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 18 primary sources cited on this page. How we verify our legal content

Maine protects resident data through a set of sector-specific statutes rather than a single comprehensive privacy law. The most distinctive is 35-A MRSA 9301, which requires broadband internet service providers to obtain opt-in consent before using or selling customer data. Maine is the only state with this requirement.
Maine has built one of the most distinctive data privacy frameworks in the United States. In 2019, the state became the first and only state to require internet service providers to obtain opt-in consent before using or selling customer data. In 2021, Maine enacted the nation's strongest government facial recognition ban. These landmark laws sit alongside data breach notification requirements, student data protections, health information rules, and a new employer surveillance law that took effect in summer 2026.
Maine does not have a comprehensive consumer data privacy law. Three bills failed in the 2025-2026 legislative session: LD 1822 died on April 13, 2026, after the House refused to concur on Senate amendments; LD 1088 and LD 1224 each received Ought Not To Pass recommendations in June 2025. This guide covers every Maine privacy statute in force, your rights as a resident, business obligations, and what federal law adds on top.
Maine's ISP Privacy Law (35-A MRSA 9301)
The Act to Protect the Privacy of Online Customer Information, signed by Governor Janet Mills on June 6, 2019, created 35-A MRSA Chapter 94. The law took effect on July 1, 2020, and it remains unique among all fifty states.

Why This Law Is Unique
Maine is the only state in the country that requires broadband internet service providers to get affirmative, opt-in consent from customers before using, disclosing, selling, or permitting access to their personal information. Every other state with consumer privacy protections, including California, uses an opt-out model where companies can collect and use data unless the consumer takes action to stop it.
Under Maine's approach, all ISP customers are protected by default without taking any action. The burden falls entirely on the provider to obtain express consent.
Who the Law Applies To
The law applies to any provider of broadband Internet access service operating in Maine and serving customers physically located in the state. Broadband internet access service is defined as a mass-market retail service by wire or radio that provides the capability to transmit data to and receive data from all or substantially all internet endpoints. Dial-up internet access service is excluded.
What Information Is Protected
The law defines customer personal information broadly in two categories.
Personally identifying information includes a customer's name, billing address, Social Security number, and other direct identifiers.
Usage-based information includes web browsing history, application usage history, precise geolocation information, financial information, health information, information about children, device identifiers, and the content of communications.
This scope is far wider than many state privacy laws because it covers not just who you are but everything you do online through your ISP connection.
Core Prohibitions
A broadband provider may not use, disclose, sell, or permit access to customer personal information unless the customer expressly consents to that use, disclosure, sale, or access.
Critically, the law also prohibits providers from penalizing customers who refuse consent. A provider cannot refuse to serve a customer, charge a penalty, or offer a discount based on whether a customer consents to the use of their data. This prevents "pay for privacy" arrangements that undermine opt-in protections.
Permitted Uses Without Consent
Providers may access customer personal information without consent for a limited set of purposes: providing the broadband service itself, marketing communications services directly to the customer, complying with court orders or other legal process, billing and collecting payment, preventing fraud, and providing emergency services.
Security and Transparency Requirements
Providers must take reasonable measures to protect customer personal information from unauthorized use, disclosure, or access, considering the nature and scope of the provider's activities, the sensitivity of the data, and the current state of technology.
Every provider must also give customers a clear, conspicuous, and nondeceptive notice at the point of sale and on the provider's publicly accessible website explaining the provider's obligations and the customer's rights under the law.
Enforcement
Chapter 94 designates no enforcement agency. The enacted text sets out what a provider must and must not do, but it contains no penalty schedule, no express enforcement provision, and no grant of rulemaking authority to any agency. It also creates no complaint procedure, so there is no statutory route for a customer to report a violation of this section specifically.
Data Breach Notification Law (10 MRSA Chapter 210-B)
Maine's Notice of Risk to Personal Data Act, codified at 10 MRSA 1346-1350, establishes the state's data breach notification requirements. The law was amended in 2019 when municipalities and school administrative units were added to the list of covered entities.

What Triggers a Notification
A security breach is defined as the unauthorized acquisition, release, or use of an individual's computerized data that includes personal information and that compromises the security, confidentiality, or integrity of that information.
Good faith acquisition, release, or use of personal information by an employee or agent acting on behalf of the entity does not qualify as a breach, provided the information is not used for or subject to further unauthorized disclosure.
What Counts as Personal Information
Under 10 MRSA 1347, personal information means an individual's first name or first initial and last name combined with one or more of the following data elements when the data is not encrypted or redacted:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number (in combination with any required security code, access code, or password)
The definition excludes publicly available government records and third-party insurance claims databases.
Notification Timeline
Entities must provide notification as expediently as possible and without unreasonable delay, but no more than 30 days after becoming aware of the breach and identifying its scope.
Entities must also notify the appropriate state regulators within the Department of Professional and Financial Regulation, or, if not regulated by that department, the Attorney General, whenever notice to affected residents is required. The statute does not set a separate deadline for this regulator notice.
If law enforcement determines that notification would compromise a criminal investigation, the entity may delay notification. Once law enforcement clears the notification, it must be sent within 7 business days.
Who Must Be Notified
Affected Maine residents whose personal information was compromised in the breach must receive notice.
The Maine Attorney General or the appropriate state regulator must be notified whenever notice to affected residents is required; the statute does not set a separate deadline for this notice.
Consumer reporting agencies must be notified when the breach requires notification to more than 1,000 persons at a single time. At exactly 1,000, this duty does not attach.
Third-party data holders that maintain personal information on behalf of another person must immediately notify the data owner when a breach is discovered, so the data owner can begin its own notification obligations.
Methods of Notification
Entities can notify affected individuals through written notice, electronic notice (compliant with the federal E-SIGN Act at 15 U.S.C. 7001), or substitute notice.
Substitute notice is permitted when the cost of direct notification exceeds $5,000, when more than 1,000 individuals must be notified, or when the entity lacks sufficient contact information. Substitute notice requires a combination of email notification, conspicuous posting on the entity's website, and notification through statewide media.
Penalties for Violations
Under 10 MRSA 1349, violations carry civil penalties of up to $500 per violation, up to a maximum of $2,500 per day a person remains in violation. Government entities and public educational institutions are exempt from monetary penalties.
The Attorney General enforces the law for most entities, while the Department of Professional and Financial Regulation enforces it for licensees and regulated entities.
There is an important safe harbor provision. Entities that comply with federal or state data security breach notification requirements that meet or exceed the standards in section 1348 are deemed in compliance with the Maine law.
Businesses can report breaches to the state through the Maine AG Data Security Breaches page or the Maine Bureau of Insurance breach notification form.
Government Facial Recognition Ban (25 M.R.S. 6001)
Maine enacted 25 M.R.S. 6001 in 2021 as the nation's strongest government facial recognition restriction. The law was approved unanimously by the Maine House and Senate on June 16 and 17, 2021, enacted unsigned on July 1, 2021, and took effect October 1, 2021.
Scope: Who Is Covered
The prohibition applies to all state, county, and municipal government departments, agencies, and their employees and officials. This includes law enforcement agencies. The ban extends to all government subdivisions and public instrumentalities. Private sector use of facial recognition is not restricted by this statute.
What Is Prohibited
No government department or official may use or possess facial surveillance technology, or enter into any agreement with a third party to obtain, access, or use such technology. Facial surveillance is defined as any automated or semi-automated process that assists in identifying or verifying an individual, or in capturing information about an individual, based on the physical characteristics of the individual's face.
Any data obtained through facial surveillance in violation of this section must be deleted upon discovery and is inadmissible in any proceeding before any public official, department, regulatory body, or authority.
Limited Law Enforcement Exception
Law enforcement agencies may request a facial recognition search when investigating a defined "serious crime" (generally one punishable by a year or more in prison, or specific listed lesser offenses) and there is probable cause to believe an unidentified person depicted in an image committed it. The same exception also covers requests made to identify a deceased person or a missing or endangered person. A request to search Maine's own facial surveillance system must go to the Bureau of Motor Vehicles. A request reaching another state's credentialing agency or the FBI must generally be routed through the State Police, except in an emergency posing imminent danger of death or serious injury, or when the Bureau of Motor Vehicles itself requests such a search for fraud prevention or investigation. The results of any search may not be used as the sole basis for establishing probable cause to arrest or for obtaining a search warrant.
