New Hampshire
New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)

New Hampshire requires businesses to notify affected residents of a data breach as quickly as possible under RSA 359-C:20, with no fixed-day deadline but a duty to act promptly. The state's Attorney General must receive notice before any individual notifications are sent.
If your business handles personal information belonging to New Hampshire residents, a data breach triggers specific legal obligations under New Hampshire's Notice of Security Breach law. N.H. Rev. Stat. 359-C:19 through 359-C:21 sets out who must notify, what triggers the duty, and how quickly you need to act. New Hampshire enacted its breach notification law in 2007 as part of the state's Right to Privacy chapter, reflecting the legislature's view that breach notification is fundamentally a privacy protection.
This guide covers the full scope of New Hampshire's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With New Hampshire's Breach Notification Law
New Hampshire's law applies to any person doing business in the state, any person that owns or licenses computerized data that includes personal information, or any person that maintains computerized data containing personal information on behalf of another. This broad scope captures businesses, government entities, and third-party service providers.
When a third party that maintains data on behalf of a data owner discovers a breach, it must notify the data owner immediately. The data owner then carries the primary responsibility to notify affected individuals and the Attorney General.
The statute applies regardless of where the business is physically located. Any business that holds personal information about New Hampshire residents must comply if it does business in the state.
What Qualifies as a Breach
Under N.H. Rev. Stat. 359-C:19, a "security breach" means the unauthorized acquisition of computerized data that compromises the security or confidentiality of personal information maintained by a person doing business in New Hampshire.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of a person doing business in the state does not constitute a security breach, provided the personal information is not used or subject to further unauthorized disclosure.
Encryption Safe Harbor
New Hampshire provides a safe harbor for encrypted data. The notification requirements do not apply to the unauthorized acquisition of personal information that has been encrypted, as long as the encryption key was not also compromised. If both the encrypted data and the key were acquired by the unauthorized person, notification is required.
Personal Information That Triggers Notification
Under N.H. Rev. Stat. 359-C:19, personal information means an individual's first name or first initial and last name combined with any one or more of the following data elements:
- Social Security number
- Driver's license number or other government identification number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to an individual's financial account
What New Hampshire's Law Does Not Cover
Compared to states that have recently updated their breach notification statutes, New Hampshire's definition of personal information is relatively narrow. The law does not include:
- Biometric data (fingerprints, retina scans, voiceprints)
- Medical or health information
- Health insurance identification numbers
- Passport numbers
- Username or email address combined with passwords
- Taxpayer identification numbers (other than SSNs)
Personal information does not include information that is lawfully obtained from publicly available sources or from federal, state, or local government records lawfully made available to the public.
Notification Timeline
New Hampshire requires notification "as quickly as possible" under N.H. Rev. Stat. 359-C:20. This language is more urgent than the "without unreasonable delay" standard used by many states, suggesting the legislature intended a particularly prompt response.
The statute does not set a specific day count, but the "as quickly as possible" standard places the burden on the notifying entity to demonstrate that any delay was justified.

When Delay Is Permitted
Notification may be delayed if:
- A law enforcement agency determines that notification will impede a criminal investigation. Notification must be made after law enforcement determines it no longer compromises the investigation.
- The entity needs time to determine the nature and scope of the incident, identify the affected individuals, and restore the reasonable integrity of the data system.
Even when delay is permitted, the entity must still act "as quickly as possible" once the reason for the delay no longer applies.
Who Must Be Notified
New Hampshire Attorney General
The New Hampshire Attorney General must be notified of any security breach before individual notifications are sent. This is a notable requirement: New Hampshire mandates that the AG receive notice first, giving the office an opportunity to coordinate with the entity before affected individuals learn of the breach.
The AG notification should include:
- The nature of the security breach
- The number of New Hampshire residents affected
- Steps taken in response to the breach
- Any services being offered to affected individuals
Affected Individuals
Every New Hampshire resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person must be notified. The notification must include:
- A description of the incident in general terms
- The approximate date of the breach
- The type of personal information involved
- Contact information for the entity providing notice
- Contact information for the Federal Trade Commission and the New Hampshire Attorney General
- Steps the individual can take to protect against identity theft
Consumer Reporting Agencies
When a breach affects more than 1,000 New Hampshire residents at a single time, the entity must also notify the nationwide consumer reporting agencies without unreasonable delay. The notification must include the timing, distribution, and content of the notification to individuals.
How to Provide Notification
New Hampshire permits the following notification methods:
- Written notice sent by mail to the last known address of the individual
- Electronic notice if the entity's primary means of communication with the individual is by electronic means, or if the notice is consistent with the E-SIGN Act (15 U.S.C. 7001)
- Telephone notice if the entity can directly reach the affected individual
Substitute Notice
New Hampshire has one of the lowest substitute notice thresholds in the nation. Substitute notice is available when:
- The cost of providing notification would exceed $5,000
- The affected class exceeds 1,000 New Hampshire residents
- The entity does not have sufficient contact information
Compare this to most states where the cost threshold is $250,000 and the affected class threshold is 500,000. New Hampshire's low thresholds make substitute notice available to smaller businesses and smaller breaches.
Substitute notice must include all of the following:
- Email notification to individuals for whom the entity has an email address
- Conspicuous posting of the notice on the entity's website
- Notification to major statewide media outlets

Enforcement and Penalties
New Hampshire's breach notification law is enforced by the Attorney General under the Consumer Protection Act (N.H. Rev. Stat. 358-A). A violation of the breach notification requirements constitutes an unfair or deceptive act or practice.
The Attorney General may seek:
- Injunctive relief to stop ongoing violations
- Civil penalties as provided under the Consumer Protection Act
- Restitution for affected consumers
- Attorney's fees and costs of investigation
New Hampshire also gives individuals a private right of action under RSA 359-C:21. Anyone injured by a breach-notification violation may sue for actual damages, plus 2 to 3 times that amount if the violation was willful or knowing, along with attorney's fees, costs, and injunctive relief.
Exemptions
Certain entities are exempt from New Hampshire's breach notification requirements if they comply with equivalent federal notification frameworks:
- Financial institutions subject to and in compliance with the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice
- HIPAA-covered entities that comply with HIPAA breach notification requirements
These entities must follow their respective federal notification frameworks, which may impose stricter or different requirements.
How New Hampshire's Privacy Laws Interact With Breach Notification

The New Hampshire Privacy Act, effective January 1, 2025, created a comprehensive consumer privacy framework. However, the Privacy Act does not contain its own breach notification requirements. Businesses subject to the Privacy Act must still follow N.H. Rev. Stat. 359-C:19-21 for breach notification.
The Privacy Act adds relevant data protection obligations:
- Data security requirement: Controllers must implement reasonable administrative, technical, and physical data security practices.
- Data minimization: Controllers must limit data collection to what is adequate, relevant, and reasonably necessary.
- Sensitive data consent: Biometric data, precise geolocation, and other sensitive categories require explicit consumer consent before processing.
Both the Privacy Act and the breach notification statute are enforced by the Attorney General under the Consumer Protection Act.
This article provides general legal information about New Hampshire data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New Hampshire for guidance specific to your situation.
More New Hampshire Laws
Frequently Asked Questions
How long does a business have to notify New Hampshire residents of a data breach?
New Hampshire law requires notification 'as quickly as possible,' which is a more urgent standard than the 'without unreasonable delay' language used by many states. There is no specific day deadline, but any delay must be justified by the need to determine the scope of the breach, identify affected individuals, restore system integrity, or comply with a law enforcement request.
Does New Hampshire require businesses to notify the Attorney General after a data breach?
Yes. The New Hampshire Attorney General must be notified before individual notifications are sent. This is a distinctive requirement. The AG notification should include the nature of the breach, the number of affected residents, steps taken in response, and any services being offered. Consumer reporting agencies must also be notified when more than 1,000 residents are affected.
What is New Hampshire's substitute notice threshold?
New Hampshire has one of the lowest substitute notice thresholds in the nation. A business may use substitute notice when the cost of standard notification exceeds $5,000, the affected class exceeds 1,000 residents, or the entity lacks sufficient contact information. Most states set these thresholds at $250,000 and 500,000 respectively. Substitute notice requires email, website posting, and major media notification.
Does encryption protect businesses from New Hampshire's breach notification requirements?
Yes, New Hampshire provides an encryption safe harbor. If the compromised personal information was encrypted and the encryption key was not also acquired by the unauthorized person, notification is not required. If both the data and the encryption key were compromised, the full notification obligations apply.
Can individuals sue for a breach notification violation in New Hampshire?
Yes. RSA 359-C:21 gives anyone injured by a breach-notification violation a private right of action for actual damages, with 2 to 3 times that amount if the violation was willful or knowing, plus attorney's fees, costs, and injunctive relief. The Attorney General can also enforce the statute separately under the Consumer Protection Act.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected a reversed claim that New Hampshire's breach notification law has no private right of action: RSA 359-C:21 actually gives injured individuals the right to sue for damages (up to treble for willful violations), fees, and injunctive relief. Also removed an added 'for an unauthorized purpose' qualifier from the good-faith exception, and fixed the consumer-reporting-agency threshold from '1,000 or more' to the statute's actual 'more than 1,000.'
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
United States Code Title 15
§ 7001General rule of validityIn forcecited in 17 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
New Hampshire Revised Statutes Annotated, TITLE XXXI TRADE AND COMMERCE, CHAPTER 359-C RIGHT TO PRIVACY
§ 359-C:19Definitions.In forcecited in 3 of our articles
In this subdivision: I. "Computerized data" means personal information stored in an electronic format. II. "Encrypted" means the transformation of data through the use of an algorithmic process into a form for which there is a low probability of assigning meaning without use of a confidential process or key, or securing the information by another method that renders the data elements completely unreadable or unusable. Data shall not be considered to be encrypted for purposes of this subdivision if it is acquired in combination with any required key, security code, access code, or password that would permit access to the encrypted data. III. "Person" means an individual, corporation, trust, partnership, incorporated or unincorporated association, limited liability company, or other form of entity, or any agency, authority, board, court, department, division, commission, institution, bureau, or other state governmental entity, or any political subdivision of the state. IV.
Official text (excerpt) · as of 2026-07-29 · Read the full section at gc.nh.gov
Also relied on in: New Hampshire Data Privacy Laws: Consumer Rights Guide (2026), New Hampshire Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 359-C:20Notification of Security Breach Required.In forcecited in 3 of our articles
I. (a) Any person doing business in this state who owns or licenses computerized data that includes personal information shall, when it becomes aware of a security breach, promptly determine the likelihood that the information has been or will be misused. If the determination is that misuse of the information has occurred or is reasonably likely to occur, or if a determination cannot be made, the person shall notify the affected individuals as soon as possible as required under this subdivision. (b) Any person engaged in trade or commerce that is subject to RSA 358-A:3, I shall also notify the regulator which has primary regulatory authority over such trade or commerce. All other persons shall notify the New Hampshire attorney general's office. The notice shall include the anticipated date of the notice to the individuals and the approximate number of individuals in this state who will be notified. Nothing in this section shall be construed to require the person to provide to any regulator or the New Hampshire attorney general's office the names of the individuals entitled to receive the notice or any personal information relating to them.
Official text (excerpt) · as of 2026-07-29 · Read the full section at gc.nh.gov
§ 359-C:21Violation.In forcecited in 2 of our articles
I. Any person injured by any violation under this subdivision may bring an action for damages and for such equitable relief, including an injunction, as the court deems necessary and proper. If the court finds for the plaintiff, recovery shall be in the amount of actual damages. If the court finds that the act or practice was a willful or knowing violation of this chapter, it shall award as much as 3 times, but not less than 2 times, such amount. In addition, a prevailing plaintiff shall be awarded the costs of the suit and reasonable attorney's fees, as determined by the court. Any attempted waiver of the right to the damages set forth in this paragraph shall be void and unenforceable. Injunctive relief shall be available to private individuals under this chapter without bond, subject to the discretion of the court. II. The New Hampshire attorney general's office shall enforce the provisions of this subdivision pursuant to RSA 358-A:4. III. The burden shall be on the person responsible for the determination under RSA 359-C:20, I to demonstrate compliance with this subdivision.
Official text (excerpt) · as of 2026-07-29 · Read the full section at gc.nh.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- N.H. Rev. Stat. 359-C:19 - Definitions(gencourt.state.nh.us).gov
- N.H. Rev. Stat. 359-C:20 - Notification Requirements(gencourt.state.nh.us).gov
- N.H. Rev. Stat. 359-C:21 - Violations(gencourt.state.nh.us).gov
- NH Attorney General - Security Breaches(doj.nh.gov).gov
- N.H. Rev. Stat. 358-A - Consumer Protection Act(gencourt.state.nh.us).gov