The NHPA compliance checklist is a 12-step plan for meeting the New Hampshire Privacy Act (NHPA), New Hampshire's consumer privacy law, which took effect January 1, 2025. It is enforced by the New Hampshire Attorney General (Data Privacy Unit, Consumer Protection and Antitrust Bureau), with civil penalties up to $10,000 per violation and no cure period. Work through every step below, then confirm your specific obligations with the free applicability calculator.
Compliance Steps
Effective: January 1, 20250
1
2
3
4
5
6
7
8
9
10
11
12
Key Enforcement Details
Enforced By
New Hampshire Attorney General (Data Privacy Unit, Consumer Protection and Antitrust Bureau)
It is a 12-step plan organizations use to meet the New Hampshire Privacy Act (NHPA), which took effect January 1, 2025. The steps below cover consumer-rights request handling, privacy-notice disclosures, opt-out mechanisms, data-processing agreements, and security safeguards required under New Hampshire law.
Who has to comply with the New Hampshire Privacy Act?
The NHPA generally applies to organizations that handle New Hampshire residents' personal data above the law's revenue and data-volume thresholds. Whether it applies to you depends on the specifics — check your exact obligations with the free applicability calculator at /calculator rather than assuming.
What is the penalty for NHPA non-compliance?
The New Hampshire Attorney General (Data Privacy Unit, Consumer Protection and Antitrust Bureau) can impose civil penalties of up to $10,000 per violation and no cure period. There is no private right of action, so enforcement comes from the state, not individual lawsuits. Figures verified July 28, 2026.
Put NHPA Into Practice on Your SiteSponsored
Termly builds and maintains a New Hampshire-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests NHPA grants.