New Jersey Privacy Law
New Jersey’s comprehensive statute has been in force since January 15, 2025, and two features set it apart from its peers. Its definition of sensitive data reaches financial account information and a consumer’s status as transgender or non-binary, categories most state statutes omit. And its enforcement runs through the Consumer Fraud Act, which carries penalties of up to $10,000 for a first offense. The state’s most active privacy litigation, however, concerns a different statute entirely: Daniel’s Law, on which the New Jersey Supreme Court answered a certified question from the Third Circuit on August 12, 2026.
The New Jersey Data Privacy Act (NJDPA)
Senate Bill 332, sponsored by Senator Troy Singleton and Senator Richard J. Codey, was approved on January 16, 2024 as P.L.2023, c.266 and took effect on the 365th day following enactment. Section 14 makes it an unlawful practice and a violation of the Consumer Fraud Act, P.L.1960, c.39, for a controller to violate the Act, and section 16 gives the Office of the Attorney General “sole and exclusive authority” to enforce while providing that nothing in the Act supplies the basis for a private right of action. Section 15 directs the Director of the Division of Consumer Affairs to promulgate implementing rules under the Administrative Procedure Act — a delegation most comparable statutes do not contain, and one the Division has since exercised.
| Effective date | January 15, 2025 |
|---|---|
| Citation | P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.) |
| Enforced by | New Jersey Attorney General (Division of Consumer Affairs) |
| Maximum penalty | Enforced as an unlawful practice under the Consumer Fraud Act, which sets civil penalties of up to $10,000 per violation for a first offense and up to $20,000 for every subsequent offense under N.J.S.A. 56:8-13 |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days, available until the first day of the 18th month following the effective date |
Who Must Comply
The NJDPA reaches a business that conducts business in New Jersey or produces products or services targeted to New Jersey residents, and during a calendar year controls or processes the personal data of at least 100,000 consumers, excluding data processed solely to complete a payment transaction, or controls or processes the personal data of at least 25,000 consumers and derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data.
The definition of sensitive data at section 1 reaches personal data revealing financial information — an account number, account log-in, financial account, or credit or debit card number with any security or access code or password permitting access — and a consumer’s status as transgender or non-binary, alongside racial or ethnic origin, religious beliefs, health condition, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data, data from a known child and precise geolocation. Section 9(a)(7) requires consent before processing for targeted advertising, sale or profiling where the controller has actual knowledge, or wilfully disregards, that the consumer is at least 13 and younger than 17
Consumer Rights Under the NJDPA
Residents of New Jersey can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in New Jersey
Daniel’s Law (N.J.S.A. 56:8-166.1)
Enacted in November 2020 as L. 2020, c. 125 following the killing of Daniel Anderl, the son of United States District Judge Esther Salas, at the family’s home in July 2020, Daniel’s Law shields the home addresses and unpublished telephone numbers of covered judicial, law enforcement and child protective services personnel. Its mechanism is a private notice rather than a public registry: an “authorized person” sends written notice to an entity in possession of the protected information asking it to cease disclosure, and if the recipient fails to cease within 10 business days it “shall be liable”, with the covered person or the covered person’s assignee entitled to injunctive relief, reasonable attorney’s fees and costs, and actual damages or liquidated damages of at least $1,000 for each violation. Punitive damages require a showing of wilful or reckless disregard of the law. Claims are assignable, which is what produced the litigation now before the federal courts: Atlas Data Privacy Corporation operates an online service through which covered persons send the required notices, and roughly 19,000 covered persons used it to send written notices to the defendants in the consolidated actions.
Identity Theft Prevention Act — Social Security number restrictions (N.J.S.A. 56:8-164)
The same 2005 act that created the breach statute, P.L.2005, c.226, restricts what any person — including a public or private entity — may do with a Social Security number. Section 13 bars publicly posting or displaying an individual’s Social Security number or any four or more consecutive digits taken from it; printing the number on materials mailed to the individual unless State or federal law requires it on the mailed document; printing the number on any card required to access the entity’s products or services; intentionally communicating or otherwise making the number available to the general public; and requiring an individual to transmit the number over the internet unless the connection is secure or the number is encrypted. The act also carries the Legislature’s findings, which frame identity theft as “one of the major law enforcement challenges of the new economy, as vast quantities of sensitive, personal information are now vulnerable to criminal interception and misuse”.
Data Breach Notification in New Jersey
N.J.S.A. 56:8-163, enacted as section 12 of the Identity Theft Prevention Act, orders its two notices in a way few state statutes do. Subsection (c)(1) requires a business or public entity that must disclose a breach to report the breach and any information pertaining to it to the Division of State Police in the Department of Law and Public Safety in advance of the disclosure to the customer, for investigation or handling, which may include dissemination or referral to other law enforcement entities. Subsection (a) then governs the customer notice itself, which is due in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or with measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system — no fixed number of days appears. The same subsection carries a harm exception: disclosure is not required where the business or public entity establishes that misuse of the information is not reasonably possible, provided the determination is documented in writing and retained for five years. Subsection (b) puts an entity that maintains records on behalf of another on an immediate duty to notify that other entity following discovery. Substitute notice under subsection (d)(3) becomes available where the cost of notice would exceed $250,000, the affected class exceeds 500,000, or contact information is insufficient. Subsection (f) requires notice to the nationwide consumer reporting agencies, without unreasonable delay, where more than 1,000 persons are notified at one time.
