New Jersey
New Jersey Data Breach Notification Laws: Reporting Rules & Timelines (2026)

New Jersey requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay under N.J.S.A. 56:8-163. Both the New Jersey Attorney General and the New Jersey State Police must receive notice before individual notifications are sent.
If your business handles personal information belonging to New Jersey residents, a data breach triggers strict notification obligations. New Jersey's breach notification law, codified at N.J. Stat. 56:8-161 through 56:8-166, requires disclosure in the most expedient time possible and without unreasonable delay, with no fixed day-count deadline. The law's broad personal information definition, its dual state-agency notification requirement, and the state's private right of action for willful, knowing, or reckless violations under the Consumer Fraud Act make New Jersey one of the more demanding states for breach response.
This guide covers the full scope of New Jersey's breach notification requirements, including what personal information triggers the law, who must be notified, the timelines, the private right of action, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With New Jersey's Breach Notification Law
New Jersey's law applies to any business or public entity that compiles or maintains computerized records that include personal information. Under N.J. Stat. 56:8-163, both private businesses and government entities must comply.
The law applies to businesses located outside New Jersey if they hold data belonging to New Jersey residents. There is no minimum size threshold. A sole proprietor that maintains one customer's personal information has the same obligations as a multinational corporation.

When a third party that maintains data on behalf of a business discovers a breach, it must notify the business immediately. The business then carries the primary responsibility to notify affected individuals and state agencies.
What Qualifies as a Breach
Under N.J. Stat. 56:8-161, a "breach of security" means the unauthorized access to electronic files, media, or data containing personal information that compromises the security, confidentiality, or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable.
Encryption Safe Harbor
New Jersey provides an encryption safe harbor. If the compromised personal information was secured by encryption or another method that renders it unreadable or unusable, and the encryption key or security credential was not also compromised, notification is not required.

Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the business for a legitimate business purpose does not constitute a breach, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Personal Information That Triggers Notification
New Jersey's 2024 amendments significantly broadened the definition of personal information. Under N.J. Stat. 56:8-161, personal information means an individual's first name or first initial and last name combined with any one or more of the following:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the account
- Username or email address combined with a password or security question and answer that would permit access to an online account
The addition of username/email plus password combinations reflects the growing risk of credential-based attacks and account takeover fraud.
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Notification Timeline
New Jersey does not set a fixed day-count deadline for breach notification.
The "Most Expedient Time Possible" Standard
Notification must be made "in the most expedient time possible and without unreasonable delay," consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. New Jersey does not have a separate deadline for social media platform breaches; the same expedient-time standard applies regardless of the type of business involved.
When Delay Is Permitted
Notification may be delayed beyond the applicable deadline only if:
- A law enforcement agency determines that notification will impede a criminal or civil investigation. The business must notify affected individuals after law enforcement determines disclosure no longer compromises the investigation.
- The entity needs time to determine the scope and nature of the breach, identify the individuals affected, and restore the reasonable integrity of the data system.
Even when delay is permitted, the business must document the reasons for any delay and must act as quickly as possible once the justification ends.
Who Must Be Notified
New Jersey Attorney General and State Police
Both the New Jersey Division of Consumer Affairs (within the AG's office) and the New Jersey State Police must be notified before individual notifications are sent. This dual-agency notification requirement is unusual among state breach notification laws.
The notice to the state agencies must include:
- The type of personal information compromised
- The date and estimated number of affected residents
- Steps taken to address the breach
- A copy of the notification to be sent to individuals
Affected Individuals
Every New Jersey resident whose personal information was or is reasonably believed to have been accessed by an unauthorized person must be notified. The notification must include:
- A description of the type of personal information compromised
- Contact information for the business providing notice
- Contact information for the consumer reporting agencies
- A description of what the business has done to protect the personal information from further breach
- Advice directing the individual to remain vigilant and review account statements and credit reports
Consumer Reporting Agencies
When a breach affects more than 1,000 New Jersey residents, the business must also notify the nationwide consumer reporting agencies without unreasonable delay.
How to Provide Notification
New Jersey permits the following notification methods:
- Written notice sent by mail or delivered to the individual
- Electronic notice consistent with the E-SIGN Act (15 U.S.C. 7001)

Substitute Notice
Substitute notice is available when:
- The cost of providing notice would exceed $250,000
- The affected class exceeds 500,000 individuals
- The business does not have sufficient contact information
Substitute notice must include all of the following:
- Email notification to individuals for whom the business has an email address
- Conspicuous posting of the notice on the business's website
- Notification to major statewide media outlets
Private Right of Action and Treble Damages
A willful, knowing, or reckless violation of New Jersey's breach notification law is an unlawful practice under the Consumer Fraud Act (N.J. Stat. 56:8-166). This matters because the Consumer Fraud Act provides a private right of action with treble damages for that class of violation.
Under the Consumer Fraud Act, a person who suffers an ascertainable loss because of a willful, knowing, or reckless violation may bring a civil action and recover:
- Treble (triple) damages for the ascertainable loss
- Reasonable attorneys' fees
- Filing fees and reasonable costs of suit
This makes New Jersey one of the more plaintiff-friendly states for data breach litigation when a violation rises to that level. Unlike most states where only the Attorney General can enforce the breach notification law, New Jersey also allows individuals to sue directly for willful, knowing, or reckless violations. A merely negligent delay in notification does not by itself trigger this private remedy.
Class Action Exposure
The private right of action, combined with treble damages, can create substantial class action exposure when a violation is willful, knowing, or reckless. A breach affecting thousands of New Jersey residents could generate claims multiplied by three, plus attorneys' fees, if that standard is met. This risk profile makes New Jersey compliance particularly important for businesses.
Enforcement and Penalties
In addition to private litigation, the New Jersey Attorney General can enforce the breach notification law under the Consumer Fraud Act. The AG may seek:
- Civil penalties of $10,000 for the first offense
- Civil penalties of $20,000 for each subsequent offense
- Injunctive relief
- Restitution for affected consumers
The escalating penalty structure means that businesses with repeat violations face rapidly increasing exposure. Combined with the private right of action, New Jersey's enforcement framework is among the most aggressive in the country.
Exemptions
Certain entities are exempt from New Jersey's breach notification requirements:
- HIPAA-covered entities that comply with HIPAA breach notification requirements are deemed in compliance with New Jersey's law
- Financial institutions regulated by federal agencies and in compliance with federal breach notification guidance may also qualify for an exemption
These exemptions are narrow and require ongoing compliance with the applicable federal framework.
How New Jersey's Privacy Laws Interact With Breach Notification
The New Jersey Data Privacy Act (NJDPA), effective January 15, 2025, created a comprehensive consumer privacy framework. The NJDPA does not contain its own breach notification requirements. Businesses subject to the NJDPA must still follow N.J. Stat. 56:8-161 for breach notification.
The NJDPA adds relevant data protection obligations:
- Data security requirement: Controllers must implement reasonable administrative, technical, and physical data security practices.
- Data minimization: Controllers must limit data collection to what is adequate, relevant, and reasonably necessary.
- Sensitive data consent: Biometric data, precise geolocation, children's data, and other sensitive categories require explicit consumer consent.
The NJDPA is enforced separately by the Attorney General under the Consumer Fraud Act. Unlike the breach notification law's private right of action for willful, knowing, or reckless violations, the NJDPA itself creates no private right of action; only the Attorney General may enforce it.
This article provides general legal information about New Jersey data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New Jersey for guidance specific to your situation.
More New Jersey Laws
Frequently Asked Questions
How long does a business have to notify New Jersey residents of a data breach?
New Jersey does not set a fixed number of days. The law requires notification 'in the most expedient time possible and without unreasonable delay,' and it has no separate deadline for social media platform breaches. Both the Attorney General and New Jersey State Police must be notified before individual notification is sent.
Can individuals sue for a data breach in New Jersey?
Yes, for willful, knowing, or reckless violations. Such a violation of New Jersey's breach notification law is an unlawful practice under the Consumer Fraud Act (N.J. Stat. 56:8-166), which provides a private right of action. Affected individuals who show an ascertainable loss can sue and recover treble (triple) damages, plus reasonable attorneys' fees and costs. A merely negligent delay does not by itself trigger this remedy.
What are the penalties for failing to notify in New Jersey?
The Attorney General can impose civil penalties of $10,000 for the first offense and $20,000 for each subsequent offense under the Consumer Fraud Act. Additionally, for willful, knowing, or reckless violations, affected individuals who show an ascertainable loss can bring private lawsuits and recover treble damages, attorneys' fees, and costs.
Does New Jersey have a special deadline for social media breach notification?
No. New Jersey does not have a separate notification deadline for social media platforms. The same 'most expedient time possible and without unreasonable delay' standard that applies to any business or public entity applies to social media operators as well.
Does encryption protect businesses from New Jersey's breach notification requirements?
Yes, New Jersey provides an encryption safe harbor. If the compromised personal information was secured by encryption or another method that renders it unreadable or unusable, and the encryption key was not also compromised, notification is not required. If the key was also acquired, the safe harbor does not apply.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Removed a fabricated 30-day/7-day breach notification deadline that does not appear in current New Jersey law (N.J.S.A. 56:8-163 uses only a 'most expedient time possible' standard), and clarified that the Consumer Fraud Act's private right of action and treble damages apply to willful, knowing, or reckless violations, not any violation.
Fixed three inline citation links that pointed to the NJ Legislature's S2062 bill-search page (the source of a since-corrected fabricated deadline) so they now point to the official statute text on njconsumeraffairs.gov.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
United States Code Title 15
§ 7001General rule of validityIn forcecited in 17 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
New Jersey Statutes (Unannotated)
§ 56:8-161Definitions relative to security of personal information.In forcecited in 2 of our articles
10. As used in sections 10 through 15 of P.L.2005, c.226 (C.56:8-161 through C.56:8-166): "Breach of security" means unauthorized access to electronic files, media or data containing personal information that compromises the security, confidentiality or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable. Good faith acquisition of personal information by an employee or agent of the business for a legitimate business purpose is not a breach of security, provided that the personal information is not used for a purpose unrelated to the business or subject to further unauthorized disclosure. "Business" means a sole proprietorship, partnership, corporation, association, or other entity, however organized and whether or not organized to operate at a profit, including a financial institution organized, chartered, or holding a license or authorization certificate under the law of this State, any other state, the United States, or of any other country, or the parent or the subsidiary of a financial institution.
Official text (excerpt) · as of 2026-08-01 · Read the full section at lis.njleg.state.nj.us
Also relied on in: New Jersey Data Privacy Laws: NJDPA Consumer Rights Guide (2026)
§ 56:8-163Disclosure of breach of security to customers.In forcecited in 2 of our articles
12. a. Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information, shall disclose any breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person. The disclosure to a customer shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection c. of this section, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Disclosure of a breach of security to a customer shall not be required under this section if the business or public entity establishes that misuse of the information is not reasonably possible. Any determination shall be documented in writing and retained for five years.
Official text (excerpt) · as of 2026-08-01 · Read the full section at lis.njleg.state.nj.us
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- N.J. Stat. 56:8-161 to 56:8-166 - Identity Theft Prevention Act (Breach Notification)(njconsumeraffairs.gov).gov
- New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
- New Jersey State Police(njsp.org).gov