New Hampshire Data Privacy Act

· About New Hampshire Privacy Act (NHPA)

Key Takeaways

  • The New Hampshire Privacy Act applies to controllers that conduct business in New Hampshire or target its residents and meet the statute’s processing thresholds, and it grants consumer rights to access, correct, delete, portability, and opt out of targeted advertising, sale, and certain profiling.
  • The law took effect on 1 January 2025, and New Hampshire’s legislature later added a child-data sales ban in HB 1460, which Governor Kelly Ayotte signed on 19 June 2026 and which takes effect on 1 January 2027.
  • From 1 January 2027, controllers may not sell a child’s personal data; the amendment defines a child by reference to COPPA as an individual under 13 and applies regardless of consent.
  • Enforcement is by the New Hampshire Attorney General, and violations are treated under the state’s consumer-protection enforcement framework, with the law providing a 30-day cure period that currently runs through 31 December 2025 unless extended by later legislative action.
  • The statute contains a broad government, nonprofit, employment, and institution-of-higher-education carve-out structure, so many public-sector and workforce contexts are outside the law’s core consumer-rights regime.
  • The most operationally significant compliance risk is mismatch between data inventory, consumer-rights handling, and the law’s opt-out and child-data restrictions, especially for businesses with advertising, data brokerage, or age-sensitive products.

What It Is

The New Hampshire Privacy Act is the state’s comprehensive consumer privacy law, codified in RSA 507-H and designed to regulate the collection, processing, and sale of personal data by qualifying controllers. It is enforced by the New Hampshire Attorney General, not a standalone privacy agency, which means enforcement follows state consumer-protection litigation and settlement practice rather than a sectoral regulator model.

The statute was adopted in 2024, became effective on 1 January 2025, and has no announced delay to the general effective date. A significant 2026 amendment, HB 1460, was enacted on 19 June 2026 and becomes effective on 1 January 2027; it adds a categorical ban on the sale of children’s personal data. The statute also includes a phased enforcement feature: a 30-day cure period for certain violations remains in the text through 31 December 2025, after which the AG may proceed without first offering cure if the legislature does not extend that window.

Who Must Comply

The law applies to a controller that conducts business in New Hampshire or produces products or services targeted to New Hampshire residents, and that, during a calendar year, controls or processes either the personal data of 100,000 or more consumers, or the personal data of 25,000 or more consumers and derives more than 25% of gross revenue from the sale of personal data. Those thresholds place the statute in the middle tier of state privacy laws: broad enough to capture digitally enabled consumer businesses, but not every employer or local nonprofit.

The law has extraterritorial reach because location outside New Hampshire does not avoid coverage if the business targets New Hampshire residents and meets the thresholds. The core regime generally excludes state agencies, political subdivisions, nonprofits, institutions of higher education, financial institutions subject to GLBA, and certain data governed by HIPAA and other federal regimes, though those entities can still face obligations under separate laws. The 2026 child-data amendment targets controllers selling personal data of a child under 13, and it is not limited to companies knowing the child’s age once the amended prohibition is in force.

Core Requirements

  1. Provide a privacy notice. Controllers must disclose the categories of personal data processed, the purposes for processing, how consumers may exercise rights, the categories of data shared, and whether personal data is sold or used for targeted advertising.
  2. Honor consumer rights. Consumers must be able to access, correct, delete, obtain a portable copy of their data, and opt out of targeted advertising, the sale of personal data, and certain profiling that produces legal or similarly significant effects.
  3. Minimize and purpose-limit processing. Controllers must limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes, and they must not process personal data for purposes incompatible with the original disclosed purpose without appropriate notice.
  4. Execute required contracts with processors. Controllers must have written contracts that bind processors to process data only on documented instructions, maintain confidentiality, implement appropriate security, assist with rights requests, and return or delete data at termination.
  5. Conduct and document data protection assessments. Assessments are required for certain high-risk processing, including targeted advertising, sale of personal data, profiling with significant effects, sensitive data processing, and activities presenting heightened risks to consumers.
  6. Implement reasonable security safeguards. Controllers must maintain administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data, and the statute’s security obligations align operationally with standard privacy-security governance programs.
  7. Prepare for the child-data sales ban. Beginning 1 January 2027, controllers may not sell the personal data of a child under 13, regardless of consent, making age-gating, ad-tech, analytics, and data-broker controls critical.

