🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-NH · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 11 sources retrieved model claude-sonnet-5 ·

United States – New Hampshire

US-NH schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 52 claims · 11 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
52Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core instrument is in force, regulator identified, scope and thresholds well documented from primary DOJ sources.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H)
Traffic-light rationale — GreenCore instrument is in force, regulator identified, scope and thresholds well documented from primary DOJ sources.

Sub-modules (5)

Regulator And AuthorityGreen

The Data Privacy Unit, housed in the Consumer Protection and Antitrust Bureau, is tasked with enforcing the NHDPA and related state/federal data privacy laws; the AG holds exclusive enforcement authority.

Claims (2):

  • The Data Privacy Unit within the Consumer Protection and Antitrust Bureau of the New Hampshire Attorney General's Office is tasked with enforcing the NHDPA and related data privacy laws.
  • The New Hampshire Attorney General has exclusive authority to enforce NHDPA violations under RSA 507-H:11, I, with no private right of action under this statute.

Act And InstrumentsGreen

Core instrument is RSA 507-H (NHDPA); breach notification runs under the separate RSA 359-C:20; NHDPA violations are also deemed unlawful acts under the general Consumer Protection Act, RSA 358-A:2.

Claims (2):

  • The New Hampshire Data Privacy Act, RSA 507-H, creates consumer rights with respect to personal data and imposes responsibilities on businesses, effective January 1, 2025.
  • A violation of the NHDPA is treated as an unlawful act under RSA 358-A:2, the New Hampshire Consumer Protection Act, layering general consumer-protection remedies onto NHDPA enforcement.

Material ScopeGreen

NHDPA covers 'personal data' linked/linkable to an identified or identifiable individual, excluding de-identified and publicly available data, and carves out numerous federally-regulated data categories (GLBA, HIPAA, FERPA, DPPA, Farm Credit Act, Airline Deregulation Act, Controlled Substances Act-listed chemicals, employment/B2B context data).

Claims (2):

  • Personal data under the NHDPA is any information linked or reasonably linkable to an identified or identifiable individual, and does not include de-identified data or publicly available information.
  • The NHDPA exempts numerous categories of federally-regulated data, including data subject to GLBA/Farm Credit Act, HIPAA, FERPA, the Driver's Privacy Protection Act, the Airline Deregulation Act, and Controlled Substances Act chemical-listing compliance data, as well as employment/B2B context data.

Territorial ScopeGreen

Applies to persons conducting business in New Hampshire or producing products/services targeted to NH residents that meet volume/revenue thresholds during a 12-month period.

Claims (1):

  • The NHDPA applies to persons conducting business in New Hampshire or targeting NH residents that, in a one-year period, controlled/processed personal data of 35,000+ unique consumers, or 10,000+ unique consumers while deriving over 25% of gross revenue from the sale of personal data.

Regulator Registration And FilingAmber

No controller registration or filing regime exists; a 2024 amendment removed a prior mandate for Secretary of State rulemaking, making the Act's consumer-rights/privacy-notice provisions self-executing rather than subject to agency rulemaking.

Claims (1):

  • New Hampshire's comprehensive privacy law received a minor 2024 amendment removing a mandate that the Secretary of State conduct rulemaking on privacy policies and consumer-rights exercise, making these provisions self-executing.
Category narrative78 words

New Hampshire's data-protection regime is anchored in RSA 507-H, the New Hampshire Data Privacy Act (NHDPA), which took effect January 1, 2025 and is enforced exclusively by a dedicated Data Privacy Unit inside the Attorney General's Consumer Protection and Antitrust Bureau. There is no independent DPA; enforcement runs through general AG consumer-protection authority, consistent with the seed's disambiguation note. A companion instrument, RSA 359-C:20, imposes an older, narrower security-breach-notification duty that predates the NHDPA and remains independently operative.

Sources and claims (8)
  1. ConfirmedNH Department of JusticeThe Data Privacy Unit within the Consumer Protection and Antitrust Bureau of the New Hampshire Attorney General's Office is tasked with enforcing the NHDPA and related data privacy laws.observed
  2. ConfirmedNH Department of JusticeThe New Hampshire Attorney General has exclusive authority to enforce NHDPA violations under RSA 507-H:11, I, with no private right of action under this statute.observed
  3. ConfirmedNH Department of JusticeThe New Hampshire Data Privacy Act, RSA 507-H, creates consumer rights with respect to personal data and imposes responsibilities on businesses, effective January 1, 2025.observed
  4. ConfirmedNH Department of JusticeA violation of the NHDPA is treated as an unlawful act under RSA 358-A:2, the New Hampshire Consumer Protection Act, layering general consumer-protection remedies onto NHDPA enforcement.observed
  5. ConfirmedNH Department of JusticePersonal data under the NHDPA is any information linked or reasonably linkable to an identified or identifiable individual, and does not include de-identified data or publicly available information.observed
  6. ConfirmedNH Department of JusticeThe NHDPA exempts numerous categories of federally-regulated data, including data subject to GLBA/Farm Credit Act, HIPAA, FERPA, the Driver's Privacy Protection Act, the Airline Deregulation Act, and Controlled Substances Act chemical-listing compliance data, as well as employment/B2B context data.observed
  7. ConfirmedNH Department of JusticeThe NHDPA applies to persons conducting business in New Hampshire or targeting NH residents that, in a one-year period, controlled/processed personal data of 35,000+ unique consumers, or 10,000+ unique consumers while deriving over 25% of gross revenue from the sale of personal data.observed
  8. ProbableIAPPNew Hampshire's comprehensive privacy law received a minor 2024 amendment removing a mandate that the Secretary of State conduct rulemaking on privacy policies and consumer-rights exercise, making these provisions self-executing.observed

#

Consent/sensitive-data provisions are well evidenced; pseudonymisation/anonymisation safe-harbour detail is not confirmed from sources searched.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H)
Traffic-light rationale — AmberConsent/sensitive-data provisions are well evidenced; pseudonymisation/anonymisation safe-harbour detail is not confirmed from sources searched.

Sub-modules (4)

Lawful BasesAmber

No enumerated Art 6-style lawful-basis list; processing is generally permitted subject to notice and consumer opt-out rights, with opt-in consent required only for sensitive data and known-child data.

Claims (1):

  • The NHDPA structures most processing around a notice-and-opt-out model rather than an enumerated lawful-bases regime, reserving affirmative consent for sensitive data and known-child processing.

Special CategoriesGreen

Sensitive data includes racial/ethnic origin, religious beliefs, mental/physical health condition or diagnosis, and precise geolocation data, among other categories; processing sensitive data requires consumer consent, and additional restrictions apply to processing a known child's data.

Claims (2):

  • Sensitive data under the NHDPA includes racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, and precise geolocation data, among other categories defined at RSA 507-H:1, XXVIII.
  • Controllers may not process sensitive data concerning a consumer without obtaining consent, and additional restrictions apply to processing sensitive data concerning a known child.

Pseudonymisation And AnonymisationRed

No detailed statutory definition or safe-harbour for pseudonymised/anonymised data beyond the exclusion of de-identified data from the 'personal data' definition was identified in sources searched (doj.nh.gov FAQ, RSA 507-H text pages).

Absence provenance: not recorded. Searched: doj.nh.gov/data-privacy-enforcement, doj.nh.gov NHDPA FAQ PDF.

Category narrative61 words

The NHDPA does not adopt a GDPR-style enumerated lawful-bases model; instead it operates a notice-and-opt-out default for most processing, reserving consent (opt-in) for sensitive data and for known children under 13. Consent must be revocable, with a 15-day compliance window. Sensitive-data and biometric/genetic-specific detail beyond the statutory sensitive-data list, and any codified anonymisation safe-harbour, were not located in primary sources searched.

Sources and claims (4)
  1. ProbableNH Department of JusticeThe NHDPA structures most processing around a notice-and-opt-out model rather than an enumerated lawful-bases regime, reserving affirmative consent for sensitive data and known-child processing.observed
  2. ConfirmedNH Department of JusticeOnce a business receives a consumer's request to revoke consent, it must stop processing the consumer's data within 15 days.observed
  3. ConfirmedNH Department of JusticeSensitive data under the NHDPA includes racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, and precise geolocation data, among other categories defined at RSA 507-H:1, XXVIII.observed
  4. ConfirmedNH Department of JusticeControllers may not process sensitive data concerning a consumer without obtaining consent, and additional restrictions apply to processing sensitive data concerning a known child.observed

#

Rights and timelines are well documented directly from AG FAQ/guidance sources.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H)
Traffic-light rationale — GreenRights and timelines are well documented directly from AG FAQ/guidance sources.

Sub-modules (5)

Access RightGreen

Consumers may confirm whether a controller is processing their personal data and obtain access.

Claims (1):

  • New Hampshire consumers have the right to confirm whether or not a controller is processing the consumer's personal data.

Rectification And ErasureGreen

Consumers have rights to correct and delete personal data controlled or processed by a business; deletion requests are the most common consumer complaint received by the Data Privacy Unit.

Claims (1):

  • Requests to delete personal data under RSA 507-H are the most common type of consumer complaint received by the Data Privacy Unit.

Restriction And ObjectionGreen

Consumers may opt out of processing for targeted advertising, sale of personal data, or profiling in furtherance of solely automated decisions producing legal or similarly significant effects.

Claims (1):

  • Consumers may opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.

Data PortabilityGreen

Consumers may obtain a copy of their personal data controlled or processed by a business in a portable, readable format.

Claims (1):

  • Consumers may obtain a copy of their personal data being controlled or processed by a business in a portable and readable format.

Deadlines And Response WindowsGreen

Controllers must respond to consumer requests, with denials communicated within 45 days; appeals of denials must be answered within 60 days; free access is limited to once per consumer per 12-month period.

Claims (2):

  • If a controller declines to act on a consumer request, it must inform the consumer without undue delay, and not later than 45 days after receipt of the request, of the justification and appeal instructions.
  • A controller has 60 days after receiving a consumer's appeal to inform the consumer in writing of any action taken or not taken, with a written explanation of its decision.
Category narrative52 words

The NHDPA grants New Hampshire consumers confirmation/access, correction, deletion, portability, and opt-out rights (targeted advertising, sale, and certain automated-decision profiling), with a standard 45-day controller response window (extendable) and a 60-day appeal-response window. Requests are free once per 12-month period, with a higher fee/refusal option for manifestly unfounded, excessive, or repetitive requests.

Sources and claims (6)
  1. ConfirmedNH Department of JusticeNew Hampshire consumers have the right to confirm whether or not a controller is processing the consumer's personal data.observed
  2. ConfirmedNH Department of JusticeRequests to delete personal data under RSA 507-H are the most common type of consumer complaint received by the Data Privacy Unit.observed
  3. ConfirmedNH Department of JusticeConsumers may opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.observed
  4. ConfirmedNH Department of JusticeConsumers may obtain a copy of their personal data being controlled or processed by a business in a portable and readable format.observed
  5. ConfirmedNH Department of JusticeIf a controller declines to act on a consumer request, it must inform the consumer without undue delay, and not later than 45 days after receipt of the request, of the justification and appeal instructions.observed
  6. ConfirmedNH Department of JusticeA controller has 60 days after receiving a consumer's appeal to inform the consumer in writing of any action taken or not taken, with a written explanation of its decision.observed

#

DPIA, security and breach-notification duties are well evidenced; DPO appointment and retention/disposal specifics are not confirmed.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H); Security Breach Notification, RSA 359-C:20
Traffic-light rationale — AmberDPIA, security and breach-notification duties are well evidenced; DPO appointment and retention/disposal specifics are not confirmed.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct and document data protection assessments for processing presenting heightened risk of harm, including targeted advertising, certain profiling, and sensitive-data processing occurring after July 1, 2024.

Claims (2):

  • If a controller processes data or causes data to be processed after July 1, 2024, it must conduct and document a data protection assessment for each processing activity presenting a heightened risk of harm to a consumer.
  • Processing presenting a heightened risk of harm includes targeted advertising, certain types of profiling, and the processing of sensitive data under RSA 507-H:8, I.

Dpo RequirementsRed

No DPO-appointment threshold or independence requirement was identified in the NHDPA text/FAQ sources reviewed.

Absence provenance: not recorded. Searched: doj.nh.gov/data-privacy-enforcement, doj.nh.gov NHDPA FAQ PDF.

Ropa RequirementsAmber

No standalone records-of-processing mandate beyond the documented data-protection-assessment requirement was identified.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Claims (1):

  • Processors must provide a report of any controller-arranged or independent assessment of the processor's policies and technical/organizational measures to the controller upon request, under RSA 507-H:7, II(e).

Joint Controller ArrangementsGreen

Processors must, per RSA 507-H:7, cooperate with reasonable assessments by the controller or an independent assessor and provide assessment reports to the controller on request.

Claims (1):

  • A processor may arrange for a qualified and independent assessor to conduct an assessment of the processor's policies and technical and organizational measures supporting its obligations under RSA 507-H.

Security MeasuresGreen

Controllers must implement reasonable data security safeguards under RSA 507-H:6, I(c), alongside data-minimisation/collection limits and antidiscrimination requirements.

Claims (2):

  • Controllers must implement reasonable data safeguards under RSA 507-H:6, I(c).
  • The NHDPA imposes limits on a controller's collection of data and antidiscrimination requirements under RSA 507-H:6, I(a) and (e).

Breach NotificationGreen

Breach notification is governed by the separate, pre-existing RSA 359-C:20, requiring notice to affected individuals, the primary regulator or AG, and (if over 1,000 affected) national consumer reporting agencies; this statute carries both AG administrative enforcement and a private right of action.

Claims (2):

  • Under RSA 359-C:20, as soon as a business becomes aware that the security or confidentiality of personal information has been compromised, it must promptly determine the likelihood of misuse and, if misuse is likely or cannot be ruled out, notify affected individuals and its primary regulator or the NH Attorney General.
  • The Attorney General's Consumer Protection and Antitrust Bureau has administrative enforcement authority over RSA 359-C:20, and private individuals also have a private right of action for violations of that statute.

Retention And DisposalRed

Beyond general data-minimisation/collection-limit language, no explicit retention-period or disposal-duty provision was located in sources searched.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF, doj.nh.gov/data-privacy-enforcement.

Claims (1):

  • The NHDPA places limits on a controller's collection of data under RSA 507-H:6, I(a), but a specific retention-period or disposal-duty provision was not identified in sources searched.
Category narrative86 words

Controllers must conduct and document data protection assessments (DPIA-equivalent) for processing presenting a heightened risk of harm (targeted advertising, certain profiling, sensitive data), for processing occurring after July 1, 2024. Controllers must implement reasonable data security safeguards and observe data-minimisation/collection limits and antidiscrimination requirements. Processors have statutory obligations under RSA 507-H:7, including cooperating with controller/independent assessments. Breach notification runs under a separate, older statute (RSA 359-C:20) rather than within the NHDPA itself. No explicit DPO-appointment threshold or formal ROPA/retention-schedule mandate was located in primary sources searched.

Sources and claims (9)
  1. ConfirmedNH Department of JusticeIf a controller processes data or causes data to be processed after July 1, 2024, it must conduct and document a data protection assessment for each processing activity presenting a heightened risk of harm to a consumer.observed
  2. ConfirmedNH Department of JusticeProcessing presenting a heightened risk of harm includes targeted advertising, certain types of profiling, and the processing of sensitive data under RSA 507-H:8, I.observed
  3. ConfirmedNH Department of JusticeProcessors must provide a report of any controller-arranged or independent assessment of the processor's policies and technical/organizational measures to the controller upon request, under RSA 507-H:7, II(e).observed
  4. ConfirmedNH Department of JusticeA processor may arrange for a qualified and independent assessor to conduct an assessment of the processor's policies and technical and organizational measures supporting its obligations under RSA 507-H.observed
  5. ConfirmedNH Department of JusticeControllers must implement reasonable data safeguards under RSA 507-H:6, I(c).observed
  6. ConfirmedNH Department of JusticeThe NHDPA imposes limits on a controller's collection of data and antidiscrimination requirements under RSA 507-H:6, I(a) and (e).observed
  7. ConfirmedNH Department of JusticeUnder RSA 359-C:20, as soon as a business becomes aware that the security or confidentiality of personal information has been compromised, it must promptly determine the likelihood of misuse and, if misuse is likely or cannot be ruled out, notify affected individuals and its primary regulator or the NH Attorney General.observed
  8. ConfirmedNH Department of JusticeThe Attorney General's Consumer Protection and Antitrust Bureau has administrative enforcement authority over RSA 359-C:20, and private individuals also have a private right of action for violations of that statute.observed
  9. UncertainNH Department of JusticeThe NHDPA places limits on a controller's collection of data under RSA 507-H:6, I(a), but a specific retention-period or disposal-duty provision was not identified in sources searched.observed

#

No comprehensive cross-border transfer regime exists under the NHDPA; this is a legitimate structural gap, not an omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists under the NHDPA; this is a legitimate structural gap, not an omission.

Sub-modules (6)

Transfer MechanismsRed

No NHDPA-specific transfer mechanism (adequacy/SCC/BCR/derogation) was located.

Absence provenance: not recorded. Searched: doj.nh.gov/data-privacy-enforcement, doj.nh.gov NHDPA FAQ PDF.

Adequacy ReceivedRed

Not applicable; US states do not receive GDPR-style adequacy decisions.

Absence provenance: not recorded. Searched: doj.nh.gov.

Adequacy GrantedRed

Not applicable; New Hampshire does not grant adequacy decisions.

Absence provenance: not recorded. Searched: doj.nh.gov.

Sccs And BcrsRed

No SCC/BCR uptake or forms provision found in the NHDPA.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Transfer Impact AssessmentRed

No TIA requirement identified; the NHDPA's data protection assessment obligation concerns in-scope high-risk processing, not cross-border transfer specifically.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Data LocalisationRed

No data-localisation mandate (partial or absolute) was identified for New Hampshire.

Absence provenance: not recorded. Searched: doj.nh.gov.

Category narrative67 words

No cross-border transfer mechanism, adequacy determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate specific to New Hampshire's NHDPA was identified. As a US state consumer-privacy statute, RSA 507-H does not operate an EU-style adequacy or SCC framework; any international-transfer exposure for NH-covered businesses would arise from separate federal or foreign-law obligations (e.g., GDPR if EU data is also in scope), which sit outside this JID's bound instrument.

#

Several sectoral exemptions are directly confirmed; others (GLBA, insurance, credit-scoring specifics) rely on inference from peer-law patterns and are marked accordingly.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H) sectoral exemptions
Traffic-light rationale — AmberSeveral sectoral exemptions are directly confirmed; others (GLBA, insurance, credit-scoring specifics) rely on inference from peer-law patterns and are marked accordingly.

Sub-modules (7)

Financial Sector OverlayAmber

RSA 507-H:3, II(n) exempts data subject to the Farm Credit Act; GLBA-covered financial institution data is commonly exempted under peer state laws but a direct NHDPA GLBA citation was not confirmed in sources reviewed.

Claims (1):

  • The NHDPA exempts personal data regulated by the Farm Credit Act (12 U.S.C. 2001 et seq.) under RSA 507-H:3, II(n).

Health Sector OverlayGreen

HIPAA-regulated data and patient-safety work product under the Patient Safety and Quality Improvement Act are exempted from NHDPA scope.

Claims (1):

  • The NHDPA exempts patient safety work product for purposes of the Patient Safety and Quality Improvement Act (42 U.S.C. 299b-21 et seq.) under RSA 507-H:3, II(g).

Telecoms And EprivacyRed

No NH-specific telecoms/ePrivacy overlay distinct from the NHDPA's general opt-out/UOOM framework was identified.

Absence provenance: not recorded. Searched: doj.nh.gov.

Employment DataGreen

Data processed in the context of an individual's application, employment, or agency/contractor role is excluded from the 'consumer' definition and thus outside NHDPA scope.

Claims (1):

  • Data processed or maintained in the course of an individual applying to, being employed by, or acting as an agent/independent contractor of a controller, processor, or third party is excluded from NHDPA scope where collected/used within the context of that role.

Credit And ScoringRed

No NH-specific credit-scoring overlay beyond the general federal FCRA framework (referenced obliquely via related federal-law exemptions) was confirmed.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

EducationGreen

Personal data regulated by FERPA is exempted from the NHDPA.

Claims (1):

  • Personal data regulated by the Family Educational Rights and Privacy Act (20 U.S.C.) is exempted from NHDPA coverage under RSA 507-H:3, II.

InsuranceRed

No NH-specific insurance-sector privacy overlay was identified in sources searched.

Absence provenance: not recorded. Searched: doj.nh.gov.

Category narrative102 words

The NHDPA carves out several federally-regulated sectors from its scope rather than layering additional NH-specific sectoral rules on top. Financial data covered by the Farm Credit Act, health data covered by HIPAA and the Patient Safety and Quality Improvement Act, and education records covered by FERPA are among the confirmed statutory exemptions. GLBA-covered financial-institution data is commonly exempted in peer state statutes but a direct NHDPA citation for this was not located; this claim is marked Probable pending fuller text verification. Employment and B2B context data are excluded from the 'consumer' definition entirely. No NH-specific insurance-sector, telecoms/eprivacy, or credit-scoring overlay was found.

Sources and claims (4)
  1. ConfirmedNH Department of JusticeThe NHDPA exempts personal data regulated by the Farm Credit Act (12 U.S.C. 2001 et seq.) under RSA 507-H:3, II(n).observed
  2. ConfirmedNH Department of JusticeThe NHDPA exempts patient safety work product for purposes of the Patient Safety and Quality Improvement Act (42 U.S.C. 299b-21 et seq.) under RSA 507-H:3, II(g).observed
  3. ConfirmedNH Department of JusticeData processed or maintained in the course of an individual applying to, being employed by, or acting as an agent/independent contractor of a controller, processor, or third party is excluded from NHDPA scope where collected/used within the context of that role.observed
  4. ConfirmedNH Department of JusticePersonal data regulated by the Family Educational Rights and Privacy Act (20 U.S.C.) is exempted from NHDPA coverage under RSA 507-H:3, II.observed

#

Cookie/tracker opt-out and UOOM support are confirmed in force; dark-patterns and clean-room specifics are unconfirmed gaps.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H)
Traffic-light rationale — GreenCookie/tracker opt-out and UOOM support are confirmed in force; dark-patterns and clean-room specifics are unconfirmed gaps.

Sub-modules (6)

Cookies And TrackersGreen

The NHDPA's opt-out right for targeted advertising functionally governs advertising cookies/trackers rather than a standalone cookie-consent statute.

Claims (1):

  • Controllers may not engage in targeted advertising or selling personal data for consumers aged 13 to under 16 without consent.

Dark PatternsRed

No explicit NHDPA dark-patterns prohibition was located in sources searched.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Opt Out SignalsGreen

New Hampshire consumers can use an opt-out preference signal (universal opt-out mechanism) to exercise sale/targeted-advertising opt-outs, and NH is among the states where UOOM requirements are already in effect.

Claims (2):

  • A consumer can designate a third party to opt out on their behalf and can use an opt-out preference signal to exercise sale/targeted-advertising opt-out rights.
  • Universal opt-out mechanism (UOOM) requirements are already in effect in New Hampshire, alongside California, Colorado, Connecticut, Montana, Nebraska and Texas, effective January 1.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule specific to New Hampshire was identified.

Absence provenance: not recorded. Searched: doj.nh.gov.

Cross Context AdvertisingGreen

Consumers may opt out of processing for targeted advertising purposes; the NHDPA does not use CPRA's distinct 'sale'/'share' terminology but achieves a similar opt-out outcome for cross-context advertising.

Claims (1):

  • Consumers have the right to opt out of the processing of personal data for purposes of targeted advertising under RSA 507-H:4, I.

Direct MarketingAmber

Consumers may opt out of the sale of personal data to third parties, which functions as the NHDPA's direct-marketing-adjacent suppression mechanism; no separate suppression-list statute was identified.

