New Jersey
New Jersey Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 3 primary sources cited on this page. How we verify our legal content

New Jersey requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay under N.J.S.A. 56:8-163. The New Jersey Division of State Police must receive notice before individual notifications are sent.
If your business handles personal information belonging to New Jersey residents, a data breach triggers strict notification obligations. New Jersey's breach notification law, codified at N.J. Stat. 56:8-161 through 56:8-166, requires disclosure in the most expedient time possible and without unreasonable delay, with no fixed day-count deadline. The law's broad personal information definition, its pre-disclosure notice requirement to the Division of State Police, and the state's private right of action for willful, knowing, or reckless violations under the Consumer Fraud Act make New Jersey one of the more demanding states for breach response.
This guide covers the full scope of New Jersey's breach notification requirements, including what personal information triggers the law, who must be notified, the timelines, the private right of action, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With New Jersey's Breach Notification Law
Under N.J. Stat. 56:8-163, the duty falls on any business that conducts business in New Jersey, and on any public entity that compiles or maintains computerized records that include personal information. Both private businesses and government entities must comply.
A company headquartered outside New Jersey is covered when it conducts business in the state. Merely holding a New Jersey resident's data, without conducting business in New Jersey, is not by itself the statutory trigger. There is no minimum size threshold. A sole proprietor that maintains one customer's personal information has the same obligations as a multinational corporation.

When a third party that maintains data on behalf of a business discovers a breach, it must notify the business immediately. The business then carries the primary responsibility to notify affected individuals and state agencies.
What Qualifies as a Breach
Under N.J. Stat. 56:8-161, a "breach of security" means the unauthorized access to electronic files, media, or data containing personal information that compromises the security, confidentiality, or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable.
Encryption Safe Harbor
New Jersey provides an encryption safe harbor. If the compromised personal information was secured by encryption or another method that renders it unreadable or unusable, and the encryption key or security credential was not also compromised, notification is not required.

Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the business for a legitimate business purpose does not constitute a breach, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Personal Information That Triggers Notification
A 2019 amendment (L.2019, c.95) broadened New Jersey's definition of personal information to include online account credentials. Under N.J. Stat. 56:8-161, personal information means an individual's first name or first initial and last name combined with any one or more of the following:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the account
- Username or email address combined with a password or security question and answer that would permit access to an online account
The addition of username/email plus password combinations reflects the growing risk of credential-based attacks and account takeover fraud.
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Notification Timeline
New Jersey does not set a fixed day-count deadline for breach notification.
The "Most Expedient Time Possible" Standard
Notification must be made "in the most expedient time possible and without unreasonable delay," consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. New Jersey does not have a separate deadline for social media platform breaches; the same expedient-time standard applies regardless of the type of business involved.
When Delay Is Permitted
The statute contains one true delay provision. Under N.J. Stat. 56:8-163(c)(2), notification must be delayed if a law enforcement agency determines that it will impede a criminal or civil investigation and has requested the delay. Notification is then made after that agency determines its disclosure will not compromise the investigation and notifies the business or public entity.
Time spent on measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system is not a separate authorization to delay. Subsection (a) folds that work into the "most expedient time possible" standard itself, so it is measured inside the notification obligation rather than suspending it.
The statute imposes no requirement to document the reasons for a law enforcement delay. New Jersey's written-documentation duty attaches to a different determination entirely, described under Exemptions below.
Who Must Be Notified
New Jersey State Police
The New Jersey Division of State Police must be notified before individual notifications are sent, per N.J. Stat. 56:8-163(c)(1). The report goes to State Police for investigation or handling, which may include referral to other law enforcement entities. The Attorney General's Division of Consumer Affairs is not a pre-disclosure notice recipient under the statute; its role is limited to enforcing the law after the fact under the Consumer Fraud Act.
The statute does not prescribe what that report has to contain. N.J. Stat. 56:8-163(c)(1) requires only that the business or public entity report "the breach of security and any information pertaining to the breach" to the Division of State Police, which leaves the level of detail to the agency's own reporting process rather than fixing it in the statute.
Affected Individuals
Every New Jersey resident whose personal information was or is reasonably believed to have been accessed by an unauthorized person must be notified.
New Jersey's statute governs the timing and the permitted methods of that notice, not its contents. Unlike several other states, N.J. Stat. 56:8-163 sets out no list of elements a consumer notification letter must contain. The single exception is the credential-only breach described below, where subsection (g)(1) requires the notice to direct the customer to change the affected password and security question. Beyond that, what goes in the letter is a matter of practice and of whatever other law applies to the breach, not of a checklist in this statute.
Consumer Reporting Agencies
When notification under this section is required for more than 1,000 persons at one time, the business must also notify the nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution, and content of the notices.
