Maine Data Privacy and Protections Act

· About Maine Data Privacy and Protections Act

Key Takeaways

  • The Maine Data Privacy and Protection Act (MDPPA) is a proposed comprehensive consumer privacy law that, in the latest legislative materials located, is set to take effect on 1 July 2025 and then phase in through 31 December 2026 and 1 January 2027. [1]
  • From 1 July 2025 through 31 December 2026, the law applies to businesses meeting the statute’s initial applicability thresholds; beginning 1 January 2027, the thresholds change to cover smaller data sets and certain revenue from personal-data sales. [1]
  • The Maine Attorney General is the enforcing authority, and the legislative materials describe civil enforcement by the state rather than a private right of action. [1]
  • Controllers must provide consumer rights, limit certain processing, publish a privacy notice, and complete data protection assessments for high-risk processing, including targeted advertising, sale of personal data, profiling, and sensitive data processing. [1]
  • The legislation includes a right to cure period in the early implementation period, but later amendments and secondary summaries indicate the timing and duration of that cure period have been debated, so the exact operational date should be confirmed against the enacted text before deployment. [1][4]
  • Because the current record located here includes committee amendment language and tracking materials, not a fully verified codified session law text, any compliance plan should treat the statute’s effective dates and thresholds as legislative-text dependent until the final enrolled law is checked. [1][12]

What It Is

The MDPPA is Maine’s comprehensive consumer data privacy framework, designed to regulate the collection, use, disclosure, sale, and protection of personal data relating to Maine residents. The legislative materials indicate it was drafted as a phased law with early applicability beginning 1 July 2025, a second phase ending 31 December 2026, and revised thresholds beginning 1 January 2027. [1]

The enforcing body is the Maine Attorney General, whose office would handle investigations and enforcement actions under the law. The amendment text located here also ties implementation and enforcement funding to legislative appropriations, which reinforces that this is a state-enforced regime rather than a self-executing industry code. [1][13]

The materials found here show an effective date of 1 July 2025 in the committee amendment text, and also show phase-in language that runs through 31 December 2026 before new thresholds begin on 1 January 2027. [1] A separate 2026 bill-tracking record shows that related privacy bills introduced in later sessions moved dates again or were superseded, so organizations should verify whether any enacted delay or replacement law changed the operative date in the final session law. [12]

Who Must Comply

The law applies by business size and data volume thresholds, not by sector alone. The amendment text states that from 1 July 2025 through 31 December 2026, it applies to persons that conduct business in Maine or produce products or services targeted to residents of Maine and meet the specified consumer-processing thresholds in the prior calendar year. [1]

Beginning 1 January 2027, the law’s reach broadens to entities that, in the preceding year, controlled or processed the personal data of not less than 50,000 consumers, excluding data processed solely to complete a payment transaction, or not less than 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data. [1]

The statute’s structure indicates extraterritorial reach to businesses outside Maine if they target Maine residents or process enough resident data to meet the thresholds. That is consistent with modern comprehensive privacy laws and with the bill’s focus on consumer residency and Maine-directed activity rather than corporate domicile. [1]

The exemption structure in the located materials is incomplete, so a conservative reading is necessary. The amendment text shows exclusions for data processed solely to complete a payment transaction in the threshold test, and any final compliance memo should confirm whether additional exemptions exist for specific entities, data types, or regulated activities in the enrolled statute. [1]

Core Requirements

  1. Consumer rights program — Controllers must provide a mechanism for consumer rights requests covering access, correction, deletion, and portability, along with any other rights adopted in the final text. [1]
  1. Privacy notice and transparency — Controllers must publish a clear privacy notice describing categories of personal data processed, purposes of processing, how consumers can exercise rights, and how sensitive data or sales are handled. [1]
  1. Data minimization and purpose limitation — The law requires processing to be limited to what is reasonably necessary and proportionate to the disclosed purposes, with special scrutiny for targeted advertising, sale, and profiling. [1]
  1. Sensitive data safeguards — Processing of sensitive data is treated as heightened-risk processing and triggers additional compliance obligations, including assessment and operational controls. [1]
  1. Data protection assessments — The statute requires documented assessments for processing that presents a heightened risk of harm, including targeted advertising, sale of personal data, profiling, and sensitive data processing. The amendment text states that the first assessments required under the law must be completed no later than 1 January 2026. [1]
  1. Controller accountability and contracts — Controllers using processors must impose appropriate contractual terms and maintain governance measures to ensure the processor acts only on documented instructions and with suitable security and confidentiality safeguards. [1]
  1. Security safeguards — The law expects reasonable administrative, technical, and physical safeguards proportionate to the volume and sensitivity of data processed, aligning with standard privacy-security governance expectations. [1]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Initial applicability begins | 1 July 2025 | Covered entities become subject to the MDPPA’s core obligations. [1] | | First data protection assessments due | 1 January 2026 | Initial assessments for covered high-risk processing must be completed. [1] | | Transition period ends | 31 December 2026 | Early phase applicability ends under the amendment language. [1] | | Lower threshold phase begins | 1 January 2027 | New consumer-count and revenue thresholds apply. [1] |

