EnglishEspañol
New Hampshire flag

New Hampshire

New Hampshire Data Privacy Laws: Consumer Rights Guide (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 19 primary sources cited on this page. How we verify our legal content

New Hampshire Data Privacy Laws: Consumer Rights Guide (2026)

Frequently Asked Questions

When did the New Hampshire Privacy Act take effect?

The New Hampshire Data Privacy Act (RSA Chapter 507-H), enacted through Senate Bill 255, took effect on January 1, 2025. Governor Chris Sununu signed the bill on March 6, 2024. The law was later amended by HB 1220 (Laws of 2024, Chapter 229) before the effective date.

Is the 60-day cure period still in effect for NHDPA violations?

No. The mandatory 60-day cure period applied only from January 1, 2025 through December 31, 2025. Since January 1, 2026, the New Hampshire Attorney General has discretion on whether to offer a cure opportunity before bringing an enforcement action. The AG may consider factors such as the number of violations, the size and complexity of the business, and the likelihood of public injury, but is no longer required to provide a cure notice before acting.

Can I sue a company in New Hampshire for violating my data privacy rights?

No, not under the NHDPA. The New Hampshire Data Privacy Act does not provide a private right of action; only the Attorney General can bring enforcement actions under RSA Chapter 507-H. However, for data breach notification violations under RSA 359-C:21, individuals do have a private right of action and can recover actual damages, with 2x to 3x damages for willful violations, plus attorney's fees and costs.

What businesses must comply with New Hampshire data privacy law?

The NHDPA applies to businesses that operate in New Hampshire or target NH residents and meet at least one of these thresholds: (1) processing the personal data of 35,000 or more unique NH consumers during any one-year period, or (2) processing the data of 10,000 or more unique consumers while deriving over 25 percent of gross revenue from selling personal data. Government agencies, nonprofits, higher education institutions, and entities covered by HIPAA or GLBA are exempt.

Does New Hampshire require businesses to honor browser opt-out signals?

Yes. Controllers subject to the NHDPA must recognize and honor universal opt-out preference signals such as the Global Privacy Control (GPC) browser setting for targeted advertising and data sales. These mechanisms must require affirmative consumer action and allow the controller to verify state residency.

How quickly must a business notify me of a data breach in New Hampshire?

Under RSA 359-C:20, businesses must notify affected individuals as soon as possible after determining a breach occurred and that misuse of personal information has happened, is reasonably likely, or cannot be ruled out. The business must also promptly notify the New Hampshire Attorney General. If 1,000 or more individuals are affected, consumer reporting agencies must also be notified.

Is New Hampshire a two-party consent state for recording?

Yes. Under RSA 570-A:2, New Hampshire is an all-party consent state, meaning it is a felony to record a telephone or in-person conversation without the consent of all parties. Businesses that record customer calls or meetings involving New Hampshire residents must obtain consent from all participants before recording.

What is the TAKE IT DOWN Act and does it affect New Hampshire residents?

The TAKE IT DOWN Act (Pub. L. 119-12) is a federal law signed May 19, 2025, that criminalizes the publication of nonconsensual intimate visual depictions, including AI-generated deepfakes. The criminal provisions took effect immediately upon signing. Platform takedown obligations became effective May 19, 2026, requiring covered platforms to remove reported content within 48 hours. New Hampshire residents who are victims of NCII may report to both the NH Attorney General and the FTC.

Updates

Corrected the statutory citation for the 45-day consumer request deadline and the 60-day appeal deadline to RSA 507-H:4, and corrected the coverage thresholds to apply over any one-year period rather than a calendar year.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

May 2026 refresh: Updated cure period status (mandatory 60-day cure expired December 31, 2025; discretionary enforcement now in effect as of January 1, 2026). Added NH Insurance Data Security Act (RSA Chapter 420-P) section. Added NH Wiretap Statute section (RSA 570-A, all-party consent). Added TAKE IT DOWN Act (Pub. L. 119-12, platform obligations effective May 19, 2026). Corrected APRA status (expired with 118th Congress, January 2025; not enacted). Added official AG FAQ document citation. Expanded practical compliance steps section. Added FAQ pairs on cure period expiration, recording consent, and TAKE IT DOWN Act. Updated from 3,150 to approximately 4,600 words.

Reviewed and approved by an editor

Sources and References

  1. RSA Chapter 507-H: Expectation of Privacy (Full Statute)(gc.nh.gov).gov
  2. NH Secretary of State: RSA 507-H as Amended by HB 1220 (Ch. 229)(sos.nh.gov).gov
  3. NH DOJ: Data Privacy Enforcement(doj.nh.gov).gov
  4. NH DOJ: Attorney General Announces Data Privacy Unit(doj.nh.gov).gov
  5. NH DOJ: NHDPA Frequently Asked Questions (Official)(doj.nh.gov).gov
  6. NH DOJ: NHDPA FAQ Document (PDF)(doj.nh.gov).gov
  7. Governor Sununu Signs Bill Protecting Consumer Data(governor.sununu.nh.gov).gov
  8. SB 255 Bill Status (NH General Court)(gc.nh.gov).gov
  9. NH Joins Bipartisan Consortium of Privacy Regulators(doj.nh.gov).gov
  10. RSA 359-C:20: Notification of Security Breach Required(gc.nh.gov).gov
  11. RSA 359-C:19: Definitions (Breach Notification)(gc.nh.gov).gov
  12. RSA 359-C:21: Violation Penalties(gc.nh.gov).gov
  13. RSA Chapter 420-P: Insurance Data Security Law(gc.nh.gov).gov
  14. NH Insurance Department: Cybersecurity Incident Reporting Requirements(insurance.nh.gov).gov
  15. RSA 570-A:2: Wiretapping and Eavesdropping Prohibition(gc.nh.gov).gov
  16. RSA 358-A: Consumer Protection Act(gc.nh.gov).gov
  17. FTC: TAKE IT DOWN Act Statute Page(ftc.gov).gov
  18. NH DOJ: Security Breach Notifications(doj.nh.gov).gov
  19. NH DOJ: File a Consumer Complaint(doj.nh.gov).gov
  20. RSA 507-H:4, Consumer Expectation of Privacy (New Hampshire General Court)(gc.nh.gov)
  21. RSA 507-H:2, Application (New Hampshire General Court)(gc.nh.gov)
Share: