New Jersey
New Jersey Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 8 primary sources cited on this page. How we verify our legal content

New Jersey regulates biometric data under the New Jersey Data Privacy Act (NJDPA), P.L. 2023, c.266, which took effect January 15, 2025. The NJDPA classifies biometric data as sensitive data, requiring affirmative opt-in consent before any collection or processing. The Attorney General has sole enforcement authority; there is no standalone biometric statute.
New Jersey takes biometric privacy seriously. The state rolled out one of the broadest biometric data definitions in the country when the New Jersey Data Privacy Act (NJDPA) took effect on January 15, 2025. Unlike states that passed narrow biometric-only statutes, New Jersey embedded biometric protections within a comprehensive consumer data privacy framework that covers everything from fingerprints to facial geometry.
If you collect, store, or process biometric data from New Jersey residents, here is what the law requires.
How New Jersey Defines Biometric Data
The NJDPA provides one of the most expansive biometric data definitions in the United States. Under N.J.S.A. 56:8-166.4, "biometric data" means:
Data generated by automatic or technological processing, measurements, or analysis of an individual's biological, physical, or behavioral characteristics, including, but not limited to, fingerprint, voiceprint, eye retinas, irises, facial mapping, facial geometry, facial templates, or other unique biological, physical, or behavioral patterns or characteristics that are used or intended to be used, singularly or in combination with each other or with other personal data, to identify a specific individual.
This definition goes further than many state laws. The inclusion of "facial mapping," "facial geometry," and "facial templates" as separate categories means New Jersey covers the full spectrum of facial recognition technology inputs and outputs. The "other unique biological, physical, or behavioral patterns" catch-all gives the law room to cover emerging technologies like gait analysis, vein pattern recognition, and keystroke dynamics.
What Is Not Biometric Data
The NJDPA carves out specific exclusions. The following do not qualify as biometric data:
- Digital or physical photographs
- Audio or video recordings
- Data generated from photographs or recordings, unless that data is specifically generated through automatic or technological processing to identify an individual
This distinction matters. A security camera recording of a customer walking through a store is not biometric data. However, running that footage through facial recognition software that generates a facial geometry template does create biometric data under New Jersey law.

Biometric Data as Sensitive Data
The NJDPA classifies biometric data as a category of sensitive data. The statute defines sensitive data as personal data revealing racial or ethnic origin, religious beliefs, mental or physical health conditions, financial information (including a consumer's account number, account log-in, financial account, or credit or debit card number in combination with a required security code, access code, or password), sex life or sexual orientation, citizenship or immigration status, status as transgender or non-binary, genetic or biometric data processed for the purpose of uniquely identifying an individual, personal data collected from a known child, or precise geolocation data.
This sensitive data classification triggers the highest level of protection the NJDPA offers.
Consent Requirements for Biometric Data
Because biometric data qualifies as sensitive data, controllers face strict consent rules under Section 9 of the NJDPA. A controller must not process sensitive data concerning a consumer without first obtaining the consumer's consent.
"Consent" under the NJDPA means a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to the processing of personal data. The statute specifically says consent does not include acceptance of a general or broad terms-of-use document, hovering over, muting, pausing, or closing a piece of content, or agreement obtained through dark patterns.
In practice, this means businesses must:
- Clearly inform the consumer about what biometric data will be collected
- Explain the specific purpose for processing the biometric data
- Obtain an affirmative opt-in before collection begins
- Allow the consumer to withdraw consent at any time
This requirement applies to any controller that conducts business in New Jersey or produces products or services targeted to New Jersey residents, and that during a calendar year either controls or processes the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction, or controls or processes the personal data of at least 25,000 consumers and derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data (N.J.S.A. 56:8-166.5).
This consent requirement runs only to consumers. The NJDPA defines "consumer" as a person acting only in an individual or household context, and it expressly excludes anyone acting in a commercial or employment context (N.J.S.A. 56:8-166.4). That means employee biometric data, such as fingerprint time clocks or facial-recognition badge access, is not covered by the NJDPA's consent and rights requirements at all.
Consumer Rights Over Biometric Data
New Jersey residents have five core rights over their biometric data under the NJDPA:
Right to Confirm and Access. Consumers can ask whether a controller processes their biometric data and obtain a copy of that data.
Right to Correct. If biometric data is inaccurate, consumers can request corrections.
Right to Delete. Consumers can request that a controller delete their biometric data.
Right to Data Portability. Consumers can obtain their biometric data in a portable, readily usable format that allows transfer to another controller.
Right to Opt Out. Consumers can opt out of the processing of their biometric data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
Controllers must respond to consumer requests within 45 days. They may extend this by an additional 45 days when reasonably necessary, provided they notify the consumer of the extension and the reason for it.

