NJ

New Jersey Privacy Law

New Jersey Data Privacy Act

Effective: January 15, 2025ActiveReviewed by PrivacyLawMap editorial teamLast verified: July 23, 2026

Overview

The New Jersey Data Privacy Act (NJDPA, codified as P.L. 2024, c.1) was signed into law by Governor Phil Murphy on January 16, 2024, making New Jersey the 13th state to enact a comprehensive consumer data privacy law. The law became effective on January 15, 2025, and is enforced by the New Jersey Attorney General through the Division of Consumer Affairs, Office of Consumer Protection. Attorney General Jennifer Davenport — confirmed unanimously by the New Jersey Senate on February 24, 2026, as part of Governor Mikie Sherrill's administration — oversees enforcement under the New Jersey Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.), which provides penalties of up to $10,000 for a first violation and $20,000 for each subsequent violation. The Division of Consumer Affairs published proposed implementing regulations on June 2, 2025, addressing consumer rights request procedures, data security practices, data inventories, data privacy impact assessments, consent requirements including dark pattern prohibitions, and loyalty program disclosure obligations. The 60-day public comment period closed on August 1, 2025, and a Notice of Adoption finalizing the rules is expected by June 2, 2026. New Jersey is a founding member of the Consortium of Privacy Regulators alongside California (CPPA), Colorado, Connecticut, New Hampshire, Oregon, and other states, positioning the state for coordinated multistate enforcement.

The NJDPA grants New Jersey consumers comprehensive privacy rights: the right to confirm whether a controller is processing their personal data, the right to access, correct, delete, and obtain a portable copy of their personal data, as well as opt-out rights for the sale of personal data, targeted advertising, and profiling that produces legal or similarly significant effects. Controllers must respond to consumer requests within 45 days, with a possible 45-day extension when reasonably necessary, and must provide an appeals process for denied requests — if the appeal is also denied, the controller must inform the consumer how to contact the Division of Consumer Affairs. The NJDPA requires controllers to conduct data protection assessments for processing activities presenting a heightened risk of harm, including targeted advertising, the sale of personal data, processing of sensitive data, and profiling. The law includes one of the broadest definitions of sensitive data among state privacy laws: racial or ethnic origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, genetic data, biometric data for identification, personal data of a known child under 13, and precise geolocation data. The NJDPA also mandates that controllers honor universal opt-out mechanisms such as the Global Privacy Control (GPC) for opt-out-of-sale and opt-out-of-targeted-advertising requests from the law's effective date, and it contains some of the strongest minor protection provisions in the country — prohibiting the sale of personal data and targeted advertising for consumers under 17 without affirmative consent.

The law applies to entities conducting business in New Jersey or targeting New Jersey consumers that control or process personal data of 100,000 or more consumers (excluding data processed solely to complete a payment transaction), or control or process personal data of 25,000 or more consumers while deriving revenue or receiving discounts on goods or services from the sale of personal data — notably, unlike states such as Connecticut or Virginia, there is no minimum percentage-of-revenue threshold, meaning any revenue from data sales can trigger applicability. The NJDPA exempts certain entities: financial institutions subject to the Gramm-Leach-Bliley Act (GLBA), entities subject to HIPAA (an entity-level exemption), nonprofit organizations, and higher education institutions. Data-level exemptions apply to information governed by FERPA, FCRA, the Driver's Privacy Protection Act, and the Farm Credit Act. That enforcement transition has now happened: the mandatory 30-day cure period — during which the Division had to give controllers notice and an opportunity to cure before taking action — ended on July 1, 2026. The Division of Consumer Affairs states the rule directly: "until July 1, 2026, if the Division identifies a potential violation that the controller can remedy, the Division will send a notice to the controller to give them the chance to fix the problem" (NJ Division of Consumer Affairs, NJDPL FAQ, date_retrieved: 2026-07-23). Since July 1, 2026, whether to offer a cure opportunity at all is entirely at the Attorney General's discretion, so a New Jersey business can now go straight from AG inquiry to enforcement action with no guaranteed window to remediate. New Jersey also maintains a separate data broker registration law requiring data brokers to register annually with the Division of Consumer Affairs, imposing additional obligations beyond the NJDPA.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

100,000+
New Jersey consumers' data processed
25,000+ consumers
AND 50%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • CRITICAL: the mandatory 30-day cure period ended July 1, 2026 — the AG now has full discretion on whether to offer a cure opportunity, so violations identified today can go straight to enforcement
  • Proposed implementing regulations (published June 2, 2025) expected to be finalized via Notice of Adoption by June 2, 2026 — regulations will formalize data security, consent, impact assessment, and consumer rights procedures
  • New AG Jennifer Davenport (Sherrill administration, confirmed February 2026) inherits enforcement authority — early enforcement priorities and posture still developing under new leadership
  • Universal opt-out mechanism (GPC) requirement has been in full effect since January 15, 2025 — one of 12 states requiring GPC recognition
  • Among the strongest minor protections in the country: sale and targeted advertising prohibited for consumers under 17 without affirmative consent, opt-in required for children under 13
  • Data broker registration requirement operates alongside NJDPA — brokers must register annually with Division of Consumer Affairs
  • Consortium of Privacy Regulators membership enables coordinated multistate enforcement actions with California, Colorado, Connecticut, New Hampshire, Oregon, and other member states
  • No percentage-of-revenue threshold for tier 2 applicability — any revenue from data sales combined with 25,000+ consumers triggers coverage, broader than states requiring 25% revenue threshold
  • Proposed regulations will require controllers to maintain data inventories and conduct data privacy impact assessments for high-risk processing activities
  • NJ Consumer Fraud Act enforcement framework provides $10,000 first violation / $20,000 subsequent violation penalty structure — among the highest state privacy law penalties

