New Hampshire
New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

New Hampshire requires a business that becomes aware of a security breach to promptly determine the likelihood that the information has been or will be misused, and to notify affected residents as quickly as possible under RSA 359-C:20 if misuse has occurred or is reasonably likely to occur, or if a determination cannot be made. There is no fixed-day deadline. Before individual notice goes out, most businesses must also notify the state's Attorney General, though businesses regulated by New Hampshire's banking, securities, insurance, or utilities regulators notify that regulator instead.
If your business handles personal information belonging to New Hampshire residents, a data breach triggers specific legal obligations under New Hampshire's Notice of Security Breach law. N.H. Rev. Stat. 359-C:19 through 359-C:21 sets out who must notify, what triggers the duty, and how quickly you need to act. New Hampshire enacted its breach notification law in 2006 (2006, 242:1), effective January 1, 2007, as part of the state's Right to Privacy chapter, reflecting the legislature's view that breach notification is fundamentally a privacy protection.
This guide covers the full scope of New Hampshire's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With New Hampshire's Breach Notification Law
New Hampshire's law applies to any person doing business in the state, any person that owns or licenses computerized data that includes personal information, or any person that maintains computerized data containing personal information on behalf of another. This broad scope captures businesses, government entities, and third-party service providers.
When a third party that maintains data on behalf of a data owner discovers a breach, it must notify the data owner immediately. The data owner then carries the primary responsibility to notify affected individuals and, depending on its industry, either the Attorney General or its primary sector regulator.
The statute applies regardless of where the business is physically located. Any business that holds personal information about New Hampshire residents must comply if it does business in the state.
What Qualifies as a Breach
Under N.H. Rev. Stat. 359-C:19, a "security breach" means the unauthorized acquisition of computerized data that compromises the security or confidentiality of personal information maintained by a person doing business in New Hampshire.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of a person doing business in the state does not constitute a security breach, provided the personal information is not used or subject to further unauthorized disclosure.
Encryption Safe Harbor
New Hampshire provides a safe harbor for encrypted data. The notification requirements do not apply to the unauthorized acquisition of personal information that has been encrypted, as long as the encryption key was not also compromised. If both the encrypted data and the key were acquired by the unauthorized person, notification is required.
Personal Information That Triggers Notification
Under N.H. Rev. Stat. 359-C:19, personal information means an individual's first name or first initial and last name combined with any one or more of the following data elements:
- Social Security number
- Driver's license number or other government identification number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to an individual's financial account
What New Hampshire's Law Does Not Cover
Compared to states that have recently updated their breach notification statutes, New Hampshire's definition of personal information is relatively narrow. The law does not include:
- Biometric data (fingerprints, retina scans, voiceprints)
- Medical or health information
- Health insurance identification numbers
- Passport numbers
- Username or email address combined with passwords
- Taxpayer identification numbers (other than SSNs)
Personal information does not include information that is lawfully made available to the general public from federal, state, or local government records. New Hampshire has no broader exclusion for information drawn from other publicly available sources.
Notification Timeline
New Hampshire requires notification "as quickly as possible" under N.H. Rev. Stat. 359-C:20. This language is more urgent than the "without unreasonable delay" standard used by many states, suggesting the legislature intended a particularly prompt response.
The statute does not set a specific day count. Under RSA 359-C:21, III, the burden is on the person responsible for the misuse determination required by RSA 359-C:20, I to demonstrate compliance with the notification subdivision.

When Delay Is Permitted
Under RSA 359-C:20, II, notification may be delayed only if a law enforcement agency, or a national or homeland security agency, determines that the notification will impede a criminal investigation or jeopardize national or homeland security.
That is the statute's only delay ground. New Hampshire does not grant an entity extra time to determine the scope of the incident, identify affected individuals, or restore the integrity of its systems, although the misuse determination required by RSA 359-C:20, I(a) necessarily precedes notice.
Even when delay is permitted, the entity must still act "as quickly as possible" once the reason for the delay no longer applies.
Who Must Be Notified
New Hampshire Attorney General (or Sector Regulator)
Before individual notifications are sent, most businesses must notify the New Hampshire Attorney General. Businesses regulated by New Hampshire's bank commissioner, director of securities regulation, insurance commissioner, public utilities commission, or the financial-institution and insurance regulators of other states or the federal government (per RSA 358-A:3, I) instead notify their own primary regulator, not the Attorney General.
Under RSA 359-C:20, I(b), that notification needs to include only two things:
- The anticipated date of the notice to affected individuals
- The approximate number of New Hampshire residents who will be notified
The entity is not required to disclose the names of affected individuals or their personal information in this notice.
Affected Individuals
Under RSA 359-C:20, I(a), a business that becomes aware of a security breach must promptly determine the likelihood that the personal information has been or will be misused. Individual notice is required if that determination is that misuse has occurred or is reasonably likely to occur, or if a determination cannot be made. Unauthorized acquisition alone does not automatically trigger notice, but a business that cannot rule out misuse must notify. Under RSA 359-C:20, IV, the notification must include:
- A description of the incident in general terms
- The approximate date of the breach
- The type of personal information involved
- The telephonic contact information of the entity providing notice, meaning a phone number and not merely an email or web address
Listing contact information for the Federal Trade Commission and the New Hampshire Attorney General, or steps to protect against identity theft, is a common best practice, but neither is a statutory requirement of the individual notice.
Consumer Reporting Agencies
When a breach requires notification of more than 1,000 New Hampshire residents, the entity must also notify the nationwide consumer reporting agencies without unreasonable delay. The notification must include the timing, distribution, and content of the notification to individuals.
How to Provide Notification
Under RSA 359-C:20, III, New Hampshire permits the following notification methods:
- Written notice sent by mail to the last known address of the individual
- Electronic notice if the entity's primary means of communication with affected individuals is by electronic means
- Telephone notice, provided that the entity keeps a log of each such notification
- Substitute notice, subject to the thresholds below
- Notice under the entity's internal notification procedures, where those procedures are maintained as part of an information security policy for the treatment of personal information
Substitute Notice
New Hampshire has one of the lowest substitute notice thresholds in the nation. Substitute notice is available when:
- The cost of providing notification would exceed $5,000
- The affected class exceeds 1,000 New Hampshire residents
- The entity does not have sufficient contact information
Compare this to most states where the cost threshold is $250,000 and the affected class threshold is 500,000. New Hampshire's low thresholds make substitute notice available to smaller businesses and smaller breaches.
Substitute notice must include all of the following:
- Email notification to individuals for whom the entity has an email address
- Conspicuous posting of the notice on the entity's website
- Notification to major statewide media outlets

Enforcement and Penalties
New Hampshire's breach notification law is enforced by the Attorney General under the Consumer Protection Act (N.H. Rev. Stat. 358-A). A violation of the breach notification requirements constitutes an unfair or deceptive act or practice.
The Attorney General may seek:
- Injunctive relief to stop ongoing violations
- Civil penalties as provided under the Consumer Protection Act
- Restitution for affected consumers
- Attorney's fees and costs of investigation
New Hampshire also gives individuals a private right of action under RSA 359-C:21. Anyone injured by a breach-notification violation may sue for actual damages. If the violation was willful or knowing, the court must award between 2 and 3 times that amount as the total recovery, not actual damages plus an additional multiple, along with attorney's fees, costs, and injunctive relief.
Exemptions
New Hampshire's statute does not contain a blanket exemption for financial institutions or HIPAA-covered entities. It provides two narrower provisions instead:
- Deemed compliance for regulated entities: Under RSA 359-C:20, V, a business subject to RSA 358-A:3, I (regulated by New Hampshire's bank commissioner, director of securities regulation, insurance commissioner, public utilities commission, or an equivalent state or federal financial or insurance regulator) that follows the security-breach notification procedures required by that regulator's laws, rules, or guidance is deemed to be in compliance with RSA 359-C's notification subdivision.
- GLBA carve-out for credit-agency notice only: Under RSA 359-C:20, VI(b), a business subject to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801 et seq., is exempt only from notifying nationwide consumer reporting agencies. It must still notify affected individuals and, where applicable, the Attorney General or its sector regulator.
There is no separate HIPAA exemption in this chapter. A HIPAA-covered entity must still comply with New Hampshire's breach notification law unless it independently qualifies for the deemed-compliance provision above.
How New Hampshire's Privacy Laws Interact With Breach Notification

The New Hampshire Privacy Act, effective January 1, 2025, created a comprehensive consumer privacy framework. However, the Privacy Act does not contain its own breach notification requirements. Businesses subject to the Privacy Act must still follow N.H. Rev. Stat. 359-C:19-21 for breach notification.
