Privacy Law Library

Identity Theft Prevention Act: Record Disposal and Social Security Number Protection

NJ SSN and Disposal Law

Data security

Businesses and public entities must destroy customer records containing personal information so the data is unreadable when the records are no longer kept. Anyone is barred from publicly posting Social Security numbers (or four or more consecutive digits), printing them on mailings or access cards, or requiring their transmission or use online without security.

Where
New Jersey
Citation
N.J.S.A. 56:8-162 (disposal), 56:8-164 (SSN), 56:8-166; P.L.2005, c.226, ss.11, 13, 15
Status
In force
In force since
2006-01-01
Enforced by
New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
People can sue
Limited
Penalties
Willful, knowing, or reckless violations are unlawful practices under the Consumer Fraud Act (56:8-166), carrying civil penalties of up to $10,000 for a first offense and $20,000 for each later offense (56:8-13), plus injunctive relief. A person who suffers an ascertainable loss of money or property from a CFA unlawful practice may sue for treble damages and attorney's fees (56:8-19).
Applies to
  • Disposal: businesses and public entities with custody or control of customer records containing personal information (56:8-162)
  • SSN rules: any person, including public and private entities (56:8-164(a))

Practices it requires

  • Do not publicly post or display, or intentionally make available to the general public, an individual's SSN or any four or more consecutive digits of it.N.J.S.A. 56:8-164(a)(1), (4)
  • Do not print an SSN on materials mailed to the individual (unless required by law) or on any card needed to access products or services; a mailed SSN may never appear on a postcard or be visible on or through the envelope.N.J.S.A. 56:8-164(a)(2)-(3), (d)

Security duties

  • Destroy customer records containing personal information that are no longer to be retained by shredding, erasing, or otherwise making the information unreadable, undecipherable, or non-reconstructable.N.J.S.A. 56:8-162
  • Do not require an SSN to be sent over the Internet unless the connection is secure or the number is encrypted, or to access a website unless a password, PIN, or other authentication device is also required.N.J.S.A. 56:8-164(a)(5)-(6)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Regulations under 56:8-165 (Division of Consumer Affairs, with the Commissioner of Banking and Insurance) were not located; none appear to have been adopted.

Research reference, not legal advice.