New Hampshire’s privacy law is deliberately unoriginal, a Connecticut clone passed so New England businesses face one standard rather than three, and that is precisely its compliance meaning: no new machinery, but one more low-threshold state pulling mid-size national businesses into the strict-tier framework as of January 2025. The 35,000-consumer bar and launch-day GPC mandate do the real work.
| Law | New Hampshire Privacy Act, RSA ch. 507-H |
|---|---|
| Effective | January 1, 2025 (GPC mandate from launch) |
| Thresholds | 35,000 consumers, or 10,000 + 25% sale revenue |
| Max penalty | $10,000 per violation (RSA 358-A) |
| Regulator | NH DOJ |
| Statute | RSA ch. 507-H |
Folding New Hampshire in
Scope by data, not office locations. The unique-consumer count excludes payment-only processing but includes analytics, accounts, and marketing lists. National e-commerce and media operations should assume coverage and verify, not the reverse.
Reuse the Connecticut build. Sensitive-data consent, DSARs with appeal flows, processor contracts, data protection assessments, and GPC handling transfer without modification from a CTDPA program. Update your applicability register, notices (list New Hampshire in rights disclosures), and DSAR routing.
Watch the teen-privacy trajectory. The 13-15 consent gate is today’s floor; Connecticut’s amendments and the regional legislative pattern suggest duty-of-care expansion. Keep New Hampshire in the children’s privacy matrix review cycle.
January 2025 cohort planning. New Hampshire arrived alongside Delaware, New Jersey, Iowa, and Nebraska; the sane response is a single national baseline at the strict-tier spec, as laid out in the multi-state strategy guide and state comparison.
Confirm your notices, opt-outs, and tracker behavior in one pass with a free scan.