Privacy Law Library

New Hampshire Privacy Act (Expectation of Privacy)

NHPA

Comprehensive privacy · Children · Biometric · Genetic · Health · Location

New Hampshire's comprehensive consumer privacy law gives NH residents rights to access, correct, delete and port their personal data and to opt out of targeted advertising, sales and significant automated profiling. Covered controllers must minimise collection, get opt-in consent for sensitive data, honor universal opt-out signals, publish a privacy notice and run data protection assessments for high-risk processing. A 2026 amendment bars selling a child's personal data starting Jan. 1, 2027.

Where
New Hampshire
Citation
N.H. Rev. Stat. Ann. ch. 507-H
Status
In force
In force since
2025-01-01
Last amended
2027-01-01
Enforced by
New Hampshire Attorney General (exclusive authority)
People can sue
No
Penalties
A violation is an unfair or deceptive act under RSA 358-A:2, enforced exclusively by the Attorney General: courts may award civil penalties up to $10,000 per violation (RSA 358-A:4, III(b)) plus injunctions and restitution, and a knowing RSA 358-A:2 violation can be prosecuted as a misdemeanor (natural persons) or felony (other persons) under RSA 358-A:6. A 60-day cure notice was mandatory during 2025 and is discretionary from Jan. 1, 2026. No private right of action (RSA 507-H:11, IV).
Applies to
  • Persons conducting business in New Hampshire or producing products or services targeted to NH residents that, in a one-year period, controlled or processed personal data of at least 35,000 unique consumers (excluding data processed solely to complete a payment transaction)
  • Persons that controlled or processed personal data of at least 10,000 unique consumers and derived more than 25 percent of gross revenue from the sale of personal data
  • Processors acting on behalf of covered controllers
  • Excludes state and local government bodies, nonprofits, institutions of higher education, registered national securities associations, GLBA financial institutions and data, and HIPAA covered entities and business associates

What a privacy notice must say

  • Provide a clear, accessible privacy notice listing categories of data processed, purposes, how to exercise and appeal rights, categories of data shared and third-party recipients, a contact email or online mechanism, and the last-updated date.RSA 507-H:6, III

Rights it gives people

  • Consumers may confirm processing and access, correct, delete and obtain a portable copy of their personal data, and opt out of targeted advertising, sale, and profiling for solely automated decisions with legal or similarly significant effects.RSA 507-H:4, I(a)-(e)
  • Provide a clear and conspicuous opt-out link and honor opt-out preference signals (universal opt-out mechanisms) for targeted advertising and sales; opt-outs may be submitted by authorized agents.RSA 507-H:6, V(a)(1); 507-H:5

Practices it requires

  • Do not sell a child's personal data.RSA 507-H:6, I(e-1) · From 2027-01-01
  • Do not sell, or process for targeted advertising, the data of a consumer the controller knows (and wilfully disregards) is 13 to 15 years old without consent; do not discriminate against consumers for exercising rights.RSA 507-H:6, I(g)
  • Holders of de-identified data must take reasonable measures against re-identification, publicly commit not to re-identify, and contractually bind recipients.RSA 507-H:9, I
  • Respond to consumer requests within 45 days (extendable once by 45 days with notice), free of charge once per 12 months, and offer an appeal process answered in writing within 60 days with a way to complain to the Attorney General.RSA 507-H:4, III-IV
  • Limit collection to what is adequate, relevant and reasonably necessary for the disclosed purposes; secondary incompatible uses require consent.RSA 507-H:6, I(a)-(b)
  • Do not process sensitive data (including health, biometric, genetic, precise geolocation, and data of a known child) without consent, or for a known child, without complying with COPPA.RSA 507-H:6, I(d); 507-H:1, XXVIII

Security duties

  • Maintain reasonable administrative, technical and physical data security practices appropriate to the volume and nature of the data.RSA 507-H:6, I(c)

Other duties

  • Controller-processor contracts must set processing instructions and require confidentiality, deletion or return of data, compliance information, flow-down to subcontractors and cooperation with assessments.RSA 507-H:7, II
  • Conduct and document data protection assessments for targeted advertising, sales, risky profiling and sensitive-data processing; produce them to the Attorney General on request.RSA 507-H:8 · Only if: Applies to processing activities created or generated after July 1, 2024

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: NH DOJ Data Privacy Unit pages (doj.nh.gov) returned HTTP 403 to automated fetches, so DOJ guidance, FAQs and any enforcement actions under RSA 507-H were not reviewed from the primary source

Research reference, not legal advice.