EnglishEspañol
Maine flag

Maine

Maine Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 11 primary sources cited on this page. How we verify our legal content

Maine Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Maine business notify people of a data breach?

Maine law requires notification no later than 30 days after the organization becomes aware of the breach and identifies its scope. This is one of the shortest hard deadlines in the country. The only exception is a law enforcement delay, which can extend the timeline by up to 7 business days after law enforcement clears the notification.

Does encrypting data protect a business from Maine breach notification requirements?

Yes. Maine provides an encryption safe harbor. If the compromised personal information was encrypted using generally accepted practices, the breach does not trigger the notification obligation. The statute does not specify particular encryption standards, but organizations should follow current industry best practices such as AES-256.

What is Maine's substitute notice provision and when does it apply?

Substitute notice is an alternative notification method available when the cost of direct notice exceeds $5,000, the affected class exceeds 1,000 individuals, or the organization lacks sufficient contact information. Maine's $5,000 cost threshold is among the lowest in the country, matched by New Hampshire. Substitute notice requires emailing affected individuals (if addresses are available), posting conspicuously on the organization's website, and notifying major statewide media outlets.

Can individuals sue under Maine's data breach notification law?

No. Maine's Notice of Risk to Personal Data Act does not create a private right of action. Only the Attorney General or the Department of Professional and Financial Regulation can enforce the statute. However, affected individuals may be able to bring claims under the Maine Unfair Trade Practices Act or pursue common law theories such as negligence.

Does Maine's breach notification law cover health insurance information or biometric data?

The law does not specifically list health insurance information or biometric data as protected personal information. Protected elements are limited to SSN, driver's license or state ID number, financial account numbers with security codes, and account passwords or PINs. However, health insurers that hold any of these data elements must still comply with notification requirements if those elements are breached.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the claim that Maine has the lowest substitute-notice cost threshold in the country (New Hampshire uses the same $5,000 figure) and clarified that the statutory notice-content requirements apply to the consumer reporting agency notice only, not to the regulator notice.

Corrected this page to reflect that LD 1822, the Maine Online Data Privacy Act, died in the Legislature on April 13, 2026, and did not become law; Maine currently has no comprehensive consumer data privacy statute beyond breach notification. Also clarified two definitional details: the information-broker exclusion includes agencies with licensing-related records, and the statute's definition of person expressly names private colleges and universities.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Maine Notice of Risk to Personal Data Act, Chapter 210-B(legislature.maine.gov).gov
  2. Title 10, Section 1347: Definitions(legislature.maine.gov).gov
  3. Title 10, Section 1348: Security Breach Notice Requirements(legislature.maine.gov).gov
  4. Title 10, Section 1349: Enforcement and Penalties(legislature.maine.gov).gov
  5. Title 10, Section 1347-A: Release or Use of Personal Information Prohibited(legislature.maine.gov).gov
  6. Maine AG: Privacy, Identity Theft and Data Security Breaches(maine.gov).gov
  7. Maine PFR: Risk to Personal Data FAQs(maine.gov).gov
  8. Electronic Maine Security Breach Reporting Form(me.accessgov.com)
  9. LD 1822: Maine Online Data Privacy Act Status (Died Between Houses, Apr 13, 2026)(legislature.maine.gov).gov
  10. Title 35-A, Section 9301: ISP Privacy Law(legislature.maine.gov).gov
  11. 15 U.S.C. Section 7001: E-SIGN Act(govinfo.gov).gov
  12. Public Law Chapter 512: Municipalities and School Districts Breach Notification(legislature.maine.gov).gov
  13. New Hampshire RSA 359-C:20, III(d): Notification of Security Breach (same $5,000 substitute-notice threshold)(gc.nh.gov)
Share: