EnglishEspañol
New Hampshire flag

New Hampshire

NHDPA Compliance Checklist: New Hampshire RSA 507-H

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

NHDPA Compliance Checklist: New Hampshire RSA 507-H

Frequently Asked Questions

Does my business have to comply with the NHDPA?

You must comply if, under RSA 507-H:2, you conduct business in New Hampshire or target New Hampshire residents and, during a one-year period, control or process the personal data of 35,000 or more unique consumers, or of 10,000 or more consumers while deriving more than 25 percent of gross revenue from selling personal data. The 35,000-consumer floor is low, so check carefully even if you fall below the line in larger states. First confirm you are not exempt at the entity level under RSA 507-H:3.

What are the first steps to comply with the NHDPA?

Start by running the applicability test in RSA 507-H:2 and checking the entity exemptions in RSA 507-H:3. If covered, publish a compliant privacy notice, build a consent gate for sensitive data, configure your site to honor a universal opt-out signal, complete data protection assessments for high-risk processing, and put compliant processor contracts in place with your vendors.

Does the NHDPA require recognizing a universal opt-out signal?

Yes. Under RSA 507-H:6, V, controllers must recognize a universal opt-out preference signal, such as Global Privacy Control, for targeted advertising and the sale of personal data. Unlike some states that phased this in later, New Hampshire's requirement has applied since the law took effect on January 1, 2025.

What is the penalty for violating the NHDPA?

Under RSA 507-H:11, a violation is an unlawful act under the New Hampshire Consumer Protection Act, RSA 358-A. That allows the Attorney General to seek civil penalties of up to $10,000 per violation under RSA 358-A:4, III(b), plus injunctive relief. There is no private right of action, so only the Attorney General can bring an enforcement action.

Is there still a cure period under the NHDPA?

Not a guaranteed one. The mandatory 60-day cure period applied only during 2025 and sunset on December 31, 2025. As of 2026, whether to grant a cure opportunity is discretionary, and the Attorney General may consider factors such as the number of violations, the size of the business, the likelihood of public injury, and whether the violation resulted from human or technical error.

Do I need a data protection assessment under the NHDPA?

Yes, for high-risk processing. Under RSA 507-H:8, a controller must conduct and document a data protection assessment for targeted advertising, the sale of personal data, certain profiling, and the processing of sensitive data. The requirement applies to processing created or generated after July 1, 2024 and is not retroactive. The Attorney General may require you to disclose a relevant assessment.

Are nonprofits exempt from the NHDPA?

Yes. Under RSA 507-H:3, nonprofit organizations are exempt at the entity level, as are institutions of higher education, government bodies, registered securities associations, and GLBA-covered financial institutions. This is broader than some states, such as Oregon, which generally cover nonprofits. Confirm any affiliated for-profit ventures are not separately covered.

What has to go into a processor contract under the NHDPA?

Under RSA 507-H:7, a contract between a controller and a processor must set out processing instructions, the nature and purpose of processing, the type of data and duration, and the rights and obligations of both parties. It must require the processor to ensure confidentiality, delete or return data at the end of services, demonstrate compliance on request, and cooperate with the controller's data protection assessments.

Updates

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. RSA Chapter 507-H: Expectation of Privacy (Full Chapter)(gc.nh.gov).gov
  2. RSA 507-H as enacted by SB 255 and amended by Chapter 229 (Secretary of State PDF)(sos.nh.gov).gov
  3. New Hampshire Department of Justice: Data Privacy Enforcement(doj.nh.gov).gov
  4. New Hampshire DOJ: Data Privacy Act FAQs(doj.nh.gov).gov
  5. New Hampshire DOJ: Attorney General Formella Announces Creation of New Data Privacy Unit(doj.nh.gov).gov
Share: