Relative to the expectation of privacy in personal information maintained by the state.
HB 522 creates a new chapter in the New Hampshire statutes establishing a statutory expectation of privacy in personal information held by third-party providers when that information is sought by a government entity. The bill defines “personal information” broadly to include identifiers such as name, date of birth, Social Security number, address, account numbers, phone numbers, location data, biometric identifiers, and genetic data. It then generally prohibits state, local, county, and federal government entities from acquiring, collecting, retaining, or using such information from third-party providers for New Hampshire residents.
The bill includes several exceptions. It allows access when a warrant is issued, when a judicially recognized warrant exception applies, in emergencies involving imminent death or serious physical injury, for 911 communications, for certain regulatory or administrative agency functions, when another state or federal law authorizes or requires the collection, and when the individual voluntarily provides or authorizes access to the information. It also preserves grand jury inquiries and states that the chapter does not create a cause of action against nongovernment entities that merely provide information to government entities. A related amendment to the biometric data statute would prohibit obtaining, retaining, or providing biometric data except as allowed under the new chapter or existing biometric law. The act would take effect January 1, 2026.
HB 522 would add a new privacy framework to New Hampshire law by restricting government access to personal data held by third-party service providers and by creating enforcement mechanisms, including misdemeanor liability for knowing violations and a private right to recover at least $1,000 per violation plus costs and attorney’s fees. It would also modify RSA 359-N:2 to align biometric-data restrictions with the new privacy chapter. The fiscal note indicates no direct revenue impact but indeterminable costs due to possible criminal enforcement and increased civil litigation, with potential effects on state, county, and local judicial and correctional systems.
The available record shows no committee transcript and no recorded votes, so there is no documented floor or committee debate to gauge support or opposition. Based on the bill’s structure, it appears to be a privacy-protection measure aimed at limiting government access to sensitive personal data while preserving law-enforcement, emergency, and regulatory exceptions. The fiscal note suggests policymakers anticipated possible administrative and litigation costs, but the overall sentiment in the materials provided cannot be characterized beyond the bill’s privacy-oriented purpose.
The main points of potential contention are the breadth of the prohibition on government acquisition of data from third-party providers, the scope of the exceptions, and the enforcement provisions. Privacy advocates would likely favor the strong default rule and private right of action, while government agencies, law enforcement, and local governments may be concerned about limits on investigative tools, compliance burdens, and exposure to misdemeanor and civil liability. The inclusion of biometric, location, and communications data may also raise concerns among technology, utility, financial, and service providers about how the restrictions would operate in practice.