Every state has a breach notification law. Maine's — the Information Security Incident Notification Act, codified at 10 M.R.S. § 1347 et seq. — has some specifics that differ from the federal patchwork and from neighboring states. If you hold data about Maine residents, this law applies to you regardless of where your business is located.
Who the Law Covers
Any person or entity that owns, licenses, or maintains computerized data that includes personal information about Maine residents must comply. "Person" under Maine law includes businesses, nonprofits, government agencies, and individuals.
This has geographic reach. A company headquartered in California with Maine customers is subject to this law when those customers' data is involved in a breach. Maine is not unique in this — most state breach notification laws follow the same logic — but it's worth stating clearly: the law follows the data, not the business address.
What Counts as Personal Information
Maine's definition of personal information has been expanded over time and is now fairly broad. Personal information means a Maine resident's first name or first initial and last name in combination with one or more of the following:
- Social Security number
- Driver's license number or state identification card number
- Account number or credit or debit card number, in combination with any required security code, access code, or password
- Medical information or health insurance information relating to diagnosis, treatment, or payment
- Biometric data
- Genetic information
- A user name or email address, in combination with a password or security question and answer that would permit access to an online account
That last category — username/email plus password or security Q&A — is notable. A credential breach that doesn't involve Social Security numbers or payment cards can still trigger Maine's notification requirement if it involves account credentials that permit access to online accounts.
Data is excluded from this definition if it is encrypted and the encryption key was not also acquired in the breach. Encryption provides a meaningful safe harbor — unencrypted data breaches are almost always reportable; encrypted data breaches usually are not (assuming the key is secure).
What Triggers Notification
A "security breach" under Maine law is the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information. Two qualifications matter here:
The "materially compromises" language means that not every unauthorized access to a system automatically triggers notification. If someone accessed a system but there's no evidence personal information was viewed, acquired, or copied, the question is whether there was material compromise. Maine law allows a documented risk determination: if you assess that the breach is unlikely to cause harm to the affected individuals, notification may not be required — but the assessment must be documented and defensible.
"Computerized data" means the law applies to electronic records, not paper records. Maine has separate provisions relating to personal information more broadly, but the breach notification statute is specific to computerized data.
Notification Timeline: 30 Days
Maine's statute (10 M.R.S. § 1348) requires notification "as expeditiously as possible and without unreasonable delay" and specifically requires notification no later than 30 days after you have:
- Determined that a security breach has occurred, AND
- Identified the scope of the breach
The clock doesn't start on the date of the breach — it starts when you've both confirmed a breach occurred and determined what was involved. This distinction matters: a forensic investigation that takes three weeks to scope the breach isn't automatically running out the clock, but you can't delay indefinitely while the investigation continues. If you've confirmed a breach and have a reasonable picture of what was affected, the 30-day window is running.
One exception: if law enforcement requests a delay to avoid interfering with an investigation, the notification can be postponed for a specific period. This requires an actual request from law enforcement, not a self-determined decision to wait.
Who You Must Notify
Maine's law requires notification to three parties:
1. Affected Maine residents: Individual written notice by first-class mail to the last known address, or by electronic notice if the person has consented to electronic communications. If you have inadequate contact information for 10 or more affected residents, substitute notice is required — posting on your website for at least 90 days and providing a toll-free number.
2. The Maine Attorney General: Notice must be provided to the AG's office simultaneously with (or before) the notice to affected individuals. The AG's office maintains records of breach notifications and uses them for enforcement oversight. This is not optional and is not just a formality — the AG's office does review notification compliance.
3. Consumer reporting agencies: If the breach affects more than 1,000 Maine residents, you must also notify all consumer reporting agencies of the timing, distribution, and content of the notices sent to residents. This is not notice to individual consumers through the credit bureaus — it's notice to the agencies themselves so they're aware a large notification is going out.
Notice Content Requirements
The notice to affected residents must include:
- A description of what happened, including the approximate date of the breach and the date it was discovered (if known)
- The type of personal information involved
- Steps the individual can take to protect themselves (for credential breaches: change passwords; for financial account information: monitor accounts, consider credit freeze)
- A description of what you're doing to investigate and prevent future breaches
- Contact information — a toll-free phone number, email address, or website where individuals can get more information and ask questions
The notice cannot be vague. "There may have been a security incident affecting some of your data" doesn't satisfy the content requirements. The type of personal information involved must be specified.
How This Interacts with Federal Law
If you're a healthcare organization subject to HIPAA, you have notification obligations under both Maine law and the HIPAA Breach Notification Rule. The content requirements for HIPAA's Breach Notification Rule largely satisfy Maine's individual notice content requirements — but Maine's 30-day deadline is stricter than HIPAA's 60-day window, so for covered entities, Maine sets the effective deadline for notifying individuals, and Maine additionally requires AG notification, which HIPAA doesn't.
If you're a financial institution subject to GLBA, the FTC's Safeguards Rule requires notification to the FTC (not to individuals) within 30 days for security events affecting 500 or more customers. Maine's law requires notification to residents and the AG. These are parallel obligations — satisfying one doesn't satisfy the other.
What Maine Does NOT Currently Have
Maine does not have a comprehensive consumer privacy law. LD 1822, which would have established consumer rights similar to the California Consumer Privacy Act, did not pass. As of 2026, Maine's privacy framework for businesses consists primarily of the breach notification law described here, plus sector-specific federal laws (HIPAA, GLBA) that apply to covered businesses. The breach notification law is your primary state-level compliance obligation for data security incidents involving Maine residents.
SOURCES
- 10 M.R.S. § 1347 et seq. — Maine Information Security Incident Notification Act: legislature.maine.gov
- Maine Attorney General's Office — Breach Notification: maine.gov/ag/consumer/identity_theft/data_breach.shtml
- National Conference of State Legislatures, State Data Breach Laws: ncsl.org/technology-and-communication/security-breach-notification-laws
Has your organization experienced a potential breach involving Maine residents, or do you want a breach response plan in place before you need it? Schedule a consultation to talk through your obligations and response process.