Enforcement and Penalties
Attorney General Authority
The NJDPA grants the Office of the Attorney General sole and exclusive authority to enforce the law. No other state agency, local government, or private individual can bring an enforcement action directly under the NJDPA.
Consumer Fraud Act Penalties
Section 14 of the NJDPA classifies any violation as "an unlawful practice and violation of P.L.1960, c.39 (C.56:8-1 et seq.)," which is the New Jersey Consumer Fraud Act (CFA). This linkage carries real consequences:
- First violation: Up to $10,000
- Subsequent violations: Up to $20,000 each
- The Attorney General can seek injunctive relief, civil penalties, and other remedies available under the CFA
The 30-Day Cure Period
During the first 18 months after the NJDPA took effect (January 15, 2025 through July 1, 2026), the Division of Consumer Affairs in the Department of Law and Public Safety, which sits within the Attorney General's office, was required to issue a notice to the controller before bringing an enforcement action, but only where a cure was deemed possible (N.J.S.A. 56:8-166.17(b)). For violations the Division did not consider curable, it could proceed directly to enforcement even during that window. If the controller cured the alleged violation within 30 days of receiving that notice, no enforcement action followed.
That mandatory cure window ended July 1, 2026. The Attorney General now has full discretion over whether to offer any cure opportunity before pursuing enforcement, and businesses should already be in compliance.
The Private Right of Action Question
The NJDPA explicitly states that "nothing in P.L.2023, c.266 shall be construed as providing the basis for...a private right of action." This means consumers cannot sue businesses directly under the NJDPA for mishandling their biometric data.
However, New Jersey legal commentators have noted a tension in the statute. The CFA itself, under N.J.S.A. 56:8-19, provides a private right of action for any person who suffers an ascertainable loss from an unlawful practice. A successful CFA plaintiff receives treble damages (three times actual losses), plus attorney fees and court costs. Since NJDPA violations are classified as CFA unlawful practices, the question of whether a consumer could bring a CFA claim based on a NJDPA violation remains untested in court. Businesses should not assume they are immune from private litigation.

Comparison with Other State Biometric Laws
New Jersey's approach differs from the two other major models in the United States:
| Feature | New Jersey (NJDPA) | Illinois (BIPA) | Texas (CUBI) |
|---|---|---|---|
| Law Type | Comprehensive privacy law | Standalone biometric statute | Standalone biometric statute |
| Biometric Definition | Broad (includes facial mapping, geometry, templates) | Narrower (retina, iris, fingerprint, voiceprint, hand/face geometry) | Similar to Illinois |
| Consent Required | Affirmative opt-in for sensitive data | Written informed consent | Informed consent |
| Private Right of Action | None under NJDPA (CFA question open) | Yes, any violation | None (AG only) |
| Damages | $10,000/$20,000 per violation (AG) | $1,000/$5,000 per violation (private) | $25,000 per violation (AG) |
| Enforcement | AG only | Private lawsuits only (no AG enforcement provision in BIPA) | AG only |
| Photo/Video Exclusion | Yes, unless processed for identification | Yes | Yes |
New Jersey's broad definition gives it wider coverage than Illinois on paper, but Illinois remains the more aggressive enforcement environment because of its private right of action, which has driven billions of dollars in settlements.
Proposed Biometric Surveillance Legislation
The New Jersey Legislature has continued to consider additional biometric protections. Senate Bill 1464 (introduced in the 2026 session) would prohibit businesses from selling, leasing, trading, or sharing information obtained through biometric surveillance systems. Violations would be treated as CFA unlawful practices with the same $10,000/$20,000 penalty structure.
This proposed legislation targets commercial facial recognition and remote biometric monitoring systems specifically. It would supplement the NJDPA's broader data privacy framework with targeted restrictions on biometric surveillance in commercial settings.
Attorney General Rulemaking
The Office of the Attorney General announced proposed rules in 2025 to implement the NJDPA through the Division of Consumer Affairs. These rules address controller obligations for data handling, consent mechanisms, universal opt-out compliance, and consumer rights processing. The public comment period ran from June 2, 2025, through August 1, 2025, and the Division is expected to publish a Notice of Adoption in 2026.
These regulations will provide more specific guidance on how businesses should handle biometric data consent, storage, and processing under the NJDPA framework.
Practical Compliance Steps for Businesses
Organizations that collect biometric data from New Jersey residents should take these steps:
Audit your biometric data collection. Identify every point where you collect fingerprints, facial scans, voiceprints, iris scans, or other biometric identifiers from New Jersey consumers. The NJDPA's consumer definition excludes anyone acting in a commercial or employment context, so employee biometric data, such as time-clock fingerprints or badge-access facial scans, falls outside the NJDPA and should be tracked separately from consumer-facing collection.
Implement affirmative consent mechanisms. Build clear, specific opt-in flows for biometric data collection. Generic privacy policy disclosures are not sufficient under the NJDPA.