Residents must be notified in the most expedient time possible and without unreasonable delay; the statute sets no fixed number of days. The breach and any information pertaining to it are reported to the Division of State Police in advance of the disclosure to the customer, for investigation or handling. Complaints are taken by the New Jersey Division of Consumer Affairs, which enforces the statute.
How the NJDPA Is Enforced
Consumer Fraud Act routing and exclusive Attorney General authority. Section 14(a) of the Act makes it an unlawful practice and a violation of the Consumer Fraud Act, P.L.1960, c.39, for a controller to violate the Act, and section 16 gives the Office of the Attorney General sole and exclusive enforcement authority. The Consumer Fraud Act supplies the penalty: as the Attorney General’s office states, a person who violates the law is liable for civil penalties of up to $10,000 per violation for a first offense and up to $20,000 for every subsequent offense under N.J.S.A. 56:8-13. Enforcement is administered through the Division of Consumer Affairs, which may proceed before an administrative law judge or in court.
A rulemaking delegation most state privacy acts lack. Section 15 directs the Director of the Division of Consumer Affairs to promulgate rules and regulations under the Administrative Procedure Act, P.L.1968, c.410, necessary to effectuate the Act’s purposes. Section 8(c) adds a narrower grant on top of it, allowing the Division to adopt rules detailing the technical specifications for one or more universal opt-out mechanisms, including rules permitting a controller to authenticate the consumer as a New Jersey resident and to determine that the mechanism represents a legitimate opt-out request, and to update those specifications over time.
Recent Enforcement in New Jersey
In the Matter of Enzo Biochem, Inc. — Division of Consumer Affairs consent order, August 2024. The Division of Consumer Affairs, Office of Consumer Protection, opened an investigation into whether Enzo Biochem, Inc. and Enzo Clinical Labs, Inc. had violated the New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 to -229, and HIPAA, conducted with the New York and Connecticut Attorney General offices. The resulting consent order was filed on August 13, 2024. It records that in early April 2023 attackers gained remote access to the respondents’ private network, exfiltrated files containing patient information on April 5 and deployed ransomware that encrypted several systems, and that the attack was discovered on April 6. Files relating to tests rendered between October 2012 and April 2023 for approximately 2.4 million patients were involved, of whom approximately 331,600 were New Jersey residents, with Social Security numbers acquired for approximately 109,200 New Jersey residents. The order records that notice to affected patients began on June 5, 2023 and that the notice did not disclose that certain patients’ address, phone number, date of birth and gender had also been involved. Under the monetary relief provision the respondents pay the Attorneys General $4,500,000 in penalties and costs within 45 days of the effective date, divided among the three offices in amounts they designate.
Pending Privacy Legislation
The unfinished business in New Jersey is regulatory and judicial rather than legislative. On June 2, 2025 the Division of Consumer Affairs proposed rules implementing the Data Privacy Act under the delegation in section 15, which the Attorney General’s office describes as giving consumers the ability to opt out of a controller selling their personal data or using it for targeted advertising and some types of profiling, to know whether a controller processes their personal data and obtain a copy, to correct inaccuracies, to delete data the controller collected from them, and to obtain a portable copy — with additional protections for children under 13. The 60-day public comment period ran from June 2, 2025 to August 1, 2025, and the office states that a summary of comments and the Division’s responses will be published in a Notice of Adoption expected in 2026, on publication of which the rules become final. Separately, the certified question in the Daniel’s Law litigation was answered on August 12, 2026, returning the consolidated cases to the Third Circuit with the state-law standard settled.
Federal Privacy Laws That Apply in New Jersey
Federal privacy law applies in New Jersey by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The NJDPA sits alongside those rules rather than displacing them: the New Jersey Attorney General (Division of Consumer Affairs) enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.
New Jersey Privacy Law FAQ
How long does a New Jersey business have to notify customers after a data breach?
Who has to be told first about a New Jersey data breach?
Is 15 days the deadline to honour an opt-out request in New Jersey?
What counts as sensitive data under the New Jersey Data Privacy Act?
Does New Jersey require businesses to honour browser-based opt-out signals?
What did the New Jersey Supreme Court decide about Daniel’s Law in 2026?
Can a New Jersey consumer sue under the Data Privacy Act?
When did the New Jersey Data Privacy Act’s cure period end?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- P.L.2023, c.266 (S332 6R) — New Jersey Data Privacy Act, as enacted legislation
- P.L.2005, c.226 — Identity Theft Prevention Act, including N.J.S.A. 56:8-163 and 56:8-164 legislation
- Atlas Data Privacy Corp. v. We Inform, LLC, A-8-25 (091145) (N.J. Aug. 12, 2026) case
- In the Matter of Enzo Biochem, Inc. — consent order, Division of Consumer Affairs, Aug. 13, 2024 docket
- New Jersey Office of the Attorney General — proposed rules implementing the Data Privacy Act agency
- New Jersey Office of the Attorney General — Consumer Fraud Act enforcement statement citing N.J.S.A. 56:8-13 agency
- New Jersey Model Civil Jury Charge 4.43 — Consumer Fraud Act case
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.