{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/new-jersey",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-jersey.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-jersey",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-jersey/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-jersey/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "new-jersey",
    "frontmatter": {
      "title": "New Jersey Consumer Privacy Law (NJDPA)",
      "description": "The New Jersey Data Privacy Act gives New Jersey consumers rights over their personal data and imposes notice, contracting, and consent duties on controllers above defined thresholds — it is enforced exclusively by the Attorney General as an unlawful practice under the Consumer Fraud Act, with no private right of action and only a temporary right to cure.",
      "state": "New Jersey",
      "lastReviewed": "2026-06-06",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "N.J.S.A. 56:8-166.4 et seq. (New Jersey Data Privacy Act), effective January 15, 2025",
        "appliesTo": "Controllers doing business in New Jersey (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving any revenue or a discount from selling data — no revenue floor, and no exemption for nonprofits",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with seven statutorily fixed contents",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's",
        "regulator": "New Jersey Attorney General, through the Division of Consumer Affairs (exclusive)",
        "bottomLine": "If you meet the 100,000-consumer (or 25,000 plus any data-sale revenue) threshold in New Jersey, the NJDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — enforced by the Attorney General as an unlawful practice under the Consumer Fraud Act, with no consumer lawsuits and a cure period that sunsets after the law's first 18 months.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "New Jersey Data Privacy Act NJDPA",
        "New Jersey privacy policy requirements",
        "New Jersey privacy notice contents",
        "NJDPA applicability thresholds",
        "NJDPA sensitive data consent",
        "NJDPA processor contract requirements",
        "New Jersey Attorney General privacy enforcement",
        "NJDPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-njdpa-apply",
        "label": "Does the New Jersey Data Privacy Act apply to your business?",
        "heading": "Does the New Jersey Data Privacy Act apply to your business?",
        "answerText": "It turns on consumer volume, not overall revenue. The NJDPA applies to controllers that do business in New Jersey or target its residents and that, in a calendar year, control or process the personal data of at least 100,000 consumers (setting aside data used only to complete a payment), or at least 25,000 consumers while deriving any revenue or a discount from selling personal data. Several categories of regulated data and entities — including GLBA-regulated financial institutions and HIPAA-covered health information — fall outside the law entirely.",
        "sources": [
          {
            "id": "stat-166-5-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.5",
            "citation": "N.J.S.A. 56:8-166.5.",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "The NJDPA applies to controllers doing business in New Jersey or targeting its residents that, in a calendar year, control or process the data of at least 100,000 consumers (excluding payment-only data), or at least 25,000 consumers while deriving revenue or a discount from the sale of personal data.",
            "verbatimQuote": "the provisions of P.L.2023, c.266 (C.56:8-166.4 et seq.) shall only apply to controllers that conduct business in the State or produce products or services that are targeted to residents of the State, and that during a calendar year either: a. control or process the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction; or b. control or process the personal data of at least 25,000 consumers and the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-5-apply"
          },
          {
            "id": "stat-166-13-exempt",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.13",
            "citation": "N.J.S.A. 56:8-166.13(b).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "The NJDPA does not apply to GLBA-regulated financial institutions and their affiliates, HIPAA-covered protected health information, FCRA-governed consumer-reporting data, and state and local government, among other carve-outs.",
            "verbatimQuote": "a financial institution, data, or an affiliate of a financial institution that is subject to Title V of the federal “Gramm-Leach-Bliley Act,” 15 U.S.C. s.6801 et seq., and the rules and implementing regulations promulgated thereunder;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-13-exempt"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your New Jersey privacy policy contain?",
        "heading": "What must your New Jersey privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data it processes and the purpose for processing them, among other required disclosures.",
        "sources": [
          {
            "id": "stat-166-6-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.6",
            "citation": "N.J.S.A. 56:8-166.6(a).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed and the purpose for processing, among other required disclosures.",
            "verbatimQuote": "A controller shall provide to a consumer a reasonably accessible, clear, and meaningful privacy notice that shall include, but may not be limited to: (1) the categories of the personal data that the controller processes; (2) the purpose for processing personal data; (3) the categories of all third parties to which the controller may disclose a consumer's personal data; (4) the categories of personal data that the controller shares with third parties, if any; (5) how consumers may exercise their consumer rights, including the controller's contact information and how a consumer may appeal a controller's decision with regard to the consumer's request; (6) the process by which the controller notifies consumers of material changes to the notification required to be made available pursuant to this subsection, along with the effective date of the notice; and (7) an active electronic mail address or other online mechanism that the consumer may use to contact the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-6-notice"
          },
          {
            "id": "stat-166-11-optout",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.11",
            "citation": "N.J.S.A. 56:8-166.11(b)(1).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "New Jersey requires a controller that processes personal data for targeted advertising or the sale of personal data to let consumers opt out through a user-selected universal opt-out mechanism, beginning no later than six months after the act's effective date.",
            "verbatimQuote": "Beginning not later than six months following the effective date of P.L.2023, c.266 (C.56:8-166.4 et seq.), a controller that processes personal data for purposes of targeted advertising, or the sale of personal data shall allow consumers to exercise the right to opt out of such processing through a user-selected universal opt-out mechanism.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-11-optout"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A contract between a controller and a processor must govern the processor's handling of the data — so a data processing agreement is a statutory requirement, not a best practice. A separate set of exceptions preserves the parties' ability to comply with other law and run defined internal operations.",
        "sources": [
          {
            "id": "stat-166-16-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.16",
            "citation": "N.J.S.A. 56:8-166.16(e).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "Processing by a processor must be governed by a binding contract between the controller and the processor that sets forth the processing instructions, including the nature and purpose of the processing.",
            "verbatimQuote": "Processing by a processor shall be governed by a contract between the controller and the processor that is binding on both parties and that sets forth: (1) the processing instructions to which the processor is bound, including the nature and purpose of the processing;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-16-contract"
          },
          {
            "id": "stat-166-15-exceptions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.15",
            "citation": "N.J.S.A. 56:8-166.15(a).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "The NJDPA's obligations do not restrict a controller's or processor's ability to comply with other law, respond to legal process, or carry out defined internal operations.",
            "verbatimQuote": "Nothing in P.L.2023, c.266 (C.56:8-166.4 et seq.) shall be construed to restrict a controller's or processor's ability to: (1) comply with federal or State law or regulations;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-15-exceptions"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. A controller may not process a consumer's sensitive data without first obtaining consent, and for a known child it must instead handle the data in accordance with the federal Children's Online Privacy Protection Act. Sensitive data includes data revealing race or ethnicity, religious beliefs, a health condition or diagnosis, financial account credentials, sex life or sexual orientation, citizenship or immigration status, or status as transgender or non-binary; genetic or biometric data used to identify a person; data collected from a known child; and precise geolocation.",
        "sources": [
          {
            "id": "stat-166-12-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.12",
            "citation": "N.J.S.A. 56:8-166.12(a)(4).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "A controller may not process a consumer's sensitive data without first obtaining consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "not process sensitive data concerning a consumer without first obtaining the consumer's consent, or, in the case of the processing of personal data concerning a known child, without processing such data in accordance with COPPA;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-12-consent"
          },
          {
            "id": "stat-166-4-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.4",
            "citation": "N.J.S.A. 56:8-166.4.",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "Sensitive data includes data revealing race or ethnicity, religious beliefs, health condition, financial account credentials, sex life or sexual orientation, citizenship or immigration status, transgender or non-binary status, genetic or biometric data, data from a known child, and precise geolocation.",
            "verbatimQuote": "means personal data revealing racial or ethnic origin; religious beliefs; mental or physical health condition, treatment, or diagnosis; financial information, which shall include a consumer's account number, account log-in, financial account, or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a consumer's financial account; sex life or sexual orientation; citizenship or immigration status; status as transgender or non-binary; genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-4-sensitive"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the NJDPA?",
        "heading": "Can a consumer sue your business under the NJDPA?",
        "answerText": "No. The Office of the Attorney General has sole and exclusive authority to enforce the NJDPA, and the law cannot be the basis for a private right of action. A violation is treated as an unlawful practice under New Jersey's Consumer Fraud Act, the state's general anti-fraud statute.",
        "sources": [
          {
            "id": "stat-166-19-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.19",
            "citation": "N.J.S.A. 56:8-166.19.",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "The Office of the Attorney General has sole and exclusive authority to enforce the NJDPA, and the act provides no private right of action.",
            "verbatimQuote": "The Office of the Attorney General shall have sole and exclusive authority to enforce a violation of P.L.2023, c.266 (C.56:8-166.4 et seq.). Nothing in P.L.2023, c.266 (C.56:8-166.4 et seq.) shall be construed as providing the basis for, or subject to, a private right of action for violations of P.L.2023, c.266 (C.56:8-166.4 et seq.).",
            "pullQuoteLocator": "The Office of the Attorney|violations of P.L.2023, c.266 (C.56:8-166.4 et seq.).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-19-enforce"
          },
          {
            "id": "stat-166-17-violation",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.17",
            "citation": "N.J.S.A. 56:8-166.17(a).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "A controller's violation of the NJDPA is an unlawful practice under the New Jersey Consumer Fraud Act.",
            "verbatimQuote": "It shall be an unlawful practice and violation of P.L.1960, c.39 (C.56:8-1 et seq.) for a controller to violate the provisions of P.L.2023, c.266 (C.56:8-166.4 et seq.).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-17-violation"
          },
          {
            "id": "stat-166-17-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.17",
            "citation": "N.J.S.A. 56:8-166.17(b).",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "For the law's first 18 months, the Division of Consumer Affairs must give notice and a 30-day chance to cure a curable violation before bringing an enforcement action.",
            "verbatimQuote": "Until the first day of the 18th month next following the effective date of P.L.2023, c.266 (C.56:8-166.4 et seq.), prior to bringing an enforcement action before an administrative law judge or a court of competent jurisdiction in this State, the Division of Consumer Affairs in the Department of Law and Public Safety shall issue a notice to the controller if a cure is deemed possible.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-17-cure"
          },
          {
            "id": "stat-166-18-rules",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.J.S.A. 56:8-166.18",
            "citation": "N.J.S.A. 56:8-166.18.",
            "url": "https://pub.njleg.gov/bills/2022/PL23/266_.PDF",
            "proposition": "The Director of the Division of Consumer Affairs is charged with promulgating rules and regulations to effectuate the purposes of the NJDPA.",
            "verbatimQuote": "The Director of the Division of Consumer Affairs in the Department of Law and Public Safety shall promulgate rules and regulations, pursuant to the “Administrative Procedure Act,” P.L.1968, c.410 (C.52:14B-1 et seq.), necessary to effectuate the purposes of P.L.2023, c.266 (C.56:8-166.4 et seq.).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-jersey#src-stat-166-18-rules"
          }
        ]
      }
    ]
  }
}
