Identity Theft Prevention Act: Record Disposal and Social Security Number Protection
NJ SSN and Disposal Law
Data security
Businesses and public entities must destroy customer records containing personal information so the data is unreadable when the records are no longer kept. Anyone is barred from publicly posting Social Security numbers (or four or more consecutive digits), printing them on mailings or access cards, or requiring their transmission or use online without security.
- Where
- New Jersey
- Citation
- N.J.S.A. 56:8-162 (disposal), 56:8-164 (SSN), 56:8-166; P.L.2005, c.226, ss.11, 13, 15
- Status
- In force
- In force since
- 2006-01-01
- Enforced by
- New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
- People can sue
- Limited
- Penalties
- Willful, knowing, or reckless violations are unlawful practices under the Consumer Fraud Act (56:8-166), carrying civil penalties of up to $10,000 for a first offense and $20,000 for each later offense (56:8-13), plus injunctive relief. A person who suffers an ascertainable loss of money or property from a CFA unlawful practice may sue for treble damages and attorney's fees (56:8-19).
- Applies to
- Disposal: businesses and public entities with custody or control of customer records containing personal information (56:8-162)
- SSN rules: any person, including public and private entities (56:8-164(a))
Practices it requires
- Do not publicly post or display, or intentionally make available to the general public, an individual's SSN or any four or more consecutive digits of it.N.J.S.A. 56:8-164(a)(1), (4)
- Do not print an SSN on materials mailed to the individual (unless required by law) or on any card needed to access products or services; a mailed SSN may never appear on a postcard or be visible on or through the envelope.N.J.S.A. 56:8-164(a)(2)-(3), (d)
Security duties
- Destroy customer records containing personal information that are no longer to be retained by shredding, erasing, or otherwise making the information unreadable, undecipherable, or non-reconstructable.N.J.S.A. 56:8-162
- Do not require an SSN to be sent over the Internet unless the connection is secure or the number is encrypted, or to access a website unless a password, PIN, or other authentication device is also required.N.J.S.A. 56:8-164(a)(5)-(6)
Sources
- Official text
- P.L.2005, c.226, chapter law text (New Jersey Legislature)
- N.J.S.A. 56:8-164, current text (NJ Legislature statutes database)
- Identity Theft Prevention Act courtesy copy (NJ Division of Consumer Affairs)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Regulations under 56:8-165 (Division of Consumer Affairs, with the Commissioner of Banking and Insurance) were not located; none appear to have been adopted.
Research reference, not legal advice.