Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

← All posts

US Regulations

Understanding the New Hampshire Privacy Act (NHPA)

A map of New Hampshire with a padlock shield labelled NHPA

Introduction

The New Hampshire Privacy Act (NHPA) establishes comprehensive data privacy rights for New Hampshire residents in response to growing concerns about data collection, handling, and misuse in today’s digital economy. Like similar laws enacted in Virginia and Connecticut, the NHPA fills the gap left by the absence of a comprehensive federal privacy law and aligns with modern expectations for transparency, accountability, and consumer control over personal information.

Enacted via Senate Bill 255 and effective January 1, 2025, the NHPA primarily focuses on personal or household data of New Hampshire residents, explicitly excluding employment-related and purely business-to-business data to narrow its scope. This law represents a significant step forward in protecting consumer privacy rights in the Granite State, reflecting a broader trend toward comprehensive data privacy laws across the United States.

The NHPA generally uses an “opt-out” model for most data processing activities, such as targeted advertising and the sale of personal data. However, it requires “opt-in” consent for processing particularly sensitive categories of data and data related to children under the age of 13, underscoring the law’s emphasis on protecting vulnerable populations.

Pandectes GDPR ComplianceThe most popular & reviewed GDPR app for Shopify 5/5 · 3,000+ reviews · Built for ShopifyInstall free on Shopify

Key Definitions Under the NHPA

  • Consumer: Defined as a New Hampshire resident acting in an individual or household context, excluding those acting in commercial, employment, or business roles. This distinction ensures that the NHPA protects personal privacy without unduly burdening business-to-business interactions.
  • Personal data: Any information linked to, or reasonably linkable to, an identified or identifiable individual, excluding de-identified or publicly available data. This broad definition ensures that the law covers a wide range of information that could impact consumer privacy.
  • Sensitive data: A special category of personal data that includes information about racial or ethnic origin, religious beliefs, mental or physical health, sex life, sexual orientation, citizenship, immigration status, genetic or biometric data, precise geolocation, and data collected from known children. Processing such data requires heightened protections and explicit consumer consent.

Data controllers are entities that determine the purposes and means of processing personal data. The NHPA governs how a consumer’s personal data and broader consumer data are collected, used, and disclosed by these controllers. Data processors act on behalf of controllers and process personal data according to their instructions. A processor is any person processing personal data on behalf of a controller.

Who Must Comply: Scope, Thresholds, and Exemptions

The NHPA applies to organizations that conduct business in New Hampshire or target products or services to its residents and process data from 35,000 or more unique New Hampshire consumers annually. For organizations that derive over 25% of their gross revenue from selling personal data, the threshold lowers to 10,000 consumers. Importantly, physical presence in New Hampshire is not required for the law to apply, reflecting the digital nature of modern commerce.

Certain categories of personal data processed remain exempt even when an organization otherwise falls within the NHPA’s scope. These exemptions help balance regulatory burden with privacy protection.

Exemptions include:

  • State and local government agencies
  • Nonprofit organizations
  • Higher education institutions
  • Financial institutions regulated under the Gramm-Leach-Bliley Act
  • HIPAA-covered entities, excluding health information from the NHPA’s scope
  • Data covered by federal laws such as the Family Educational Rights and Privacy Act (FERPA), the Driver’s Privacy Protection Act (DPPA), and the Fair Credit Reporting Act
  • Employment and business-to-business (B2B) data

These carve-outs ensure the NHPA complements existing federal privacy protections and avoids duplication.

A laptop on a wooden desk beside a small US flag and signed documents

A Google-Approved Consent Platform for Shopify

Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.

View the App on Shopify

Consumer Rights Under the NHPA

The NHPA empowers consumers with a range of rights designed to give them control over their personal data. These rights include:

  • The right to submit consumer rights requests to confirm whether their data is being processed and to access that data in a clear and usable format.
  • The right to correct inaccuracies in their personal data to ensure the information held by businesses is accurate and up to date.
  • The right to delete personal data provided to businesses, with some exceptions for legitimate business or legal purposes.
  • The right to obtain data portability, enabling consumers to receive a copy of their personal data in a commonly used and machine-readable format.
  • The right to opt out of the sale of personal data, targeted advertising, and certain types of profiling that produce legal or similarly significant effects.

Businesses are required to respond to consumer rights requests within 45 days, with a possible 45-day extension for complex requests. Consumers also have the right to appeal denials of their requests, ensuring accountability and transparency.

Business Obligations

Under the NHPA, data controllers must:

  • Limit data collection and processing to what is adequate, relevant, and reasonably necessary, embodying the principle of data minimization.
  • Provide clear, accessible, and comprehensive privacy notices that detail the categories of data collected, the purposes of processing, third-party disclosures, and how consumers can exercise their rights.
  • Obtain explicit consumer consent before processing sensitive data or data from known children, reflecting the law’s heightened protections for these categories.
  • Implement reasonable administrative, technical, and physical data security practices to protect personal data from unauthorized access, disclosure, alteration, or destruction.
  • Avoid discrimination or retaliation against consumers who exercise their privacy rights.