Honor consumer rights requests. Set up systems to process access, correction, deletion, portability, and opt-out requests within the 45-day response window.
Review vendor contracts. If you share biometric data with processors, ensure your contracts require them to follow the same protections required by the NJDPA.
The cure period has already ended. The mandatory 30-day cure window closed July 1, 2026. The Attorney General now has full discretion over whether to offer any cure opportunity before pursuing enforcement, so businesses should already be compliant.
Sources and References
This article references New Jersey statutes and official government publications. For the full text of the NJDPA, visit the New Jersey Legislature. For Attorney General enforcement updates, visit njoag.gov. For the NJDPA definitions codified at N.J.S.A. 56:8-166.4, see the New Jersey Cybersecurity & Communications Integration Cell overview.
This article provides general legal information about New Jersey biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official New Jersey government sources.
More New Jersey Laws
Frequently Asked Questions
Does New Jersey have a standalone biometric privacy law like Illinois BIPA?
No. New Jersey protects biometric data through the New Jersey Data Privacy Act (NJDPA), P.L. 2023, c.266, which is a comprehensive consumer data privacy law that took effect January 15, 2025. Biometric data is classified as sensitive data under the NJDPA, triggering the highest level of protection including mandatory affirmative consent before collection. New Jersey does not have a separate biometric-specific statute.
Can I sue a company in New Jersey for collecting my biometric data without consent?
Not directly under the NJDPA. The statute explicitly states it does not provide the basis for a private right of action. Only the Attorney General can enforce the NJDPA. However, because NJDPA violations are classified as unlawful practices under the New Jersey Consumer Fraud Act (CFA), and the CFA does allow private lawsuits with treble damages, some legal experts believe consumers may eventually be able to bring CFA claims based on NJDPA violations. This question has not been tested in court.
What biometric data does New Jersey law cover?
The NJDPA covers data generated by automatic or technological processing of biological, physical, or behavioral characteristics used to identify a person. This explicitly includes fingerprints, voiceprints, eye retinas, irises, facial mapping, facial geometry, and facial templates. The definition also includes a catch-all for other unique biological, physical, or behavioral patterns. Photographs, audio recordings, and video recordings are excluded unless they are specifically processed through technology to identify an individual.
What are the penalties for violating New Jersey biometric privacy rules?
NJDPA violations are treated as Consumer Fraud Act violations. The Attorney General can impose penalties of up to $10,000 for a first offense and up to $20,000 for each subsequent offense. The AG can also seek injunctive relief and other remedies. During the first 18 months (through July 1, 2026), the Division of Consumer Affairs was required to issue a 30-day cure notice before enforcement only where it deemed a cure possible. That mandatory cure window has now ended, and the Attorney General has full discretion over whether to offer a cure opportunity before pursuing enforcement.
Do employers in New Jersey need consent to collect employee fingerprints?
No. The NJDPA's consent and rights requirements apply only to consumers, and the statute defines that term to exclude anyone acting in a commercial or employment context (C.56:8-166.4). Employee biometric data, such as fingerprint time clocks or facial scans for building access, falls outside the NJDPA entirely, so employers are not required to obtain NJDPA-style consent for it. New Jersey does not have a BIPA-style statute covering workplace biometric data specifically, so employers should look to general data-security and negligence principles under New Jersey law and consult employment counsel about their specific obligations.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the NJDPA applicability thresholds to include the discount-on-goods-or-services alternative and the payment-transaction exclusion, and named the Division of Consumer Affairs as the agency that had to issue the 30-day cure notice.
Corrected this page to state that the NJDPA does not cover employee/workplace biometric data (its consumer definition excludes employment contexts), fixed the cure-period sunset date to July 1, 2026 (was misstated as July 15, 2026 and as still upcoming rather than already past), clarified that the AG's cure notice was conditional rather than guaranteed, and fixed the comparison table to show Illinois BIPA has no Attorney General enforcement mechanism.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the description of what does not count as valid NJDPA consent: the statute excludes acceptance of broad terms-of-use, hovering/muting/pausing/closing content, and dark patterns -- not 'pre-checked boxes, silence, or inactivity,' which do not appear in the definition.
Corrected the NJDPA sensitive-data list to include 'financial information' and 'status as transgender or non-binary,' both of which N.J.S.A. 56:8-166.4 enumerates but the article had omitted.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Jersey Statutes (Unannotated)
§ 56:8-166.12Controller, personal data, responsibilities, security.In forcecited in 2 of our articles
9. a. A controller shall: (1) limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; (2) except as otherwise provided in P.L.2023, c.266 (C.56:8-166.4 et seq.), not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; (3) take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data and to secure personal data during both storage and use from unauthorized acquisition.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: NJDPA Compliance Checklist: New Jersey Privacy
§ 56:8-166.4Definitions.In forcecited in 5 of our articles
1. As used in P.L.2023, c.266 (C.56:8-166.4 et seq.): "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" means: the ownership of or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; the control in any manner over the election of a majority of the directors or individuals exercising similar functions; or the power to exercise a controlling influence over the management or policies of a company. "Biometric data" means data generated by automatic or technological processing, measurements, or analysis of an individual's biological, physical, or behavioral characteristics, including, but not limited to, fingerprint, voiceprint, eye retinas, irises, facial mapping, facial geometry, facial templates, or other unique biological, physical, or behavioral patterns or characteristics that are used or intended to be used, singularly or in combination with each other or with other personal data, to identify a specific individual.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: New Jersey Data Privacy Laws: NJDPA Consumer Rights Guide (2026), NJDPA Consumer Rights: New Jersey Privacy Law, What Is the NJDPA? New Jersey Data Privacy Act
§ 56:8-19Action, counterclaim by injured person; recovery of damages, costs.In force
7. Any person who suffers any ascertainable loss of moneys or property, real or personal, as a result of the use or employment by another person of any method, act, or practice declared unlawful under this act or the act hereby amended and supplemented may bring an action or assert a counterclaim therefor in any court of competent jurisdiction. In any action under this section the court shall, in addition to any other appropriate legal or equitable relief, award threefold the damages sustained by any person in interest. In all actions under this section, including those brought by the Attorney General, the court shall also award reasonable attorneys' fees, filing fees and reasonable costs of suit.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Cited in 275 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Gennari v. Weichert Co. Realtors (Supreme Court of New Jersey 1997, 148 N.J. 582)“…in interest. [L.1971 c. 247 § 7, codified at N.J.S.A 56:8-19.] Then, in 1975, the Legislature…”
- Cox v. Sears Roebuck & Co. (Supreme Court of New Jersey 1994, 138 N.J. 2)“…6,830 for Cox, trebling it to $20,490 as required by N.J.S.A. 56:8-19, and dismissed Seal’s’ counterclaim. De…”
- Bosland v. Warnock Dodge, Inc. (Supreme Court of New Jersey 2009, 197 N.J. 543)“…c. 247, § 7, the provision subsequently codified at N.J.S.A. 56:8-19. That section, which is central to the…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 56:8-1Definitions.In forcecited in 3 of our articles
1. (a) The term "advertisement" shall include the attempt directly or indirectly by publication, dissemination, solicitation, indorsement or circulation or in any other way to induce directly or indirectly any person to enter or not enter into any obligation or acquire any title or interest in any merchandise or to increase the consumption thereof or to make any loan; (b) The term "Attorney General" shall mean the Attorney General of the State of New Jersey or any person acting on his behalf; (c) The term "merchandise" shall include any objects, wares, goods, commodities, services or anything offered, directly or indirectly to the public for sale; (d) The term "person" as used in this act shall include any natural person or his legal representative, partnership, corporation, company, trust, business entity or association, and any agent, employee, salesman, partner, officer, director, member, stockholder, associate, trustee or cestuis que trustent thereof; (e) The term "sale" shall include any sale, rental or distribution, offer for sale, rental or distribution or attempt directly or indirectly to sell, rent or distribute; (f) The term "senior citizen" means a…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Cited in 891 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Anthony D'agostino v. Ricardo Maldonado (068940) (Supreme Court of New Jersey 2013, 216 N.J. 168)“…the application of the New Jersey Consumer Fraud Act (CFA), N.J.S.A. 56:8-1 to -20 to a mortgage foreclosure rescue…”
- Tahir Zaman v. Barbara Felton (072128) (Supreme Court of New Jersey 2014, 219 N.J. 199)“…nder of title, violations of the Consumer Fraud Act (CFA), N.J.S.A. 56:8-1 to -195, and violations of other federa…”
- Manahawkin Convalescent v. Frances O'neill (071033) (Supreme Court of New Jersey 2014, 217 N.J. 99)“…the contract’s validity under the Consumer Fraud Act (CFA), N.J.S.A. 56:8-1 to -20, and the Truth-in- Consumer Cont…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: New Jersey Lemon Law (2026): How to Qualify & Get a Refund
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- New Jersey Data Privacy Act (P.L. 2023, c.266)(njleg.state.nj.us).gov
- NJDPA Bill Text (S332)(njleg.state.nj.us).gov
- NJ Attorney General Consumer Protection(njoag.gov).gov
- NJDPA Proposed Rules Announcement(njoag.gov).gov
- NJ Cybersecurity NJDPA Overview(cyber.nj.gov).gov
- NJ Consumer Fraud Act(njconsumeraffairs.gov).gov
- NJ Consumer Fraud Act Jury Charges (56:8-19)(njcourts.gov).gov
- Proposed Biometric Surveillance Bill S1464(njleg.gov).gov