1
Assess applicability carefully — the NHPA has no revenue threshold (unlike CCPA's $25M trigger), so businesses of any size can be subject if they process data of 35,000+ NH consumers or 10,000+ consumers with 25%+ revenue from data sales. Exclude only payment transaction data from consumer counts. Check entity-level exemptions: GLBA-regulated financial institutions, HIPAA-covered entities, nonprofits, and higher education institutions are exempt, but note that these are entity-level (not data-level) exemptions
2
Implement Global Privacy Control (GPC) recognition — since January 1, 2025, controllers have had to honor valid opt-out preference signals for personal-data sales and targeted advertising. Test across major browsers (Chrome, Firefox, Safari, Edge, Brave). Ensure GPC signals propagate to all downstream processors and third parties within a reasonable timeframe. Log all GPC signal detections and downstream propagation actions for enforcement-audit readiness
3
Update privacy notices with all NHPA-required disclosures: categories of personal data processed, purposes of processing, categories of personal data shared with third parties, categories of third parties with whom data is shared, how consumers can exercise their rights (access, correction, deletion, portability, opt-out), and a clear description of the appeals process. Include a dated "Last Updated" field and ensure the notice is not "largely unreadable" — Connecticut's $85K TicketNetwork settlement for unreadable privacy notices is directly applicable precedent
4
5
Obtain opt-in consent before processing any sensitive personal data: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, biometric data used for identification purposes, genetic data, precise geolocation data, and personal data of known children under 13. Consent must be freely given, specific, informed, and unambiguous — avoid dark patterns, pre-checked boxes, or bundled consent that makes it impossible to consent to some categories but not others
6
Implement separate opt-out mechanisms for (a) sale of personal data, (b) targeted advertising, and (c) profiling that produces legal or similarly significant effects. Each mechanism must be clearly presented and easy to use. Do not require consumers to create an account or provide unnecessary personal information to exercise opt-out rights. Ensure that when a consumer opts out through GPC, the opt-out applies to both sale and targeted advertising simultaneously
7
Conduct data protection assessments (DPAs) for every processing activity that presents a heightened risk of harm: targeted advertising, sale of personal data, processing of sensitive data, and profiling. Each DPA must identify and weigh the benefits of the processing (to the controller, the consumer, other stakeholders, and the public) against the potential risks to consumer rights, as mitigated by safeguards the controller employs. Factor in the use of de-identified data and the reasonable expectations of consumers. Make DPAs available to the AG upon request — the NH DOJ FAQ guidance indicates the AG may request DPAs as part of an investigation
8
Establish and maintain processor contracts with all entities processing personal data on the controller's behalf. Contracts must clearly set forth processing instructions, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties. Include confidentiality requirements, subcontractor flow-down provisions, and audit rights. Any contract signed before January 1, 2025 that has not been refreshed to include NHPA-compliant terms is likely noncompliant
9
Implement data minimization practices — collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed processing purpose. Establish retention schedules and delete personal data that is no longer necessary. Document the business justification for each data category retained beyond 12 months
10
Prepare for post-cure-period enforcement environment — since January 1, 2026, the AG has full discretion on whether to offer a cure opportunity. Build an AG-inquiry response playbook: (1) preserve all relevant documents and data upon receiving AG notice, (2) designate legal counsel as the single point of contact, (3) conduct a rapid internal audit of the alleged violation within 5 business days, (4) prepare a remediation plan with specific timelines, (5) respond to the AG within the requested timeframe. Voluntary remediation may still be considered favorably but is no longer guaranteed to prevent enforcement action
11
Map compliance against related state laws — if you also operate in Connecticut, Delaware, Rhode Island, Maryland, or other states with similar thresholds, identify the NHPA-specific requirements that multistate compliance may not automatically cover: GPC recognition (if not already honoring GPC for other states), the specific DPA requirements under RSA 507-H, the appeals-to-AG mechanism, and the 45+45 day response timeline (which differs from some states' 30-day or 60-day windows)
12
Conduct regular compliance monitoring — test GPC recognition monthly across all consumer-facing properties, perform quarterly audits of consumer request response times and outcomes, refresh DPAs annually or when processing activities change materially, and ensure all staff who handle consumer data or privacy requests receive documented training on NHPA requirements