Student and Teacher Information Protection and Privacy
NH Student and Teacher Privacy Act
Students · Government records · Biometric · Employees
Limits what student and teacher personal data the state education department may collect, keep and disclose, and requires public data inventories, a state data security and breach plan, and annual local data and privacy governance plans that vet every school software tool. It also bars schools from RFID tracking, remote surveillance software on school-issued devices, and classroom recording for teacher evaluation without school board approval and written consent.
- Where
- New Hampshire
- Citation
- N.H. Rev. Stat. Ann. 189:65 to 189:68
- Status
- In force
- Last amended
- 2025-07-01
- Enforced by
- New Hampshire Department of Education and State Board of Education
- People can sue
- No
- Penalties
- No specific civil or criminal penalty in these sections; compliance is enforced administratively and through district governance and vendor contracts.
- Applies to
- New Hampshire Department of Education and its statewide longitudinal data system (SLDS)
- School districts and local education agencies
- Testing entities contracted to administer the state assessment
- Service providers to school districts (through district data governance plans)
What a privacy notice must say
- The Department and each local education agency must publicize FERPA and state rights, including inspection within 14 days, amendment requests and written consent before disclosure.RSA 189:66, IV
- The Department must publish an annually updated index of student personally identifiable data elements it collects or proposes to collect.RSA 189:66, I
Practices it requires
- Schools may not require RFID identification devices, install remote surveillance software on school-supplied student devices, or record classrooms for teacher evaluations without school board approval after a public hearing and written consent.RSA 189:68, II-IV
- Testing entities may receive only name, unique pupil identifier and birth date to identify test takers and may not disclose or reuse the data; SAT/ACT takers may have their personal information destroyed after testing.RSA 189:67, II-III
- The Department may not collect or keep specified sensitive data in the SLDS, including SSNs, biometric information, health, political or religious information and family income.RSA 189:68, I
Security duties
- Each local education agency must adopt and annually update a data and privacy governance plan that inventories and reviews all software and digital tools, sets access policies and a breach response plan, and requires service providers to meet state data protection standards.RSA 189:66, V
Breach duties
- The Department's data security plan must require notice as soon as practicable to teachers or students whose data was likely breached and to state officials, plus an annual public breach report.RSA 189:66, II-III
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: effective_date: enacted by 2014, 68:1; the fetched RSA page does not show that act's effective date, so it is left null
Research reference, not legal advice.