New Hampshire
Privacy Laws
Overview
BREACH NOTIFICATION – Mandated Timeframe
As soon as possible
FINES & PENALTIES – Violations
Up to triple damages
Regulation Levels
-
Breach Reporting
-
Consumer Notification
-
Vendor Management
-
Vendor Contract Required
PRIVACY AND SECURITY LAWS
Laws related to personal information and privacy and security.
Breach Reporting
Required
Vendor Obligations
Required
Consumer Notification
Required
Vendor Contracts
Not Required
Vendor Notification
Required
Privacy Program
Not Required
QUICK FACTS
New Hampshire Privacy Law Information
If any New Hampshire residents are affected by a breach, the breached Organization must give notice to each affected individual and the Attorney General as as soon as possible. Breach notifications to the Attorney General and affected NH residents must include specific information and may only be delivered by specific means. If an Organization is required to notify more than 1,000 consumers of a breach of security, the Organization must notify all consumer reporting agencies without unreasonable delay. The Organization will be responsible to complete any required regulatory reporting and consumer notifications.
If a breach affects residents of other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
Vendors must cooperate with the Organizations to provide all necessary information regarding a breach incident and any remediation taken relating to an incident. Vendors must notify Organizations immediately after discovery of a breach or suspected breach.
New Hampshire passed the Insurance Data Security Law, which includes requirements for insurance licensees to protect personal information and investigate and respond to breaches of security. Effective January 1, 2020, licensees must comply with the breach notification requirements, including Commissioner notification within 3 business days. Sector-specific laws (health, education) provide for an individuals right to access their personal information. Entities handling personal health information and student data must comply with additional protection and disclosure requirements.
New Hampshire Statutes and Laws
Health Data Collection and Availability of Data
Data Inventory and Policies Publication
Limits on Disclosure of Information
Student Privacy
Student Online Personal Information
Destruction of records
Medical records, patient information
Right to Privacy
Insurance data security law
DISCLAIMER
The information provided is not legal guidance or recommendations and are for informational purposes only.