New Hampshire Privacy Law
New Hampshire Privacy Act
Overview
The New Hampshire Privacy Act (NHPA, codified as RSA 507-H) was signed into law by Governor Chris Sununu on March 6, 2024, making New Hampshire the 14th state to enact a comprehensive consumer data privacy law. The law became effective on January 1, 2025, and is enforced by the New Hampshire Attorney General through the dedicated Data Privacy Unit within the Consumer Protection and Antitrust Bureau. Attorney General John Formella created this unit specifically to enforce RSA 507-H, staffing it with Assistant Attorney General Warren Cormack and Investigative Paralegal Isaiah Hutchinson. Violations of the NHPA constitute violations of RSA 358-A (Regulation of Business Practices for Consumer Protection), carrying civil penalties of up to $10,000 per violation. In October 2025 New Hampshire joined the Consortium of Privacy Regulators — a national, bipartisan organization of state privacy regulators collaborating on enforcement — alongside California, Colorado, Connecticut, New Jersey, Oregon, and other states, signaling New Hampshire's commitment to active, coordinated enforcement.
The NHPA provides New Hampshire consumers with broad privacy rights: the right to confirm whether a controller is processing their personal data, the right to access, correct, delete, and port personal data, as well as opt-out rights for data sales, targeted advertising, and profiling. Controllers must respond to consumer requests within 45 days, with a possible 45-day extension when reasonably necessary, and must provide an appeals process for denied requests. If the appeal is also denied, the controller must provide the consumer with a mechanism to contact the Attorney General. The NHPA requires controllers to conduct data protection assessments for processing activities that present a heightened risk of harm: targeted advertising, sale of personal data, processing of sensitive data, and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, or intrusion upon solitude or seclusion.
The law applies to entities conducting business in New Hampshire or targeting New Hampshire consumers that control or process personal data of 35,000 or more consumers (excluding payment transaction data), or control or process personal data of 10,000 or more consumers while deriving more than 25% of gross revenue from the sale of personal data. Notably, the NHPA has no standalone revenue threshold — unlike the CCPA which includes a $25 million revenue trigger — meaning even smaller businesses can fall within scope if they handle sufficient New Hampshire consumer data. The NHPA exempts certain entities and data types: financial institutions subject to GLBA, entities subject to HIPAA (though this is an entity-level exemption, unlike Colorado's data-level approach), nonprofits, higher education institutions, and data subject to FERPA, FCRA, the Driver's Privacy Protection Act, and the Farm Credit Act. The NHPA also requires controllers to honor universal opt-out mechanisms such as the Global Privacy Control (GPC) for opt-out-of-sale and opt-out-of-targeted-advertising requests. A critical enforcement transition occurred on January 1, 2026: the mandatory 60-day cure period expired, and the Attorney General now has discretion to determine whether to offer a cure opportunity based on factors including the number of violations, the size and complexity of the controller or processor, the nature and extent of processing, the likelihood of injury to the public, and the safety of persons or property.
Applicability Thresholds
Conditions are joined by OR — meeting ANY one triggers applicability.
Consumer Rights
Key Changes in 2025-2026
- Mandatory 60-day cure period expired January 1, 2026 — AG now has full discretion on whether to offer cure opportunities based on the number of violations, controller complexity, likelihood of public injury, and safety concerns
- AG Formella's Data Privacy Unit is now fully operational with dedicated enforcement staff (Assistant AG Warren Cormack) and the New Hampshire legislature has appropriated additional funding to the Consumer Protection Division for NHPA enforcement
- New Hampshire joined the Consortium of Privacy Regulators in October 2025, enabling coordinated multistate enforcement with California (CPPA), Colorado, Connecticut, New Jersey, Oregon, and other member states
- Universal opt-out mechanism (GPC) recognition has been required since January 1, 2025 under RSA 507-H:6(V)(a)(1)(B)
- Lower applicability thresholds (35,000 consumers) than most states position NH to capture businesses that fall below Virginia (100,000) or Connecticut (100,000) thresholds but serve sufficient NH consumers
- Post-cure-period enforcement environment means businesses can no longer rely on a guaranteed cure window — the AG can proceed directly to enforcement action for any violation at their discretion
- NH DOJ published official FAQ guidance document (revised) clarifying data protection assessment requirements, sensitive data categories, and consumer rights request handling procedures
- Monitoring for 2026 legislative session amendments that may expand protections, add children's privacy provisions, or introduce sector-specific requirements
Enforcement Details
Sensitive Data Categories
Consent model: opt-in
Universal Opt-Out / GPC Requirements
The NHPA requires controllers to honor opt-out preference signals such as Global Privacy Control (GPC) for targeted advertising and personal-data sales. RSA 507-H:6(V)(a)(1)(B) made this requirement effective January 1, 2025. Source check: New Hampshire General Court, RSA 507-H:6, date_retrieved 2026-07-19.
