New Hampshire
New Hampshire Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 12 primary sources cited on this page. How we verify our legal content

New Hampshire has no BIPA-style biometric privacy statute reaching private businesses. Private companies are covered by the New Hampshire Data Privacy Act (RSA 507-H), effective January 1, 2025, which classifies biometric identifiers as sensitive personal data and requires opt-in consent before processing them for identification purposes. A separate standalone chapter, RSA 359-N (Regulation of Biometric Information), binds government agencies only.
New Hampshire does not have a private-sector biometric privacy statute like Illinois's BIPA or Texas's CUBI. For businesses, biometric data protections come from the New Hampshire Data Privacy Act (NHDPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent before processing.
New Hampshire does have a standalone biometric chapter, but it points at the public sector. RSA chapter 359-N, titled Regulation of Biometric Information and effective July 1, 2014, restricts what government agencies may collect and gives individuals their own right to sue. A narrower provision, RSA 260:10-b, separately bars the state from collecting biometric data in connection with driver licensing or motor vehicle registration.
The NHDPA was New Hampshire's first comprehensive data privacy framework. Governor Chris Sununu signed SB 255 on March 6, 2024, and HB 1220 (Chapter 229, Laws of 2024) on July 19, 2024, which amended certain provisions. The law took effect on January 1, 2025.
For an overview of the state's broader privacy framework, see the parent guide to New Hampshire Data Privacy Laws.
How the NHDPA Defines Biometric Data
The NHDPA defines biometric data under RSA 507-H:1, IV as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics

The law draws a clear boundary around what does not qualify. A physical or digital photograph, a video or audio recording, or data generated from those recordings is not biometric data unless that data is specifically generated to identify a specific individual.
One notable feature of the NHDPA definition is its inclusion of "other unique biological patterns or characteristics." This open-ended language is broader than some peer states, which limit their definitions to a specific list of identifiers. While the statute does not explicitly mention biomarkers by name, the "other unique biological patterns or characteristics" language could potentially encompass health-related biological markers if they are used for identification purposes.
New Hampshire previously considered a biometric privacy bill (HB 536) in 2019, titled "AN ACT adding biometric information to the consumer protection act." It would have added a broad definition of biometric information, covering physiological, biological, and behavioral characteristics, DNA, keystroke patterns, and health or exercise data, to RSA 358-A, and made misuse of that information by a business an unlawful trade practice. It did not pass. RSA 358-A:2 contains no biometric provision today.
Sensitive Data Classification and Consent
Under the NHDPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data." This is the highest protection category in the law.
Other categories of sensitive data under RSA 507-H:1, XXVIII include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health conditions or diagnoses
- Sex life or sexual orientation
- Citizenship or immigration status
- Genetic data processed for identification
- Precise geolocation data
- Personal data collected from a known child under 13
Consent requirement. Controllers must obtain a consumer's opt-in consent before processing sensitive data, including biometric data, under RSA 507-H:6, I(d). A business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without first receiving your affirmative agreement.
This consent must meet the standard in RSA 507-H:1, VII: a clear affirmative act that is freely given, specific, informed, and unambiguous. A buried clause in a terms-of-service agreement does not meet this standard. The law specifically excludes agreements obtained through deceptive design patterns, passive actions like hovering or closing content, or general terms of service containing unrelated information.
Revocation of consent. Controllers must provide a mechanism for consumers to revoke consent that is at least as easy as the method used to grant it. Once a consumer revokes consent, the controller must stop processing within 15 days.

Who Must Comply
The NHDPA applies to entities that conduct business in New Hampshire or produce products or services targeted to New Hampshire residents and meet one of these thresholds during a one-year period:
- Process personal data of 35,000 or more unique New Hampshire consumers (excluding data processed solely for payment transactions), or
- Process personal data of 10,000 or more unique New Hampshire consumers and derive more than 25% of gross revenue from the sale of personal data
The 35,000-consumer threshold is the lowest among state comprehensive privacy laws, meaning more businesses fall under the NHDPA than under comparable laws in many other states.
Key Exemptions
The NHDPA carves out several categories of entities and data types from coverage under RSA 507-H:3:
Entity exemptions:
- State and local government agencies
- Nonprofit organizations
- Institutions of higher education
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- HIPAA-covered entities and their business associates
- National securities associations registered under the Securities Exchange Act
Data exemptions:
- Protected health information under HIPAA
- Data regulated under the Fair Credit Reporting Act (FCRA)
- Data covered by the Family Educational Rights and Privacy Act (FERPA)
- Data under the Driver's Privacy Protection Act (DPPA)
- Data regulated under the Farm Credit Act
- Employment and emergency contact information
- Airline industry data under the Airline Deregulation Act
Government agencies are exempt from the NHDPA but not from biometric regulation. RSA 359-N:2 prohibits a New Hampshire government agency from issuing or using an identification system that requires the collection or retention of biometric data, from requiring an individual to provide biometric data as a condition of doing business with or obtaining services from the agency, and from otherwise obtaining, retaining, or providing biometric data except as the chapter allows. Paragraph II requires biometric data collected for an employee, vendor, or contractor identification or access card to be destroyed when that relationship ends, and provides that the data is not subject to subpoena. Paragraph III carves out public safety employment screening, security clearances, and investigations of internal misconduct. RSA 359-N:1 defines a government agency as any employee, agent, elected official, or entity of the state, a municipality, or any other political subdivision of New Hampshire.
Employee data exemption. The NHDPA excludes persons acting in a commercial or employment context from the definition of "consumer" under RSA 507-H:1. Employees, owners, directors, officers, and contractors whose interactions with a controller occur solely within that professional role are not covered consumers.
This means that if a private employer collects your fingerprints for a timekeeping system or uses facial recognition for building access in New Hampshire, the NHDPA does not apply to that collection, and no separate New Hampshire statute regulates private employer use of biometric data. Public employment is different. RSA 359-N:2, II requires a government agency to destroy biometric data collected for an employee, vendor, or contractor identification or access card when the relationship terminates and shields that data from subpoena, subject to the carve-out in RSA 359-N:2, III for public safety screening, security clearances, and internal misconduct investigations.
Consumer Rights Over Biometric Data
Because biometric data is sensitive personal data under the NHDPA, New Hampshire consumers have these rights under RSA 507-H:4:
Right to confirm and access. You can ask any covered business whether it processes your biometric data and request access to that data.
Right to correct. If a business holds inaccurate biometric data about you, you can request a correction.
Right to delete. You can request that a business delete the biometric data it holds about you.
Right to data portability. You can obtain a copy of your biometric data in a portable and readily usable format.
Right to opt out. You can opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Businesses must respond to consumer rights requests within 45 days. They can extend this period by an additional 45 days when reasonably necessary, but must notify the consumer of the extension and the reason. Consumers who receive an unfavorable decision can appeal, and the business must respond to the appeal within 60 days.
Data Protection Assessments
Controllers that process sensitive data, including biometric data, must conduct data protection assessments under RSA 507-H:8. These assessments are required for any processing activity that presents a heightened risk of harm, specifically:
- Processing personal data for targeted advertising
- The sale of personal data
- Processing of sensitive data (including biometric data)
- Profiling that creates a foreseeable risk of unfair treatment, disparate impact, or intrusion upon solitude
Each assessment must weigh the benefits of the processing to the controller, the consumer, and the public against the potential risks to consumer rights. The New Hampshire Attorney General can request these assessments during investigations.

Breach Notification and Biometric Data
New Hampshire's breach notification law at RSA 359-C:20 operates separately from the NHDPA.
Under RSA 359-C:19, personal information for breach notification purposes is defined as an individual's first name or initial and last name combined with one or more specified data elements, such as Social Security numbers, financial account numbers, or government identification numbers. The current breach notification statute does not explicitly list biometric identifiers among the triggering data elements.
However, the NHDPA's data security provisions at RSA 507-H:6, I(c) require controllers to implement reasonable administrative, technical, and physical data security practices to protect personal data, including biometric data. A biometric data breach by a covered controller could trigger enforcement action by the Attorney General under the NHDPA even if it does not trigger the separate breach notification statute.
Entities that experience a breach must promptly determine whether misuse has occurred or is reasonably likely. If it has, they must notify affected individuals as soon as possible and report the breach to the New Hampshire Attorney General or their primary regulator.
