Join our Newsletter — 33% off our NHI Course

How should organisations determine whether New Hampshire privacy law applies to their data processing activities?

Organisations should first map whether they do business in New Hampshire or target New Hampshire residents, then test the law’s threshold conditions. The key triggers are controlling or processing 35,000 consumers’ personal data, or 10,000 consumers if more than 25% of revenue comes from selling personal data. Exemptions for nonprofits, higher education, HIPAA, and GLBA covered entities should be checked separately.

How to test whether the New Hampshire law reaches your processing

The practical starting point is jurisdiction and scope. Organisations should ask whether they do business in New Hampshire or intentionally target New Hampshire residents, then confirm whether the processing crosses the law’s quantitative threshold. That means counting affected consumers and checking whether personal data sales create the lower threshold that the statute uses for businesses with significant revenue from selling personal data.

That threshold test matters because New Hampshire privacy laws are not usually triggered by a single data event; they are triggered by a combination of market presence, resident reach, and processing volume. A company can be active in the state and still fall outside the law if it does not meet the statutory volume or revenue criteria.

One useful way to approach the analysis is to separate the question into three gates: territorial reach, consumer count, and revenue dependence on personal data sales. If any gate fails, the law may not apply. If all applicable gates are met, the organisation should treat the statute as in scope and move to the exemption analysis.

Which data and entity exclusions should be checked next

Once scope appears to be met, the next question is whether a statutory exemption removes the activity from coverage. The most common exclusions to verify are nonprofit entities, higher education institutions, and entities already covered by HIPAA or GLBA. Those carve-outs can be outcome-determinative, so they should be checked before investing effort in a full compliance gap assessment.

Exemptions are often misunderstood because they apply to the entity or the regulated activity, not necessarily to every item of data a business touches. That means an organisation should not assume it is exempt just because part of its business operates under a regulated regime. The analysis should be tied to the legal entity and the processing activity being evaluated.

For mixed organisations, the safest interpretation is to map each processing stream to the business unit, legal entity, and data category involved. That is especially important where one part of the organisation may rely on a sector-specific exemption while another part handles consumer data that is not protected by that exemption.

Why a threshold-based privacy test can still be operationally tricky

Threshold-based privacy laws look simple on paper, but they can become messy in practice because organisations often maintain fragmented records of where consumers are located, how many records are processed, and whether revenue is attributable to data sales. If those inputs are not reliable, the legal conclusion can be wrong even when the rule is straightforward.

That is why the determination should be evidence-led, not assumption-led. Legal, privacy, revenue, and data governance teams should align on the same count methodology and the same definition of “selling personal data” before concluding that the law does or does not apply. Otherwise, the organisation may undercount its exposure or overlook a qualifying business line.

The operational implication is that scope analysis should be repeatable. A one-time memo is rarely enough if the company changes product lines, monetisation models, or customer geography. Reassessing the triggers on a regular cadence is part of keeping the scope determination credible.

Risk and Threat Considerations

Misclassifying scope can create compliance exposure in both directions: overcalling applicability can waste effort, but undercalling it can leave consumer rights, notice, and governance obligations unaddressed. The main failure mode is incomplete fact gathering, especially where resident targeting, consumer counts, or revenue from data sales are spread across different systems.

Failure mechanism: Organisations rely on fragmented business data, incomplete customer-location logic, or an outdated exemption analysis, then apply the wrong statutory test to the wrong processing population.

Impact: The result can be a false sense of non-applicability, missed legal obligations, inconsistent privacy notices, and avoidable remediation work once the gap is discovered.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022, GDPR and SOC 2 (AICPA) define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Scope testing is a governance and risk decision for privacy compliance.
Recommendation — Define a repeatable scope-review process for privacy obligations and revalidate it when business facts change.
ISO/IEC 27001:2022 A.5.31 — Legal, statutory, regulatory and contractual requirements The question is about determining applicability of a state privacy law.
Recommendation — Maintain a current inventory of applicable legal obligations and review them against processing changes.
GDPR Art. 30 — Records of processing activities A documented processing inventory is needed to test scope, thresholds, and exemptions reliably.
Recommendation — Keep processing records accurate enough to support jurisdiction and exemption analysis.
SOC 2 (AICPA) CC2.2 — Information and communication The scope decision depends on reliable communication of business facts across teams.
Recommendation — Ensure privacy, legal, finance, and operations share the data needed for a defensible applicability decision.

Practitioner Guidance

What to verify: Confirm that the scope decision is supported by source data for resident targeting, consumer counts, and any revenue tied to selling personal data. If those inputs cannot be evidenced, treat the conclusion as provisional rather than settled.

Decision rule: If the business model or customer base changes frequently, build a recurring review into the privacy program instead of relying on a static applicability memo. If the model is stable, document the basis for the threshold calculation and the exemption analysis so the conclusion can be defended later.

Practitioner takeaway: The right question is not simply whether the company “does business” in the state, but whether the organisation can prove how the law’s thresholds and exemptions were tested against current facts.