New Hampshire — Comprehensive Law

New Hampshire Privacy Law

New Hampshire wrote its cure period as a two-stage rule and then told the Attorney General what to think about when the first stage ended. Under RSA 507-H:11, II a notice of violation and sixty days to cure were mandatory through December 31, 2025; under paragraph III, from January 1, 2026 the decision became discretionary and the statute lists six factors the Attorney General may weigh. The chapter is also notable for what it does not contain: no rulemaking authority of any kind, and a single administrative duty on the Secretary of State to “notice and post a link” to the chapter. Penalties come from the state’s general Consumer Protection Act, which counts violations without regard to how many people were affected and gives defendants a good-faith-misunderstanding defence. The breach statute routes notice to whichever regulator already supervises the business, and only to the Attorney General if none does.

The New Hampshire Data Privacy Act (NHPA)

Enacted by 2024, ch. 5 and amended the same session by 2024, ch. 229, RSA chapter 507-H took effect January 1, 2025. Section 507-H:2, I sets a two-branch threshold measured over a one-year period and excludes personal data controlled or processed solely to complete a payment transaction from the count. Section 507-H:6, V(a)(1)(B) required controllers, not later than January 1, 2025, to allow consumers to opt out of targeted advertising and the sale of personal data through an opt-out preference signal sent by a platform, technology or mechanism, and paragraph (2) resolves a conflict between such a signal and an existing controller-specific setting or loyalty-programme participation in the signal’s favour, allowing the controller to notify the consumer of the conflict and invite confirmation. Section 507-H:11, V provides that a violation of the chapter “shall constitute an unfair method of competition or any unfair or deceptive act or practice” under RSA 358-A:2, enforced by the Attorney General; paragraph IV forecloses any private right of action under the chapter or any other law. The chapter contains no rulemaking provision, and the only duty it places on the Secretary of State, at § 507-H:2, II, is to notice and post a link to RSA 507-H on the office’s website.

Effective dateJanuary 1, 2025
CitationN.H. Rev. Stat. Ann. ch. 507-H
Enforced byNew Hampshire Attorney General
Maximum penaltyCivil penalties of up to $10,000 for each violation under RSA 358-A:4, III(b), which a violation of RSA 507-H becomes by operation of § 507-H:11, V
Private right of actionNo, enforcement by the state only
Right to cure60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against six statutory factors

Who Must Comply

The NHPA reaches a business that conducts business in New Hampshire or produces products or services targeted to New Hampshire residents, and during a one-year period controlled or processed the personal data of not less than 35,000 unique consumers, excluding data processed solely to complete a payment transaction, or controlled or processed the personal data of not less than 10,000 unique consumers while deriving more than 25% of gross revenue from the sale of personal data.

The chapter grants no rulemaking authority to anyone, the Secretary of State’s only duty is to post a link to it, and its penalties are borrowed from a consumer-protection act that counts violations without regard to the number of people affected.

Consumer Rights Under the NHPA

Residents of New Hampshire can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in New Hampshire

Insurance Data Security Law (N.H. Rev. Stat. Ann. ch. 420-P)

Chapter 420-P puts insurance licensees on a much shorter clock than the general breach statute and gives them two safe harbours the general statute does not. Section 420-P:6, I requires a licensee to notify the Insurance Commissioner within three business days of determining that a cybersecurity event has occurred, where New Hampshire is the licensee’s state of domicile or home state as defined in RSA 402-J and the event has a reasonable likelihood of materially harming a New Hampshire consumer or any material part of the licensee’s normal operations, or where the licensee reasonably believes the nonpublic information of 250 or more New Hampshire consumers is involved and the event either triggers notice to another supervisory body or carries that same likelihood of material harm. Paragraph II requires the licensee to supply the listed information electronically and imposes a continuing obligation to update and supplement. Section 420-P:4 requires an information security program. The first safe harbour treats a licensee that maintains HIPAA-compliant programs and certifies as much in writing as meeting the chapter’s requirements; the second, unusual among state insurance data security laws, treats a licensee in compliance with the New York Department of Financial Services cybersecurity regulation at N.Y. Comp. Codes R. & Regs. tit. 23, § 500 as meeting them, on the same written certification. Neither safe harbour relieves the licensee of the investigation duty in § 420-P:5 or the commissioner and consumer notification duties in § 420-P:6. Section 420-P:8 makes material furnished to the department confidential, not subject to the right-to-know law at RSA 91-A, not subject to subpoena, and not discoverable or admissible in a private civil action.