Remedies
A person injured or aggrieved by a violation may bring an action for injunctive or declaratory relief or a writ of mandamus. A public employee or official who violates the law may be subject to disciplinary action, including retraining, suspension, or termination.
Maine's Comprehensive Privacy Bill Failures (2025-2026)
Maine does not have a comprehensive consumer data privacy law in force. Three bills attempted to establish one in the 132nd Legislature's 2025-2026 session; all three failed.
LD 1822 (Maine Online Data Privacy Act): Introduced by Rep. Amy Kuhn (D-Falmouth), LD 1822 passed the House on February 10, 2026, and the Senate on March 5, 2026 (18-16). Because the Senate amended the bill, it returned to the House for concurrence. On April 9, 2026, the House voted not to recede and concur on the Senate's amendments. The bill was placed in Legislative Files as DEAD on April 13, 2026.
LD 1088 (Maine Consumer Data Privacy Act): Referred to the Judiciary Committee, LD 1088 received a divided committee report in June 2025. The Ought Not To Pass recommendation was accepted on a roll-call vote of 18 Yeas to 14 Nays. That vote gave LD 1088 a final disposition of Accepted Report A (ONTP) on June 25, 2025, closing out the bill for that session rather than carrying it forward.
LD 1224 (An Act to Comprehensively Protect Consumer Privacy): The Judiciary Committee reported LD 1224 with an Ought Not To Pass recommendation on June 16, 2025, and the bill received a final disposition of Ought Not To Pass Pursuant To Joint Rule 310 on June 17, 2025.
The failure of all three bills leaves Maine without comprehensive consumer-facing data rights covering most private-sector businesses, beyond the sectoral statutes described in this article. Legislation may be re-introduced in future sessions.
Maine Right to Repair Data Law
In November 2023, Maine voters approved Question 4 (the Right to Repair Law) by an 84% margin. The law requires automakers selling vehicles in Maine to provide owners and independent repair shops with access to mechanical data from those vehicles through an owner-authorized, standardized, interoperable platform.
The implementation has been disputed. The Alliance for Automotive Innovation filed suit in January 2025 challenging Attorney General Aaron Frey's enforcement of the law, arguing that compliance is impossible because the Attorney General has not designated the "independent entity" the law requires to establish the standardized access platform. A Right to Repair Working Group convened by the Legislature has been considering proposed amendments and recommendations.
Student Information Privacy Act (20-A MRSA Chapter 13)
Maine enacted the Student Information Privacy Act in 2015, with amendments in 2017 to expand protections. The law regulates how online service operators, educators, and third parties collect and use the personal information of K-12 students enrolled in Maine educational institutions.

Prohibited Activities
Under 20-A MRSA 953, an operator may not knowingly do any of the following without explicit written or electronic consent from a student's parent or an eligible student:
- Sell student data. Operators cannot sell student data, though acquisitions by successor entities are permitted if the restrictions continue to apply.
- Engage in targeted advertising. Operators cannot use student data to deliver targeted advertising on their own platform or any other website.
- Build non-educational profiles. Operators cannot create profiles of students unless the profiles are used strictly for K-12 educational purposes.
- Disclose personally identifiable information except for advancing educational purposes, complying with legal requirements, responding to judicial process, protecting security, ensuring user safety, or sharing with service providers under contractual restrictions.
Security and Data Deletion
Operators must implement and maintain reasonable security procedures and practices to protect student data from unauthorized access, destruction, use, modification, and disclosure.
When a school requests deletion of student data, the operator must delete it within 45 days.
The Maine Department of Education provides guidance on student data privacy compliance, and the state participates in the Maine Student Privacy Alliance.
Health Care Information Confidentiality (22 MRSA 1711-C)
Maine's health care information confidentiality law, codified at 22 MRSA 1711-C, provides protections that supplement federal HIPAA requirements. The law applies to health care practitioners, facilities, pharmacies, home health providers, and hospice programs operating in Maine.
