EnglishEspañol
New Jersey flag

New Jersey

NJDPA Compliance Checklist: New Jersey Privacy

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

NJDPA Compliance Checklist: New Jersey Privacy

Frequently Asked Questions

How do I know if the NJDPA applies to my business?

Under N.J.S.A. 56:8-166.5, the NJDPA applies if you conduct business in New Jersey or target New Jersey residents and, during a calendar year, control or process the personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving any revenue, or a discount, from selling personal data. Count only New Jersey residents in an individual or household context; the low trigger has no percentage-of-revenue floor.

Does the NJDPA's data-sale trigger have a revenue percentage floor?

No. New Jersey's 25,000-consumer trigger under N.J.S.A. 56:8-166.5 applies if the controller derives any revenue at all, or even receives a discount on goods or services, from the sale of personal data. Unlike states that require a set share of revenue from data sales, New Jersey has no percentage floor, so a small data sale or a data-for-discount deal can bring a business in.

Do I need consent to process financial information under the NJDPA?

Often, yes. Under N.J.S.A. 56:8-166.4, financial information is sensitive data, meaning a consumer's account number, account log-in, financial account, or credit or debit card number combined with a required security code, access code, or password. Processing sensitive data requires opt-in consent under N.J.S.A. 56:8-166.12(a)(4), so handling payment credentials for purposes beyond completing a transaction generally needs the consumer's affirmative consent.

When did the universal opt-out requirement start?

Under N.J.S.A. 56:8-166.11(b)(1), the NJDPA requires controllers to recognize a universal opt-out mechanism such as Global Privacy Control no later than six months after the January 15, 2025 effective date, by approximately July 15, 2025. As of 2026, businesses must detect and honor these browser or device signals to opt consumers out of targeted advertising and the sale of personal data.

When did the NJDPA cure period end?

Under N.J.S.A. 56:8-166.17(b), the NJDPA gave a controller 30 days to cure an alleged violation after notice from the Division of Consumer Affairs, but that mandatory cure notice applied only until the first day of the 18th month after the effective date, which was July 1, 2026. That date has passed, so the Attorney General may now bring enforcement without first offering a chance to cure.

What are the penalties for violating the NJDPA?

Under N.J.S.A. 56:8-166.17(a), a violation is an unlawful practice under the New Jersey Consumer Fraud Act, which carries civil penalties of up to $10,000 for a first violation and $20,000 for each subsequent violation, along with the other remedies that Act provides. Under N.J.S.A. 56:8-166.19, the Office of the Attorney General has sole and exclusive authority to enforce the law, and there is no private right of action.

Do I need to do data protection assessments?

Yes, for higher-risk processing. Under N.J.S.A. 56:8-166.12(a)(9), a controller must conduct and document a data protection assessment for processing that presents a heightened risk of harm, which N.J.S.A. 56:8-166.12(c) defines to include targeted advertising, the sale of personal data, certain profiling, and processing sensitive data. Keep the assessments on file, because N.J.S.A. 56:8-166.12(b) requires the controller to make an assessment available to the Division of Consumer Affairs on request.

Is New Jersey writing privacy regulations?

Yes. N.J.S.A. 56:8-166.18 directs the Director of the Division of Consumer Affairs to promulgate rules to effectuate the Act, and the Division published proposed privacy regulations on June 2, 2025, with comments due August 1, 2025. The proposed rules address privacy-notice detail, dark patterns, and consent, so businesses should track the rulemaking and comply with the adopted rules in addition to the statute.

Updates

Corrected the statutory citations behind the compliance steps: data protection assessments are required by N.J.S.A. 56:8-166.12, the universal opt-out duty is N.J.S.A. 56:8-166.11(b)(1), sensitive-data consent is N.J.S.A. 56:8-166.12(a)(4), and the cure period and rulemaking are N.J.S.A. 56:8-166.17(b) and 56:8-166.18 rather than 56:8-166.19.

Updated the cure-period section to reflect that New Jersey's mandatory 30-day cure notice already ended on July 1, 2026 (previously stated as an upcoming sunset around July 15, 2026), and added the NJDPA's actual applicability exemptions to Step 1.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.J.S.A. 56:8-166.4: Definitions (Sensitive Data, Financial Information)(pub.njleg.state.nj.us).gov
  2. N.J.S.A. 56:8-166.5: Applicability and Thresholds(pub.njleg.state.nj.us).gov
  3. N.J.S.A. 56:8-166.6: Privacy Notice and Consumer Rights(pub.njleg.state.nj.us).gov
  4. N.J.S.A. 56:8-166.7: Verified Request and 45-Day Response(pub.njleg.state.nj.us).gov
  5. N.J.S.A. 56:8-166.16: Data Protection Assessments and Processor Obligations(pub.njleg.state.nj.us).gov
  6. N.J.S.A. 56:8-166.19: Authority and Enforcement(pub.njleg.state.nj.us).gov
  7. New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
  8. NJCCIC: New Jersey Enacts Comprehensive Data Privacy Law(cyber.nj.gov).gov
  9. New Jersey Legislature: S332 bill page (2022-2023 session)(njleg.state.nj.us).gov
  10. NJ Office of the Attorney General: Proposed NJDPA Rules Announced (June 2, 2025; comments due August 1, 2025)(njoag.gov)
Share: