New Hampshire Privacy Law
New Hampshire wrote its cure period as a two-stage rule and then told the Attorney General what to think about when the first stage ended. Under RSA 507-H:11, II a notice of violation and sixty days to cure were mandatory through December 31, 2025; under paragraph III, from January 1, 2026 the decision became discretionary and the statute lists six factors the Attorney General may weigh. The chapter is also notable for what it does not contain: no rulemaking authority of any kind, and a single administrative duty on the Secretary of State to “notice and post a link” to the chapter. Penalties come from the state’s general Consumer Protection Act, which counts violations without regard to how many people were affected and gives defendants a good-faith-misunderstanding defence. The breach statute routes notice to whichever regulator already supervises the business, and only to the Attorney General if none does.
The New Hampshire Data Privacy Act (NHPA)
Enacted by 2024, ch. 5 and amended the same session by 2024, ch. 229, RSA chapter 507-H took effect January 1, 2025. Section 507-H:2, I sets a two-branch threshold measured over a one-year period and excludes personal data controlled or processed solely to complete a payment transaction from the count. Section 507-H:6, V(a)(1)(B) required controllers, not later than January 1, 2025, to allow consumers to opt out of targeted advertising and the sale of personal data through an opt-out preference signal sent by a platform, technology or mechanism, and paragraph (2) resolves a conflict between such a signal and an existing controller-specific setting or loyalty-programme participation in the signal’s favour, allowing the controller to notify the consumer of the conflict and invite confirmation. Section 507-H:11, V provides that a violation of the chapter “shall constitute an unfair method of competition or any unfair or deceptive act or practice” under RSA 358-A:2, enforced by the Attorney General; paragraph IV forecloses any private right of action under the chapter or any other law. The chapter contains no rulemaking provision, and the only duty it places on the Secretary of State, at § 507-H:2, II, is to notice and post a link to RSA 507-H on the office’s website.
| Effective date | January 1, 2025 |
|---|---|
| Citation | N.H. Rev. Stat. Ann. ch. 507-H |
| Enforced by | New Hampshire Attorney General |
| Maximum penalty | Civil penalties of up to $10,000 for each violation under RSA 358-A:4, III(b), which a violation of RSA 507-H becomes by operation of § 507-H:11, V |
| Private right of action | No, enforcement by the state only |
| Right to cure | 60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against six statutory factors |
Who Must Comply
The NHPA reaches a business that conducts business in New Hampshire or produces products or services targeted to New Hampshire residents, and during a one-year period controlled or processed the personal data of not less than 35,000 unique consumers, excluding data processed solely to complete a payment transaction, or controlled or processed the personal data of not less than 10,000 unique consumers while deriving more than 25% of gross revenue from the sale of personal data.
The chapter grants no rulemaking authority to anyone, the Secretary of State’s only duty is to post a link to it, and its penalties are borrowed from a consumer-protection act that counts violations without regard to the number of people affected.
Consumer Rights Under the NHPA
Residents of New Hampshire can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in New Hampshire
Insurance Data Security Law (N.H. Rev. Stat. Ann. ch. 420-P)
Chapter 420-P puts insurance licensees on a much shorter clock than the general breach statute and gives them two safe harbours the general statute does not. Section 420-P:6, I requires a licensee to notify the Insurance Commissioner within three business days of determining that a cybersecurity event has occurred, where New Hampshire is the licensee’s state of domicile or home state as defined in RSA 402-J and the event has a reasonable likelihood of materially harming a New Hampshire consumer or any material part of the licensee’s normal operations, or where the licensee reasonably believes the nonpublic information of 250 or more New Hampshire consumers is involved and the event either triggers notice to another supervisory body or carries that same likelihood of material harm. Paragraph II requires the licensee to supply the listed information electronically and imposes a continuing obligation to update and supplement. Section 420-P:4 requires an information security program. The first safe harbour treats a licensee that maintains HIPAA-compliant programs and certifies as much in writing as meeting the chapter’s requirements; the second, unusual among state insurance data security laws, treats a licensee in compliance with the New York Department of Financial Services cybersecurity regulation at N.Y. Comp. Codes R. & Regs. tit. 23, § 500 as meeting them, on the same written certification. Neither safe harbour relieves the licensee of the investigation duty in § 420-P:5 or the commissioner and consumer notification duties in § 420-P:6. Section 420-P:8 makes material furnished to the department confidential, not subject to the right-to-know law at RSA 91-A, not subject to subpoena, and not discoverable or admissible in a private civil action.
