Analysis

Protecting Privacy Through Stronger Procurement Policy: How Maine Could Pioneer a Better Approach to Technology Procurement 

September 3, 2026 | Stephanie Forbes, EPIC Clerk

Nearly everyone—including state and local governments—relies on some kind of technology to do their jobs. From automated fraud detection systems to AI-driven surveillance technology, states contract with technology companies to outsource many of their needs and modernize their processes. However, without prioritizing strong privacy safeguards for individuals’ personal data, state governments could be putting their constituents at risk.

In 2023, EPIC explored state AI procurement in Outsourced & Automated, a report that outlined some of the main risks that derive from government procurement of privately owned AI tools. First, and most directly, the use of private-sector technology opens individuals up to risks of privacy harms and the misuse of their personal data. As the report uncovered, some of the companies that many state governments have contracted with to provide AI systems are themselves data brokers. Second, states’ use of automated decision-making systems introduces risks of inaccuracy and bias that affects the reliability of outputs. It’s well understood that these biases are most likely to disparately impact lower-income and minority communities. To mitigate these risks and build trust in both governments and the technology they procure, EPIC recommends adding transparency and oversight to the procurement process so governments and companies can be held accountable for any harm. Increased transparency will also help ensure that governments are using taxpayer dollars effectively to procure technology that truly serves constituents’ needs. 

The United States has recently experienced one of the biggest data breaches in history through the Trump Administration’s mishandling of personal data, including through inadequate oversight of technology vendors. EPIC has been fighting back against this invasion of privacy, including by filing several lawsuits aimed at combatting this unlawful data access. A recent report from the Center for Democracy and Technology (CDT) provided empirical evidence that an overwhelming majority of Americans are concerned about the security of their personal data in government hands and want the government to be held accountable for the protection of their data. The report showed that individuals of color are particularly concerned about their data being shared across law enforcement and immigration agencies. Older Americans are also increasingly among the most concerned about the privacy and security of their personal data, citing concerns of identity theft and fraud. Without adequate oversight of the procurement of technology from private companies, personal data is even more at risk of misuse, and Americans are left with minimal or no recourse.   

This blog post will focus on Maine as a case study for how states can close loopholes in technology procurement that otherwise leave personal data vulnerable to privacy and  security risks. The state’s aging population combined with its privacy-minded yet technology-forward philosophy makes it uniquely situated to address procurement oversight.

A Closer Look at Maine

Maine is one of the oldest, most rural states in the country, and it has been facing issues of population decline, especially in the northernmost Aroostook County bordering Canada. Around the state, these factors, combined with affordability issues across the country, have led to short staffing in local public offices. To offset staffing concerns, local governments and police departments in Maine have begun turning to technology to ease their burden. For example, each of the three towns in Aroostook County is governed by one shared government in which leaders admit they frequently rely on AI tools like ChatGPT to help carry out the functions of governing. Other police departments around the state have begun using AI tools to generate reports based on body cam footage.  

Additionally, Mainers have been fighting against increased costs and striving to find a way to modernize the state’s economy to reduce the wealth disparity between urban and rural Maine. Amid AI hype and fear of falling behind, the Maine Artificial Intelligence Task Force was born in 2024 via an Executive Order that tasked an interdisciplinary group of 21 individuals from around the state with putting together a report about how Maine’s economy and public sector could benefit from AI while mitigating risks to the workforce. The resulting report focuses on innovative ways to solicit AI solutions in Maine and retain talent—an area of concern for the aging state. However, while the report calls for updates and developments in the procurement process, the report neglects to highlight what to include in such contracts to ensure Mainers are protected while the state aims to make strides toward economic growth and innovation. 

At the same time, Mainers have felt ongoing pressure over the past year to keep their data safe. Beginning in January 2026 with “Operation Catch of the Day” and resulting most recently in a Colombian man being shot in Biddeford, surges in ICE deployment have raised the stakes for the small New England state—especially for immigrants and people of color. In response to the risks of rogue agency practices, abuses of power among law enforcement, and public pushback over government entanglement with companies like Palantir, calls to limit data-sharing with the federal government led Maine to pass three ICE Out laws that took effect this summer to limit local law enforcement agencies’ ability to share data with ICE. 

