EnglishEspañol
New Hampshire flag

New Hampshire

New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a business have to notify New Hampshire residents of a data breach?

New Hampshire law requires notification 'as quickly as possible,' which is a more urgent standard than the 'without unreasonable delay' language used by many states. There is no specific day deadline. The duty is triggered by a risk determination: the business must promptly assess the likelihood that the information has been or will be misused, and must notify if misuse has occurred, is reasonably likely to occur, or cannot be determined. RSA 359-C:20, II permits delay only where a law enforcement agency, or a national or homeland security agency, determines that notice would impede a criminal investigation or jeopardize national or homeland security.

Does New Hampshire require businesses to notify the Attorney General after a data breach?

Most businesses, yes. Before individual notice goes out, businesses must notify the New Hampshire Attorney General, unless they are regulated by the state's banking, securities, insurance, or utilities regulators, in which case they notify that regulator instead. That notification must include only the anticipated date individual notice will go out and the approximate number of affected New Hampshire residents. Consumer reporting agencies must also be notified when more than 1,000 residents are affected.

What is New Hampshire's substitute notice threshold?

New Hampshire has one of the lowest substitute notice thresholds in the nation. A business may use substitute notice when the cost of standard notification exceeds $5,000, the affected class exceeds 1,000 residents, or the entity lacks sufficient contact information. Most states set these thresholds at $250,000 and 500,000 respectively. Substitute notice requires email, website posting, and major media notification.

Does encryption protect businesses from New Hampshire's breach notification requirements?

Yes, New Hampshire provides an encryption safe harbor. If the compromised personal information was encrypted and the encryption key was not also acquired by the unauthorized person, notification is not required. If both the data and the encryption key were compromised, the full notification obligations apply.

Can individuals sue for a breach notification violation in New Hampshire?

Yes. RSA 359-C:21 gives anyone injured by a breach-notification violation a private right of action for actual damages. If the violation was willful or knowing, the court must award 2 to 3 times that amount as the total recovery, plus attorney's fees, costs, and injunctive relief. The Attorney General can also enforce the statute separately under the Consumer Protection Act.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected New Hampshire's breach notification trigger to the statutory misuse determination, removed a delay ground and an E-SIGN condition that are not in RSA 359-C, and restored the statute's telephone-log, telephonic-contact, internal-procedures and public-records provisions.

Corrected who must be notified of a New Hampshire data breach: most businesses notify the Attorney General before individual notice, but businesses regulated by the state's banking, securities, insurance, or utilities regulators notify that regulator instead. Removed an inaccurate HIPAA exemption and clarified the real financial-regulator provisions, narrowed the Attorney General and individual notice content lists to match the statute, corrected the private-lawsuit damages calculation for willful violations (2-3 times actual damages total, not damages plus a multiple), and updated four dead statute-citation links to their current gc.nh.gov addresses.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected a reversed claim that New Hampshire's breach notification law has no private right of action: RSA 359-C:21 actually gives injured individuals the right to sue for damages (up to treble for willful violations), fees, and injunctive relief. Also removed an added 'for an unauthorized purpose' qualifier from the good-faith exception, and fixed the consumer-reporting-agency threshold from '1,000 or more' to the statute's actual 'more than 1,000.'

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.H. Rev. Stat. 359-C:19 - Definitions(gc.nh.gov).gov
  2. N.H. Rev. Stat. 359-C:20 - Notification Requirements(gc.nh.gov).gov
  3. N.H. Rev. Stat. 359-C:21 - Violations(gc.nh.gov).gov
  4. NH Attorney General - Security Breaches(doj.nh.gov).gov
  5. N.H. Rev. Stat. 358-A - Consumer Protection Act(gc.nh.gov).gov
Share: