May 19, 2009 – Maine Governor Baldacci signed Public Law 161-1, which makes several changes to Maine’s existing data breach notification statute. The most significant change is the inclusion of a provision allowing an entity suffering a security breach involving personal information to delay notification to affected Maine residents for no longer than seven business days after a law enforcement agency determines that notification will not compromise a criminal investigation. A provision prohibiting “unauthorized persons” from releasing or using “an individual’s personal information acquired through a security breach” was also added to the statute. The changes are scheduled to take effect on Sept. 15, 2009.

A copy of the bill as enacted can be found here.