Privacy Law Library

New Hampshire Right to Privacy Act (financial and credit records)

NH Right to Privacy Act

Financial · Government records

Protects the confidentiality of customers' financial and credit records by barring financial institutions and creditors from handing them to state or local agencies investigating the customer unless the customer authorizes it or the agency uses a qualifying administrative subpoena, search warrant or judicial subpoena. It sets notice and record-keeping duties around those disclosures.

Where
New Hampshire
Citation
N.H. Rev. Stat. Ann. 359-C:1 to 359-C:18
Status
In force
In force since
1977-09-17
Last amended
2013-07-01
Enforced by
Courts, through customer suits and criminal prosecution
People can sue
Yes
Penalties
Wilful or knowing participation in, or inducing, a violation is a misdemeanor; aggrieved customers may obtain injunctive relief and recover costs and reasonable attorney's fees (these remedies are exclusive).
Applies to
  • Banks, trust companies, savings and loan associations, credit unions and other financial institutions, and creditors that extend credit with finance charges
  • State and local agency officers, employees and agents seeking customer financial or credit records in investigations

What a privacy notice must say

  • Agencies examining records under customer authorization must notify the customer in writing within 30 days; administrative and judicial subpoenas must be served on the customer, who may move to quash.RSA 359-C:7, IV; 359-C:8; 359-C:10

Rights it gives people

  • Customer waivers of rights are void except for authorizations under RSA 359-C:7; aggrieved customers may seek injunctions, costs and attorney's fees within 3 years.RSA 359-C:13 to 359-C:16

Practices it requires

  • Financial institutions and creditors may not give state or local agencies a customer's financial or credit records for an investigation of that customer except under customer authorization, administrative subpoena, search warrant or judicial subpoena meeting the chapter's requirements.RSA 359-C:4, I; 359-C:5, I
  • Customer authorization must be signed, dated, time-limited and specific, and may not be made a condition of doing business.RSA 359-C:7, I-II

Other duties

  • Keep for 5 years a record of every examination or disclosure of a customer's records, including who examined them, for what purpose and under what authority.RSA 359-C:4, IV

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.