What NHPA says about fingerprinting
The New Hampshire Privacy Act was enacted as Senate Bill 255 in 2024 and took effect on 1 January 2025. It is codified at NH RSA Chapter 507-H (RSA 507-H:1 through RSA 507-H:11). Like every law in the Virginia cluster, it does not mention 'fingerprinting', 'device identifier', or 'browser fingerprint' in its text. It does not need to: RSA 507-H:1 defines 'personal data' as 'any information that is linked or reasonably linkable to an identified or identifiable natural person'. A browser or device fingerprint hash - assembled from canvas rendering, font enumeration, GPU strings, audio context, time zone, and similar device signals - qualifies the moment a controller uses it to recognise a returning New Hampshire consumer. Linkability to the same browser session across visits is enough; a name or email address is not required.
NHPA is structurally close to Virginia's VCDPA and Connecticut's CTDPA. It is an opt-out regime: processing is permitted by default, and consumers have the right to opt out of three specific purposes. The consequential distinctions are where NHPA sits in the threshold landscape, how enforcement works, and what the 1 January 2026 date changes operationally.
When NHPA applies to you
RSA 507-H:2 sets a two-leg threshold. A controller falls inside NHPA if it conducts business in New Hampshire or produces products or services targeted to New Hampshire residents, AND it either (a) controls or processes the personal data of at least 35,000 New Hampshire consumers in a calendar year, or (b) controls or processes the personal data of at least 10,000 New Hampshire consumers AND derives more than 25% of its gross revenue from the sale of personal data.
These thresholds are the second-lowest in the US-state cluster, tied with Delaware (Delaware's second leg requires 20% of gross revenue from sale rather than 25%). Virginia's equivalent thresholds are 100,000 consumers or 25,000-with-50%-revenue-from-sale. A SaaS product that handles 40,000 New Hampshire user sessions per year is inside NHPA but well outside VCDPA on the consumer-count leg alone. The practical consequence is that NHPA catches companies at a much earlier stage of growth than most of the cluster.
'Consumer' under NHPA means a New Hampshire resident acting in an individual or household context. Employees, contractors, and individuals acting in an exclusively commercial or employment capacity are excluded under RSA 507-H:2(c). A fingerprint captured on an internal admin tool used solely by employees, or on a B2B SaaS where every user is acting on behalf of a business entity, does not trigger NHPA obligations.
The three opt-out rights that touch fingerprinting
RSA 507-H:5 grants New Hampshire consumers five rights: access, correction, deletion, portability, and opt-out. The opt-out right divides into three categories of processing, and each intersects with fingerprinting in a distinct way.
Targeted advertising under RSA 507-H:1 means displaying advertisements to a consumer where the advertisement is selected based on personal data obtained from the consumer's activities across non-affiliated websites or applications. Using a fingerprint to recognise a returning visitor and serve ads drawn from cross-site behavioural data is the canonical case. First-party retargeting on your own properties, frequency capping, and contextual advertising are excluded.
Sale of personal data under NHPA means exchange for 'monetary or other valuable consideration' by the controller to a third party. The 'other valuable consideration' language makes NHPA's sale definition broader than Virginia's monetary-only test. Sharing fingerprint hashes with an ad-tech partner for non-monetary value - audience extension, data enrichment, or mutual lift - is more likely to qualify as sale under NHPA than under VCDPA.
Profiling means automated processing performed on personal data to evaluate, analyse, or predict personal aspects related to an individual. The opt-out applies when profiling produces legal or similarly significant effects - credit decisions, employment, insurance pricing, housing, healthcare access. Profiling a fingerprint to refine a marketing segment does not trigger the opt-out; profiling a fingerprint as an input to an underwriting or fraud-risk score tied to a consequential decision does.
Common fingerprinting purposes under NHPA
| Purpose | Personal data under NHPA? | DPA required? | Opt-out right applies? | Notes |
|---|---|---|---|---|
| Anti-fraud at login or payment | Yes | No (not heightened-risk processing) | No | Narrow, strictly-necessary use; lowest compliance friction |
| Account-takeover detection | Yes | No | No | Same strictly-necessary lane as anti-fraud |
| Bot mitigation on a public form | Yes | No | No | Security purpose; opt-out not required |
| Cross-site targeted advertising | Yes | Yes | Yes - targeted advertising opt-out | UOOM (GPC) must be checked before firing fingerprint script |
| Sharing fingerprint hashes with ad-tech partner | Yes | Yes | Yes - likely sale under 'other valuable consideration' clause | Broader sale definition than VCDPA; review whether monetary consideration is required |
| Selling fingerprint-derived audience segments | Yes | Yes | Yes - sale opt-out | Clearest sale scenario; opt-out and DPA both required |
| Profiling for credit, insurance, or employment | Yes | Yes | Yes - profiling with legal or significant effect | Highest-risk category; RSA 358-A restitution exposure if consumers harmed |
| Product analytics on your own service | Yes | No | No | First-party analytics; no cross-context advertising |
| Frequency capping on your own site | Yes | No | No (first-party carve-out) | Not targeted advertising under RSA 507-H:1 |
| Fingerprinting employees on an internal tool | No (employee carve-out) | No | No | RSA 507-H:2(c) exclusion applies |
The 1 January 2026 dual-trigger: cure sunset and mandatory UOOM
NHPA launched on 1 January 2025 with a 60-day right to cure after the AG issued a notice of violation. That cure period lapsed on 1 January 2026. Simultaneously, NHPA's mandatory Universal Opt-Out Mechanism recognition activated on the same date, and the AG recognises the Global Privacy Control (GPC) browser signal as a valid UOOM under RSA 507-H:6.
The two changes land together, which is operationally important. Before 1 January 2026, a controller that missed a GPC check could potentially receive a notice, fix the script, and avoid a penalty. After 1 January 2026, there is no notice-and-cure cushion. A fingerprinting deployment that ignores a GPC signal from a New Hampshire browser on 2 January 2026 is immediately in violation of RSA 507-H:6, with no automatic path to avoid the RSA 358-A enforcement consequences.
Practically, any fingerprinting deployment serving New Hampshire consumers that was not already UOOM-compliant before 31 December 2025 should be treated as an open enforcement exposure from 1 January 2026 forward. The cure-period window to remedy that gap has closed.
Data Protection Assessments under NHPA
RSA 507-H:8 requires a controller to conduct and document a Data Protection Assessment before engaging in four categories of processing: targeted advertising, sale of personal data, processing of sensitive data, and profiling that presents a reasonably foreseeable risk of substantial injury to consumers. The assessment must weigh the benefits of the processing against the risks to the consumer.
Like VCDPA's equivalent obligation, the NHPA DPA is an internal record and is not published. The AG can require production in an enforcement context. The absence of a documented assessment is itself a violation, independent of any underlying processing failure. For a fingerprinting deployment that powers targeted advertising, an adequate NHPA assessment names the signal categories collected, the hash construction, the retention window, the recipients, the de-identification approach if any, and the operational mechanism by which the controller honours opt-out requests and GPC signals.
The most under-documented obligation in NHPA deployments is the DPA for the targeted-advertising flow. Controllers that built a UOOM gate correctly but never documented the assessment are still non-compliant with RSA 507-H:8.
Sensitive data and fingerprinting under NHPA
RSA 507-H:1 defines sensitive data to include precise geolocation data, racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, and personal data collected from a known child. A fingerprint hash is not, by itself, sensitive data. The moment the fingerprint is used as a join key to derive precise geolocation - for example by correlating the fingerprint with a Wi-Fi BSSID dataset - or to infer any of the listed categories, the processing crosses into the opt-in regime. Processing sensitive data requires opt-in consent under RSA 507-H:5(a)(5); an opt-out mechanism is not sufficient.
NHPA enforcement contexts
- RSA 507-H:9 vest enforcement authority exclusively in the New Hampshire AG (Consumer Protection and Antitrust Bureau). There is no private right of action and no class-action exposure under NHPA itself.
- The NH Consumer Protection Act (RSA 358-A) procedural machinery applies: the AG may seek civil penalties up to $10,000 per violation, restitution to consumers for actual damages, injunctive relief requiring operational changes to the controller's data pipelines, and recovery of the AG's investigative and legal costs from the violating controller.
- NHPA is new (effective 1 January 2025) and enforcement precedent is limited. The NH AG's Consumer Protection and Antitrust Bureau handles NHPA matters alongside a broad portfolio of RSA 358-A consumer protection work; dedicated privacy unit capacity is smaller than Colorado or Connecticut.
- The 1 January 2026 cure-period sunset removes the pre-penalty notice that shielded early NHPA violations from immediate penalty. Controllers should not expect the enforcement posture to remain the same as it was in the first year of the law.
- Because enforcement runs through RSA 358-A rather than a standalone NHPA penalty schedule, the AG has the same investigative and settlement tools it uses in other consumer protection matters - including civil investigative demands and negotiated assurances of discontinuance that can include compliance reporting obligations.
How the NH Consumer Protection Act changes NHPA enforcement
Most Virginia-cluster states carry standalone penalty schedules written into the privacy statute. NHPA is different: RSA 507-H:9 delegates enforcement to RSA Chapter 358-A, the general NH Consumer Protection Act. Connecticut uses the same structure - CTDPA enforcement flows through CUTPA. The operational consequence is that the AG's enforcement toolkit is not limited to what RSA 507-H explicitly describes.
Under RSA 358-A, the AG can pursue: civil penalties up to $10,000 per violation (each consumer affected by a distinct violation is, in principle, a separate violation); an order of restitution requiring the controller to compensate consumers for actual harm caused by the non-compliant processing; injunctive relief imposing specific requirements on how the controller must reconfigure its fingerprinting deployment; and recovery of the AG's costs of investigation and litigation from the defendant controller.
The restitution and injunctive-relief tools are the differentiators from a straightforward per-violation penalty. For a fingerprinting deployment that processes tens of thousands of New Hampshire consumers without a valid opt-out mechanism, the aggregate restitution exposure - calculated on consumer-level harm rather than per-processing-activity - can exceed the per-violation penalty total. Controllers familiar with VCDPA's $7,500-per-violation cap should not assume NHPA's exposure is bounded by the same ceiling in practice.
How Benny the Doorman fits into an NHPA-aware deployment
Benny is a fingerprinting SDK and hosted API. The opt-out gating, UOOM check, and consent preference management are the controller's responsibility, implemented in the controller's CMP or application layer. Three integration steps make a Benny deployment NHPA-aware.
First, install a GPC header check upstream of every Benny API call used for targeted advertising or sale-flagged purposes. The check belongs at the application layer before the Benny call is issued, not inside Benny itself. As of 1 January 2026, failing to check the GPC signal before firing the fingerprint is a stand-alone violation of RSA 507-H:6 with no cure-period cushion.
Second, produce and retain a Data Protection Assessment under RSA 507-H:8 for each purpose category before going live - targeted advertising, sale, sensitive data, or covered profiling. Benny's technical documentation enumerates the signal categories collected, the hash construction, the default retention window, and the per-call data flow, which maps directly to the technical detail an NHPA assessment must capture.
Third, where the same Benny deployment supports both a strictly-necessary purpose (anti-fraud) and a regulated purpose (targeted advertising), keep those data flows architecturally separate with distinct retention windows and access scopes. The RSA 507-H:6 opt-out must be honoured on the regulated flow without disabling the anti-fraud flow, which sits in the strictly-necessary lane and is not subject to the opt-out right.
Frequently asked questions
Is browser fingerprinting illegal under NHPA?
No. Fingerprinting is not banned in New Hampshire. It is regulated as personal data when the fingerprint hash can be linked back to an identifiable New Hampshire consumer. Lawful use requires honouring opt-out requests for targeted advertising, sale, and covered profiling; checking the GPC signal before any fingerprint call used for those purposes (mandatory from 1 January 2026); and completing a Data Protection Assessment under RSA 507-H:8 before deploying fingerprinting for any of those purpose categories.
How does the NH Consumer Protection Act change NHPA enforcement?
NHPA routes enforcement through RSA 358-A (the NH Consumer Protection Act) rather than carrying a standalone penalty schedule. This gives the AG tools beyond a per-violation fine: restitution calculated on consumer-level harm, injunctive relief requiring structural changes to the controller's fingerprinting deployment, and recovery of the AG's costs from the defendant. A controller facing NHPA enforcement is not exposed only to $10,000 per violation - it is exposed to the full RSA 358-A enforcement toolkit, which in aggregate can substantially exceed the headline penalty for large-scale processing violations.
What are NHPA's applicability thresholds?
NHPA applies if a controller processes the personal data of at least 35,000 New Hampshire consumers in a calendar year, or at least 10,000 New Hampshire consumers and derives more than 25% of its gross revenue from the sale of personal data. These are the second-lowest thresholds in the US-state cluster, tied with Delaware (whose second leg requires 20% gross revenue from sale rather than 25%). Virginia's equivalent thresholds are 100,000 consumers or 25,000-with-50%-revenue-from-sale.
What happened on 1 January 2026 under NHPA?
Two things happened simultaneously. First, the 60-day cure period lapsed, meaning the AG can now pursue penalties immediately upon identifying a violation without first issuing a notice-and-cure opportunity. Second, mandatory Universal Opt-Out Mechanism recognition activated: controllers must treat the Global Privacy Control browser signal as a binding opt-out for targeted advertising and sale processing. Any fingerprinting deployment that was not UOOM-compliant before 31 December 2025 has open enforcement exposure from that date forward.
Do I need to honour Global Privacy Control under NHPA?
Yes, as of 1 January 2026. NHPA requires controllers to recognise Universal Opt-Out Mechanisms, and the NH AG recognises GPC as a valid UOOM under RSA 507-H:6. A fingerprinting deployment that fires before checking the GPC header on a New Hampshire browser is in violation of RSA 507-H:6, with no cure-period cushion available after the 1 January 2026 sunset.
Does NHPA apply to anti-fraud fingerprinting?
Yes, anti-fraud fingerprinting is personal-data processing under NHPA when the hash is linkable to a New Hampshire consumer. But the opt-out rights for targeted advertising, sale, and profiling do not apply to anti-fraud use, and a Data Protection Assessment is not required unless the processing carries a reasonably foreseeable risk of substantial injury. Narrowly-scoped anti-fraud fingerprinting is one of the lowest-friction use cases under NHPA, as it is under every Virginia-cluster law.
Is sharing fingerprint hashes with an ad-tech partner 'sale' under NHPA?
Potentially yes. NHPA's sale definition covers exchange for 'monetary or other valuable consideration', which is broader than Virginia's monetary-only definition. Sharing fingerprint hashes with an ad-tech partner for audience extension, mutual lift, or data enrichment - without a direct dollar payment - is more likely to qualify as sale under NHPA than under VCDPA. Controllers relying on the Virginia 'no monetary consideration means no sale' argument should re-check that analysis for New Hampshire.
When is a Data Protection Assessment required under NHPA?
RSA 507-H:8 requires a DPA before processing for targeted advertising, sale of personal data, processing of sensitive data, and profiling that presents a reasonably foreseeable risk of substantial injury to consumers. The assessment must weigh the benefits against the risks and be retained and made available to the AG on request. Absence of a documented assessment is a standalone violation, separate from any underlying processing failure.
How is NHPA different from VCDPA for fingerprinting?
Four key differences. First, NHPA's applicability thresholds are 35,000 or 10,000-with-25%-revenue-from-sale, well below VCDPA's 100,000 or 25,000-with-50% thresholds - NHPA catches far smaller companies. Second, NHPA's sale definition includes 'other valuable consideration', making non-monetary data sharing more likely to count as sale than under VCDPA. Third, NHPA enforcement runs through RSA 358-A (adding restitution and injunctive relief on top of per-violation penalties) rather than a standalone penalty schedule. Fourth, NHPA's cure period sunset on 1 January 2026 versus VCDPA's notice-and-cure mechanism that remains in place.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