Claims (1):

  • A consumer can opt out of the sale of personal data to third parties, and the controller must provide a process for submitting such opt-out requests.
Category narrative87 words

The NHDPA gives consumers a right to opt out of targeted advertising and sale of personal data, and requires controllers to provide an opt-out submission process; consumers may designate a third party or use an opt-out preference signal (a universal opt-out mechanism). Universal opt-out mechanism (UOOM)/Global Privacy Control-style signal support is already in effect in New Hampshire as of January 1 alongside California, Colorado, Connecticut, Montana, Nebraska and Texas. No NH-specific dark-patterns prohibition, clean-room/data-collaboration-room rule, or direct-marketing suppression-list rule distinct from the general opt-out framework was identified.

Sources and claims (5)
  1. ConfirmedNH Department of JusticeControllers may not engage in targeted advertising or selling personal data for consumers aged 13 to under 16 without consent.observed
  2. ConfirmedNH Department of JusticeA consumer can designate a third party to opt out on their behalf and can use an opt-out preference signal to exercise sale/targeted-advertising opt-out rights.observed
  3. ConfirmedIAPPUniversal opt-out mechanism (UOOM) requirements are already in effect in New Hampshire, alongside California, Colorado, Connecticut, Montana, Nebraska and Texas, effective January 1.observed
  4. ConfirmedNH Department of JusticeConsumers have the right to opt out of the processing of personal data for purposes of targeted advertising under RSA 507-H:4, I.observed
  5. ConfirmedNH Department of JusticeA consumer can opt out of the sale of personal data to third parties, and the controller must provide a process for submitting such opt-out requests.observed

#

Profiling opt-out and DPIA trigger are confirmed; biometric/genetic specificity, ADM transparency/explanation rights, and surveillance carve-outs are unconfirmed.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H)
Traffic-light rationale — AmberProfiling opt-out and DPIA trigger are confirmed; biometric/genetic specificity, ADM transparency/explanation rights, and surveillance carve-outs are unconfirmed.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.

Claims (1):

  • Consumers may opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer, under RSA 507-H:4, I.

Automated Decision Making TransparencyAmber

No explicit ADM-explanation or transparency-notice right beyond the opt-out mechanism was identified in sources searched.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Ai Risk AssessmentsAmber

The NHDPA's data protection assessment requirement for certain profiling functions as a de facto AI/ADM risk-assessment trigger, though it is not styled as an AI-specific regime.

Claims (1):

  • Processing for purposes of certain types of profiling is treated as heightened-risk processing under RSA 507-H:8, I(c), triggering the controller's data protection assessment duty.

Biometric RegimeRed

No distinct biometric-data regime (facial recognition, fingerprint, gait) beyond general sensitive-data treatment was confirmed from sources reviewed.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Genetic DataRed

No distinct genetic-data regime beyond general sensitive-data treatment was confirmed from sources reviewed.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

State Surveillance CarveoutsRed

No state-surveillance/national-security carve-out provision was identified in sources searched.

Absence provenance: not recorded. Searched: doj.nh.gov.

Category narrative59 words

The NHDPA provides an Article-22-style opt-out (rather than a full ADM-transparency/explanation right) for profiling in furtherance of solely automated decisions producing legal or similarly significant effects, and requires a documented data protection assessment for such profiling. Biometric and genetic-data-specific statutory detail beyond the general sensitive-data definition, an AI-specific risk-assessment regime, and state-surveillance carve-outs were not confirmed in sources searched.

Sources and claims (2)
  1. ConfirmedNH Department of JusticeConsumers may opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer, under RSA 507-H:4, I.observed
  2. ConfirmedNH Department of JusticeProcessing for purposes of certain types of profiling is treated as heightened-risk processing under RSA 507-H:8, I(c), triggering the controller's data protection assessment duty.observed

#

Children's consent thresholds and guardian/conservator representation rights are directly confirmed from AG guidance sources.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H)
Traffic-light rationale — GreenChildren's consent thresholds and guardian/conservator representation rights are directly confirmed from AG guidance sources.

Sub-modules (5)

Age VerificationAmber

The NHDPA distinguishes 'known child' (under 13) status for consent purposes and applies heightened consent requirements for the 13-to-under-16 age band for targeted advertising/sale, implying an age-awareness rather than formal age-verification obligation.

Claims (1):

  • The NHDPA applies a 'known child' consent standard for children under 13 and a heightened consent requirement for targeted advertising/sale for consumers aged 13 to under 16.

Minor Profiling BansGreen

Controllers may not process sensitive data concerning a known child without consent, and may not engage in targeted advertising or sale of personal data for consumers aged 13 to under 16 without consent.

Claims (1):

  • Controllers may not process sensitive data concerning a known child without consent, and may not engage in targeted advertising or selling personal data for subjects aged 13 to under 16 without consent.

Education SettingsAmber

Education-sector data protection is addressed through the general FERPA exemption from NHDPA scope rather than a bespoke education-setting clause.

Claims (1):

  • Personal data regulated by the Family Educational Rights and Privacy Act (20 U.S.C.) is exempted from NHDPA coverage under RSA 507-H:3, II.

Dependent AdultsGreen

In the case of processing personal data concerning a consumer subject to a guardianship, conservatorship, or other protective arrangement, the guardian or conservator may exercise consumer rights on the consumer's behalf.

Claims (1):

  • In the case of processing personal data concerning a consumer subject to a guardianship, conservatorship, or other protective arrangement, the guardian or conservator may exercise consumer rights on that consumer's behalf.
Category narrative81 words

The NHDPA requires opt-in consent for processing personal data of a known child under 13 for sensitive-data purposes, and bars targeted advertising or sale of personal data for consumers aged 13 to under 16 without consent. Parents/legal guardians may exercise consumer rights on behalf of a known child, and guardians/conservators may exercise rights on behalf of consumers under a guardianship, conservatorship, or other protective arrangement. Education-setting-specific rules are addressed via the general FERPA exemption rather than a bespoke NHDPA education-sector clause.

Sources and claims (4)
  1. ConfirmedNH Department of JusticeThe NHDPA applies a 'known child' consent standard for children under 13 and a heightened consent requirement for targeted advertising/sale for consumers aged 13 to under 16.observed
  2. ConfirmedNH Department of JusticeIn the case of processing personal data of a known child, the parent or legal guardian may exercise NHDPA consumer rights on the child's behalf.observed
  3. ConfirmedNH Department of JusticeControllers may not process sensitive data concerning a known child without consent, and may not engage in targeted advertising or selling personal data for subjects aged 13 to under 16 without consent.observed
  4. ConfirmedNH Department of JusticeIn the case of processing personal data concerning a consumer subject to a guardianship, conservatorship, or other protective arrangement, the guardian or conservator may exercise consumer rights on that consumer's behalf.observed

#

Penalty levels, cure-period mechanics, and recent enforcement activity are directly confirmed from AG and IAPP sources; the precise date of the cure-period sunset to AG discretion needs primary-statute confirmation.

Primary frameworkNew Hampshire Data Privacy Act (RSA 507-H); RSA 359-C:20 (breach notification)
Traffic-light rationale — GreenPenalty levels, cure-period mechanics, and recent enforcement activity are directly confirmed from AG and IAPP sources; the precise date of the cure-period sunset to AG discretion needs primary-statute confirmation.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AG can seek civil penalties up to $10,000 per violation and criminal penalties up to $100,000 per violation for purposeful non-compliance; the AG must generally issue a notice of violation with a 60-day cure opportunity before suing, though it is not required to do so.

Claims (3):

  • The Attorney General has the ability to seek civil penalties of up to $10,000 for each violation of the NHDPA.
  • The Attorney General can seek criminal penalties, up to $100,000 per violation, if there is sufficient evidence a business is purposely failing to comply with the NHDPA.
  • If the AG determines a cure is possible, it will issue a notice of violation with a 60-day cure period before initiating an action, though issuing this notice is discretionary, not mandatory.

Enforcement Activity IndexGreen

The Data Privacy Unit has issued several Notices of Violation during the law's initial cure period leading to corrective action without litigation, and opened multiple privacy investigations, several ongoing as of October 2025.

Claims (1):

  • The Data Privacy Unit has issued several Notices of Violation during the law's initial cure period, leading to corrective actions without litigation, and has opened multiple privacy investigations, several of which remain ongoing.

Regulator Funding And CapacityGreen

The Data Privacy Unit is now fully staffed with an Assistant Attorney General and an Investigative Paralegal; the legislature's budget process allotted the Consumer Protection division additional settlement-fund resources (an attorney, paralegal, and investigator) specifically to support enforcement.

Claims (2):

  • The Data Privacy Unit, now fully staffed, includes an Assistant Attorney General and an Investigative Paralegal.
  • As part of the state budget process, the Senate added resources to the Department of Justice's Consumer Protection and Antitrust Bureau, allotting an additional $1 million in settlement funds to pay for an attorney, paralegal, and investigator dedicated to privacy enforcement.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to NHDPA claims was identified; the statute channels enforcement exclusively through the AG.

Absence provenance: not recorded. Searched: doj.nh.gov NHDPA FAQ PDF.

Private Right Of ActionAmber

The NHDPA (RSA 507-H:11, IV) does not provide a private right of action, consistent with most state comprehensive privacy laws; however, the separate, older breach-notification statute (RSA 359-C:20) does carry a private right of action alongside AG administrative enforcement.

Claims (2):

  • The NHDPA does not provide for a private right of action, per RSA 507-H:11, IV.
  • Unlike the NHDPA, the separate RSA 359-C:20 security-breach-notification statute provides private individuals with a private right of action, in addition to AG administrative enforcement.

Recent Developments 180DAmber

New Hampshire joined a bipartisan multistate consortium of privacy regulators to coordinate enforcement and share expertise while retaining independent case authority, announced in the roughly 180-day recent-developments window (article dated October 8, 2025); the NHDPA's 60-day cure period was designed to sunset to AG discretion in 2026, a transition relevant to the current run date of August 2026.

