USPrivacyAtlasState Privacy & Data Security Law Matcher

Comprehensive Privacy Law

New Jersey Data Privacy Act

NJDPA

New Jersey · Jan 15, 2025 (amended Jan 2026 and Jun 30, 2026)

Applies at 100,000+ New Jersey consumers, or 25,000+ if you sell personal data (no revenue-percentage test — confirmed atypical vs. peer states). Notably has no general nonprofit exemption and no higher-education exemption — both notable outliers vs. peer states. A January 2026 amendment (P.L.2025, c.367) expanded the law's HIPAA carve-out, but it remains data-level only (covers PHI and HIPAA-safeguarded 'treated like PHI' data) — not a whole-entity exemption for covered entities/business associates. GLBA financial institutions do get a genuine entity-level exemption, unchanged by the amendment. NJ separately enacted A5328 (signed and effective Jun 30, 2026), which bans selling sensitive data by any entity at any size and creates a data-broker/data-collector registry — that ban reaches businesses well below the NJDPA's own thresholds, so see the Data Broker entry for New Jersey.

N.J. Stat. § 56:8-166.4 et seq.Read statute →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual revenue, data volume, and data types.