Enforcement: The Data Privacy Unit
The New Hampshire Attorney General has exclusive enforcement authority over the NHDPA under RSA 507-H:11. The NHDPA itself carries no private right of action, which means individual consumers cannot file lawsuits against businesses for NHDPA violations. A separate cause of action does exist against the public sector. Under RSA 359-N:4, any individual aggrieved by a violation of the biometric chapter, including the loss or misuse of biometric data lawfully collected, may bring a civil action against the government agency for an injunction of the practice, actual damages or $2,500 for each violation, whichever is greater, and reasonable attorney's fees and court costs.
In preparation for the law's January 2025 effective date, Attorney General John Formella created the Data Privacy Unit within the Consumer Protection and Antitrust Bureau. The unit handles investigations, processes consumer complaints, and publishes guidance for businesses.
The enforcement process works as follows:
- The Data Privacy Unit identifies a potential violation
- During 2025, the Attorney General must issue a written notice identifying the specific provisions believed to have been violated
- The business has 60 days to cure the alleged violation
- If the business cures the violation and provides a written statement that it will not continue to violate, the Attorney General takes no action
- Beginning January 1, 2026, the mandatory cure period becomes discretionary, and the Attorney General may consider factors like violation count, entity size, processing scope, and likelihood of injury
- Violations are treated as unfair or deceptive trade practices under RSA 358-A:2, and the civil penalty of up to $10,000 for each violation is set by RSA 358-A:4, III(b)
New Hampshire also joined a bipartisan consortium of state privacy regulators to collaborate on data privacy enforcement across state lines.
Consumers can file data privacy complaints through the New Hampshire DOJ website.
How New Hampshire Compares to Other States
New Hampshire's approach to biometric privacy falls in the middle of the spectrum among U.S. states:
Stronger than states with no protections. Many states still lack any specific biometric data protections. New Hampshire's classification of biometric data as sensitive data requiring consent puts it ahead of states like Georgia and Alabama, which have no dedicated biometric privacy statutes and no comprehensive privacy laws in effect.
Broader definition than some peers. The NHDPA's inclusion of "other unique biological patterns or characteristics" is more open-ended than states that list only specific biometric identifiers. This could provide broader coverage as biometric technology evolves.
Lower applicability threshold. The 35,000-consumer processing threshold is lower than most state privacy laws, bringing more businesses under the law's requirements.
Weaker than dedicated private-sector biometric laws. States like Illinois, Texas, and Washington have standalone biometric privacy statutes that reach private businesses, with specific requirements for notice, consent, retention schedules, and data destruction. Illinois's BIPA includes a private right of action that has produced significant litigation and settlements. New Hampshire's standalone chapter, RSA 359-N, is narrower in reach because it binds only government agencies, though it does let individuals sue those agencies.
Similar to other comprehensive privacy law states. New Hampshire's approach closely mirrors states like Connecticut, Kentucky, and Montana, which classify biometric data as sensitive data within their comprehensive consumer privacy frameworks and require opt-in consent.
Sources and References
This article references New Hampshire statutes and official state government publications. For the full text of the NHDPA, visit the New Hampshire General Court website. For the government-agency biometric chapter, see RSA 359-N. For guidance on consumer rights and filing complaints, visit the New Hampshire Department of Justice Data Privacy Enforcement page.
This article provides general legal information about New Hampshire biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official New Hampshire government sources.
More New Hampshire Laws
Frequently Asked Questions
Does New Hampshire have a standalone biometric privacy law like Illinois?
Not for private businesses, but New Hampshire does have a standalone biometric chapter for the public sector. RSA 359-N, Regulation of Biometric Information, effective July 1, 2014, restricts what state, municipal, and other government agencies may collect and lets an aggrieved individual sue them. Private companies are instead covered by the New Hampshire Data Privacy Act (NHDPA), RSA 507-H, effective January 1, 2025, which classifies biometric data as sensitive data requiring opt-in consent but does not include the detailed retention, destruction, and private right of action provisions found in Illinois BIPA.
Can I sue a company in New Hampshire for collecting my fingerprints without consent?