What Is Protected
The law protects health care information, defined as data that identifies an individual and relates to their physical, mental, or behavioral condition, medical history, or treatment received. This includes genetic information and individual cell components.
Consent Requirements
Written authorization requires a signed document specifying the recipient, the type of information, the purpose of disclosure, and the duration of the authorization (maximum 30 months for general authorizations).
Oral authorization is permitted when written consent is impractical. The practitioner must document the authorizing person's name, date, the information disclosed, and recipient details.
Key Protections
The statute includes a critical restriction on reproductive and gender-affirming health care communications. These records cannot be disclosed in civil proceedings without written consent or a court order showing good cause.
Penalties: Intentional violations carry civil penalties of up to $5,000 plus costs. Repeated violations increase penalties to $10,000 for individual practitioners and $50,000 for facilities. Individuals may sue for injunctive relief and recover damages under common law.
The Maine DHHS Privacy Office provides guidance on compliance with both state and federal health information privacy requirements.
Employee Electronic Monitoring Law (LD 61)
Maine enacted LD 61, the Act to Regulate Employer Surveillance to Protect Workers. The law took effect around July 14, 2026, 90 days after the close of the legislative session, and is now in force.
Definition of Employer Surveillance
The law broadly defines employer surveillance as monitoring an employee through an electronic device or system, including computers, telephones, wire or radio systems, electromagnetic or photoelectronic systems, and similar technologies.
Prohibited Practices
Employers may not use audiovisual monitoring in an employee's residence, personal vehicle, or on the employee's private property unless the monitoring is required for duties of the job. Employers also cannot require employees to install surveillance software on personal devices, though they may request it. Employees have the right to decline.
Notice Requirements
Employers using surveillance must provide written notice: to prospective employees during the interview process, to all current employees at least once per calendar year, and before implementing any new surveillance systems.
The Maine Department of Labor has published a required workplace poster with employee surveillance rights.
Exemptions and Penalties
The law exempts security and safety camera systems, GPS tracking and vehicle safety systems installed on employer-owned vehicles, and monitoring in licensed personal care service settings. Violations carry a civil fine of $100 to $500 per violation, enforced by the Maine Department of Labor. Maine joins Connecticut, Delaware, and New York as one of four states regulating workplace electronic monitoring.
Federal Privacy Framework in Maine
Several federal statutes apply directly to individuals and businesses in Maine.

TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025): This federal law makes it a crime to knowingly publish nonconsensual intimate images or AI-generated sexual deepfakes of real people online. The criminal prohibitions took effect immediately upon signing. Platforms that host user-generated content must remove flagged material within 48 hours of a valid takedown notice. Platform obligations have been enforced by the FTC since May 19, 2026, with civil penalties up to $53,088 per violation. This law applies to Maine-based platforms and benefits Maine residents equally.
HIPAA governs health information held by covered entities and business associates, supplemented by Maine's 22 MRSA 1711-C.
FERPA protects student education records at institutions receiving federal education funding, supplemented by Maine's Student Information Privacy Act.
COPPA restricts online collection of personal information from children under 13. Maine's student privacy act extends additional protections in the K-12 context.
The Gramm-Leach-Bliley Act regulates financial institutions' collection and disclosure of consumer financial information, with enforcement by the FTC and federal financial regulators.
FTC Act Section 5 prohibits unfair or deceptive acts or practices. The FTC has brought enforcement actions against companies in all states for privacy and data-security failures based on this authority, independent of state law.
APRA (American Privacy Rights Act): A bicameral comprehensive federal privacy draft in 2024 did not pass. Revised versions were discussed in 2025. As of May 2026, no federal comprehensive consumer privacy law has been enacted.