Claims (2):

  • New Hampshire joined a bipartisan consortium of privacy regulators to collaborate on data privacy enforcement, coordinating with other state AG offices with similar privacy laws while retaining independent authority over its own cases and consumer data.
  • The NHDPA's 60-day cure period was designed, as a legislative compromise, to sunset to attorney-general discretion in 2026.
Category narrative128 words

The AG holds exclusive NHDPA enforcement authority with civil penalties up to $10,000 per violation and criminal penalties up to $100,000 per violation for purposeful non-compliance; the NHDPA itself carries no private right of action. A 60-day cure period currently applies before the AG may bring an action, though this was designed to sunset to AG discretion in 2026 per the enacting legislature's compromise. The Data Privacy Unit is now fully staffed (an Assistant AG and an investigative paralegal) and has already issued Notices of Violation during the cure period, opened multiple ongoing investigations, and joined a multistate bipartisan consortium of privacy regulators for enforcement coordination. Separately, the older breach-notification statute (RSA 359-C:20) does carry a private right of action, an important contrast to the NHDPA's AG-exclusive model.

Sources and claims (10)
  1. ConfirmedNH Department of JusticeThe Attorney General has the ability to seek civil penalties of up to $10,000 for each violation of the NHDPA.observed
  2. ConfirmedNH Department of JusticeThe Attorney General can seek criminal penalties, up to $100,000 per violation, if there is sufficient evidence a business is purposely failing to comply with the NHDPA.observed
  3. ConfirmedNH Department of JusticeIf the AG determines a cure is possible, it will issue a notice of violation with a 60-day cure period before initiating an action, though issuing this notice is discretionary, not mandatory.observed
  4. ConfirmedNH Department of JusticeThe Data Privacy Unit has issued several Notices of Violation during the law's initial cure period, leading to corrective actions without litigation, and has opened multiple privacy investigations, several of which remain ongoing.observed
  5. ConfirmedNH Department of JusticeThe Data Privacy Unit, now fully staffed, includes an Assistant Attorney General and an Investigative Paralegal.observed
  6. ProbableIAPPAs part of the state budget process, the Senate added resources to the Department of Justice's Consumer Protection and Antitrust Bureau, allotting an additional $1 million in settlement funds to pay for an attorney, paralegal, and investigator dedicated to privacy enforcement.observed
  7. ConfirmedNH Department of JusticeThe NHDPA does not provide for a private right of action, per RSA 507-H:11, IV.observed
  8. ConfirmedNH Department of JusticeUnlike the NHDPA, the separate RSA 359-C:20 security-breach-notification statute provides private individuals with a private right of action, in addition to AG administrative enforcement.observed
  9. ConfirmedNH Department of JusticeNew Hampshire joined a bipartisan consortium of privacy regulators to collaborate on data privacy enforcement, coordinating with other state AG offices with similar privacy laws while retaining independent authority over its own cases and consumer data.observed
  10. UncertainIAPPThe NHDPA's 60-day cure period was designed, as a legislative compromise, to sunset to attorney-general discretion in 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – New Hampshire
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 52 claim(s), 11 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1 coverage (NH DOJ primary sources) for regulator_and_framework, data_subject_rights, controller_processor_duties (DPIA/security/breach), adtech_and_commercial_privacy (opt-out/UOOM), children_and_vulnerable_groups, and enforcement_and_redress. Sectoral_watch relies on a mix of T1 (statutory exemption citations) and T3 (peer-law inference for GLBA/insurance/credit-scoring). cross_border_and_adequacy is a confirmed structural gap (no T1/T2/T3/T4 source describes a transfer regime because none exists under RSA 507-H) and is emitted red with explicit absent_field_provenance. algorithmic_biometric_and_surveillance_governance and lawful_processing_and_special_data's pseudonymisation sub-module rely partly on T3 inference where the NHDPA text did not surface biometric/genetic/anonymisation-specific clauses in the excerpts retrieved. DPO requirements, ROPA specifics, retention/disposal, dark patterns, and clean-room provisions are emitted as explicit gaps with absent_field_provenance rather than fabricated.

Unresolved questions (5):

  • Has the NHDPA's mandatory 60-day cure period actually sunset to AG discretion in 2026 per the original legislative design, and if so on what exact date?
  • Does RSA 507-H contain an explicit GLBA exemption analogous to peer state statutes, or does financial-sector data fall outside scope solely via the Farm Credit Act citation?
  • Is House Bill 195 (introduced January 8, 2025, amending the definition of 'personal information') still pending, enacted, or abandoned as of the run date?
  • Does the NHDPA contain an explicit biometric or genetic data sub-category within its sensitive-data definition beyond what was surfaced in the FAQ excerpts?
  • Is there a codified pseudonymisation/de-identification safe-harbour standard (e.g., a defined de-identification process) within RSA 507-H beyond the bare exclusion of 'de-identified data' from the personal-data definition?

Escalate to primary-source review: yes