EnglishEspañol
New Jersey flag

New Jersey

New Jersey Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 8 primary sources cited on this page. How we verify our legal content

New Jersey Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does New Jersey have a standalone biometric privacy law like Illinois BIPA?

No. New Jersey protects biometric data through the New Jersey Data Privacy Act (NJDPA), P.L. 2023, c.266, which is a comprehensive consumer data privacy law that took effect January 15, 2025. Biometric data is classified as sensitive data under the NJDPA, triggering the highest level of protection including mandatory affirmative consent before collection. New Jersey does not have a separate biometric-specific statute.

Can I sue a company in New Jersey for collecting my biometric data without consent?

Not directly under the NJDPA. The statute explicitly states it does not provide the basis for a private right of action. Only the Attorney General can enforce the NJDPA. However, because NJDPA violations are classified as unlawful practices under the New Jersey Consumer Fraud Act (CFA), and the CFA does allow private lawsuits with treble damages, some legal experts believe consumers may eventually be able to bring CFA claims based on NJDPA violations. This question has not been tested in court.

What biometric data does New Jersey law cover?

The NJDPA covers data generated by automatic or technological processing of biological, physical, or behavioral characteristics used to identify a person. This explicitly includes fingerprints, voiceprints, eye retinas, irises, facial mapping, facial geometry, and facial templates. The definition also includes a catch-all for other unique biological, physical, or behavioral patterns. Photographs, audio recordings, and video recordings are excluded unless they are specifically processed through technology to identify an individual.

What are the penalties for violating New Jersey biometric privacy rules?

NJDPA violations are treated as Consumer Fraud Act violations. The Attorney General can impose penalties of up to $10,000 for a first offense and up to $20,000 for each subsequent offense. The AG can also seek injunctive relief and other remedies. During the first 18 months (through July 1, 2026), the Division of Consumer Affairs was required to issue a 30-day cure notice before enforcement only where it deemed a cure possible. That mandatory cure window has now ended, and the Attorney General has full discretion over whether to offer a cure opportunity before pursuing enforcement.

Do employers in New Jersey need consent to collect employee fingerprints?

No. The NJDPA's consent and rights requirements apply only to consumers, and the statute defines that term to exclude anyone acting in a commercial or employment context (C.56:8-166.4). Employee biometric data, such as fingerprint time clocks or facial scans for building access, falls outside the NJDPA entirely, so employers are not required to obtain NJDPA-style consent for it. New Jersey does not have a BIPA-style statute covering workplace biometric data specifically, so employers should look to general data-security and negligence principles under New Jersey law and consult employment counsel about their specific obligations.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the NJDPA applicability thresholds to include the discount-on-goods-or-services alternative and the payment-transaction exclusion, and named the Division of Consumer Affairs as the agency that had to issue the 30-day cure notice.

Corrected this page to state that the NJDPA does not cover employee/workplace biometric data (its consumer definition excludes employment contexts), fixed the cure-period sunset date to July 1, 2026 (was misstated as July 15, 2026 and as still upcoming rather than already past), clarified that the AG's cure notice was conditional rather than guaranteed, and fixed the comparison table to show Illinois BIPA has no Attorney General enforcement mechanism.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the description of what does not count as valid NJDPA consent: the statute excludes acceptance of broad terms-of-use, hovering/muting/pausing/closing content, and dark patterns -- not 'pre-checked boxes, silence, or inactivity,' which do not appear in the definition.

Corrected the NJDPA sensitive-data list to include 'financial information' and 'status as transgender or non-binary,' both of which N.J.S.A. 56:8-166.4 enumerates but the article had omitted.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. New Jersey Data Privacy Act (P.L. 2023, c.266)(njleg.state.nj.us).gov
  2. NJDPA Bill Text (S332)(njleg.state.nj.us).gov
  3. NJ Attorney General Consumer Protection(njoag.gov).gov
  4. NJDPA Proposed Rules Announcement(njoag.gov).gov
  5. NJ Cybersecurity NJDPA Overview(cyber.nj.gov).gov
  6. NJ Consumer Fraud Act(njconsumeraffairs.gov).gov
  7. NJ Consumer Fraud Act Jury Charges (56:8-19)(njcourts.gov).gov
  8. Proposed Biometric Surveillance Bill S1464(njleg.gov).gov
Share: