LD 1224 creates the Maine Consumer Privacy Act, a comprehensive consumer data privacy framework that would regulate how covered businesses collect, use, share, sell, delete, and otherwise process personal data of Maine residents. The bill defines key privacy terms such as personal data, sensitive data, biometric data, targeted advertising, sale of personal data, profiling, de-identified data, and precise geolocation data, and it applies to businesses that conduct business in Maine or target Maine residents above specified data-processing thresholds. The act would take effect July 1, 2026, with some obligations phased in later, including an opt-out preference signal requirement by December 1, 2027 and a lower applicability threshold beginning January 1, 2028.
Under the bill, consumers would gain rights to confirm whether their data is being processed, access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling that produces legal or similarly significant effects. Controllers would have to provide clear privacy notices, limit collection to what is reasonably necessary, maintain reasonable data security practices, obtain consent before processing sensitive data, and honor parental consent rules for children. The bill also imposes contract, oversight, and assessment requirements on processors and controllers, including data protection assessments for higher-risk processing activities and obligations related to de-identified and pseudonymous data.
The bill would significantly affect Maine’s statutory landscape by creating a new chapter in Title 10 and making violations an unfair trade practice enforceable exclusively by the Attorney General under the Maine Unfair Trade Practices Act. It preempts local privacy ordinances, establishes a Maine Privacy Fund to support enforcement, and requires the Attorney General to report to the Legislature on implementation by February 1, 2027. The bill also includes broad exemptions for government entities, financial institutions, certain insurers, and numerous categories of regulated data such as health information, educational records, and other federally protected information.
Because no committee transcript or vote history was provided, there is no recorded legislative debate or roll-call sentiment to summarize. Based on the bill text itself, the measure appears to reflect a strong pro-privacy policy approach, with extensive consumer rights and compliance obligations, but also a structured set of exemptions and safe harbors intended to limit overlap with existing federal and state privacy regimes. The bill’s enforcement design, including Attorney General-only enforcement and a 30-day cure period, suggests an effort to balance consumer protection with business compliance concerns.
The most likely points of contention are the bill’s compliance burden on businesses, the scope of covered entities and data, the treatment of targeted advertising and data sales, and the extent of exemptions for health, financial, educational, employment, and research data. Another likely issue is the Attorney General’s exclusive enforcement authority and the absence of a private right of action, which may be viewed as limiting consumer remedies while reducing litigation risk for businesses. The phased-in thresholds and cure period indicate an attempt to moderate those concerns, but the bill still represents a substantial expansion of privacy regulation in Maine.
The bill would add a new consumer privacy chapter to Maine law, establishing duties for data controllers and processors and creating enforceable rights for Maine residents over their personal data. It would amend the state’s regulatory framework by making privacy violations an unfair trade practice, vesting enforcement exclusively in the Attorney General, preempting local privacy rules, and creating the Maine Privacy Fund to finance enforcement. It would also interact with and defer to several existing state and federal privacy regimes, including HIPAA, GLBA, COPPA, FERPA, the Driver’s Privacy Protection Act, and certain insurance and research laws.
No committee discussion or vote record was provided, so there is no formal legislative sentiment to report from those sources. The bill text indicates a generally strong consumer-privacy orientation, with broad rights, consent requirements, and limits on targeted advertising, sale, and profiling. At the same time, the inclusion of exemptions, cure periods, and delayed implementation suggests the bill was drafted with an awareness of business and compliance concerns, implying a policy balance rather than an uncompromising prohibition model.
Likely areas of contention include the compliance costs for businesses that collect or monetize consumer data, the breadth of the definitions of personal, sensitive, and biometric data, and the restrictions on targeted advertising and data sales. Businesses and industry groups may object to the data protection assessment requirements, opt-out preference signal mandate, and the potential operational burden of responding to consumer requests. Consumer advocates may focus on the lack of a private right of action and the Attorney General-only enforcement model, while regulated sectors such as health care, finance, education, insurance, and research may be attentive to how broadly the bill’s exemptions are applied.