Privacy Law Library

New Jersey Data Privacy Act

NJDPA

Comprehensive privacy · Children · Health · Biometric · Genetic · Location · Data security

New Jersey's comprehensive consumer privacy law gives residents rights to confirm, access, correct, delete and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. It requires consent for processing sensitive data and for targeted advertising, sale, or profiling of known 13-to-16-year-olds, and requires data protection assessments for high-risk processing. A January 2026 amendment (P.L.2025, c.367) added exemptions and a HIPAA-based de-identification standard, and a June 2026 amendment (P.L.2026, c.25) flatly bans the sale of sensitive data by anyone.

Where
New Jersey
Citation
N.J.S.A. 56:8-166.4 to 56:8-166.19; enacted by P.L.2023, c.266 (S332); amended by P.L.2025, c.367 (A5017, approved Jan. 20, 2026) and P.L.2026, c.25, s.1 (A5328, approved June 30, 2026)
Status
In force
In force since
2025-01-15
Last amended
2026-06-30
Enforced by
New Jersey Attorney General (sole and exclusive authority, 56:8-166.19), acting through the Division of Consumer Affairs
People can sue
No
Penalties
A violation is an unlawful practice under the Consumer Fraud Act (56:8-166.17(a)), carrying civil penalties of up to $10,000 for a first offense and up to $20,000 for each later offense (N.J.S.A. 56:8-13), plus injunctive relief and restitution. Since June 30, 2026, selling, offering for sale, or licensing sensitive data carries a civil penalty of $50,000 per record (56:8-166.23). A mandatory 30-day cure notice applied, where cure was deemed possible, until the first day of the 18th month after the effective date (through June 30, 2026) (56:8-166.17(b)).
Applies to
  • Controllers that conduct business in New Jersey or produce products or services targeted to New Jersey residents and that, during a calendar year, control or process personal data of at least 100,000 consumers (excluding data processed solely to complete a payment transaction), or at least 25,000 consumers while deriving revenue or a discount from the sale of personal data (56:8-166.5)
  • Since P.L.2026, c.25 (June 30, 2026): the ban on selling sensitive data in 56:8-166.12(a)(6) applies to all individuals and legal entities regardless of the number of consumers whose data they control or process
  • 'Consumer' means a New Jersey resident acting in an individual or household context; people acting in a commercial or employment context are excluded (56:8-166.4)
  • Exemptions include HIPAA protected health information (and, since P.L.2025, c.367, information treated like PHI by HIPAA covered entities and business associates), GLBA-covered financial institutions and data, insurance institutions subject to N.J.S.A. 17:23A-1 et seq., insurance-support organizations and national securities associations (added by P.L.2025, c.367), FCRA-governed consumer reporting activity, MVC sales permitted by the DPPA, state agencies and political subdivisions, and human-subjects research data including ICH good-clinical-practice research (56:8-166.13). There is no general nonprofit exemption.

What a privacy notice must say

  • Provide a reasonably accessible, clear, and meaningful privacy notice listing categories of personal data processed, processing purposes, categories of third parties and data shared, how to exercise and appeal rights, how material changes are notified, and an active email address or online contact mechanism.N.J.S.A. 56:8-166.6(a)
  • Clearly and conspicuously disclose any sale of personal data or processing for targeted advertising or significant-decision profiling, and how to opt out.N.J.S.A. 56:8-166.6(b) · Only if: If the controller sells personal data or processes it for targeted advertising or profiling

Rights it gives people

  • Honor opt-outs sent by an authorized agent, including a browser setting or global device setting, and allow opt-out of targeted advertising and sale through a user-selected universal opt-out mechanism.N.J.S.A. 56:8-166.11(a), (b)(1) · Only if: Universal opt-out duty applies to controllers that process data for targeted advertising or sale · From 2025-07-15
  • Consumers may confirm processing and access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects.N.J.S.A. 56:8-166.10(a)

Practices it requires

  • Do not sell sensitive data at all; this ban applies to every individual and legal entity regardless of volume thresholds.N.J.S.A. 56:8-166.12(a)(6), as amended by P.L.2026, c.25, s.1 · From 2026-06-30
  • Respond to verified requests within 45 days (extendable once by 45 days with notice), free of charge once per 12 months, and offer an appeal process with a written decision within 45 days that points to the Division of Consumer Affairs complaint channel if the appeal is denied.N.J.S.A. 56:8-166.7(a), (d), (f)
  • Obtain consent before processing personal data for targeted advertising, sale, or significant-decision profiling where the controller knows or wilfully disregards that the consumer is 13 to 16 years old.N.J.S.A. 56:8-166.12(a)(8) (formerly (a)(7))
  • Provide a consent-revocation mechanism at least as easy as giving consent, and stop processing within 15 days of revocation.N.J.S.A. 56:8-166.12(a)(7) (formerly (a)(6))
  • Do not process sensitive data (including health, genetic or biometric identifiers, precise geolocation, financial account credentials, citizenship/immigration status, transgender or non-binary status, and a known child's data) without consent; process a known child's data in line with COPPA.N.J.S.A. 56:8-166.12(a)(4); 56:8-166.4

Security duties

  • Maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data; limit collection to what is adequate, relevant, and reasonably necessary.N.J.S.A. 56:8-166.12(a)(1), (a)(3)

Other duties

  • Data de-identified under the HIPAA standard (45 C.F.R. Part 164), with recipients contractually barred from re-identification, qualifies as de-identified data outside the Act.N.J.S.A. 56:8-166.4 ('de-identified data'), as amended by P.L.2025, c.367, s.2 · From 2026-01-20
  • Conduct and document a data protection assessment before processing that presents a heightened risk (targeted advertising, risky profiling, sale, sensitive data) and provide it to the Division of Consumer Affairs on request.N.J.S.A. 56:8-166.12(a)(10), (b), (c) · Only if: Applies to processing of personal data acquired on or after 2025-01-15
  • Bind processors by written contract setting processing instructions, data types, duration, confidentiality, deletion or return, and audit or assessment rights.N.J.S.A. 56:8-166.16(e)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Implementing rules: the Division of Consumer Affairs proposed N.J.A.C. 13:45L on June 2, 2025 (comments closed August 1, 2025). Secondary sources (Troutman Pepper, June 2026) report the proposal lapsed unadopted on June 2, 2026 under the one-year Administrative Procedure Act limit and that no re-proposal has issued. I could not confirm this on the Division's own site, which blocked automated access. | Section renumbering inside 56:8-166.12(a) after P.L.2026, c.25 is taken from the chapter law text; the codified compilation was not checked separately.

Research reference, not legal advice.