Data processors must follow documented instructions from controllers, maintain confidentiality, and assist controllers in meeting their compliance obligations.

The NHPA requires businesses to honor universal opt-out signals, such as the Global Privacy Control (GPC), for the sale of personal data and targeted advertising. This ensures consumers can exercise their opt-out rights seamlessly across multiple platforms without submitting individual requests to each business.

Consent must be obtained for sensitive data processing as part of consumer consent requirements. Consumers must be able to revoke that consent as easily as it was granted, with revocation honored within 15 days, ensuring ongoing control over their personal data.

Data Protection Assessments

To address heightened risks, businesses must conduct and document data protection impact assessments for processing activities that present a heightened risk of harm to consumers. These include targeted advertising, sale of personal data, profiling that produces legal or similarly significant effects, and processing sensitive data.

These assessments evaluate potential privacy risks and the effectiveness of mitigation measures, helping businesses implement privacy-by-design and privacy-by-default principles.

Enforcement and Penalties

The New Hampshire Attorney General has exclusive enforcement authority over the NHPA. There is no private right of action, meaning consumers cannot sue businesses directly under the law.

A 60-day cure period applies for violations identified in 2025, allowing businesses to rectify issues before enforcement actions proceed. After 2025, cure opportunities become discretionary based on factors such as the nature of the violation, size and complexity of the business, and likelihood of consumer harm.

Violations can incur civil penalties of up to $10,000 per violation. Each violation is treated as an unfair or deceptive act under New Hampshire’s consumer protection laws, emphasizing the seriousness of compliance.

Privacy Notices and Transparency Requirements

The NHPA requires businesses to provide an accessible privacy notice that is clear, conspicuous, and meaningful to consumers. This notice must include a detailed description of the categories of personal data collected, the purposes for which the data is processed, the categories of third parties with whom the data may be shared, and instructions on how consumers can exercise their rights.

Businesses must include a clear and conspicuous link to this accessible privacy notice on their websites or digital platforms, ensuring that consumers can easily find and review the information before engaging with the business.

Addressing Consumer Requests

Businesses must establish and maintain effective mechanisms to receive and address consumer requests related to their personal data. This includes providing secure and reliable methods for consumers to submit requests to access, correct, delete, or opt out of the sale or sharing of their personal data.

Controllers are required to respond to consumer requests within 45 days, with an additional 45-day extension permitted for complex or numerous requests. Failure to respond within these timeframes may result in enforcement actions.

Furthermore, the NHPA mandates that businesses provide a process for consumers to appeal denials of their requests. This appeal process must be conspicuously available and operate within a reasonable timeframe, typically 60 days for a response from the business.

A gavel and a set of scales of justice on a courtroom desk

Make Your Shopify Store GDPR & Cookie Compliant in Minutes

Start Free on Shopify

Excluding Personal Data Controlled Under Other Laws

The NHPA acknowledges that certain categories of personal data are excluded from its scope because they are governed by other federal or state laws. This includes data protected under the Family Educational Rights and Privacy Act (FERPA), medical and health information covered by HIPAA, and financial data regulated under the Gramm-Leach-Bliley Act.

By excluding personal data controlled under these specific laws, the NHPA avoids overlap and conflict with existing regulatory frameworks, allowing businesses to comply with multiple privacy requirements without redundancy.

Conclusion

Data privacy laws continue to evolve rapidly, and New Hampshire may refine the NHPA or issue additional guidance over time to address emerging technologies and privacy challenges. Legislative proposals like HB 1694-FN, which suggest broadening opt-out rights to cover nearly all purposes of processing, signal a regulatory direction toward increasing consumer control.

Businesses should:

  • Monitor updates from the New Hampshire Attorney General and the Data Privacy Unit for clarifications, enforcement guidance, or new rules.
  • Treat NHPA compliance as an ongoing process, including periodic reviews of data protection assessments, physical data security practices, administrative controls, and privacy notices.

Emerging technologies such as artificial intelligence, machine learning, advanced profiling, and new advertising models will introduce new data protection challenges under the NHPA’s profiling and high-risk processing provisions. Adopting privacy-by-design and privacy-by-default principles now reduces the cost and disruption of future regulatory changes.

Early and thoughtful compliance is more than a legal checkbox. For online merchants, SaaS providers, and businesses operating in New Hampshire or targeting its residents, it is a competitive differentiator that signals respect for your customers’ data. That kind of trust compounds over time, building stronger customer relationships and brand loyalty in an increasingly privacy-conscious market.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free