Maine has strong ISP privacy protections and data broker registration requirements, but no comprehensive consumer privacy law.
Maine Privacy & Accessibility Laws
Maine has enacted notable privacy protections, including the nation's first ISP privacy law and data broker registration requirements. While Maine does not have a comprehensive consumer privacy law like the CCPA, its targeted privacy regulations are among the strongest in the nation. Maine state agencies must ensure their digital services are accessible to individuals with disabilities.
Privacy Law Status
Accessibility Requirements
Maine state agencies must ensure websites and digital services are accessible under ADA Title II and state IT accessibility policies.
Maine Privacy Regulations
Maine has enacted several significant privacy protections:
Key Maine Privacy Laws
- ISP Privacy Law (35-A M.R.S. ยง 9301): First-in-nation requirement for ISP opt-in consent to use customer data
- Data Broker Registration Act: Requires data brokers to register with the state
- Notice of Risk to Personal Data Act: Strong data breach notification requirements
- Student Information Privacy Act: Protects student educational data
Maine ISP Privacy Law
Maine's groundbreaking ISP privacy law (effective July 1, 2020) requires internet service providers to obtain opt-in consent before using, disclosing, selling, or providing access to customer personal information.
| Requirement | Details |
|---|---|
| Covered Entities | Internet service providers serving Maine customers |
| Consent Requirement | Opt-in consent required before using, selling, or sharing customer data |
| Protected Data | Web browsing history, app usage, location data, content of communications |
| Enforcement | Maine Attorney General with $5,000+ penalties per violation |
Data Broker Registration
Maine requires data brokers to register annually with the state:
- Annual registration fee: $300
- Must disclose data collection and opt-out procedures
- Failure to register: $10,000+ penalty per violation
- Registration deadline: January 31 each year
Data Breach Notification Requirements
| Requirement | Details |
|---|---|
| Notification Timeline | As expeditiously as possible, no later than 30 days after discovery |
| Regulator Notification | Required notification to Maine Department of Professional and Financial Regulation |
| Covered Data | Name plus SSN, driver's license, financial account, taxpayer ID, or medical/health information |
| Penalties | Up to $500 per affected Maine resident |
Accessibility Requirements
Maine government agencies must ensure digital accessibility for all residents:
State Government Obligations
- Maine state agencies must comply with ADA Title II for all public-facing digital content
- Office of Information Technology provides accessibility guidance
- State websites must follow WCAG 2.1 Level AA guidelines
- Educational institutions must ensure accessible digital learning materials
- State IT procurement requires vendor accessibility compliance
Private Sector Considerations
- Businesses with physical locations in Maine are subject to ADA Title III
- Maine Human Rights Act provides additional protections
- Website accessibility claims can be brought under federal ADA
- Healthcare providers must ensure accessible patient portals
Enforcement
Privacy Enforcement
- Maine Attorney General - Primary enforcement authority
- Consumer Protection Division - Investigates complaints
- Department of Professional and Financial Regulation - Data broker oversight
Contact:
Office of the Attorney General
Consumer Protection Division
6 State House Station
Augusta, ME 04333
(207) 626-8849
Accessibility Enforcement
- U.S. Department of Justice - ADA Title II and III enforcement
- Maine Human Rights Commission - State disability discrimination
- Private litigation - Federal ADA and state claims
Contact:
Disability Rights Maine
24 Stone Street, Suite 204
Augusta, ME 04330
(207) 626-2774
Business Obligations
| Obligation | Description |
|---|---|
| ISP Data (if applicable) | Obtain opt-in consent before using, selling, or sharing customer data |
| Data Broker Registration | Register annually with the state if operating as a data broker |
| Breach Notification | Notify affected individuals within 30 days and notify state regulator |
| Data Security | Implement reasonable security measures to protect personal information |
| Student Data | EdTech companies must follow Student Information Privacy Act requirements |
Consumer Rights
Maine residents have the following privacy rights:
- ISP Opt-In Rights: Affirmative consent required before ISP uses personal data
- Data Broker Transparency: Right to know about registered data brokers
- Breach Notification: Right to notification within 30 days of a data breach
- Consumer Protection: Protection against unfair or deceptive data practices
- Credit Freeze: Right to place security freezes on credit reports
- Student Data Rights: Parents and students have rights regarding educational data
Legislative Developments
Maine legislators continue to consider additional privacy legislation. The state's proactive approach to ISP privacy and data broker registration suggests strong interest in further consumer protections.
Related Resources
- US Privacy Laws Overview
- ADA Title II Requirements
- ADA Title III for Businesses
- All State Laws
- Privacy Compliance Guide
- Report a Violation
Need Help with Maine Compliance?
Maine's targeted privacy laws create specific obligations for ISPs and data brokers. Contact our experts for guidance on opt-in consent requirements, data broker registration, and accessibility compliance.