Similar protections are necessary for all types of Mainers’ personal data. With procurement protections in place, Mainers could be confident that any out-of-state technology company that their tax dollars go to support is compliant with the state’s ethos and protects their privacy and civil liberties. Or, better yet, such protections could create an opportunity for home-grown technology solutions that would further benefit the state while also protecting Mainers’ privacy. However, as it stands now the state continues to spend taxpayer dollars to outsource its technology solutions with few requirements in the contracts.

Maine spends millions of dollars on a wide array of technology procurement, from administrative tools to surveillance technology. 

EPIC surveyed several contracts that the state of Maine has entered into that were either publicly available or made available upon request. Based on the contracts EPIC was able to review, Maine spends millions of dollars each year procuring technology, with towns like Lewiston pledging nearly $70,000 per year on Flock cameras alone.  

Most of Maine’s current contracts with technology companies are for surveillance technology used by law enforcement, such as body cameras, automated license plate readers (ALPRs), street cameras, and communication surveillance technology used in prisons. Other contracts cover e-filing systems in courts, and some AI tools used for administrative purposes.  

ALPR providers like Flock—a company that operates over 80,000 AI-powered cameras across 49 states—have received the most attention and pushback in the state. As reports showed that local and state police departments around the country were allowing ICE to access the national network of ALPR data controlled by Flock, advocates including the ACLU of Maine began to expose municipal contracts with the company and push back against the threats posed to privacy and other civil liberties protected under the First and Fourth Amendments. A separate 404 Media report showed that inadequate cybersecurity protections led to Flock cameras being accessible online without any sort of password protection, such that anyone could watch live feeds and access up to 30 days of archived video. In some cases, the live feeds allowed viewers to watch cameras overlooking unsuspecting children playing on a playground.

Other surveillance technologies, including Verkada’s AI-enabled cameras, have been implemented around the state, such as in Houlton—another small town in Aroostook County. Despite only having a population of around 6,000, the town had planned to install roughly 50 cameras, just shy of 10 cameras per 1,000 people. When these plans were shared in 2024, the nearby Caribou Police Department raised concerns and was surprised to hear these cameras were being implemented in the County. Nonetheless, Houlton and other towns, including Calais, cited a lack of police staff as their main reason for implementing the cameras. 

The cameras faced scrutiny after reporting revealed that not only were the cameras equipped with facial recognition technology that is illegal to use under Maine law, but the cameras were also being accessed in real time to watch footage at all hours of the day, including by non-police town employees and unidentified users who accessed the system after receiving the password. Access logs for the technology showed that both police and non-police employees used the cameras in a more advanced way to search for specific people and vehicles as well. Reports from around the country show police officers often use the cameras’ search capabilities to stalk their former partners; it’s not hard to imagine the same happening in Maine. 

Citing privacy concerns and risks of data misuse, rampant public pushback and grassroots advocacy in the state led several towns and cities including Saco, York, and South Portland to cancel their plans and deactivate existing ALPRs and surveillance cameras. Amid controversy, Houlton similarly deactivated its Verkada cameras while their use underwent legal review. Ultimately, the town agreed to remove the cameras and delete the data to avoid suit from residents requesting information under the Freedom of Access Act (FOAA).     

Available contracts contain an inconsistent mix of provisions that, taken together, leave loopholes in privacy protection for Mainers. 

By relying on FOAA requests—largely from the ACLU of Maine—and through accessing publicly available documents, EPIC was able to review many government contracts with technology companies across the state. EPIC’s review indicates that the contracts have varying degrees of privacy protection. EPIC considered a series of factors when reviewing these contracts for privacy protections, including the following provisions: data minimization, purpose limitation, agreements between vendors and other entities handling data, data ownership, cybersecurity requirements, independent audits, and the process for ensuring data remains protected when a contract ends or is terminated.    