Enforcement Details

Enforced By
New Jersey Attorney General (Division of Consumer Affairs, Office of Consumer Protection)
Penalty Per Violation
$10,000
Cure Period
None — immediate enforcement
Private Right of Action
No — AG enforcement only

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health condition, treatment, or diagnosisSexual orientationCitizenship or immigration statusGenetic dataBiometric data for identificationPersonal data of a known child under 13Precise geolocation data

Universal Opt-Out / GPC Requirements

GPC / Universal Opt-Out Required

The NJDPA requires controllers to honor universal opt-out mechanisms such as Global Privacy Control (GPC) for opt-out-of-sale and opt-out-of-targeted-advertising requests from the law's effective date (January 15, 2025). New Jersey joins California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, Oregon, and Texas in requiring GPC recognition.

Effective: January 15, 2025

Minor / Child Protections

The NJDPA requires opt-in consent for processing personal data of known children under 13. For consumers under 17, the law prohibits the sale of personal data and targeted advertising without affirmative consent. This is one of the broader minor protection provisions among state privacy laws.

Compliance Checklist

  1. 1Determine applicability: assess whether you process personal data of 100,000+ NJ consumers (excluding payment-only data) OR 25,000+ consumers while deriving any revenue from data sales — note that NJ has no minimum revenue percentage threshold unlike CT/VA (25%) or other states. Check entity-level HIPAA and GLBA exemptions
  2. 2Implement GPC/universal opt-out signal recognition: detect and honor Global Privacy Control signals for opt-out-of-sale and opt-out-of-targeted-advertising, ensure downstream propagation to processors and third-party recipients, test across all major browsers, and log all signal receipt and processing for compliance documentation
  3. 3Update privacy notices with all NJDPA-required disclosures: categories of personal data processed, purposes, categories of third parties receiving data, consumer rights and how to exercise them, sensitive data processing practices, and sale/targeted advertising disclosures. Reference proposed regulations for specific format requirements once finalized
  4. 4Build consumer rights request intake and fulfillment system: support access, correction, deletion, and portability requests with 45-day initial response window plus 45-day extension when reasonably necessary. Acknowledge receipt within 10 business days per proposed regulations. Maintain logs of all requests for at least 24 months
  5. 5Obtain opt-in consent for all sensitive data processing: implement clear, affirmative consent mechanisms for all 9 sensitive data categories (racial/ethnic origin, religious beliefs, health data, sexual orientation, citizenship/immigration status, genetic data, biometrics, children's data, precise geolocation). Avoid dark patterns per proposed regulations
  6. 6Implement minor protection controls: prohibit sale of personal data and targeted advertising for consumers under 17 without affirmative consent, require opt-in for all processing of known children under 13 data. Age-gate or age-verify where feasible to prevent inadvertent violations
  7. 7Establish appeals process for denied consumer requests: provide clear mechanism for consumers to appeal, respond to appeals within a reasonable timeframe, and if the appeal is denied, inform the consumer how to file a complaint with the Division of Consumer Affairs
  8. 8Conduct data protection assessments for high-risk processing: targeted advertising, sale of personal data, processing of sensitive data, and profiling with risk of unfair treatment or disparate impact. Document benefit-vs-risk analysis and maintain assessments for AG review upon request
  9. 9Review and update processor contracts: ensure all data processing agreements include NJDPA-compliant provisions on data use limitations, confidentiality, subcontractor flow-down requirements, and assistance with consumer rights requests. Refresh pre-2025 contracts
  10. 10Implement data minimization and retention practices: collect only data reasonably necessary for disclosed purposes, establish retention schedules, and document justification for data retained beyond 12 months. Proposed regulations will require maintaining a data inventory
  11. 11Operate under post-cure-period enforcement (in force since July 1, 2026): maintain an AG-inquiry response playbook — (1) designate a privacy response team and external counsel contact, (2) document all compliance measures proactively, (3) keep a rapid-response process for AG notices ready, since cure is now discretionary rather than guaranteed, (4) run a compliance audit now if you have not already, as there is no longer a statutory window to remediate after notice, (5) monitor proposed regulation adoption for additional requirements
  12. 12Check data broker registration: if your business qualifies as a data broker under NJ's separate data broker law, register annually with the Division of Consumer Affairs and comply with additional broker-specific obligations
  13. 13Map multistate compliance obligations: compare NJDPA requirements against CT CTDPA, DE DPDPA, MD MODPA, and other northeastern state laws to identify conflicts and build unified compliance processes. NJ's broader sensitive data definition and stronger minor protections may require NJ-specific controls even if compliant with other states
Put NJDPA Into Practice on Your SiteSponsored

Termly builds and maintains a New Jersey-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests NJDPA grants.

Start Free with Termly

New Jersey Privacy Law FAQ

Official Resources