New Hampshire · verified through August 25, 2026

New Hampshire: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

NH · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

n.a. - New Hampshire's comprehensive privacy act was not verified from an official source in this session

Official name / citation
n.a.
Status / effective date
n.a.
Principal enforcer
New Hampshire Attorney General (Consumer Protection and Antitrust Bureau)

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

RSA 359-C, 'Right to Privacy', including notice of security breach - https://gc.nh.gov/rsa/html/nhtoc/nhtoc-xxxi-359-c.htm

Public enforcement context

Tier 1*

23andMe (bankruptcy claims; trustee)

$150 million in allowed state claims, with actual state recovery limited to $18 million; separate $46.75 million consumer class settlement · July 14, 2026

A coalition of 42 attorneys general settled bankruptcy claims arising from the 2023 breach of 23andMe genetic data affecting about 6.9 million customers worldwide. New Hampshire is named among the 42 participating jurisdictions on the Michigan AG page; no New Hampshire share is stated there.

Legal basis: State data-privacy, consumer-protection and genetic-information privacy claims asserted in the bankruptcy (no single statute named)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.