USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

New Jersey Privacy & Data Security Laws

Every statute below can apply to a business handling New Jersey residents' data, depending on your revenue, the number of New Jersey consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Jan 15, 2025 (amended Jan 2026 and Jun 30, 2026)
New Jersey Data Privacy Act
NJDPA

Applies at 100,000+ New Jersey consumers, or 25,000+ if you sell personal data (no revenue-percentage test — confirmed atypical vs. peer states). Notably has no general nonprofit exemption and no higher-education exemption — both notable outliers vs. peer states. A January 2026 amendment (P.L.2025, c.367) expanded the law's HIPAA carve-out, but it remains data-level only (covers PHI and HIPAA-safeguarded 'treated like PHI' data) — not a whole-entity exemption for covered entities/business associates. GLBA financial institutions do get a genuine entity-level exemption, unchanged by the amendment. NJ separately enacted A5328 (signed and effective Jun 30, 2026), which bans selling sensitive data by any entity at any size and creates a data-broker/data-collector registry — that ban reaches businesses well below the NJDPA's own thresholds, so see the Data Broker entry for New Jersey.

N.J. Stat. § 56:8-166.4 et seq.Read statute →

Data Security & Breach Notification · 1

Varies by state
New Jersey data breach notification law
NJ Breach Notification

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

N.J. Stat. § 56:8-163Read statute →

Children & Minors Online Safety · 1

Not yet effective — signed Aug 11, 2026, effective Sep 1, 2027 (the act runs from "the first day of the 13th month following" enactment)
New Jersey Kids Code Act (New Jersey Age-Appropriate Design Code)
NJ Kids Code

Newly enacted design code, not yet in force, and broader in reach than most: it applies to a "covered online service provider" whose service is reasonably likely to be accessed by a covered child (under 13) or covered minor (13–17) and that either has annual gross revenue above $25,000,000 (inflation-adjusted biennially from Jan 1, 2029) or annually processes personal data of 25,000+ consumers or households. Duties include defaulting minors' privacy settings to the highest level, blocking adult-to-minor direct messaging unless the adult is a parent or the minor opts in, not displaying a minor's location to other users by default, and no notifications by default or between 10 p.m. and 6 a.m. The enforcement design is the part to watch: a violation is an unlawful practice under the Consumer Fraud Act AND the act carries its own private right of action — an injured minor may sue directly, and a parent or the Attorney General may sue on the minor's behalf, with $5,000 per violation or treble damages (whichever is greater) for negligent or worse violations, plus punitive damages for reckless or knowing ones. Signed Aug 11, 2026 as one of three kids' online-safety bills; the other two fund research rather than impose duties. Thresholds, duties, enforcement and the effective-date formula were read off the enacted third-reprint bill text, but the eventual N.J. Stat. section numbers were not confirmed from a primary source — reconfirm the citation before quoting it.

N.J. A4015 (2026), third reprint — N.J. Stat. codification and P.L. chapter number pendingRead statute →

Data Broker Registration & Duties · 1

Sale ban effective immediately on signing, Jun 30, 2026; broker registration Mar 27, 2027
New Jersey Data Broker Registration and Sensitive Data Sale Ban (A5328)
NJ A5328

One of the most expansive sensitive-data restrictions in the country, and the one most likely to catch a business by surprise: the ban on selling or licensing sensitive data applies to every individual and legal entity regardless of size, explicitly including businesses that fall below the NJDPA's own 100,000/25,000-consumer thresholds. Civil penalties run to $50,000 per record sold, offered for sale, or licensed. Limited carve-outs exist for HIPAA-covered entities and GLBA financial institutions. Separately, both "data brokers" and the broader category of "data collectors" must register with the NJ Division of Consumer Affairs from Mar 27, 2027, with tiered fees from $5,000 up to $1,500,000 based on consumer volume and $2,500/day penalties for failing to register.

N.J. A5328 (2026), amending N.J. Stat. § 56:8-166.4 et seq.Read statute →