The Privacy Act adds relevant data protection obligations:
- Data security requirement: Controllers must implement reasonable administrative, technical, and physical data security practices.
- Data minimization: Controllers must limit data collection to what is adequate, relevant, and reasonably necessary.
- Sensitive data consent: Biometric data, precise geolocation, and other sensitive categories require explicit consumer consent before processing.
Both the Privacy Act and the breach notification statute are enforced by the Attorney General under the Consumer Protection Act.
This article provides general legal information about New Hampshire data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New Hampshire for guidance specific to your situation.
More New Hampshire Laws
Frequently Asked Questions
How long does a business have to notify New Hampshire residents of a data breach?
New Hampshire law requires notification 'as quickly as possible,' which is a more urgent standard than the 'without unreasonable delay' language used by many states. There is no specific day deadline. The duty is triggered by a risk determination: the business must promptly assess the likelihood that the information has been or will be misused, and must notify if misuse has occurred, is reasonably likely to occur, or cannot be determined. RSA 359-C:20, II permits delay only where a law enforcement agency, or a national or homeland security agency, determines that notice would impede a criminal investigation or jeopardize national or homeland security.
Does New Hampshire require businesses to notify the Attorney General after a data breach?
Most businesses, yes. Before individual notice goes out, businesses must notify the New Hampshire Attorney General, unless they are regulated by the state's banking, securities, insurance, or utilities regulators, in which case they notify that regulator instead. That notification must include only the anticipated date individual notice will go out and the approximate number of affected New Hampshire residents. Consumer reporting agencies must also be notified when more than 1,000 residents are affected.
What is New Hampshire's substitute notice threshold?
New Hampshire has one of the lowest substitute notice thresholds in the nation. A business may use substitute notice when the cost of standard notification exceeds $5,000, the affected class exceeds 1,000 residents, or the entity lacks sufficient contact information. Most states set these thresholds at $250,000 and 500,000 respectively. Substitute notice requires email, website posting, and major media notification.
Does encryption protect businesses from New Hampshire's breach notification requirements?
Yes, New Hampshire provides an encryption safe harbor. If the compromised personal information was encrypted and the encryption key was not also acquired by the unauthorized person, notification is not required. If both the data and the encryption key were compromised, the full notification obligations apply.
Can individuals sue for a breach notification violation in New Hampshire?
Yes. RSA 359-C:21 gives anyone injured by a breach-notification violation a private right of action for actual damages. If the violation was willful or knowing, the court must award 2 to 3 times that amount as the total recovery, plus attorney's fees, costs, and injunctive relief. The Attorney General can also enforce the statute separately under the Consumer Protection Act.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected New Hampshire's breach notification trigger to the statutory misuse determination, removed a delay ground and an E-SIGN condition that are not in RSA 359-C, and restored the statute's telephone-log, telephonic-contact, internal-procedures and public-records provisions.
Corrected who must be notified of a New Hampshire data breach: most businesses notify the Attorney General before individual notice, but businesses regulated by the state's banking, securities, insurance, or utilities regulators notify that regulator instead. Removed an inaccurate HIPAA exemption and clarified the real financial-regulator provisions, narrowed the Attorney General and individual notice content lists to match the statute, corrected the private-lawsuit damages calculation for willful violations (2-3 times actual damages total, not damages plus a multiple), and updated four dead statute-citation links to their current gc.nh.gov addresses.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected a reversed claim that New Hampshire's breach notification law has no private right of action: RSA 359-C:21 actually gives injured individuals the right to sue for damages (up to treble for willful violations), fees, and injunctive relief. Also removed an added 'for an unauthorized purpose' qualifier from the good-faith exception, and fixed the consumer-reporting-agency threshold from '1,000 or more' to the statute's actual 'more than 1,000.'
