New Hampshire Data Privacy Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Rights
Honour consumer rights per NH RSA 507-H:6 including: (a) right to confirm processing and access personal data, (b) right to correct inaccuracies, (c) right to delete, (d) right to data portability, (e) right to appeal denial within 60 days. Respond within 45 days (extendable by 45 days with notice). Recognise authorised agents with reasonable verification. Apply to all consumer requests including requests through Universal Opt-Out Mechanism (UOOM) - NH DPA REQUIRES UOOM honour by 1 January 2025.
- Consumer rights portal
- Verification procedures
- 45-day response tracking
- 60-day appeal handling
- Authorised agent register
- UOOM honour evidence (mandatory)
- Late responses
- No appeal process
- Ignoring UOOM
- No verification procedures
Enforcement and Compliance
Acknowledge exclusive enforcement by New Hampshire Attorney General John Formella (in office since January 2021). No private right of action. Civil penalty up to USD 10,000 per violation under NH Consumer Protection Act (RSA 358-A). PERMANENT 60-day cure period (NH joins permanent cure jurisdictions Iowa + Indiana + Kentucky + Maryland + Nebraska + Tennessee + Texas + Maine - one of few not sunsetting). Effective date: 1 January 2025. Maintain compliance documentation including AG notification readiness + cure response procedures + executive accountability.
- AG notification readiness procedure
- 60-day cure response template
- Executive accountability matrix
- Compliance attestation
- Annual compliance review
- Penalty exposure analysis
- No AG notification readiness
- No cure response template
- No executive accountability
- Stale compliance review
Opt-Out Rights
Provide consumer opt-out rights for: (a) targeted advertising, (b) sale of personal data, (c) profiling that produces legal or similarly significant effects. NH DPA REQUIRES recognition of Universal Opt-Out Mechanisms (UOOM) including Global Privacy Control (GPC) signals from 1 January 2025 (third state after California + Colorado + Connecticut). Maintain prominent clear and conspicuous link to privacy choices page. Process opt-out within 15 days. Apply to authenticated consumer requests + browser/device signals + authorised agent submissions.
- Privacy choices page
- UOOM honour configuration (GPC + ADPPA signals)
- 15-day processing tracking
- Browser signal detection
- Authorised agent opt-out
- Cross-domain implementation
- No UOOM honour
- Late opt-out processing
- Missing GPC detection
- No browser signal detection
Privacy Notice and Data Hygiene
Provide a reasonably accessible + clear + meaningful privacy notice per NH RSA 507-H:6 including: (1) categories of personal data processed, (2) purposes of processing, (3) how consumers exercise rights and appeal, (4) categories of personal data shared with third parties, (5) categories of third parties, (6) clear and conspicuous opt-out method. Apply data minimisation - process only personal data adequate + relevant + reasonably necessary in relation to disclosed purposes. Apply purpose limitation - do not process personal data for incompatible purposes without consent.
- Privacy Notice covering 6 mandatory elements
- Annual notice review
- Data inventory tied to purposes
- Minimisation justification
- Purpose change consent
- Notice version history
- Missing notice elements
- Stale notice
- No minimisation justification
- Purpose creep
Risk and Vendor Management
Conduct and document Data Protection Assessments (DPAs) per NH RSA 507-H:8 for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts per NH RSA 507-H:7 with required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).
- DPA register with assessments
- Risk vs benefit analysis
- Processor contract template with NH-H:7 clauses
- Subprocessor list with consent
- Annual processor audit
- No DPA register
- Missing risk analysis
- Processor contracts missing NH-H:7 clauses
- No subprocessor visibility
Scope and Applicability
Determine applicability of the New Hampshire Data Privacy Act (NH DPA) per NH RSA 507-H + Senate Bill 255-A enacted 6 March 2024 + effective 1 January 2025. NH DPA applies to controllers conducting business in NH or targeting NH residents that: (a) controlled or processed personal data of 35,000+ NH residents (excluding payment transactions), OR (b) controlled or processed personal data of 10,000+ NH residents AND derived 25%+ revenue from sale of personal data. Document exemptions: GLBA financial institutions + HIPAA covered entities + FERPA institutions + nonprofits + state/local governments + air carriers + B2B data limited exemption + small businesses (limited carve-out).
- Applicability memorandum
- Consumer count by jurisdiction
- Revenue analysis
- Exemption documentation
- Annual applicability review
- NH business registration
- No applicability memo
- Stale consumer counts
- Missing exemption documentation
- No annual review
Security and Breach
Establish + implement + maintain reasonable administrative + technical + physical data security practices to protect the confidentiality + integrity + accessibility of personal data appropriate to the volume + nature of the personal data. Align with NIST Cybersecurity Framework or equivalent risk-based programme. Comply with New Hampshire breach notification law (RSA 359-C:19 to 359-C:22) requiring notification to AG and affected residents without unreasonable delay (typically 60 days). Maintain incident response plan covering preparation + detection + containment + eradication + recovery + lessons learned.
- Written security programme
- NIST CSF alignment evidence
- Incident response plan
- Annual tabletop exercise
- NH breach notification procedures
- RSA 359-C compliance
- No written programme
- Missing NIST alignment
- No incident response plan
- Inadequate breach procedures
Sensitive Data and Minors
Obtain affirmative opt-in consent before processing sensitive data including racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic or biometric data processed for unique identification + precise geolocation + data of known children under 13. Process children under 13 per COPPA + parental consent. For known minors aged 13 to under 16 obtain opt-in consent for sale of personal data + targeted advertising (similar to Connecticut/Maryland teen protections).
- Sensitive data inventory
- Opt-in consent records
- Age verification mechanism
- COPPA compliance attestation
- Teen opt-in tracking (13-15)
- Parental consent (under 13)
- No sensitive data inventory
- Missing consent records
- No teen opt-in
- No age verification
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the New Hampshire Data Privacy Act framework page.