Law note · New Hampshire

New Hampshire Data Privacy Act (NHDPA), general applicability and controller and processor duties

cite RSA 507-H:2, 507-H:6, 507-H:7, 507-H:10 stage IN FORCE in force since 2025-01-01 reviewed 2026-08-27

NHDPA governs private-sector processing of New Hampshire residents' personal data. It applies to a person conducting business in New Hampshire, or producing a product or service targeted to New Hampshire residents, that in a year controlled or processed the personal data of at least 35,000 unique consumers (excluding data processed solely to complete a payment transaction), or 10,000 consumers while deriving more than 25 percent of gross revenue from the sale of personal data.

Controllers must limit collection to what is adequate, relevant, and reasonably necessary and describe their purposes in a privacy notice; processors act only on the controller's instructions and assist with rights requests, security, and breach notification.

What it asks of an app

  • Determine whether you conduct business in New Hampshire, or produce a product or service targeted to New Hampshire residents, and controlled or processed the personal data of at least 35,000 unique consumers, or 10,000 consumers while deriving more than 25 percent of gross revenue from selling personal data, before relying on any NHDPA exemption.
  • Limit personal data collection to what is adequate, relevant, and reasonably necessary, and describe your purposes in a privacy notice.
  • Confirm a processor you use acts only on your instructions and assists with rights requests, security, and breach notification.

When LexLint raises it

Declared activities: automated_outreach, crawls_web, deploys_chatbot, processes_biometrics, processes_voice, trains_models

Primary source: official New Hampshire statute text, RSA chapter 507-H, New Hampshire General Court website

← Back to the example  ·  Lint your app →