New Jersey
NJDPA Consumer Rights: New Jersey Privacy Law
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

The New Jersey Data Privacy Act (NJDPA), N.J.S.A. 56:8-166.4 et seq., gives New Jersey residents the right to confirm and access the personal data a business holds about them, to correct inaccuracies, to delete their data, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. A controller generally must respond within 45 days of a verified request.
As of 2026, these rights are fully in force. If a controller declines a request, it must explain why and give the consumer a way to appeal, and it must honor a universal opt-out signal such as Global Privacy Control. Enforcement runs through the New Jersey Attorney General and the Division of Consumer Affairs under the Consumer Fraud Act, with no private right of action.
Jurisdiction scope: This covers New Jersey's Data Privacy Act (N.J.S.A. 56:8-166.4 et seq.). It is general legal information, not legal advice.
The core consumer rights
The NJDPA sets out its consumer rights at N.J.S.A. 56:8-166.10, a familiar set modeled on the framework most state privacy laws share. The rights apply to a "consumer," which under N.J.S.A. 56:8-166.4 means a New Jersey resident acting in an individual or household context, not someone acting in a commercial or employment role.
A consumer may confirm whether a controller is processing their personal data and access that data. A consumer may correct inaccuracies, taking into account the nature of the data and the purpose of processing. A consumer may delete personal data the controller holds about them. A consumer may also obtain a copy of their personal data in a portable and, to the extent technically feasible, readily usable format that allows the data to be transmitted to another controller.
Alongside these access-style rights, the NJDPA gives consumers three opt-out rights. A consumer may opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.
The 45-day response deadline
The timing rules sit at N.J.S.A. 56:8-166.7. A controller that receives a verified consumer request must respond without undue delay and in any event within 45 days of receiving the request.
The controller may extend that period once by an additional 45 days where reasonably necessary, considering the complexity and number of the consumer's requests. To use the extension, the controller must inform the consumer of the extension, and the reason for it, within the initial 45-day window.
Cost is limited, but the free entitlement is capped. N.J.S.A. 56:8-166.7(d) provides that information supplied in response to a consumer request shall be provided free of charge once per consumer during any twelve-month period, so it is the first request in a 12-month period that the statute guarantees at no cost. Separately, where requests from a consumer are manifestly unfounded, excessive, or repetitive, the controller may charge a reasonable fee to cover the administrative costs of complying or decline to act, and it bears the burden of demonstrating that the request meets that standard.
Verifying the consumer and the request
For the access-style rights, a controller must be able to authenticate the request as coming from the consumer it concerns. If a controller cannot authenticate such a request using commercially reasonable efforts, N.J.S.A. 56:8-166.7(e) says it is not required to comply, and it must notify the consumer that it cannot authenticate the request until the consumer provides additional information reasonably necessary to do so.
The three opt-out rights work differently. The same subsection provides that a controller shall not be required to authenticate an opt-out request, and that a controller may deny an opt-out request only where it has a good faith, reasonable, and documented belief that the request is fraudulent. An inability to authenticate is therefore not a ground for ignoring an opt-out, and a controller that denies one as fraudulent must tell the person who made the request that it believes the request is fraudulent, why, and that it will not comply.
This verification step protects consumers from someone else accessing, changing, or deleting their data. It also means a consumer may need to provide enough information to confirm identity before a controller will release or erase data.
For requests submitted through an authorized agent, including a browser-based opt-out signal for the opt-out rights, the controller may use technology to determine whether the consumer is a New Jersey resident and whether the agent is authorized to act on the consumer's behalf.

Appeals when a controller says no
If a controller declines to take action on a request, the consumer is not at a dead end. Under N.J.S.A. 56:8-166.6 and 56:8-166.7, a controller that refuses must inform the consumer, without undue delay and within the 45-day window, of the justification for declining and of how to appeal.
The controller must establish a conspicuous and readily accessible process for a consumer to appeal the refusal. Within 45 days of receiving an appeal (N.J.S.A. 56:8-166.7(f)), the controller must inform the consumer in writing of any action taken or not taken in response, with a written explanation of the reasons.
If the appeal is denied, the controller must also provide the consumer with an online mechanism, if available, or another method to contact the Division of Consumer Affairs in the Department of Law and Public Safety to submit a complaint. That gives consumers a path to the regulator when a business will not resolve the request.
Opt-outs and the universal opt-out mechanism
The three opt-out rights, covering targeted advertising, the sale of personal data, and certain profiling, are central to how the NJDPA works in practice. A controller must give consumers a clear and conspicuous way to exercise each of these rights, typically through links or settings in its privacy notice.
The NJDPA also requires controllers to recognize a universal opt-out mechanism. This is a browser or device setting, such as Global Privacy Control, that signals a consumer's choice to opt out of targeted advertising and the sale of personal data without filling out a form on each website. The obligation to honor such a signal took effect no later than six months after the January 15, 2025 effective date, by approximately July 15, 2025.
When a consumer sends a universal opt-out signal, the controller must treat it as a valid request to opt out for that browser or device. The mechanism cannot unfairly disadvantage another controller, cannot be a default setting that conflicts with the consumer's express choice, and must be consumer-friendly and easy to use.

Sensitive data and the financial-information consent gate
Some data carries a higher bar. Under N.J.S.A. 56:8-166.12(a)(4), a controller may not process sensitive data concerning a consumer without first obtaining the consumer's consent, and the sensitive-data category defined at N.J.S.A. 56:8-166.4 is unusually broad.
Sensitive data in New Jersey includes financial information, defined as a consumer's account number, account log-in, financial account, or credit or debit card number combined with any required security code, access code, or password that would permit access to the account. It also includes status as transgender or nonbinary, along with data revealing racial or ethnic origin, religious beliefs, health condition, treatment, or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data, the personal data of a known child, and precise geolocation data.
Because financial information is treated as sensitive, a business that processes that kind of payment-credential data for non-payment purposes generally needs the consumer's affirmative consent first. Consent under the Act must be a clear affirmative act that is freely given, specific, informed, and unambiguous, and it cannot be obtained through dark patterns. Consumers also retain the right to revoke consent.
Teen protections for 13-to-16 year olds
The NJDPA adds an extra layer of protection for teenagers. Where a controller knows that a consumer is at least 13 and younger than 17, it must obtain consent before processing that consumer's personal data for targeted advertising, the sale of personal data, or profiling.
For teens in that 13-to-16 band, the usual opt-out approach is not enough. The controller needs affirmative consent before it may use their data for those three high-impact activities. This reaches an age group that the federal Children's Online Privacy Protection Act, which covers children under 13, does not address.
Personal data collected from a known child under 13 is itself sensitive data under N.J.S.A. 56:8-166.4, so it already requires consent. Together, these rules give New Jersey minors broader protection than the consumer rights that apply to adults.
Rights and deadlines at a glance
The table below summarizes the consumer rights and the key timing rules. The deadlines are statutory minimums; a controller may always respond faster.
| Right or step | What it covers | Deadline |
|---|---|---|
| Confirm and access | Confirm processing and get a copy of the data | 45 days (one 45-day extension) |
| Correct | Fix inaccurate personal data | 45 days |
| Delete | Erase personal data the controller holds | 45 days |
| Portability | Receive data in a portable, usable format | 45 days |
| Opt out (targeted ads, sale, profiling) | Stop those processing activities | Honor promptly; recognize universal signal |
| Appeal | Challenge a refusal to act | 45 days, in writing, then route to Division of Consumer Affairs |
| Sensitive data | Financial info, transgender or nonbinary status, and more | Opt-in consent required before processing |
For how a business operationalizes these rights, see the NJDPA compliance checklist.
Related guides
- New Jersey data privacy laws parent hub
- What is the NJDPA?
- NJDPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More New Jersey Laws
Frequently Asked Questions
What rights does the NJDPA give New Jersey consumers?
Under the NJDPA, N.J.S.A. 56:8-166.4 et seq., a New Jersey consumer may confirm and access the personal data a controller holds, correct inaccuracies, delete the data, and obtain a portable copy. The consumer may also opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.
How long does a business have to respond to my request?
Under N.J.S.A. 56:8-166.7, a controller must respond within 45 days of receiving a verified request. It may extend that period once by an additional 45 days where reasonably necessary, but only if it tells you about the extension and the reason within the first 45 days. Under N.J.S.A. 56:8-166.7(d) the response must be free of charge once per consumer during any twelve-month period, and a controller may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive.
Can I appeal if a company refuses my NJDPA request?
Yes. Under N.J.S.A. 56:8-166.6 and 56:8-166.7, if a controller declines to act, it must explain why and provide a conspicuous, readily accessible appeal process. It must respond to the appeal in writing with its reasons within 45 days. If the appeal is denied, the controller must give you a way to contact the New Jersey Division of Consumer Affairs to submit a complaint.
Does the NJDPA require honoring Global Privacy Control?
Yes. The NJDPA requires controllers to recognize a universal opt-out mechanism such as Global Privacy Control, a browser or device signal that opts you out of targeted advertising and the sale of your personal data. That obligation took effect no later than six months after the January 15, 2025 effective date, by approximately July 15, 2025.
Is my financial information protected as sensitive data?
Yes. Under N.J.S.A. 56:8-166.4, sensitive data includes financial information, meaning a consumer's account number, account log-in, financial account, or credit or debit card number combined with a required security code, access code, or password that permits access to the account. Most states do not treat financial information as sensitive, and under N.J.S.A. 56:8-166.12(a)(4) a controller may not process sensitive data without first obtaining your consent.
What protections does the NJDPA give to teenagers?
Where a controller knows a consumer is at least 13 and younger than 17, the NJDPA requires consent before processing that teen's personal data for targeted advertising, the sale of data, or profiling. For teens in that band, opt-out is not enough; affirmative consent is required. Data collected from a known child under 13 is sensitive data, so it also requires consent.
Do I have a right to opt out of the sale of my data?
Yes. The NJDPA gives consumers the right to opt out of the sale of their personal data, of targeted advertising, and of profiling that produces legal or similarly significant effects. A controller must provide a clear way to exercise these rights and must also recognize a universal opt-out signal such as Global Privacy Control.
Can I sue a company under the NJDPA?
No. The NJDPA does not create a private right of action, so an individual generally cannot sue a business directly for a violation. Enforcement runs through the New Jersey Attorney General and the Division of Consumer Affairs under the Consumer Fraud Act. If a controller will not resolve your request, you can submit a complaint to the Division of Consumer Affairs.
Updates
Corrected the citation for New Jersey's sensitive-data consent rule to N.J.S.A. 56:8-166.12(a)(4), added the statute's once-per-twelve-month limit on free responses, and noted that a controller is not required to authenticate an opt-out request.
Corrected the appeal-response deadline to the statutory 45 days in all three places and clarified the citation for the consumer rights provisions.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Jersey Statutes (Unannotated)
§ 56:8-166.10Consumer rights, personal data.In forcecited in 5 of our articles
7. a. A consumer shall have the right to: (1) confirm whether a controller processes the consumer's personal data and accesses such personal data, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller's trade secrets; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the information and the purposes of the processing of the information; (3) delete personal data concerning the consumer; (4) obtain a copy of the consumer's personal data held by the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another entity without hindrance, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller's trade secrets; and (5) opt out of the processing of personal data for the purposes of (a) targeted advertising; (b) the sale of personal data; or (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. b.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State, New Jersey Data Privacy Laws: NJDPA Consumer Rights Guide (2026), What Is the NJDPA? New Jersey Data Privacy Act
§ 56:8-166.7Personal data; controller, verified request, consumer, response period.In forcecited in 4 of our articles
4. a. A controller that receives a verified request from a consumer shall provide a response to the consumer within 45 days of the controller's receipt of the request. The controller may extend the response period by 45 additional days where reasonably necessary, considering the complexity and number of the consumer's requests, provided that the controller informs the consumer of any such extension within the initial 45-day response period and the reason for the extension and shall provide the information for all disclosures of personal data that occurred in the prior 12 months. b. This section shall not apply to personal data collected prior to the effective date of P.L.2023, c.266 (C.56:8-166.4 et seq.) unless the controller continues to process such information thereafter. c. If a controller declines to take action regarding the consumer's request, the controller shall inform the consumer without undue delay, but not later than 45 days after receipt of the request, of the justification for declining to take action and instructions for how to appeal the decision.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: NJDPA Compliance Checklist: New Jersey Privacy
§ 56:8-166.6Controller, consumer, privacy notice, personal data; disclosure, sale.In forcecited in 3 of our articles
3. a. A controller shall provide to a consumer a reasonably accessible, clear, and meaningful privacy notice that shall include, but may not be limited to: (1) the categories of the personal data that the controller processes; (2) the purpose for processing personal data; (3) the categories of all third parties to which the controller may disclose a consumer's personal data; (4) the categories of personal data that the controller shares with third parties, if any; (5) how consumers may exercise their consumer rights, including the controller's contact information and how a consumer may appeal a controller's decision with regard to the consumer's request; (6) the process by which the controller notifies consumers of material changes to the notification required to be made available pursuant to this subsection, along with the effective date of the notice; and (7) an active electronic mail address or other online mechanism that the consumer may use to contact the controller.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
§ 56:8-166.4Definitions.In forcecited in 5 of our articles
1. As used in P.L.2023, c.266 (C.56:8-166.4 et seq.): "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" means: the ownership of or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; the control in any manner over the election of a majority of the directors or individuals exercising similar functions; or the power to exercise a controlling influence over the management or policies of a company. "Biometric data" means data generated by automatic or technological processing, measurements, or analysis of an individual's biological, physical, or behavioral characteristics, including, but not limited to, fingerprint, voiceprint, eye retinas, irises, facial mapping, facial geometry, facial templates, or other unique biological, physical, or behavioral patterns or characteristics that are used or intended to be used, singularly or in combination with each other or with other personal data, to identify a specific individual.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: New Jersey Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.J.S.A. 56:8-166.6 and 56:8-166.10: Privacy Notice, Consumer Rights, and Appeals (P.L.2023, c.266)(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.6: Privacy Notice, Consumer Rights, and Appeals(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.7: Verified Request, 45-Day Response Period(pub.njleg.state.nj.us).gov
- New Jersey Legislature: S332 bill page (2022-2023 session)(njleg.state.nj.us).gov
- New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
- NJCCIC: New Jersey Enacts Comprehensive Data Privacy Law(cyber.nj.gov).gov