Penalty Comparison Table
| Law | Statute | Penalty Per Violation | Maximum | Enforced By |
|---|---|---|---|---|
| ISP Privacy Law | 35-A MRSA 9301 | None specified | None specified | No agency designated by statute |
| Data Breach Notification | 10 MRSA 1348-1349 | Up to $500 | $2,500/day | AG / Dept. of Prof. & Financial Reg. |
| Health Information | 22 MRSA 1711-C | Up to $5,000 | $50,000 (facilities) | Courts / AG |
| Student Privacy | 20-A MRSA Ch. 13 | Statutory | Varies | AG |
| Employee Monitoring | LD 61 | $100-$500 | Per violation | Dept. of Labor |
| TAKE IT DOWN Act | Pub. L. 119-12 | Up to $53,088 | Per violation | FTC |
How to File a Data Privacy Complaint in Maine
If you believe your data privacy rights have been violated in Maine, you can file a complaint through the Maine Attorney General's Consumer Protection Division. The AG's office handles complaints related to data breaches, identity theft, and privacy violations.
For ISP-specific privacy concerns, note that the ISP privacy law names no enforcer and sets up no complaint process of its own. General consumer complaints about a provider's data practices can be raised through the Attorney General's Consumer Protection Division, which handles consumer complaints generally.
For workplace surveillance violations, now that LD 61 is in force, complaints should be filed with the Maine Department of Labor.
For health information violations, you can file complaints with the Maine DHHS Privacy Office or, where HIPAA applies, with the U.S. Department of Health and Human Services Office for Civil Rights.
More Maine Laws
Updates
Corrected the consumer reporting agency notice threshold to more than 1,000 persons, clarified that the 30-day breach notice clock runs from when the entity becomes aware of the breach and identifies its scope, and removed the unsupported statement that the Public Utilities Commission enforces Maine's ISP privacy law.
Corrected LD 1088's status (a final Ought Not To Pass vote on June 25, 2025, not a carryover to the next session), updated the employer-surveillance law (LD 61) and TAKE IT DOWN Act FTC-enforcement language from future to present tense now that both are in force, and restored the facial-recognition law's "serious crime" threshold, deceased/missing-person identification grounds, and State Police/BMV request routing.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the breach-notification timing for state regulators/Attorney General: 10 MRSA 1348(5) sets no 'immediately' deadline for that notice (the immediate-notice standard in the statute applies only to a third-party data holder notifying the data owner, not to AG/regulator notification).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maine Revised Statutes, Title 10: COMMERCE AND TRADE, Part 3: REGULATION OF TRADE, Chapter 210-B: NOTICE OF RISK TO PERSONAL DATA
§ 1348Security breach notice requirementsIn forcecited in 2 of our articles
1. Notification to residents. The following provisions apply to notification to residents by information brokers and other persons. A. If an information broker that maintains computerized data that includes personal information becomes aware of a breach of the security of the system, the information broker shall conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused and shall give notice of a breach of the security of the system following discovery or notification of the security breach to a resident of this State whose personal information has been, or is reasonably believed to have been, acquired by an unauthorized person. [PL 2005, c. 583, §6 (NEW); PL 2005, c. 583, §14 (AFF).] B.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.maine.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2012
Opinions citing this section in our collection:
- Digital Fed. Credit Union v. Hannaford Bros. Co. (Superior Court of Maine 2012)“…the possible misuse of that personalized information, see 10 M.R.S. § 1348 (2011), to date, the Legislature has n…”
- Digital Federal Credit Union v. Hannaford Brothers Co. (Superior Court of Maine 2012)“…the possible misuse of that personalized information, see 10 M.R.S. § 1348 (2011), to date, the Legislature has n…”
- In Re Hannaford Bros. Co. Customer Data Security Breach Litigation (District Court, D. Maine 2009, 613 F. Supp. 2d 108)“…ring on the claims asserted here. 80 . 10 M.R.S.A. § 1348(1). 81 .…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Maine Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 1349Enforcement; penaltiesIn forcecited in 2 of our articles