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Hampshire Revised Statutes Annotated, TITLE XXXI TRADE AND COMMERCE, CHAPTER 359-C RIGHT TO PRIVACY
§ 359-C:20Notification of Security Breach Required.In forcecited in 3 of our articles
I. (a) Any person doing business in this state who owns or licenses computerized data that includes personal information shall, when it becomes aware of a security breach, promptly determine the likelihood that the information has been or will be misused. If the determination is that misuse of the information has occurred or is reasonably likely to occur, or if a determination cannot be made, the person shall notify the affected individuals as soon as possible as required under this subdivision. (b) Any person engaged in trade or commerce that is subject to RSA 358-A:3, I shall also notify the regulator which has primary regulatory authority over such trade or commerce. All other persons shall notify the New Hampshire attorney general's office. The notice shall include the anticipated date of the notice to the individuals and the approximate number of individuals in this state who will be notified. Nothing in this section shall be construed to require the person to provide to any regulator or the New Hampshire attorney general's office the names of the individuals entitled to receive the notice or any personal information relating to them.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at gc.nh.gov
Also relied on in: New Hampshire Data Privacy Laws: Consumer Rights Guide (2026), New Hampshire Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 359-C:19Definitions.In forcecited in 3 of our articles
In this subdivision: I. "Computerized data" means personal information stored in an electronic format. II. "Encrypted" means the transformation of data through the use of an algorithmic process into a form for which there is a low probability of assigning meaning without use of a confidential process or key, or securing the information by another method that renders the data elements completely unreadable or unusable. Data shall not be considered to be encrypted for purposes of this subdivision if it is acquired in combination with any required key, security code, access code, or password that would permit access to the encrypted data. III. "Person" means an individual, corporation, trust, partnership, incorporated or unincorporated association, limited liability company, or other form of entity, or any agency, authority, board, court, department, division, commission, institution, bureau, or other state governmental entity, or any political subdivision of the state. IV.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at gc.nh.gov
§ 359-C:21Violation.In forcecited in 2 of our articles
I. Any person injured by any violation under this subdivision may bring an action for damages and for such equitable relief, including an injunction, as the court deems necessary and proper. If the court finds for the plaintiff, recovery shall be in the amount of actual damages. If the court finds that the act or practice was a willful or knowing violation of this chapter, it shall award as much as 3 times, but not less than 2 times, such amount. In addition, a prevailing plaintiff shall be awarded the costs of the suit and reasonable attorney's fees, as determined by the court. Any attempted waiver of the right to the damages set forth in this paragraph shall be void and unenforceable. Injunctive relief shall be available to private individuals under this chapter without bond, subject to the discretion of the court. II. The New Hampshire attorney general's office shall enforce the provisions of this subdivision pursuant to RSA 358-A:4. III. The burden shall be on the person responsible for the determination under RSA 359-C:20, I to demonstrate compliance with this subdivision.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at gc.nh.gov
United States Code Title 15
§ 6801Protection of nonpublic personal informationIn forcecited in 4 of our articles
It is the policy of the Congress that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers’ nonpublic personal information. In furtherance of the policy in subsection (a), each agency or authority described in section 6805(a) of this title, other than the Bureau of Consumer Financial Protection, shall establish appropriate standards for the financial institutions subject to their jurisdiction relating to administrative, technical, and physical safeguards— to insure the security and confidentiality of customer records and information; to protect against any anticipated threats or hazards to the security or integrity of such records; and to protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 250 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Individual Reference Services Group, Inc. v. Federal Trade Commission (District Court, District of Columbia 2001, 145 F. Supp. 2d 6)“…o. 106-102, 113 Stat. 1338 (1999) (codified as amended at 15 U.S.C.A. § 6801 'et seq. (2000)) (the “GL…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 371 F. Supp. 3d 1150)“…p. , 799 F.3d 236 , 247 (3d Cir. 2015). See 15 U.S.C. § 6801 (b). See 16 C.F.R. § 314.4…”
- Leland Stevens v. Interactive Financial Advisors (Court of Appeals for the Seventh Circuit 2016, 830 F.3d 735)“…clients to a non- affiliated third party like Stevens. See 15 U.S.C. § 6801; 17 C.F.R. § 248.10. This prevented Ste…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Data Privacy Laws: Breach Notification & Consumer Rights (2026), Oklahoma Data Privacy Laws: OKCDPA, Breach Notification & Consumer Rights (2026), Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.H. Rev. Stat. 359-C:19 - Definitions(gc.nh.gov).gov
- N.H. Rev. Stat. 359-C:20 - Notification Requirements(gc.nh.gov).gov
- N.H. Rev. Stat. 359-C:21 - Violations(gc.nh.gov).gov
- NH Attorney General - Security Breaches(doj.nh.gov).gov
- N.H. Rev. Stat. 358-A - Consumer Protection Act(gc.nh.gov).gov