How to Provide Notification
New Jersey permits the following notification methods:
- Written notice sent by mail or delivered to the individual
- Electronic notice consistent with the E-SIGN Act (15 U.S.C. 7001)

Substitute Notice
Substitute notice is available when:
- The cost of providing notice would exceed $250,000
- The affected class exceeds 500,000 individuals
- The business does not have sufficient contact information
Substitute notice must include all of the following:
- Email notification to individuals for whom the business has an email address
- Conspicuous posting of the notice on the business's website
- Notification to major statewide media outlets
Credential-Only Breaches
When a breach involves a user name or email address together with a password or security question and answer that would permit access to an online account, and no other category of personal information, N.J. Stat. 56:8-163(g)(1) permits notice in electronic or other form that directs the affected customer to promptly change the password and security question or answer, or to take other appropriate steps to protect that account and any other online accounts using the same credentials.
Subsection (g)(2) adds a restriction that catches businesses operating email services. An entity that furnishes an email account may not send the breach notice to the email account that was itself breached. It must use another method allowed by the statute, or give clear and conspicuous notice to the customer online when the customer connects to the account from an Internet Protocol address or online location the entity knows the customer customarily uses.
Private Right of Action and Treble Damages
A willful, knowing, or reckless violation of New Jersey's breach notification law is an unlawful practice under the Consumer Fraud Act (N.J. Stat. 56:8-166). This matters because the Consumer Fraud Act provides a private right of action with treble damages for that class of violation.
Under the Consumer Fraud Act, a person who suffers an ascertainable loss because of a willful, knowing, or reckless violation may bring a civil action and recover:
- Treble (triple) damages for the ascertainable loss
- Reasonable attorneys' fees
- Filing fees and reasonable costs of suit
This makes New Jersey one of the more plaintiff-friendly states for data breach litigation when a violation rises to that level. Unlike most states where only the Attorney General can enforce the breach notification law, New Jersey also allows individuals to sue directly for willful, knowing, or reckless violations. A merely negligent delay in notification does not by itself trigger this private remedy.
Class Action Exposure
The private right of action, combined with treble damages, can create substantial class action exposure when a violation is willful, knowing, or reckless. A breach affecting thousands of New Jersey residents could generate claims multiplied by three, plus attorneys' fees, if that standard is met. This risk profile makes New Jersey compliance particularly important for businesses.
Enforcement and Penalties
In addition to private litigation, the New Jersey Attorney General can enforce the breach notification law under the Consumer Fraud Act. The AG may seek:
- Civil penalties of up to $10,000 for the first offense
- Civil penalties of up to $20,000 for the second and each subsequent offense
- Injunctive relief
- Restitution for affected consumers
N.J. Stat. 56:8-13 states those figures as maximums rather than set amounts, providing a penalty of not more than $10,000 for the first offense and not more than $20,000 for the second and each subsequent offense, so the penalty in any given case is whatever is fixed within those ceilings. The escalating structure still means that businesses with repeat violations face rapidly increasing exposure. Combined with the private right of action, New Jersey's enforcement framework is among the most aggressive in the country.
Exemptions
New Jersey's Identity Theft Prevention Act does not include a HIPAA-covered-entity exemption or a financial-institution exemption from breach notification. The statute's definition of a covered business explicitly includes financial institutions, with no carve-out for entities already regulated at the federal level.
Four provisions can relieve a business of the duty to notify. Two of them work by keeping the incident outside the definition of a breach in the first place, and two operate on the notification duty itself:
- Encryption safe harbor. Information secured by encryption, or by another method that renders it unreadable or unusable, with the encryption key uncompromised, does not meet the definition of a breach of security.
- Good faith acquisition. A good faith acquisition of personal information by an employee or agent for a legitimate business purpose is not a reportable breach, provided the information is not used for a purpose unrelated to the business or subject to further unauthorized disclosure.
- Misuse not reasonably possible. N.J. Stat. 56:8-163(a) provides that disclosure to a customer is not required if the business or public entity establishes that misuse of the information is not reasonably possible. This is the risk-of-harm analysis most often relied on in real New Jersey breach response. The statute attaches a condition: any such determination must be documented in writing and retained for five years.
- Own notification procedures. Under subsection (e), a business or public entity that maintains its own notification procedures as part of an information security policy, and is otherwise consistent with the requirements of the section, is deemed to be in compliance if it notifies affected customers in accordance with those policies.
How New Jersey's Privacy Laws Interact With Breach Notification
The New Jersey Data Privacy Act (NJDPA), effective January 15, 2025, created a comprehensive consumer privacy framework. The NJDPA does not contain its own breach notification requirements. Businesses subject to the NJDPA must still follow N.J. Stat. 56:8-161 for breach notification.
The NJDPA adds relevant data protection obligations:
- Data security requirement: Controllers must implement reasonable administrative, technical, and physical data security practices.
- Data minimization: Controllers must limit data collection to what is adequate, relevant, and reasonably necessary.
- Sensitive data consent: Biometric data, precise geolocation, children's data, and other sensitive categories require explicit consumer consent.
The NJDPA is enforced separately by the Attorney General under the Consumer Fraud Act. Unlike the breach notification law's private right of action for willful, knowing, or reckless violations, the NJDPA itself creates no private right of action; only the Attorney General may enforce it.
This article provides general legal information about New Jersey data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New Jersey for guidance specific to your situation.
More New Jersey Laws
Frequently Asked Questions
How long does a business have to notify New Jersey residents of a data breach?
New Jersey does not set a fixed number of days. The law requires notification 'in the most expedient time possible and without unreasonable delay,' and it has no separate deadline for social media platform breaches. The New Jersey Division of State Police must be notified before individual notification is sent.
Can individuals sue for a data breach in New Jersey?
Yes, for willful, knowing, or reckless violations. Such a violation of New Jersey's breach notification law is an unlawful practice under the Consumer Fraud Act (N.J. Stat. 56:8-166), which provides a private right of action. Affected individuals who show an ascertainable loss can sue and recover treble (triple) damages, plus reasonable attorneys' fees and costs. A merely negligent delay does not by itself trigger this remedy.
What are the penalties for failing to notify in New Jersey?
The Attorney General can seek civil penalties of up to $10,000 for the first offense and up to $20,000 for the second and each subsequent offense under the Consumer Fraud Act (N.J. Stat. 56:8-13). Those figures are statutory maximums, not fixed amounts. Additionally, for willful, knowing, or reckless violations, affected individuals who show an ascertainable loss can bring private lawsuits and recover treble damages, attorneys' fees, and costs.
Does New Jersey have a special deadline for social media breach notification?
No. New Jersey does not have a separate notification deadline for social media platforms. The same 'most expedient time possible and without unreasonable delay' standard that applies to any business or public entity applies to social media operators as well.
Does encryption protect businesses from New Jersey's breach notification requirements?
Yes, New Jersey provides an encryption safe harbor. If the compromised personal information was secured by encryption or another method that renders it unreadable or unusable, and the encryption key was not also compromised, notification is not required. If the key was also acquired, the safe harbor does not apply.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the exemptions section to include the statutory risk-of-harm exception and the own-notification-procedures provision, removed notice-content requirements that do not appear in the statute, added the credential-breach notification rules, narrowed the scope description to businesses conducting business in New Jersey, and clarified that the civil penalties are maximums.
Corrected who must be notified before a breach disclosure (New Jersey law requires advance notice to the Division of State Police only, not the Attorney General), removed an inaccurate HIPAA/financial-institution exemption section, and corrected the personal-information definition's amendment date from 2024 to 2019.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed a fabricated 30-day/7-day breach notification deadline that does not appear in current New Jersey law (N.J.S.A. 56:8-163 uses only a 'most expedient time possible' standard), and clarified that the Consumer Fraud Act's private right of action and treble damages apply to willful, knowing, or reckless violations, not any violation.
Fixed three inline citation links that pointed to the NJ Legislature's S2062 bill-search page (the source of a since-corrected fabricated deadline) so they now point to the official statute text on njconsumeraffairs.gov.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Jersey Statutes (Unannotated)
§ 56:8-163Disclosure of breach of security to customers.In forcecited in 2 of our articles
12. a. Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information, shall disclose any breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person. The disclosure to a customer shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection c. of this section, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Disclosure of a breach of security to a customer shall not be required under this section if the business or public entity establishes that misuse of the information is not reasonably possible. Any determination shall be documented in writing and retained for five years.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: New Jersey Data Privacy Laws: NJDPA Consumer Rights Guide (2026)
§ 56:8-161Definitions relative to security of personal information.In forcecited in 2 of our articles
10. As used in sections 10 through 15 of P.L.2005, c.226 (C.56:8-161 through C.56:8-166): "Breach of security" means unauthorized access to electronic files, media or data containing personal information that compromises the security, confidentiality or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable. Good faith acquisition of personal information by an employee or agent of the business for a legitimate business purpose is not a breach of security, provided that the personal information is not used for a purpose unrelated to the business or subject to further unauthorized disclosure. "Business" means a sole proprietorship, partnership, corporation, association, or other entity, however organized and whether or not organized to operate at a profit, including a financial institution organized, chartered, or holding a license or authorization certificate under the law of this State, any other state, the United States, or of any other country, or the parent or the subsidiary of a financial institution.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2020
Opinions citing this section in our collection:
- Too Much Media, LLC v. Hale (Supreme Court of New Jersey 2011, 206 N.J. 209)“…olated the New Jersey Identity Theft Protection Act, N.J.S.A. 56:8-161 to -67, and profited from the security…”
- K.S. VS. RYAN VERRECCHIO (L-2394-16, MONMOUTH COUNTY AND STATEWIDE) (New Jersey Superior Court Appellate Division 2019)“…n a claim under the Identity Theft Statute in the CFA. See N.J.S.A. 56:8-161 to -166.1. Affirmed. 7 N.J…”
- SAFONOF v. DIRECTSAT USA (District Court, D. New Jersey 2020)“…numerous violations of the law, including Identity Theft, N.J.S.A. 56:8-161, 163, the Computer Fraud and Abuse Act…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.J. Stat. 56:8-161 to 56:8-166 - Identity Theft Prevention Act (Breach Notification)(njconsumeraffairs.gov).gov
- New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
- New Jersey State Police(njsp.org).gov