Consumer Protection Act (N.H. Rev. Stat. Ann. ch. 358-A)

RSA 358-A:2 declares it unlawful to use any unfair method of competition or any unfair or deceptive act or practice in the conduct of any trade or commerce, followed by a non-exhaustive list. Two features of its remedial provisions bear directly on privacy enforcement. First, RSA 358-A:4, III(b) allows the court to award the state civil penalties of up to $10,000 for each violation and then directs that “the court shall determine the number of unlawful acts or practices which have occurred without regard to the number of persons affected thereby” — a counting rule that decouples the penalty from the size of the affected population. The same subparagraph creates an affirmative defence to the assessment of civil penalties where the defendant acted pursuant to a good faith misunderstanding concerning the requirements of the chapter. Second, RSA 358-A:10, I gives a private plaintiff actual damages or $1,000, whichever is greater, mandatory double-to-treble damages for a willful or knowing violation, and mandatory costs and fees, with any attempted waiver void — but RSA 507-H:11, IV forecloses that route for violations of the privacy chapter itself. RSA 358-A:4, III-a adds a receivership power, and paragraph IV requires county attorneys and law enforcement officers receiving notice of an alleged violation to forward it to the department of justice.

Data Breach Notification in New Hampshire

RSA 359-C:20 turns on a determination rather than on the fact of acquisition, and it resolves uncertainty against the business. Paragraph I(a) requires a person who owns or licenses computerized data containing personal information, on becoming aware of a security breach, to promptly determine the likelihood that the information has been or will be misused; notification to affected individuals follows if misuse has occurred, is reasonably likely to occur, or if a determination cannot be made. Paragraph I(b) then routes the regulatory notice by reference to who already supervises the business: a person engaged in trade or commerce that is subject to RSA 358-A:3, I — the exemption for conduct permitted under laws administered by a state or federal regulator — notifies that regulator, and all other persons notify the New Hampshire Attorney General’s office. The notice states the anticipated date of individual notice and the approximate number of New Hampshire residents to be notified, and the paragraph expressly provides that nothing requires the names of those individuals or any personal information about them to be given to the regulator or the Attorney General. Paragraph I(c) puts a person maintaining data it does not own on an immediate duty to notify and cooperate with the owner or licensee, with cooperation defined to include sharing information relevant to the breach but not to require disclosure of confidential business information or trade secrets. Paragraph II permits delay where a law enforcement, national security or homeland security agency determines notification will impede an investigation or jeopardise security.

Residents must be notified as quickly as possible after the determination that misuse has occurred or is reasonably likely. Regulated businesses notify their primary regulator; all other persons notify the Attorney General — no headcount threshold. Complaints are taken by the New Hampshire Attorney General, which enforces the statute.

How the NHPA Is Enforced

A cure period that expired into a checklist. RSA 507-H:11 sets out three stages. Paragraph I gives the Attorney General exclusive authority to enforce the chapter. Paragraph II provides that during the period beginning January 1, 2025 and ending December 31, 2025 the Attorney General “shall”, and following that period “may”, issue a notice of violation before initiating any action where the office determines that a cure is possible, with sixty days to cure from receipt. Paragraph III then supplies the criteria for the discretionary stage: beginning January 1, 2026, in deciding whether to grant an opportunity to cure the Attorney General may consider the number of violations; the size and complexity of the controller or processor; the nature and extent of its processing activities; the substantial likelihood of injury to the public; the safety of persons or property; and whether the alleged violation was likely caused by human or technical error.