Effective: January 1, 2025
Minor / Child Protections
The NHPA requires opt-in consent for processing personal data of known children under 13, which is classified as sensitive data. For teen consumers aged 13-17, the law restricts targeted advertising and data sales without affirmative consent. Controllers that willfully disregard a consumer's age are treated as having actual knowledge of the consumer's age.
Compliance Checklist
- 1Assess applicability carefully — the NHPA has no revenue threshold (unlike CCPA's $25M trigger), so businesses of any size can be subject if they process data of 35,000+ NH consumers or 10,000+ consumers with 25%+ revenue from data sales. Exclude only payment transaction data from consumer counts. Check entity-level exemptions: GLBA-regulated financial institutions, HIPAA-covered entities, nonprofits, and higher education institutions are exempt, but note that these are entity-level (not data-level) exemptions
- 2Implement Global Privacy Control (GPC) recognition — since January 1, 2025, controllers have had to honor valid opt-out preference signals for personal-data sales and targeted advertising. Test across major browsers (Chrome, Firefox, Safari, Edge, Brave). Ensure GPC signals propagate to all downstream processors and third parties within a reasonable timeframe. Log all GPC signal detections and downstream propagation actions for enforcement-audit readiness
- 3Update privacy notices with all NHPA-required disclosures: categories of personal data processed, purposes of processing, categories of personal data shared with third parties, categories of third parties with whom data is shared, how consumers can exercise their rights (access, correction, deletion, portability, opt-out), and a clear description of the appeals process. Include a dated "Last Updated" field and ensure the notice is not "largely unreadable" — Connecticut's $85K TicketNetwork settlement for unreadable privacy notices is directly applicable precedent
- 4Build consumer rights request intake and response system with 45-day initial response deadline, optional 45-day extension (with written notice of reason for extension), and a documented appeals process. If the appeal is denied, provide the consumer with a mechanism to contact the NH Attorney General ([email protected] or the Consumer Protection Complaint Form). Maintain a 24-month log of all requests, responses, appeals, and outcomes
- 5Obtain opt-in consent before processing any sensitive personal data: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, biometric data used for identification purposes, genetic data, precise geolocation data, and personal data of known children under 13. Consent must be freely given, specific, informed, and unambiguous — avoid dark patterns, pre-checked boxes, or bundled consent that makes it impossible to consent to some categories but not others
- 6Implement separate opt-out mechanisms for (a) sale of personal data, (b) targeted advertising, and (c) profiling that produces legal or similarly significant effects. Each mechanism must be clearly presented and easy to use. Do not require consumers to create an account or provide unnecessary personal information to exercise opt-out rights. Ensure that when a consumer opts out through GPC, the opt-out applies to both sale and targeted advertising simultaneously
- 7Conduct data protection assessments (DPAs) for every processing activity that presents a heightened risk of harm: targeted advertising, sale of personal data, processing of sensitive data, and profiling. Each DPA must identify and weigh the benefits of the processing (to the controller, the consumer, other stakeholders, and the public) against the potential risks to consumer rights, as mitigated by safeguards the controller employs. Factor in the use of de-identified data and the reasonable expectations of consumers. Make DPAs available to the AG upon request — the NH DOJ FAQ guidance indicates the AG may request DPAs as part of an investigation
- 8Establish and maintain processor contracts with all entities processing personal data on the controller's behalf. Contracts must clearly set forth processing instructions, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties. Include confidentiality requirements, subcontractor flow-down provisions, and audit rights. Any contract signed before January 1, 2025 that has not been refreshed to include NHPA-compliant terms is likely noncompliant
- 9Implement data minimization practices — collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed processing purpose. Establish retention schedules and delete personal data that is no longer necessary. Document the business justification for each data category retained beyond 12 months
- 10Prepare for post-cure-period enforcement environment — since January 1, 2026, the AG has full discretion on whether to offer a cure opportunity. Build an AG-inquiry response playbook: (1) preserve all relevant documents and data upon receiving AG notice, (2) designate legal counsel as the single point of contact, (3) conduct a rapid internal audit of the alleged violation within 5 business days, (4) prepare a remediation plan with specific timelines, (5) respond to the AG within the requested timeframe. Voluntary remediation may still be considered favorably but is no longer guaranteed to prevent enforcement action
- 11Map compliance against related state laws — if you also operate in Connecticut, Delaware, Rhode Island, Maryland, or other states with similar thresholds, identify the NHPA-specific requirements that multistate compliance may not automatically cover: GPC recognition (if not already honoring GPC for other states), the specific DPA requirements under RSA 507-H, the appeals-to-AG mechanism, and the 45+45 day response timeline (which differs from some states' 30-day or 60-day windows)
- 12Conduct regular compliance monitoring — test GPC recognition monthly across all consumer-facing properties, perform quarterly audits of consumer request response times and outcomes, refresh DPAs annually or when processing activities change materially, and ensure all staff who handle consumer data or privacy requests receive documented training on NHPA requirements
Termly builds and maintains a New Hampshire-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests NHPA grants.