Skip to content

Evidence request lists

New Hampshire Data Privacy Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consumer Rights

NHPA-2
Consumer Rights - Access, Correct, Delete, Portability, Appeal

Honour consumer rights per NH RSA 507-H:6 including: (a) right to confirm processing and access personal data, (b) right to correct inaccuracies, (c) right to delete, (d) right to data portability, (e) right to appeal denial within 60 days. Respond within 45 days (extendable by 45 days with notice). Recognise authorised agents with reasonable verification. Apply to all consumer requests including requests through Universal Opt-Out Mechanism (UOOM) - NH DPA REQUIRES UOOM honour by 1 January 2025.

Artefacts an auditor will ask for
  • Consumer rights portal
  • Verification procedures
  • 45-day response tracking
  • 60-day appeal handling
  • Authorised agent register
  • UOOM honour evidence (mandatory)
Where this commonly fails
  • Late responses
  • No appeal process
  • Ignoring UOOM
  • No verification procedures

Enforcement and Compliance

NHPA-8
AG Formella Enforcement, Permanent 60-Day Cure, and Penalties

Acknowledge exclusive enforcement by New Hampshire Attorney General John Formella (in office since January 2021). No private right of action. Civil penalty up to USD 10,000 per violation under NH Consumer Protection Act (RSA 358-A). PERMANENT 60-day cure period (NH joins permanent cure jurisdictions Iowa + Indiana + Kentucky + Maryland + Nebraska + Tennessee + Texas + Maine - one of few not sunsetting). Effective date: 1 January 2025. Maintain compliance documentation including AG notification readiness + cure response procedures + executive accountability.

Artefacts an auditor will ask for
  • AG notification readiness procedure
  • 60-day cure response template
  • Executive accountability matrix
  • Compliance attestation
  • Annual compliance review
  • Penalty exposure analysis
Where this commonly fails
  • No AG notification readiness
  • No cure response template
  • No executive accountability
  • Stale compliance review

Opt-Out Rights

NHPA-3
Opt-Out Rights, UOOM, and Universal Opt-Out Mechanism

Provide consumer opt-out rights for: (a) targeted advertising, (b) sale of personal data, (c) profiling that produces legal or similarly significant effects. NH DPA REQUIRES recognition of Universal Opt-Out Mechanisms (UOOM) including Global Privacy Control (GPC) signals from 1 January 2025 (third state after California + Colorado + Connecticut). Maintain prominent clear and conspicuous link to privacy choices page. Process opt-out within 15 days. Apply to authenticated consumer requests + browser/device signals + authorised agent submissions.

Artefacts an auditor will ask for
  • Privacy choices page
  • UOOM honour configuration (GPC + ADPPA signals)
  • 15-day processing tracking
  • Browser signal detection
  • Authorised agent opt-out
  • Cross-domain implementation
Where this commonly fails
  • No UOOM honour
  • Late opt-out processing
  • Missing GPC detection
  • No browser signal detection

Privacy Notice and Data Hygiene

NHPA-5
Privacy Notice, Data Minimisation, and Purpose Limitation

Provide a reasonably accessible + clear + meaningful privacy notice per NH RSA 507-H:6 including: (1) categories of personal data processed, (2) purposes of processing, (3) how consumers exercise rights and appeal, (4) categories of personal data shared with third parties, (5) categories of third parties, (6) clear and conspicuous opt-out method. Apply data minimisation - process only personal data adequate + relevant + reasonably necessary in relation to disclosed purposes. Apply purpose limitation - do not process personal data for incompatible purposes without consent.

Artefacts an auditor will ask for
  • Privacy Notice covering 6 mandatory elements
  • Annual notice review
  • Data inventory tied to purposes
  • Minimisation justification
  • Purpose change consent
  • Notice version history
Where this commonly fails
  • Missing notice elements
  • Stale notice
  • No minimisation justification
  • Purpose creep

Risk and Vendor Management

NHPA-7
Data Protection Assessments and Processor Contracts

Conduct and document Data Protection Assessments (DPAs) per NH RSA 507-H:8 for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts per NH RSA 507-H:7 with required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).

Artefacts an auditor will ask for
  • DPA register with assessments
  • Risk vs benefit analysis
  • Processor contract template with NH-H:7 clauses
  • Subprocessor list with consent
  • Annual processor audit
Where this commonly fails
  • No DPA register
  • Missing risk analysis
  • Processor contracts missing NH-H:7 clauses
  • No subprocessor visibility

Scope and Applicability

NHPA-1
Applicability, Thresholds, and Scope

Determine applicability of the New Hampshire Data Privacy Act (NH DPA) per NH RSA 507-H + Senate Bill 255-A enacted 6 March 2024 + effective 1 January 2025. NH DPA applies to controllers conducting business in NH or targeting NH residents that: (a) controlled or processed personal data of 35,000+ NH residents (excluding payment transactions), OR (b) controlled or processed personal data of 10,000+ NH residents AND derived 25%+ revenue from sale of personal data. Document exemptions: GLBA financial institutions + HIPAA covered entities + FERPA institutions + nonprofits + state/local governments + air carriers + B2B data limited exemption + small businesses (limited carve-out).

Artefacts an auditor will ask for
  • Applicability memorandum
  • Consumer count by jurisdiction
  • Revenue analysis
  • Exemption documentation
  • Annual applicability review
  • NH business registration
Where this commonly fails
  • No applicability memo
  • Stale consumer counts
  • Missing exemption documentation
  • No annual review

Security and Breach

NHPA-6
Reasonable Data Security and Breach Response

Establish + implement + maintain reasonable administrative + technical + physical data security practices to protect the confidentiality + integrity + accessibility of personal data appropriate to the volume + nature of the personal data. Align with NIST Cybersecurity Framework or equivalent risk-based programme. Comply with New Hampshire breach notification law (RSA 359-C:19 to 359-C:22) requiring notification to AG and affected residents without unreasonable delay (typically 60 days). Maintain incident response plan covering preparation + detection + containment + eradication + recovery + lessons learned.

Artefacts an auditor will ask for
  • Written security programme
  • NIST CSF alignment evidence
  • Incident response plan
  • Annual tabletop exercise
  • NH breach notification procedures
  • RSA 359-C compliance
Where this commonly fails
  • No written programme
  • Missing NIST alignment
  • No incident response plan
  • Inadequate breach procedures

Sensitive Data and Minors

NHPA-4
Sensitive Data, Children, and Minors 13-16 Opt-In Consent

Obtain affirmative opt-in consent before processing sensitive data including racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic or biometric data processed for unique identification + precise geolocation + data of known children under 13. Process children under 13 per COPPA + parental consent. For known minors aged 13 to under 16 obtain opt-in consent for sale of personal data + targeted advertising (similar to Connecticut/Maryland teen protections).

Artefacts an auditor will ask for
  • Sensitive data inventory
  • Opt-in consent records
  • Age verification mechanism
  • COPPA compliance attestation
  • Teen opt-in tracking (13-15)
  • Parental consent (under 13)
Where this commonly fails
  • No sensitive data inventory
  • Missing consent records
  • No teen opt-in
  • No age verification
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the New Hampshire Data Privacy Act framework page.