Some contracts—especially more recent ones—include some mention of a combination of these factors, but it was hardly consistent across the board. 

Towns contracting with Flock, for example, have a brief sales agreement that refers to Flock’s terms and conditions for additional contract provisions. There, “customers” find that though they retain “all right, title, and interest in” their data, that right is practically nonexistent as they grant a “non-exclusive, royalty-free, irrevocable, perpetual, worldwide license” for Flock to “use and disclose” their data to provide its services and make improvements. The company also retains the right to control how it will deliver data or provide access to its customers, stripping towns even further of their “interest in” their own data. Flock’s license plate reader policy included a few more specific provisions on the above factors, including where data would be stored, when it would be deleted, and a broad provision allowing Flock to access, use, and disclose such data to law enforcement authorities or third parties where the company finds it “reasonably necessary,” leaving government entities with little say over what these terms mean in practice. While Flock’s policies technically address many of the types of privacy provisions EPIC looked for, the terms of these provisions reserve essentially all control over personal data to Flock rather than providing any clear protections for residents.    

In one cooperative master agreement originally signed by the state in 2016 with companies including LexisNexis, Carahsoft, Docusign, Salesforce, Google, and Amazon to provide various IT and AI tools, some basic considerations of data ownership were included, depending on the type of service being provided. Amendments were made to add a data privacy section in 2025 that simply requires compliance with some sectoral federal privacy laws, such as the Health Insurance Portability and Accountability Act (HIPAA) and the Family Educational Rights and Privacy Act (FERPA), while also requiring compliance with NIST cybersecurity standards for subcontractors. This agreement neglects to include key privacy provisions, such as data minimization, and also lacks a privacy-protective process for safeguarding data when services are terminated.  

A separate $3 million contract between the Maine State Police and Motorola for body-worn cameras to be used by police officers includes some bare provisions that give ownership of rights and interest in the content and data from cameras to the police department and limits the vendor’s ability to sublease or transfer any of their obligations or responsibilities without the department’s consent. The contract requires compliance with FBI security standards and other cybersecurity best practices under NIST, yet neglects many other privacy-protective provisions. 

Beyond these contracts’ fragmented approach to data privacy, others remained silent on privacy protections altogether, including what should happen with data when a contract is ended. 

Maine lacks a comprehensive privacy law and fails to mandate privacy protections in the state’s procurement contracts. 

Despite years of work in the Legislature on data privacy and amid immense amounts of lobbying, Maine failed to pass what would have been one of the strongest comprehensive privacy bills in the country by the close of the 2026 legislative session. The nearly-passed bill mirrored Maryland’s landmark privacy law and would have granted key privacy protections to Mainers. And while technology procurement in Maine is governed by statutory requirements at both the state and federal level, these regulations fail to mandate important privacy protections, including clarity over data ownership, data minimization requirements, or purpose limitation provisions. Thus, without a comprehensive privacy law, technology procurement is still left without any additional privacy requirements that could have been imposed on businesses operating in the state. 

In Maine, oversight of technology solutions is governed by MaineIT under its statutory authority. The procurement process itself is overseen by the Office of State Procurement Services, where the Chief Procurement Officer also has the ability to adopt rules to govern the awarding of contracts. The two teams work together to ensure that potential new tools meet technical requirements and aren’t on any statewide or federal lists of prohibited technologies prior to obtaining approval. 

In 2009, Maine became one of the first states in the country to pass a law limiting the use of ALPRs except for certain public safety and law enforcement purposes. The law also requires data to be kept confidential as defined under Maine law and to be available only for use by the collecting agency for its intended purpose for 21 days before it must be deleted. Notably, Maine also became one of the first states to enact a ban on the use of facial recognition technology in 2021. Therefore, any technology implemented by the state may not incorporate any form of facial recognition—even though many surveillance tools offer such a capability. To help the state enforce these laws, procurement contracts should allow government officials to have appropriate transparency and oversight to ensure that any potential facial recognition technology is turned off, private actors cannot access or use ALPRs, and any collected data is deleted after the 21-day limit. 

