Skip to main content

Data Protection Map

New Hampshire

Data Breach Requirements: N.H. RSA § 359-C:19 et seq.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

The term “personal information” means an individual’s first name or initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:
(1) Social Security number.
(2) Driver’s license number or other government identification number.
(3) Account number, credit card number, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.


Security Breach Definition

The term “security breach” unauthorized acquisition of computerized data that compromises the security or confidentiality of personal information maintained by a person doing business in this state.


Good Faith Exception

Good faith acquisition of personal information by an employee or agent of a person for the purposes of the person’s business shall not be considered a security breach, provided that the personal information is not used or subject to further unauthorized disclosure.


Risk of Harm Analysis

Any person doing business in this state who owns or licenses computerized data that includes personal information shall, when it becomes aware of a security breach, promptly determine the likelihood that the information has been or will be misused. If the determination is that misuse of the information has occurred or is reasonably likely to occur, or if a determination cannot be made, the person shall notify the affected individuals.


Notification Timeline

A breach notification shall be made as soon as possible or as quickly as possible.


Security and Investigation Exceptions

A breach notification may be delayed if a law enforcement agency or national or homeland security agency determines that the notification will impede a criminal investigation or jeopardize national or homeland security.


Notification Content Requirements

A breach notice shall include at a minimum:
(a) A description of the incident in general terms.
(b) The approximate date of breach.
(c) The type of personal information obtained as a result of the security breach.
(d) The telephonic contact information of the person subject to this section.


Delivery Methods

A breach notice may be provided by one of the following methods:
(a) Written notice.
(b) Electronic notice, if the agency or business’ primary means of communication with affected individuals is by electronic means.
(c) Telephonic notice, provided that a log of each such notification is kept by the person or business who notifies affected persons.
(d) Substitute notice, if the person demonstrates that the cost of providing notice would exceed $5,000, that the affected class of subject individuals to be notified exceeds 1,000, or the person does not have sufficient contact information or consent to provide notice pursuant to subparagraphs I(a)-I(c).
(e) Notice pursuant to the person’s internal notification procedures maintained as part of an information security policy for the treatment of personal information.


Substitute Notice

Substitute notice shall consist of all of the following:
(1) Email notice when the person has an email address for the affected individuals.
(2) Conspicuous posting of the notice on the person’s business website, if the person maintains one.
(3) Notification to major statewide media.


Notice to Government Agencies

Any person engaged in trade or commerce that is subject to RSA 358-A:3, Section I, shall also notify the regulator that has primary regulatory authority over such trade or commerce. All other persons shall notify the New Hampshire attorney general’s office as soon as possible or as quickly as possible. The notice shall include the anticipated date of the notice to the individuals and the approximate number of individuals in this state who will be notified. The person is not required to provide to any regulator or the New Hampshire attorney general’s office the names of the individuals entitled to receive the notice or any personal information relating to them.


Consumer Reporting Agencies

If a person is required to notify more than 1,000 consumers of a breach, the person shall also notify, without unreasonable delay, all consumer reporting agencies of the anticipated date of the notification to the consumers, the approximate number of consumers who will be notified, and the content of the notice. Nothing in this paragraph shall be construed to require the person to provide to any consumer reporting agency the names of the consumers entitled to receive the notice or any personal information relating to them. This requirement does not apply to a person who is subject to Title V of the Gramm-Leach-Bliley Act.


Preemption and Compliance

Any person engaged in trade or commerce that is subject to RSA 358-A:3 and who maintains procedures for security breach notification pursuant to the laws, rules, regulations, guidances, or guidelines issued by a state or federal regulator shall be deemed to be in compliance with this subdivision if he or she acts in accordance with such laws, rules, regulations, guidances, or guidelines.


Data Processor Obligations

Any person or business that maintains computerized data that includes personal information that the person or business does not own shall notify and cooperate with the owner or licensee of the information of any breach of the security of the data immediately following discovery if the personal information was acquired by an unauthorized person. Cooperation includes sharing with the owner or licensee information relevant to the breach, except that such cooperation shall not be deemed to require the disclosure of confidential or business information or trade secrets.