Not under the NHDPA. The New Hampshire Attorney General has exclusive enforcement authority over that law, and it does not include a private right of action against businesses. If you believe a company collected your biometric data without consent, you can file a complaint with the Attorney General's Data Privacy Unit through the DOJ website at doj.nh.gov, and the AG can pursue civil penalties of up to $10,000 for each violation under RSA 358-A:4, III(b). A government agency is different: RSA 359-N:4 lets any individual aggrieved by a violation of the biometric chapter sue the agency for an injunction, actual damages or $2,500 per violation, whichever is greater, plus reasonable attorney's fees and court costs.
Does the NHDPA protect my biometric data at work?
Not if you work for a private employer. The NHDPA exempts data collected in an employment context, so if a private employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the NHDPA does not regulate that activity, and New Hampshire has no separate statute governing private employer use of biometric data. Public employment is treated differently: RSA 359-N:2, II requires a government agency to destroy biometric data taken for an employee, vendor, or contractor identification or access card once the relationship ends and shields that data from subpoena, with a carve-out in RSA 359-N:2, III for public safety screening, security clearances, and internal misconduct investigations. The breach notification law (RSA 359-C:20) may also apply if a data breach occurs, depending on the type of information compromised.
What makes New Hampshire's biometric data definition broader than other states?
The NHDPA defines biometric data to include fingerprints, voiceprints, eye retinas, irises, and 'other unique biological patterns or characteristics' used for identification. That final catch-all phrase is broader than states that limit their definitions to a specific enumerated list. While the statute does not explicitly name biomarkers, the open-ended language could extend to newer forms of biological identification as technology evolves.
What penalties can businesses face for violating biometric data rules in New Hampshire?
Violations of the NHDPA are treated as unfair or deceptive trade practices under RSA 358-A:2. The civil penalty itself comes from RSA 358-A:4, III(b), which allows a court to award the state up to $10,000 for each violation in an action brought by the Attorney General. During 2025, businesses receive a mandatory 60-day cure period before any enforcement action. Starting January 1, 2026, the cure period becomes discretionary, meaning the Attorney General can pursue penalties without offering a chance to fix the violation first.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the page to reflect that New Hampshire does have a standalone biometric statute, RSA 359-N, which binds government agencies and gives individuals a right to sue them, and attributed the $10,000 civil penalty to RSA 358-A:4, III(b).
Repointed the SB 255 bill-status links to session-qualified URLs after New Hampshire recycled its bill-status IDs, and replaced a dead HB 1220 link with its session-law citation.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Hampshire Revised Statutes Annotated, TITLE LII ACTIONS, PROCESS, AND SERVICE OF PROCESS, CHAPTER 507-H EXPECTATION OF PRIVACY
§ 507-H:6Controller Responsibilities.In forcecited in 2 of our articles
I. A controller shall: (a) Limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; (b) Except as otherwise provided in this chapter, not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; (c) Establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data appropriate to the volume and nature of the personal data at issue; (d) Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with COPPA; (e) Not process personal data in violation of the laws of this state and federal laws that prohibit unlawful discrimination against consumers; (f) Provide an effective mechanism for a consumer…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at gc.nh.gov
Also relied on in: NHDPA Compliance Checklist: New Hampshire RSA 507-H
§ 507-H:1Definitions.In forcecited in 5 of our articles
In this chapter: I. "Affiliate" means a legal entity that shares common branding with another legal entity, or is controlled by, or is under common control with, another legal entity. II. "Control" or "Controlled" means ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or, the power to exercise controlling influence over the management of a company. III. "Authenticate" means to use reasonable means to determine that a request to exercise any of the rights afforded under RSA 507-H:4, I(a)-(d) is being made by, or on behalf of, the consumer who is entitled to exercise such consumer rights with respect to the personal data at issue. IV. "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises or other unique biological patterns, or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at gc.nh.gov
Also relied on in: What Is the NHDPA? New Hampshire Data Privacy Act, New Hampshire Data Privacy Laws: Consumer Rights Guide (2026), NHDPA Consumer Rights: New Hampshire Data Privacy