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | General effective date | 1 January 2025 | New Hampshire Privacy Act obligations become enforceable for covered controllers. | | Cure-period sunset in current text | 31 December 2025 | The statute’s 30-day cure feature currently expires unless extended by later legislation. | | HB 1460 signed | 19 June 2026 | Child-personal-data sales prohibition enacted. | | Child-data sales ban effective | 1 January 2027 | Selling a child’s personal data is prohibited. |

The Attorney General may seek injunctive relief, restitution, disgorgement, and civil penalties under the state’s consumer-enforcement authority, and the practical exposure can include document-production burdens, consent decrees, and mandated compliance reporting. The law does not create a private right of action, so consumer claims run through state enforcement rather than individual lawsuits under the statute itself.

How to Comply

  1. Build a data map. Inventory consumer, child, and sensitive data flows, including ad-tech, analytics, CRM, and third-party sharing, so the business can determine threshold coverage and opt-out exposure.
  2. Classify processing by purpose. Separate internal use, targeted advertising, sale, profiling, and processor-only activity, because the legal analysis turns on purpose and downstream disclosure.
  3. Refresh notices and rights intake. Align external notices, cookie banners, DSAR workflows, and appeal handling so each right can be exercised within statutory timelines.
  4. Harden contracts and vendor controls. Use processor agreements, due diligence, and vendor monitoring consistent with ISO 27001 supplier-security controls and privacy governance.
  5. Run data protection assessments. Treat assessments as a recurring control for high-risk processing; NIST CSF 2.0 helps structure governance, identify, protect, detect, respond, and recover steps, while ISO 42001 is useful where automated decision-making or AI profiling is involved.
  6. Segment children’s data flows now. If the business reaches minors, create age-sensitive rules for advertising, data sale, retention, and disclosure ahead of the 1 January 2027 ban.
  7. Test security and retention controls. Keep collection and storage aligned with necessity, with logging, deletion, access controls, and breach-response procedures mapped to the sensitivity of the data.

Related Regulations

  • Colorado Privacy Act — Shares similar consumer rights and assessment obligations, but Colorado’s sensitive-data and profiling framework is more detailed in some areas.
  • Connecticut Data Privacy Act — Uses a similar threshold-and-rights model and is useful for benchmarking notice, opt-out, and processor-contract language.
  • Virginia Consumer Data Protection Act — Closely tracks the modern state privacy template, but its enforcement and exemption structure differ in ways that matter for multi-state programs.
  • COPPA — The New Hampshire child-data amendment borrows COPPA’s definition of a child, so age-screening and parental-consent controls should be aligned even though the laws regulate different conduct.
  • GLBA and HIPAA — These federal regimes create important carve-outs and preemption issues for financial and health data, so scope analysis must be done carefully before assuming NHPA coverage.

FAQ

Does the New Hampshire Privacy Act apply to companies outside New Hampshire?

Yes, if the company conducts business in New Hampshire or targets New Hampshire residents and meets the statute’s thresholds. Physical presence in the state is not required. The key questions are consumer volume, revenue from personal-data sales, and whether the business is directed at New Hampshire residents.

Does the law apply to small businesses?

Usually not, unless they process personal data at threshold levels. The statute generally covers controllers processing personal data of 100,000 or more consumers, or 25,000 or more consumers and deriving more than 25% of gross revenue from the sale of personal data. Smaller organizations can still face obligations under other laws or contracts.

Can businesses still sell children’s data if they get consent?

No, once HB 1460 is effective on 1 January 2027, the sale of a child’s personal data is prohibited. The amendment is a categorical ban and is not framed as a consent-based permission rule. That means consent will not cure a prohibited sale after the effective date.

Is there a private right of action?

No private right of action is created by the New Hampshire Privacy Act. Enforcement is by the Attorney General, which means violations are handled through public enforcement rather than consumer-filed statutory claims. Businesses should still expect demand letters, investigations, and settlement leverage where violations are found.

Does the law exempt employee data?

The statute’s scope is narrower than a pure consumer-data law, but workforce and B2B data handling are not automatically outside risk if the business also processes consumer data at threshold volumes. Separate employment-specific and sector-specific laws still apply. Multi-purpose data systems should be assessed by data category and processing purpose, not by business label alone.

What changes in 2027?

The major change is the child-data sales prohibition effective 1 January 2027. Companies with youth audiences, location-based products, ad-tech, or brokered-data models should rework their sale definitions, vendor restrictions, and age-gating before that date. Waiting until 2027 risks both technical and contractual noncompliance.

Sources

Put it into practice

More compliance guides