Back to the hub

Does New Hampshire's Data Privacy Act apply to your business?

New Hampshire's Data Privacy Act, effective January 1, 2025, applies to businesses operating in New Hampshire or targeting its residents that, in a one-year period, controlled or processed personal data of at least 35,000 unique consumers, or 10,000 consumers while deriving more than 25 percent of gross revenue from selling data.

Applies to: Businesses that conduct business in New Hampshire or target its residents and meet the 35,000-consumer threshold or the 10,000-consumer plus over-25-percent-data-sale threshold.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

New Hampshire's Data Privacy Act has been in force since January 1, 2025, and it belongs to the lower-threshold group of state privacy laws. If you only track the 100,000-consumer states, New Hampshire is a common blind spot: its entry point is much lower, so a mid-sized business that stays under Virginia's line can still be covered here. The test itself is short, which makes it easy to check once you have your New Hampshire numbers.

Who the New Hampshire Data Privacy Act covers

Under RSA 507-H:2, the chapter applies to persons that conduct business in New Hampshire, or produce products or services targeted to New Hampshire residents, and that during a one-year period controlled or processed the personal data of at least 35,000 unique consumers, excluding personal data used solely to complete a payment transaction, or at least 10,000 unique consumers while deriving more than 25 percent of gross revenue from the sale of personal data. Only New Hampshire residents acting in a personal capacity count toward either figure.

The 25 percent branch is the detail to watch

Most lower-threshold states pair a 10,000-consumer branch with a 20 percent data-sale revenue test. New Hampshire sets that figure at more than 25 percent instead. The difference is small but real: if selling data is a meaningful but not dominant part of your income, the exact percentage decides whether the second branch catches you. Read the number in the statute rather than assuming it matches a neighboring state.

How New Hampshire compares

The 35,000-consumer entry point lines New Hampshire up with the Connecticut Data Privacy Act, Delaware's Personal Data Privacy Act, and the Rhode Island Data Transparency and Privacy Protection Act, though each sets its own data-sale branch. Connecticut has since gone further and added triggers that ignore volume entirely. Our privacy thresholds by state table and the US state privacy laws hub show how the states line up so you can check them together rather than one at a time.

Next step

Because New Hampshire uses a low consumer count and a slightly different data-sale percentage, it is easy to be covered here while assuming you are too small. The free 2-minute Obligation Scan checks the RSA 507-H:2 test against your business and lists the notice, consent, and opt-out duties that follow, so you can act on the law rather than guess at the threshold.

Compliance checklist

  • Count the New Hampshire consumers whose personal data you controlled or processed over a one-year period, excluding payment-only data, and check whether you reach 35,000.
  • If under 35,000, check the second branch: 10,000 consumers plus more than 25 percent of gross revenue from selling personal data.
  • Confirm you conduct business in New Hampshire or target its residents, and review the RSA 507-H:3 exclusions.
  • If covered, publish a clear privacy notice and honor rights to access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, and profiling.
  • Obtain opt-in consent before processing sensitive data, and run data protection assessments for high-risk processing.

Sources

Last verified: 2026-08-07

Informational, not legal advice.