Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Age-appropriate design code
Amends the New Hampshire Privacy Act to prohibit a controller from selling a known child's personal data, including location data, to a third party for money or other value, regardless of consent, going beyond the prior opt in framework that applied only to minors 13 to 15. Passed the House 214 to 145 on February 12, 2026, passed the Senate with amendment on April 9, 2026, the House concurred on May 7, 2026, and Governor Ayotte signed it on June 19, 2026.
Note and primary source →
Bars a controller from processing personal data for targeted advertising or from selling it, without consent, where the controller has actual knowledge or willfully disregards that the consumer is at least 13 and under 16 years old, and requires a data protection assessment for any processing activity that presents a heightened risk of harm to consumers, including minors.
Note and primary source →
Breach notification
cite RSA 359-C:19-21
stage IN FORCE in force since 2007-01-01
source official New Hampshire statute text, RSA chapter 359-C, New Hampshire General Court website
A person doing business in New Hampshire that owns or licenses computerized data including personal information must, on becoming aware of a security breach, determine the likelihood of misuse and notify affected individuals and the Attorney General's office as soon as possible, with notice to consumer reporting agencies required once more than 1,000 residents are affected. "Personal information" excludes information lawfully made available to the public from government records.
The codified text's own source note dates this subdivision to 2006, 242:1, effective January 1, 2007. Unlike the comprehensive act, this statute arms an injured person with a private right of action, including treble damages for a willful or knowing violation.
What it asks of an app →
Comprehensive regime
NHDPA governs private-sector processing of New Hampshire residents' personal data. It applies to a person conducting business in New Hampshire, or producing a product or service targeted to New Hampshire residents, that in a year controlled or processed the personal data of at least 35,000 unique consumers (excluding data processed solely to complete a payment transaction), or 10,000 consumers while deriving more than 25 percent of gross revenue from the sale of personal data.
Controllers must limit collection to what is adequate, relevant, and reasonably necessary and describe their purposes in a privacy notice; processors act only on the controller's instructions and assist with rights requests, security, and breach notification.
What it asks of an app →
Data subject rights
cite RSA 507-H:4
stage IN FORCE in force since 2025-01-01
source official New Hampshire statute text, RSA chapter 507-H, New Hampshire General Court website
NHDPA gives a New Hampshire consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling with legal or similarly significant effects.
A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available if the controller informs the consumer within the initial period, and must offer an internal appeal of a denial, decided within 60 days, after which the consumer may complain to the Attorney General.
What it asks of an app →
Enforcement supervision
cite RSA 507-H:11
stage IN FORCE in force since 2025-01-01
source official New Hampshire statute text, RSA chapter 507-H, New Hampshire General Court website
The New Hampshire Attorney General has exclusive authority to enforce NHDPA. The Attorney General was required to give a controller a notice of violation and 60 days to cure through December 31, 2025, and may do so at its discretion afterward; an uncured violation is treated as an unfair trade practice under RSA 358-A, subject to a civil penalty of up to $10,000 per violation, and the chapter creates no private right of action.
What it asks of an app →
Sensitive categories
cite RSA 507-H:1, IV, XXVIII; RSA 507-H:6
stage IN FORCE in force since 2025-01-01
source official New Hampshire statute text, RSA chapter 507-H, New Hampshire General Court website
NHDPA classifies genetic or biometric data processed to uniquely identify a person, along with racial or ethnic origin, religious belief, a health condition, sexual orientation, citizenship or immigration status, a known child's data, and precise geolocation, as sensitive data requiring the consumer's opt-in consent.
"Biometric data" means data from automatic measurement of a biological characteristic, such as a fingerprint, voiceprint, or eye retina or iris, used to identify a specific individual; the definition excludes a photograph, or data from an audio or video recording, only until that data is generated to identify a specific individual, at which point the exclusion lifts and the data is biometric, and sensitive, data.
What it asks of an app →