The located legislative materials do not provide a finalized penalty schedule in the snippets retrieved, but they identify the Maine Attorney General as the enforcer. In Maine comprehensive privacy frameworks, enforcement is typically by civil action seeking injunctive relief and monetary penalties, so the final enrolled text should be checked for the exact maximum civil penalty per violation and any cure-period conditions before relying on a penalty figure. [1][13]

How to Comply

  1. Map data and classify it — Build a record of processing that identifies personal data, sensitive data, sale, targeted advertising, profiling, and processors. Align this work with ISO 27001 asset and risk controls and with NIST CSF 2.0 governance and identify functions.
  1. Set the applicability test — Determine whether Maine thresholds are met in the current and prior year, including the 2025–2026 transitional test and the post-2027 threshold. Keep a documented legal memo because the law phases in. [1]
  1. Update notices and consent flows — Rewrite the privacy notice to explain categories, purposes, consumer rights, sales, targeted ads, and sensitive data practices. If the final text requires consent for specific processing, operationalize consent capture and withdrawal. [1]
  1. Build a rights-management workflow — Create intake, authentication, SLA, escalation, and response templates for rights requests. Test the workflow against deletion, correction, access, and appeal cases if those rights are included in the final codified text. [1]
  1. Run data protection assessments — Use a reusable assessment template for targeted advertising, sale, profiling, and sensitive data. This maps well to ISO 42001 risk assessment, impact documentation, and continual improvement practices. [1]
  1. Harden processor governance — Amend vendor contracts to cover instructions, confidentiality, security, assistance with rights requests, and deletion or return at termination. Monitor subprocessors and cross-border transfers where applicable. [1]
  1. Operationalize security controls — Implement risk-based administrative, technical, and physical safeguards, including access control, encryption, logging, incident response, and retention controls. This is where ISO 27001 and NIST CSF 2.0 most directly map to the statute. [1]
  1. Track legislative updates — Recheck the enacted text and attorney-general guidance before launch, because the records located here show active 2025–2026 amendments and related privacy bills with changing dates. [1][12]

Related Regulations

Virginia Consumer Data Protection Act — Maine’s law is structurally similar to Virginia’s consumer-rights and controller-obligation model, so existing Virginia-style programs can be adapted with state-specific threshold and notice updates.

Connecticut Data Privacy Act — Connecticut’s framework overlaps on rights, assessments, and sensitive-data processing, making it a useful benchmark for assessment templates and processor contracting.

Colorado Privacy Act — Colorado is especially relevant because of its formal data protection assessment requirements and controller obligations, which are operationally close to Maine’s high-risk processing duties.

EU GDPR — GDPR overlaps on transparency, lawful processing, minimization, and processor governance, but Maine uses a U.S. state consumer-privacy trigger and likely narrower remedy structure.

Maine data breach notification law — The older breach-notification regime remains relevant because MDPPA governance does not replace incident-response and notification duties for unauthorized access to personal information.

FAQ

Does the Maine Data Privacy and Protection Act apply to companies outside Maine?

Yes, if an out-of-state company conducts business in Maine or targets Maine residents and meets the statute’s data-processing thresholds. The law is built around resident data and business activity, not corporate headquarters. [1]

When do the first compliance obligations start?

The committee amendment text states the act takes effect on 1 July 2025, and the first data protection assessments must be completed by 1 January 2026. The law then shifts to a different threshold structure on 1 January 2027. [1]

Does the law cover sensitive data and targeted advertising?

Yes. The legislative text identifies targeted advertising, sale of personal data, profiling, and sensitive data processing as heightened-risk activities that trigger data protection assessments and tighter compliance controls. [1]

Is there a private right of action?

The located materials point to enforcement by the Maine Attorney General and do not indicate a private right of action in the retrieved text. That means enforcement should be treated as state-driven unless the final codified statute says otherwise. [1][13]

What if a company only processes data to complete payment transactions?

The phase-in threshold language expressly excludes data processed solely to complete a payment transaction from the consumer-count calculation. That exclusion affects threshold analysis, but it does not necessarily eliminate all other compliance obligations if the entity otherwise falls within scope. [1]

Sources

Put it into practice

More compliance guides