Mainers’ data remains potentially vulnerable and subject to potentially unfavorable contract negotiating tactics from large tech companies. 

Without a comprehensive privacy law or any regulation requiring consistent, privacy-protective provisions in technology procurement contracts, Mainers’ personal data is left vulnerable. Many of the companies that Maine and other states are contracting with are operating at a large scale with significant control over the market, meaning they often have the upper hand in contract negotiation. That dynamic leaves small states like Maine likely to fall prey to the outsized power of tech companies that could simply refuse the negotiating tactics of the state’s procurement team. Legally required privacy-protective provisions could help Maine advocate for better contract language and avoid caving to the company’s self-interested terms out of mere convenience. 

Privacy-protective and more consistent contract provisions can also help Mainers ensure that their tax dollars are paying for technology that is effective in achieving its goals. Oversight of key provisions in the procurement process can help Mainers avoid paying millions to put themselves, their rights, and their data at risk.  

Recommendations for policymakers in Maine and beyond 

Maine should leverage the recent successful pushback against ALPR procurement in the state to push for a required Code of Conduct or Data Privacy Agreement whenever state or local officials contract with a technology company. A clear, consistent set of obligations could help the state leverage better agreements with vendors and make it easier to terminate contracts if a violation occurs. 

Maine has already used state procurement to successfully regulate vendor conduct in other industries. For example, Maine has a Code of Conduct applicable to apparel, footwear, and textiles that could serve as an example. The law requires prospective vendors to sign an affidavit stating that they will comply with the Code of Conduct and will hold their suppliers to the same standard. The Code seeks to promote fair compensation and standards for health, labor, and environmental conditions and requires businesses to comply with best practices and applicable laws to do so. 

Using this approach, policymakers in Maine could require a similar Code of Conduct for data privacy practices when working with technology companies. This kind of requirement could help restore people’s trust that the government will protect their personal data and use their taxpayer dollars wisely by setting high standards for any company that chooses to contract with the government. EPIC recommends including at least the following in any such Code: 

  • Data Minimization: Data collection should be limited to what is strictly necessary to accomplish the purposes set out in the contract, and data should be deleted in a short time period after its use is no longer necessary for the originally intended purpose. 
  • Purpose Limitation: Any use or transfer of personal data should be limited to what is reasonably necessary for the intended purpose as defined by the state agency procuring such technology. 
  • Data Ownership: The state should retain ownership and exclusive control of any data collected with external technology, and any sale or transfer of personal and sensitive data to unauthorized third parties should be prohibited.
  • Adequate Cybersecurity Protection: Contracting vendors and all of their subcontractors must abide by state and federally required cybersecurity standards and comply with the state’s applicable data breach laws. 
  • Independent Audits: States should have the right to seek an independent audit of companies that have contracted with them to ensure compliance with the aforementioned requirements and other contractual provisions as necessary.
  • Effectiveness and Accuracy Verification: Upon request, companies must prove that their technology actually works effectively as promised within the procurement contract or marketing materials and serves the purpose stated by the government. 
  • Termination Procedure: When a vendor is found to be in breach of the contract, including the above requirements, states should reserve the right to terminate the agreement and request the immediate deletion of all data collected pursuant to that agreement.   

EPIC recommends that Maine policymakers take action to pass a law imposing the above requirements when state and local governments are procuring technology from private companies. 

While this blog post focused on Maine as one example of how a state could close the oversight gap in technology procurement, there are plenty more states that are well-positioned to take similar steps. To avoid taxpayer dollars being spent on ineffective technology that needlessly puts personal data at risk, policymakers around the country must take action. 

Support Our Work

EPIC's work is funded by the support of individuals like you, who allow us to continue to protect privacy, open government, and democratic values in the information age.

Donate