1. Enforcement. The appropriate state regulators within the Department of Professional and Financial Regulation shall enforce this chapter for any person that is licensed or regulated by those regulators. The Attorney General shall enforce this chapter for all other persons. 2. Civil violation. A person that violates this chapter commits a civil violation and is subject to one or more of the following: A. A fine of not more than $500 per violation, up to a maximum of $2,500 for each day the person is in violation of this chapter, except that this paragraph does not apply to State Government, municipalities, school administrative units, the University of Maine System, the Maine Community College System or Maine Maritime Academy; [PL 2019, c. 512, §3 (AMD).] B. Equitable relief; or [PL 2005, c. 379, §1 (NEW); PL 2005, c. 379, §4 (AFF).] C. Enjoinment from further violations of this chapter. [PL 2005, c. 379, §1 (NEW); PL 2005, c. 379, §4 (AFF).] 3. Cumulative effect. The rights and remedies available under this section are cumulative and do not affect or prevent rights and remedies available under federal or state law. 4. Exceptions.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.maine.gov
§ 1347DefinitionsIn forcecited in 3 of our articles
As used in this chapter, unless the context otherwise indicates, the following terms have the following meanings. [PL 2005, c. 379, §1 (NEW); PL 2005, c. 379, §4 (AFF).] 1. Breach of the security of the system. "Breach of the security of the system" or "security breach" means unauthorized acquisition, release or use of an individual's computerized data that includes personal information that compromises the security, confidentiality or integrity of personal information of the individual maintained by a person. Good faith acquisition, release or use of personal information by an employee or agent of a person on behalf of the person is not a breach of the security of the system if the personal information is not used for or subject to further unauthorized disclosure to another person. 2. Encryption. "Encryption" means the disguising of data using generally accepted practices. 3. Information broker.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.maine.gov
Also relied on in: Maine Biometric Privacy Laws: Facial Recognition Ban & Current Protections (2026)
Maine Revised Statutes, Title 25: INTERNAL SECURITY AND PUBLIC SAFETY, Part 14: SURVEILLANCE, Chapter 701: FACIAL SURVEILLANCE
§ 6001Facial surveillanceIn forcecited in 3 of our articles
1. Definitions. As used in this chapter, unless the context otherwise indicates, the following terms have the following meanings. A. "Another jurisdiction" has the same meaning as in Title 17‑A, section 2, subsection 3‑B. [PL 2021, c. 394, §1 (NEW).] B. "Bureau of Motor Vehicles" means the Department of the Secretary of State, Bureau of Motor Vehicles. [PL 2021, c. 394, §1 (NEW).] C. "Department" means a state, county or municipal government or a department, agency or subdivision thereof or any other entity identified in law as a public instrumentality, including, but not limited to, a law enforcement agency. [PL 2021, c. 394, §1 (NEW).] D. "Facial surveillance" means an automated or semi-automated process that assists in identifying or verifying an individual, or in capturing information about an individual, based on the physical characteristics of an individual's face. [PL 2021, c. 394, §1 (NEW).] E. "Facial surveillance system" means any computer software or application that performs facial surveillance. [PL 2021, c. 394, §1 (NEW).] F. "Law enforcement agency" has the same meaning as in section 3701, subsection 1. [PL 2021, c. 394, §1 (NEW).] G.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.maine.gov
Also relied on in: Maine Surveillance Camera Laws (2026 Guide)
Maine Revised Statutes, Title 20-A: EDUCATION, Part 1: GENERAL PROVISIONS, Chapter 13: THE STUDENT INFORMATION PRIVACY ACT
§ 953Restrictions on operator's use of student dataIn force
