Maine’s current consumer privacy law gives residents tools to understand and control certain personal data held by businesses. The law is useful when a company keeps collecting information, sells or shares it, uses it for targeted advertising, or refuses to correct an inaccurate profile. It does not cover every record held by every organization, and a privacy request is not a way to erase information that another law requires a business to keep.

Which Maine law applies

The Maine Legislature enacted the Maine Consumer Data Privacy Act in Title 10, chapter 1057 of the Maine Revised Statutes. The official chapter text is the place to check the operative definitions, covered entities, exemptions, and rights. The law took effect on July 1, 2026, so a Maine resident making a request now should use the current statute rather than an older online privacy article.

The statute regulates covered businesses that collect, use, disclose, sell, or otherwise process personal data. Coverage can depend on the business’s activities and thresholds, not simply on whether the business has a website or has one Maine customer. Government agencies, employment records, certain financial information, health information, education records, and other categories can be exempt in whole or in part. A company should identify the reason for a refusal instead of treating every request as automatically outside the law.

Privacy law is different from a general right to inspect every file a company has about you. The relevant question is which data is covered, what the business did with it, and which request you made.

What rights a Maine resident may exercise

For covered personal data, the statute provides consumer rights that can include confirmation of whether a controller is processing your data, access to the data, correction of inaccuracies, and deletion in circumstances described by the law. A resident may also have a right to obtain data in a usable format and to opt out of certain processing, including targeted advertising, the sale of personal data, or profiling that produces significant effects.

The right is not absolute. A controller can refuse or limit a request when an exemption applies, when fulfilling it would conflict with another legal obligation, or when the request would reveal another person’s information. Sensitive data generally receives stronger protection, and a business may need consent before collecting or using certain sensitive categories.

Read the company’s privacy notice before writing. It should explain what categories of data are collected, why they are used, whether they are sold or shared, and how to submit a request. A privacy notice cannot eliminate a statutory right simply by using vague language, but it can tell you the correct channel and identity-verification process.

How to make a useful request

  1. Identify yourself clearly. Use the name, email address, phone number, or account identifier the company actually associates with your records. Do not send unnecessary identity documents.
  2. Choose the exact request. Ask for access, correction, deletion, a processing confirmation, a copy, or an opt-out. Combining every possible demand can make the response harder to evaluate.
  3. Describe the relevant account or transaction. Include an order number, subscription, loyalty account, or approximate date if it helps locate the data.
  4. Ask how the company will verify you. Use the company’s published request portal or privacy email, and save the confirmation.
  5. Keep the response and deadline. Download the privacy notice and preserve the company’s acknowledgment, questions, denial, and any appeal instructions.

A request such as “delete everything” may not tell the company whether you mean an account, marketing profile, device identifier, recorded call, or all of them. A short list of categories produces a better record. If you are asking for correction, state the inaccurate item and the correct information, with supporting documents when appropriate.

Identity verification and authorized agents

A controller can use reasonable verification to avoid disclosing personal data to an impostor. Verification should be proportionate to the sensitivity of the information. A request for a low-risk marketing preference should not automatically require a full copy of a driver’s license. Ask whether the company can verify you through the account, a code sent to a known address, or other less intrusive method.

If someone acts for you, the company may require proof of authorization. Keep the authorization narrow and current. A request from an agent should identify the consumer, the specific right being exercised, and the permitted scope. Do not give an unknown service broad access to your accounts merely because it promises to submit a privacy request.

What happens after the request

The controller should acknowledge and evaluate the request under the process described in its notice and Maine law. It may ask a clarifying question, request verification, provide a partial response, or explain that an exemption applies. A partial response should identify what was withheld and why whenever the company can do so without revealing protected information.

Compare the response to the request you actually made. An access response may list categories without providing the underlying data you requested. A deletion response may remove an account but retain records needed for security, legal compliance, accounting, or dispute resolution. A correction response may update a customer profile but leave a separate data broker or service provider record unchanged.

Save a copy before closing an account. Deletion can make it harder to prove what the company collected, what it told you, or how an inaccurate record affected you. If you need the information for a dispute, download it and preserve the original emails before asking for erasure.