Pending Privacy Legislation

RSA chapter 507-H stands as enacted by 2024, ch. 5 and amended in the same session by 2024, ch. 229, which took effect January 1, 2025 at 12:01 a.m. The chapter’s own timetable has since done the work that amendments do elsewhere: the universal opt-out obligation in § 507-H:6, V(a)(1)(B) attached not later than January 1, 2025, the mandatory notice-and-cure in § 507-H:11, II ran through December 31, 2025, and the discretionary standard in paragraph III began January 1, 2026. No provision of the chapter has been amended since, and no rulemaking has been authorised that could supply detail the statute leaves open. RSA 359-C:20 and RSA 358-A likewise carry no privacy-specific amendment of recent vintage; RSA 358-A:4 was last amended in 1996.

Federal Privacy Laws That Apply in New Hampshire

Federal privacy law applies in New Hampshire by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The NHPA sits alongside those rules rather than displacing them: the New Hampshire Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Consumer Protection Act (N.H. Rev. Stat. Ann. ch. 358-A), which the New Hampshire Attorney General enforces against businesses whose stated data practices differ from their actual ones.

New Hampshire Privacy Law FAQ

Does anyone have rulemaking authority under New Hampshire’s privacy chapter?
No. RSA chapter 507-H contains no provision authorising the Attorney General, the Secretary of State or any other officer to adopt rules, and no reference to rulemaking under RSA 541-A. The single administrative duty the chapter creates is at § 507-H:2, II, which provides that “[t]he secretary of state shall notice and post a link to RSA 507-H on the secretary of state’s website.”
What happened to New Hampshire’s right to cure after 2025?
It became discretionary rather than disappearing. RSA 507-H:11, II made a notice of violation and a sixty-day cure mandatory from January 1, 2025 through December 31, 2025 where the Attorney General determined a cure was possible, and made it permissive thereafter. Paragraph III lists six factors the Attorney General may consider from January 1, 2026 in deciding whether to grant the opportunity: the number of violations; the size and complexity of the controller or processor; the nature and extent of its processing activities; the substantial likelihood of injury to the public; the safety of persons or property; and whether the violation was likely caused by human or technical error.
Who gets notified of a data breach in New Hampshire?
It depends on who regulates the business. RSA 359-C:20, I(b) requires a person engaged in trade or commerce subject to RSA 358-A:3, I to notify the regulator with primary regulatory authority over that trade or commerce; all other persons notify the New Hampshire Attorney General’s office. Either notice states the anticipated date of individual notice and the approximate number of New Hampshire residents who will be notified, and the paragraph expressly provides that nothing requires the person to give the regulator or the Attorney General the names of those individuals or any personal information about them.
What if a business cannot tell whether breached data will be misused?
RSA 359-C:20, I(a) requires notice anyway. The paragraph directs a person who becomes aware of a security breach to promptly determine the likelihood that the information has been or will be misused, and then requires notification to the affected individuals if the determination is that misuse has occurred or is reasonably likely to occur “or if a determination cannot be made”. Notice is to be given as soon as possible after that determination.
How are penalties counted under New Hampshire’s Consumer Protection Act?
Without reference to how many people were affected. RSA 358-A:4, III(b) allows the court to award the state civil penalties of up to $10,000 for each violation and provides that “the court shall determine the number of unlawful acts or practices which have occurred without regard to the number of persons affected thereby”. The same subparagraph makes it an affirmative defence to the assessment of civil penalties that the defendant acted pursuant to a good faith misunderstanding concerning the requirements of the chapter, and provides that no order requires payment until appeals are exhausted.
Can a New Hampshire consumer sue over a privacy violation?
Not under the privacy chapter. RSA 507-H:11, IV provides that nothing in the chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations under the chapter or any other law. That paragraph sits alongside paragraph V, which makes a violation of the chapter an unfair or deceptive act under RSA 358-A:2 — a statute that does carry a private action at RSA 358-A:10 for violations reached on their own terms.
Does a New York cybersecurity certification satisfy New Hampshire’s insurance data security law?
In part. RSA chapter 420-P contains a New York regulatory safe harbour under which a licensee in compliance with N.Y. Comp. Codes R. & Regs. tit. 23, § 500, effective March 1, 2017, is considered to meet the chapter’s requirements on submitting a written certification of that compliance to the commissioner. The safe harbour is expressly qualified: such a licensee remains subject to the investigation requirements of RSA 420-P:5, the commissioner notification requirements of RSA 420-P:6, I and II, and the consumer notification requirements of RSA 420-P:6, III.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.