Consumer Protection Act (N.H. Rev. Stat. Ann. ch. 358-A)
RSA 358-A:2 declares it unlawful to use any unfair method of competition or any unfair or deceptive act or practice in the conduct of any trade or commerce, followed by a non-exhaustive list. Two features of its remedial provisions bear directly on privacy enforcement. First, RSA 358-A:4, III(b) allows the court to award the state civil penalties of up to $10,000 for each violation and then directs that “the court shall determine the number of unlawful acts or practices which have occurred without regard to the number of persons affected thereby” — a counting rule that decouples the penalty from the size of the affected population. The same subparagraph creates an affirmative defence to the assessment of civil penalties where the defendant acted pursuant to a good faith misunderstanding concerning the requirements of the chapter. Second, RSA 358-A:10, I gives a private plaintiff actual damages or $1,000, whichever is greater, mandatory double-to-treble damages for a willful or knowing violation, and mandatory costs and fees, with any attempted waiver void — but RSA 507-H:11, IV forecloses that route for violations of the privacy chapter itself. RSA 358-A:4, III-a adds a receivership power, and paragraph IV requires county attorneys and law enforcement officers receiving notice of an alleged violation to forward it to the department of justice.
Data Breach Notification in New Hampshire
RSA 359-C:20 turns on a determination rather than on the fact of acquisition, and it resolves uncertainty against the business. Paragraph I(a) requires a person who owns or licenses computerized data containing personal information, on becoming aware of a security breach, to promptly determine the likelihood that the information has been or will be misused; notification to affected individuals follows if misuse has occurred, is reasonably likely to occur, or if a determination cannot be made. Paragraph I(b) then routes the regulatory notice by reference to who already supervises the business: a person engaged in trade or commerce that is subject to RSA 358-A:3, I — the exemption for conduct permitted under laws administered by a state or federal regulator — notifies that regulator, and all other persons notify the New Hampshire Attorney General’s office. The notice states the anticipated date of individual notice and the approximate number of New Hampshire residents to be notified, and the paragraph expressly provides that nothing requires the names of those individuals or any personal information about them to be given to the regulator or the Attorney General. Paragraph I(c) puts a person maintaining data it does not own on an immediate duty to notify and cooperate with the owner or licensee, with cooperation defined to include sharing information relevant to the breach but not to require disclosure of confidential business information or trade secrets. Paragraph II permits delay where a law enforcement, national security or homeland security agency determines notification will impede an investigation or jeopardise security.
Residents must be notified as quickly as possible after the determination that misuse has occurred or is reasonably likely. Regulated businesses notify their primary regulator; all other persons notify the Attorney General — no headcount threshold. Complaints are taken by the New Hampshire Attorney General, which enforces the statute.
How the NHPA Is Enforced
A cure period that expired into a checklist. RSA 507-H:11 sets out three stages. Paragraph I gives the Attorney General exclusive authority to enforce the chapter. Paragraph II provides that during the period beginning January 1, 2025 and ending December 31, 2025 the Attorney General “shall”, and following that period “may”, issue a notice of violation before initiating any action where the office determines that a cure is possible, with sixty days to cure from receipt. Paragraph III then supplies the criteria for the discretionary stage: beginning January 1, 2026, in deciding whether to grant an opportunity to cure the Attorney General may consider the number of violations; the size and complexity of the controller or processor; the nature and extent of its processing activities; the substantial likelihood of injury to the public; the safety of persons or property; and whether the alleged violation was likely caused by human or technical error.
Pending Privacy Legislation
RSA chapter 507-H stands as enacted by 2024, ch. 5 and amended in the same session by 2024, ch. 229, which took effect January 1, 2025 at 12:01 a.m. The chapter’s own timetable has since done the work that amendments do elsewhere: the universal opt-out obligation in § 507-H:6, V(a)(1)(B) attached not later than January 1, 2025, the mandatory notice-and-cure in § 507-H:11, II ran through December 31, 2025, and the discretionary standard in paragraph III began January 1, 2026. No provision of the chapter has been amended since, and no rulemaking has been authorised that could supply detail the statute leaves open. RSA 359-C:20 and RSA 358-A likewise carry no privacy-specific amendment of recent vintage; RSA 358-A:4 was last amended in 1996.
Federal Privacy Laws That Apply in New Hampshire
Federal privacy law applies in New Hampshire by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The NHPA sits alongside those rules rather than displacing them: the New Hampshire Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Consumer Protection Act (N.H. Rev. Stat. Ann. ch. 358-A), which the New Hampshire Attorney General enforces against businesses whose stated data practices differ from their actual ones.
New Hampshire Privacy Law FAQ
Does anyone have rulemaking authority under New Hampshire’s privacy chapter?
What happened to New Hampshire’s right to cure after 2025?
Who gets notified of a data breach in New Hampshire?
What if a business cannot tell whether breached data will be misused?
How are penalties counted under New Hampshire’s Consumer Protection Act?
Can a New Hampshire consumer sue over a privacy violation?
Does a New York cybersecurity certification satisfy New Hampshire’s insurance data security law?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- N.H. Rev. Stat. Ann. ch. 507-H — Expectation of Privacy statute
- N.H. Rev. Stat. Ann. ch. 359-C — Right to Privacy (breach notification at 359-C:20) statute
- N.H. Rev. Stat. Ann. ch. 358-A — Regulation of Business Practices for Consumer Protection statute
- N.H. Rev. Stat. Ann. ch. 420-P — Insurance Data Security Law statute
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.