1. Prohibitions. An operator may not knowingly engage in any of the following activities with respect to the operator's website, service or application without explicit written or electronic consent from a student's parent or an eligible student: A. Use student data to engage in targeted advertising on the operator's website, service or application or targeted advertising on any other website, service or application when the targeting of the advertising is based upon any student data and state-assigned student identifiers or other persistent unique identifiers that the operator has acquired because of the use of the operator's website, service or application; [PL 2015, c. 256, §1 (NEW).] B. Use student data, including state-assigned student identifiers or other persistent unique identifiers, created or gathered by the operator to amass a profile of a student except for kindergarten to grade 12 school purposes. For purposes of this paragraph, "amass a profile" does not include collection and retention of account information that remains under the control of a student, parent or school administrative unit; [PL 2015, c. 256, §1 (NEW).] C. Sell student data.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.maine.gov
Maine Revised Statutes, Title 22: HEALTH AND WELFARE, Part 4: HOSPITALS AND MEDICAL CARE, Chapter 401: GENERAL PROVISIONS
§ 1711-CConfidentiality of health care informationIn forcecited in 3 of our articles
1. Definitions. As used in this section, unless the context otherwise indicates, the following terms have the following meanings. A. "Authorized representative of an individual" or "authorized representative" means an individual's legal guardian; agent pursuant to Title 18‑C, section 5‑803; agent pursuant to Title 18‑C, Article 5, Part 9; or other authorized representative or, after death, that person's personal representative or a person identified in subsection 3‑B. For a minor who has not consented to health care treatment in accordance with the provisions of state law, "authorized representative" means the minor's parent, legal guardian or guardian ad litem. [PL 2017, c. 402, Pt. C, §44 (AMD); PL 2019, c. 417, Pt. B, §14 (AFF).] A-1. "Authorization to disclose" means authorization to disclose health care information in accordance with subsection 3, 3‑A or 3‑B. [PL 1999, c. 512, Pt. A, §5 (NEW); PL 1999, c. 512, Pt. A, §7 (AFF).] A-2. "Aiding and assisting legally protected health care activity" has the same meaning as in Title 14, section 9002, subsection 1. [PL 2023, c. 648, Pt. F, §1 (NEW).] B.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.maine.gov
Cited in 19 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State of Maine v. Gregory S. Olah (Supreme Judicial Court of Maine 2018, 184 A.3d 360)“…5 See 22 M.R.S. § 1711-C (2017);5 34-B M.R.S. § 1207 (2017)…”
- Estate of Carol A. Kennelly v. Mid Coast Hospital (Supreme Judicial Court of Maine 2020, 2020 ME 115)“…d, and the panel now includes Justice Horton. 2 116-158); 22 M.R.S. § 1711-C (2020),1 or the physician-patient privi…”
- Saunders v. Tisher (Supreme Judicial Court of Maine 2006, 902 A.2d 830)“…edical devices or health care equipment and supplies .... 22 M.R.S. § 1711-C(1)(C) (2005). [¶ 12] The language of…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Maine Medical Recording Laws: Patient Rights, HIPAA, and Consent (2026), Maine Medical Records Retention Laws (2026 Guide)
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 35-A MRSA 9301: Privacy of Broadband Internet Access Service Customer Personal Information(legislature.maine.gov).gov
- Public Law Chapter 216: An Act To Protect the Privacy of Online Customer Information(legislature.maine.gov).gov
- Governor Mills Signs Internet Privacy Legislation (June 2019)(maine.gov).gov
- 10 MRSA 1347: Data Breach Notification Definitions(legislature.maine.gov).gov
- 10 MRSA 1348: Security Breach Notice Requirements(legislature.maine.gov).gov
- 10 MRSA 1349: Enforcement and Penalties for Breach Notification Violations(legislature.maine.gov).gov
- 25 M.R.S. 6001: Maine Facial Surveillance Government Ban(legislature.maine.gov).gov
- Maine AG: Data Security Breaches (Consumer Protection)(maine.gov).gov
- Maine AG: Consumer Protection - Privacy, Identity Theft and Data Security Breaches(maine.gov).gov
- Maine Bureau of Insurance: Breach Notification Form(maine.gov).gov
- 20-A MRSA Chapter 13: The Student Information Privacy Act(legislature.maine.gov).gov
- 20-A MRSA 953: Restrictions on Operator Use of Student Data(legislature.maine.gov).gov
- Maine Department of Education: Data Privacy(maine.gov).gov
- 22 MRSA 1711-C: Confidentiality of Health Care Information(legislature.maine.gov).gov
- Maine DHHS: Privacy and Security of Health Information(maine.gov).gov
- Maine Department of Labor: Employer Surveillance Notice Poster(maine.gov).gov
- 15 MRSA 709-712: Maine Wiretapping and Electronic Surveillance Law(legislature.maine.gov).gov
- TAKE IT DOWN Act: FTC Legal Library (Pub. L. 119-12)(ftc.gov).gov
- Maine Question 4 (2023): Right to Repair Law Vehicle Data Access Requirement (Ballotpedia)(ballotpedia.org)
- Maine Passes Statewide Facial Recognition Ban (IAPP)(iapp.org)