Opting out of sale, targeted advertising, or profiling

An opt-out is different from deletion. If you want a company to stop targeted advertising, you may not need to delete your account. If you want to stop the sale of data, read the company’s explanation of what it calls a sale; the statutory definition may not match everyday language. If a decision based on profiling affects access to a service, employment-related opportunity, housing-related opportunity, or another significant outcome, identify the decision and ask what review or appeal process is available.

Browser settings, cookie controls, account settings, and universal opt-out signals may affect how a company receives your preference. Do not assume that changing an advertising preference at one company changes the settings of a data broker, mobile application, or affiliated business. Test the result by reviewing the confirmation and later privacy notices.

Common reasons a request goes wrong

Residents often send a request to customer service rather than the privacy channel, use an old email address, or ask for records that belong to a separate company. A business may also misclassify a request as a password-reset problem, claim that it cannot find the account, or respond with a generic privacy policy instead of addressing the right exercised.

Reply in writing. Quote the original request, identify the unanswered part, and ask the company to treat the message as a formal request under the Maine Consumer Data Privacy Act. Do not create multiple duplicate accounts while the request is pending. Duplicates can make it difficult to tell whether the company failed to respond or simply found another account.

Watch for an attempted waiver. A consumer cannot necessarily waive a statutory privacy right by clicking through a broad consumer agreement. At the same time, a company can apply reasonable procedures and statutory exemptions. The strongest complaint is specific: what data was requested, when, from whom, what response arrived, and which part appears incomplete.

When to escalate

Start with the company’s appeal or review process if one is provided. Send the appeal within the stated period and attach the request, response, identity-verification record, and a short explanation. Ask for a substantive reason if the company continues to deny the request.

The Maine Attorney General’s consumer-protection resources provide information about privacy and identity-theft issues. The Attorney General can explain available complaint channels, but a complaint does not guarantee that a particular record will be deleted or that compensation will be paid. Keep your own evidence and avoid sending sensitive documents through an unverified link.

If the issue involves a data-security breach, use the separate Maine breach-information resources. A breach question may require a different notice, investigation, or remedy than an ordinary access or deletion request. Do not confuse a company’s failure to honor a privacy request with proof that a breach occurred.

A practical example

A Maine customer discovers that an online retailer continues sending ads based on an old medical-related purchase. The customer asks for access to the personal data used for targeting and opts out of targeted advertising. The retailer verifies the account, removes the advertising preference, and says it must retain the transaction record for accounting. The answer may be reasonable if the retained record falls within an applicable exception, but the customer can still ask whether the retained record is used for advertising and preserve the written response. The customer’s goal is not to erase every lawful business record; it is to stop an identified use and understand what remains.

Separate privacy rights from other disputes

A privacy request does not automatically resolve identity theft, a billing dispute, inaccurate credit reporting, or a data-security incident. If a company has harmed you in another way, preserve the evidence for that issue before closing an account. Save invoices, account histories, fraud alerts, breach notices, and messages showing how the data was used. State clearly whether you are asking for a statutory privacy response, correction of an account record, or investigation of a separate problem.

Businesses also use service providers and affiliated brands. Ask whether the response covers the controller that received your request and whether a separate company makes the advertising, analytics, or account decision. A controller may be able to identify categories without naming every vendor, but a generic answer should not prevent you from asking a precise follow-up. Keep your request narrow enough to receive a clear answer and broad enough to address the use that concerns you.

The bottom line

Maine residents should treat a privacy request like a small legal record: identify the business, choose the right, verify identity carefully, ask for a specific response, and save every step. The Maine statute gives meaningful control over covered personal data, while exemptions and other legal duties limit what a company must disclose or delete. A precise request makes it easier to tell the difference.

Disclaimer: This guide provides general legal information and is not legal advice. Laws vary by state and may change over time. The outcome of any legal issue depends on the specific facts, documents, and circumstances involved. For advice about your situation, consult a qualified attorney licensed in your jurisdiction.