§ 507-H:4Consumer Expectation of Privacy.In forcecited in 4 of our articles
I. A consumer shall have the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) Delete personal data provided by, or obtained about, the consumer; (d) Obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; and (e) Opt-out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, except as provided in RSA 507-H:6, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer. II.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at gc.nh.gov
§ 507-H:3Exclusions.In force
I. This chapter shall not apply to any: (a) Body, authority, board, bureau, commission, district or agency of this state or of any political subdivision of this state; (b) Nonprofit organization; (c) Institution of higher education; (d) National securities association that is registered under 15 U.S.C. section 78o-3 of the Securities Exchange Act of 1934, as amended; (e) Financial institution or data subject to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801 et seq.; or, (f) A covered entity or business associate, as defined in 45 C.F.R. 160.103.(b). II. The following information and data shall be exempt from this chapter: (a) Protected health information under HIPAA; (b) Patient-identifying information for purposes of 42 U.S.C. section 290dd-2; (c) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at gc.nh.gov
New Hampshire Revised Statutes Annotated, TITLE XXXI TRADE AND COMMERCE, CHAPTER 359-C RIGHT TO PRIVACY
§ 359-C:20Notification of Security Breach Required.In forcecited in 3 of our articles
I. (a) Any person doing business in this state who owns or licenses computerized data that includes personal information shall, when it becomes aware of a security breach, promptly determine the likelihood that the information has been or will be misused. If the determination is that misuse of the information has occurred or is reasonably likely to occur, or if a determination cannot be made, the person shall notify the affected individuals as soon as possible as required under this subdivision. (b) Any person engaged in trade or commerce that is subject to RSA 358-A:3, I shall also notify the regulator which has primary regulatory authority over such trade or commerce. All other persons shall notify the New Hampshire attorney general's office. The notice shall include the anticipated date of the notice to the individuals and the approximate number of individuals in this state who will be notified. Nothing in this section shall be construed to require the person to provide to any regulator or the New Hampshire attorney general's office the names of the individuals entitled to receive the notice or any personal information relating to them.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at gc.nh.gov
Also relied on in: New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 359-C:19Definitions.In forcecited in 3 of our articles
In this subdivision: I. "Computerized data" means personal information stored in an electronic format. II. "Encrypted" means the transformation of data through the use of an algorithmic process into a form for which there is a low probability of assigning meaning without use of a confidential process or key, or securing the information by another method that renders the data elements completely unreadable or unusable. Data shall not be considered to be encrypted for purposes of this subdivision if it is acquired in combination with any required key, security code, access code, or password that would permit access to the encrypted data. III. "Person" means an individual, corporation, trust, partnership, incorporated or unincorporated association, limited liability company, or other form of entity, or any agency, authority, board, court, department, division, commission, institution, bureau, or other state governmental entity, or any political subdivision of the state. IV.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at gc.nh.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- RSA Chapter 507-H - Expectation of Privacy (Full Text)(gc.nh.gov).gov
- RSA 507-H:1 - Definitions(gc.nh.gov).gov
- RSA 507-H:3 - Exclusions(gc.nh.gov).gov
- RSA 507-H:4 - Consumer Rights(gc.nh.gov).gov
- Senate Bill 255 (2024) - Bill Status(gc.nh.gov).gov
- NH DOJ - Data Privacy Enforcement(doj.nh.gov).gov
- AG Formella Announces Data Privacy Unit(doj.nh.gov).gov
- NH Joins Bipartisan Privacy Enforcement Consortium(doj.nh.gov).gov
- RSA 359-C:20 - Breach Notification(gc.nh.gov).gov
- RSA 359-C:19 - Breach Notification Definitions(gc.nh.gov).gov
- NH DOJ - Security Breach Notifications(doj.nh.gov).gov
- RSA 507-H as Amended by Chapter 229 (HB 1220)(sos.nh.gov).gov
- RSA Chapter 359-N - Regulation of Biometric Information (Full Text)(gc.nh.gov)
- RSA 359-N:2 - Collection of Biometric Data Prohibited(gc.nh.gov)
- RSA 359-N:4 - Violations; Civil Action Against a Government Agency(gc.nh.gov)
- RSA 358-A:4 - Enforcement and Civil Penalties(gc.nh.gov)
- RSA 260:10-b - Collection of Biometric Data Prohibited (Motor Vehicles)(gc.nh.gov)
- HB 536-FN (2019) - AN ACT adding biometric information to the consumer protection act(gc.nh.gov)