EnglishEspañol
New Jersey flag

New Jersey

NJDPA Consumer Rights: New Jersey Privacy Law

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

NJDPA Consumer Rights: New Jersey Privacy Law

Frequently Asked Questions

What rights does the NJDPA give New Jersey consumers?

Under the NJDPA, N.J.S.A. 56:8-166.4 et seq., a New Jersey consumer may confirm and access the personal data a controller holds, correct inaccuracies, delete the data, and obtain a portable copy. The consumer may also opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.

How long does a business have to respond to my request?

Under N.J.S.A. 56:8-166.7, a controller must respond within 45 days of receiving a verified request. It may extend that period once by an additional 45 days where reasonably necessary, but only if it tells you about the extension and the reason within the first 45 days. Under N.J.S.A. 56:8-166.7(d) the response must be free of charge once per consumer during any twelve-month period, and a controller may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive.

Can I appeal if a company refuses my NJDPA request?

Yes. Under N.J.S.A. 56:8-166.6 and 56:8-166.7, if a controller declines to act, it must explain why and provide a conspicuous, readily accessible appeal process. It must respond to the appeal in writing with its reasons within 45 days. If the appeal is denied, the controller must give you a way to contact the New Jersey Division of Consumer Affairs to submit a complaint.

Does the NJDPA require honoring Global Privacy Control?

Yes. The NJDPA requires controllers to recognize a universal opt-out mechanism such as Global Privacy Control, a browser or device signal that opts you out of targeted advertising and the sale of your personal data. That obligation took effect no later than six months after the January 15, 2025 effective date, by approximately July 15, 2025.

Is my financial information protected as sensitive data?

Yes. Under N.J.S.A. 56:8-166.4, sensitive data includes financial information, meaning a consumer's account number, account log-in, financial account, or credit or debit card number combined with a required security code, access code, or password that permits access to the account. Most states do not treat financial information as sensitive, and under N.J.S.A. 56:8-166.12(a)(4) a controller may not process sensitive data without first obtaining your consent.

What protections does the NJDPA give to teenagers?

Where a controller knows a consumer is at least 13 and younger than 17, the NJDPA requires consent before processing that teen's personal data for targeted advertising, the sale of data, or profiling. For teens in that band, opt-out is not enough; affirmative consent is required. Data collected from a known child under 13 is sensitive data, so it also requires consent.

Do I have a right to opt out of the sale of my data?

Yes. The NJDPA gives consumers the right to opt out of the sale of their personal data, of targeted advertising, and of profiling that produces legal or similarly significant effects. A controller must provide a clear way to exercise these rights and must also recognize a universal opt-out signal such as Global Privacy Control.

Can I sue a company under the NJDPA?

No. The NJDPA does not create a private right of action, so an individual generally cannot sue a business directly for a violation. Enforcement runs through the New Jersey Attorney General and the Division of Consumer Affairs under the Consumer Fraud Act. If a controller will not resolve your request, you can submit a complaint to the Division of Consumer Affairs.

Updates

Corrected the citation for New Jersey's sensitive-data consent rule to N.J.S.A. 56:8-166.12(a)(4), added the statute's once-per-twelve-month limit on free responses, and noted that a controller is not required to authenticate an opt-out request.

Corrected the appeal-response deadline to the statutory 45 days in all three places and clarified the citation for the consumer rights provisions.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.J.S.A. 56:8-166.6 and 56:8-166.10: Privacy Notice, Consumer Rights, and Appeals (P.L.2023, c.266)(pub.njleg.state.nj.us).gov
  2. N.J.S.A. 56:8-166.6: Privacy Notice, Consumer Rights, and Appeals(pub.njleg.state.nj.us).gov
  3. N.J.S.A. 56:8-166.7: Verified Request, 45-Day Response Period(pub.njleg.state.nj.us).gov
  4. New Jersey Legislature: S332 bill page (2022-2023 session)(njleg.state.nj.us).gov
  5. New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
  6. NJCCIC: New Jersey Enacts Comprehensive Data Privacy Law(cyber.nj.gov).gov
Share: