EnglishEspañol
New Hampshire flag

New Hampshire

What Is the NHDPA? New Hampshire Data Privacy Act

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

What Is the NHDPA? New Hampshire Data Privacy Act

Frequently Asked Questions

What is the NHDPA?

The NHDPA, or New Hampshire Data Privacy Act, is New Hampshire's comprehensive consumer data privacy law codified at RSA Chapter 507-H. It was enacted as Senate Bill 255, signed by Governor Chris Sununu on March 6, 2024, and took effect January 1, 2025. It gives New Hampshire residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and share it.

When did the New Hampshire Data Privacy Act take effect?

The NHDPA took effect on January 1, 2025. That single effective date applied to all of its core obligations, including the universal opt-out preference signal requirement. As of 2026, the law is fully operative and the Attorney General's Data Privacy Unit is actively enforcing it.

Who has to comply with the NHDPA?

Under RSA 507-H:2, the NHDPA applies to a business that conducts business in New Hampshire or targets New Hampshire residents and that, during a one-year period, controls or processes the personal data of 35,000 or more unique consumers, or of 10,000 or more consumers while deriving more than 25 percent of gross revenue from the sale of personal data. The 35,000-consumer floor is one of the lowest in the country, so the law reaches many smaller and mid-size companies.

Does the NHDPA apply to nonprofits?

No. Under RSA 507-H:3, nonprofit organizations are exempt at the entity level, as are institutions of higher education, government bodies, registered securities associations, GLBA-covered financial institutions, and HIPAA covered entities and business associates. This is different from a state like Oregon, which generally covers nonprofits. A New Hampshire nonprofit is generally outside the NHDPA.

What counts as sensitive data under the NHDPA?

Under RSA 507-H:1, sensitive data includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, or citizenship or immigration status. It also includes genetic or biometric data used to identify a person, personal data collected from a known child, and precise geolocation data. Processing sensitive data requires opt-in consent under RSA 507-H:6.

Does the New Hampshire Secretary of State write privacy rules?

No. As of 2026, RSA 507-H:2, II directs the Secretary of State only to post a link to RSA 507-H on the office's website. The statute does not grant the Secretary of State or any other agency rulemaking authority over privacy notices or opt-out mechanisms. The NHDPA is largely self-executing from its statutory text, and the Attorney General's guidance interprets the law rather than adding binding regulations.

How is the NHDPA different from the CCPA?

Key differences: New Hampshire's coverage threshold is 35,000 consumers with no dollar floor, while California's CCPA uses a $26.625 million revenue trigger among its tests; New Hampshire exempts nonprofits at the entity level; New Hampshire requires opt-in consent for sensitive data while California uses an opt-out right to limit; California has a dedicated privacy agency issuing regulations while New Hampshire's law is self-executing; and California has a limited private right of action for certain breaches while New Hampshire has none.

Who enforces the NHDPA?

The New Hampshire Attorney General has exclusive enforcement authority under RSA 507-H:11, acting through a dedicated Data Privacy Unit. Violations are treated as unlawful acts under the New Hampshire Consumer Protection Act, RSA 358-A, which allows civil penalties of up to $10,000 per violation. There is no private right of action, and the 60-day cure period that controllers relied on during 2025 sunset on December 31, 2025.

Updates

Corrected the description of the HIPAA exemption: RSA 507-H:3, I(f) excludes covered entities and business associates from the chapter outright, with no conflict-with-federal-law limitation.

Updated the California revenue-threshold comparison to the CPI-adjusted figure and clarified the Attorney General retains a discretionary cure option after the mandatory period sunset.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. RSA Chapter 507-H: Expectation of Privacy (Full Chapter)(gc.nh.gov).gov
  2. RSA 507-H as enacted by SB 255 and amended by Chapter 229 (Secretary of State PDF)(sos.nh.gov).gov
  3. New Hampshire Department of Justice: Data Privacy Enforcement(doj.nh.gov).gov
  4. New Hampshire DOJ: Data Privacy Act FAQs(doj.nh.gov).gov
  5. New Hampshire SB 255 (2024 Regular Session): Bill Text(legiscan.com)
  6. RSA 507-H:3 Exclusions (New Hampshire General Court)(gc.nh.gov)
Share: