State Guide
New Jersey Privacy & Data Security Laws
Every statute below can apply to a business handling New Jersey residents' data, depending on your revenue, the number of New Jersey consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies at 100,000+ New Jersey consumers, or 25,000+ if you sell personal data (no revenue-percentage test — confirmed atypical vs. peer states). Notably has no general nonprofit exemption. A January 2026 amendment added an entity- and data-level HIPAA exemption; NJ separately enacted a data-broker registry and sensitive-data-sale ban in 2026.
Data Security & Breach Notification · 1
Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.