← All jurisdictions
ME · data breach notification
highMaine
10 M.R.S. §1346 et seq. (§1348)
Individual deadline
30 days
Trigger standard
Qualified
AG / regulator
Required
| Notice to individuals | 30 calendar days from discovery |
| Risk-of-harm standard | notice where misuse has occurred or it is reasonably possible that misuse will occur |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | Maine Attorney General (or Dept. of Professional & Financial Regulation for regulated entities), required for any affected resident; within 30 days Written notice (portal offline since late 2025 — mail/email) |
| Credit reporting agencies | Notify CRAs above 1,000 residents. |
| Substitute notice | Typically available above $250,000 cost / 500,000 affected (verify). |
| Private right of action | No, enforcement by the state. |
| Penalties | Up to $500 per violation, capped at $2,500 per day |
Rule last verified July 10, 2026 · confidence high. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a Maine breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →