Publications
February 6, 2012

What to do After a Data Breach: A Primer on Maine's Security Breach Law

Your company just discovered a security breach resulting in the disclosure of personal information concerning customers, vendors, employees, or other individuals.  What now? 

The purpose of this primer is to provide an introduction to what you need to know about notification requirements under Maine's Notice of Risk to Personal Data Act, 10 M.R.S. §§ 1346-1350-B (the "Act").

The essential purpose of the Notice of Risk to Personal Data Act is informational -- to ensure prompt notification to persons at risk of identity theft.  The Act prohibits use of personal information acquired through a security breach, imposes prompt notification requirements in the event of a security breach, provides for enforcement and penalties, and requires that law enforcement provide a police report in connection with any reported misuse of personal information. 

In the absence of a uniform federal law governing notice requirements in the event of a data breach, the states have enacted a patchwork of notice requirements.  At present 46 states plus the District of Columbia, Puerto Rico and the Virgin Islands (and New York City) have enacted security breach notification laws.  The holdouts are Alabama, Kentucky, New Mexico, and South Dakota.  Maine law applies to Maine residents.  Notification to residents of other states is governed by the law of the state of residence. 

The Act is a key part of the legal puzzle when it comes to notification of data breaches involving Maine residents, but it is not the whole story.  A response to a data breach by financial institutions involves federal law.  State law tort claims (e.g., negligence) and unfair trade practices acts at the state and federal level provide incentives to respond thoughtfully to security breaches.  Relevant contracts may also address data breach, confidentiality, or related requirements.  As in any risk management situation – data breaches are no exception – insurance should also be top of mind.

Download What to do after a Data Breach: A Primer on Maine's security breach law" for more information on:

  • How does the Act define a security breach?
  • Who is subject to the Act?
  • How is "personal information" defined?
  • Does the Act apply to paper records?
  • Do I have to investigate once I become aware of a security breach?
  • What triggers the duty to notify?
  • Who has to be notified?
  • Does Maine have a notification form?
  • What are the required contents of the notification?
  • How quickly do I have to notify?
  • Are there penalties for non-compliance with the Act?
  • Does the Act create a private right of action?

Questions?

For further information about security breach reporting requirements and related privacy or confidentiality issues, please contact Sig Schutz at Preti Flaherty's Portland, Maine office at [email protected] or 207-791-3000.  Sig and other attorneys at Preti Flaherty have advised numerous companies in responding to security breaches and the firm has served as defense counsel in security breach litigation.

Firm Highlights

Event

Building a Strong Discipline and Performance Management Framework

As an HR professional, hiring the right talent, addressing employee needs, and managing terminations are just a few of the most challenging problems that arise. During this year's three-part Employment Breakfast Webinar Series, we'll...

Publication

Failure to Follow Your Contract's Notice Requirements Can be Costly

In Kinetic Systems, Inc. v. IPS-Integrated Projects Services, LLC et. al., No.: 20-cv-1125 (D.N.H. February 6, 2024), the U.S. District Court for the District of New Hampshire granted summary judgment for a general contractor...

Event

When to Say Goodbye: Navigating Leave and Terminations

As an HR professional, hiring the right talent, addressing employee needs, and managing terminations are just a few of the most challenging problems that arise. During this year's three-part Employment Breakfast Webinar Series, we'll...

News

Attorney Jeffrey Thaler Named to 2024 Lawdragon Green 500: Leaders in Energy Law

Preti Flaherty’s attorney Jeffrey Thaler has been recognized by  Lawdragon  as one of the top 500 Leaders in Energy Law. This is Jeff’s third time named to this prestigious list since the first publication...

News

Preti Attorneys File Suit Against Al-Generated Robocalls in the 2024 NH Presidential Primary

Representing the League of Women Voters of New Hampshire, the League of Women Voters of the United States, and individual voters, Preti Flaherty, with co-counsel, filed a federal lawsuit against Steve Kramer, Lingo Telecom...

News

Benchmark Litigation Names Preti Flaherty 2024 “Maine Firm of the Year"

Benchmark Litigation  has named Preti Flaherty as 2024 Litigation Firm of the Year in the State of Maine. Through extensive peer- and- client reviewed research, as well as analysis of casework; the Benchmark Awards...

Publication

USCIS Announces H-1B Registration Period for FY2025: New “Beneficiary Centric” Registration Process and Increased Fees

USCIS has recently announced a series of changes that will impact the FY2025 H-1B registration system and cap filing season. H-1B Registration Period and Organizational Accounts As in prior years, under this process, prospective petitioners...

Event

Good Energy: Jazz, Cocktails, and Camaraderie

Preti Flaherty and Phelps Dunbar will be hosting an afterhours event: ‘Good Energy: Jazz, Cocktails, and Camaraderie’ at The Oceantic Network’s annual IPF Offshore Wind Conference. The event will be held on April 23...

Publication

Important Updates to American Arbitration Association Construction Industry Rules and Mediation Procedures

The American Arbitration Association (AAA) updated its Construction Industry Rules and Mediation procedures (AAA Rules), effective March 1, 2024, marking the first update since 2015. The updates are important because the AAA Rules are...

Publication

Helping Employers Navigate the New Independent Contractor Rule and Compliance Challenges

On March 11 th , the United States Department of Labor’s (DOL) new Independent Contractor Rule goes into effect.  As your organization readies itself for compliance, it’s imperative to scrutinize your independent contractor classifications...