Privacy Law Library

Notice of Security Breach

NH Breach Notification Law

Breach notification

Requires anyone doing business in New Hampshire to investigate a breach of computerized personal information (name plus SSN, driver's license or government ID number, or financial account/card number with access code) and notify affected individuals as soon as possible when misuse has occurred, is reasonably likely, or cannot be ruled out. The Attorney General or the entity's primary regulator must also be told, and nationwide consumer reporting agencies when more than 1,000 consumers are notified.

Where
New Hampshire
Citation
N.H. Rev. Stat. Ann. 359-C:19 to 359-C:21
Status
In force
In force since
2007-01-01
Enforced by
New Hampshire Attorney General (under RSA 358-A:4); private individuals may also sue
People can sue
Yes
Penalties
Injured persons may recover actual damages, doubled or trebled for willful or knowing violations, plus costs and attorney's fees; the Attorney General enforces under RSA 358-A:4 (civil penalties up to $10,000 per violation).
Applies to
  • Any person doing business in New Hampshire (including individuals, businesses and state and local government entities) that owns or licenses computerized data containing personal information
  • Persons that maintain computerized personal information they do not own (must notify the owner or licensee)

Breach duties

  • Upon becoming aware of a security breach, promptly determine the likelihood of misuse; if misuse occurred, is reasonably likely, or cannot be determined, notify affected individuals as soon as possible.RSA 359-C:20, I(a)
  • Notify the New Hampshire Attorney General's office (or, for persons subject to RSA 358-A:3, I, their primary regulator) with the anticipated date of individual notice and approximate number of NH individuals notified.RSA 359-C:20, I(b)
  • A person maintaining data it does not own must notify and cooperate with the owner or licensee immediately after discovering a breach.RSA 359-C:20, I(c)
  • Notice may be written, electronic, telephonic (with a log) or substitute notice (email, website posting and statewide media) if costs exceed $5,000, more than 1,000 people are affected, or contact information is lacking.RSA 359-C:20, III
  • Notice must describe the incident generally, the approximate date of breach, the type of personal information obtained, and the notifying person's telephone contact information.RSA 359-C:20, IV
  • When more than 1,000 consumers must be notified, also notify nationwide consumer reporting agencies of timing, number and content of notices (not required for GLBA-covered persons).RSA 359-C:20, VI

Other duties

  • Notification may be delayed when law enforcement or national or homeland security agencies determine notice would impede an investigation or jeopardize security.RSA 359-C:20, II

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: NH DOJ security breach notification page (doj.nh.gov) returned HTTP 403, so the Attorney General's submission process and published breach notices were not verified

Research reference, not legal advice.