New Jersey
NJDPA Compliance Checklist: New Jersey Privacy
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

Complying with the New Jersey Data Privacy Act (NJDPA), N.J.S.A. 56:8-166.4 et seq., starts with confirming whether the law applies, then publishing a compliant privacy notice, standing up consumer-rights and appeal workflows, obtaining opt-in consent for sensitive data including financial information, recognizing a universal opt-out signal, documenting data protection assessments, and binding processors with written contracts. The Director of the Division of Consumer Affairs is also actively writing rules, so the regulatory layer has to be tracked alongside the statute.
As of 2026, the timing matters. The law took effect January 15, 2025, the universal opt-out obligation kicked in around July 15, 2025, and the 30-day mandatory right to cure, which applied only until the first day of the 18th month after the effective date, ended July 1, 2026, so the Attorney General may now proceed straight to enforcement without first offering a chance to cure. Penalties run under the Consumer Fraud Act up to $10,000 for a first violation and $20,000 for each subsequent violation.
Jurisdiction scope: This covers New Jersey's Data Privacy Act (N.J.S.A. 56:8-166.4 et seq.). It is general legal information, not legal advice.
Step 1: Confirm applicability, including the discount trigger
The first step is the threshold analysis under N.J.S.A. 56:8-166.5. The NJDPA applies to a controller that conducts business in New Jersey, or produces products or services targeted to New Jersey residents, and that during a calendar year meets one of two data thresholds.
The high trigger is controlling or processing the personal data of at least 100,000 consumers, excluding data processed solely to complete a payment transaction. The low trigger is at least 25,000 consumers combined with deriving revenue, or receiving a discount on the price of goods or services, from the sale of personal data.
Pay close attention to the low trigger. There is no percentage-of-revenue floor, so a business with 25,000 consumers is covered if it derives any revenue at all from selling data, or even if it merely receives a discount in exchange for data. A data-for-discount arrangement with a vendor can trigger coverage. Count only New Jersey residents acting in an individual or household context; under N.J.S.A. 56:8-166.4, employees and business-to-business contacts generally do not count.
Even a business that clears these thresholds can still fall outside the NJDPA. N.J.S.A. 56:8-166.13 exempts protected health information handled by a HIPAA-covered entity or business associate, financial institutions and their affiliates subject to the Gramm-Leach-Bliley Act, New Jersey-regulated insurance institutions, insurance-support organizations, national securities associations registered under Section 15A of the Securities Exchange Act (both added by the A5017 amendment signed January 20, 2026), state agencies and political subdivisions, consumer reporting agency data governed by the Fair Credit Reporting Act, New Jersey Motor Vehicle Commission data covered by the federal Driver's Privacy Protection Act, and certain human-subjects research data. Confirm whether one of these carve-outs applies before building a compliance program.
Step 2: Publish a compliant privacy notice
A covered controller must provide consumers with a reasonably accessible, clear, and meaningful privacy notice under N.J.S.A. 56:8-166.6. The notice is the public-facing record of how the business handles personal data, and it is the first thing a regulator will read.
The notice should describe the categories of personal data processed, the purposes for processing, the categories of data shared with third parties and the categories of those third parties, and how consumers may exercise their rights. It must also explain how a consumer may appeal a controller's decision on a request, and how the controller notifies consumers of material changes to the notice.
If the business sells personal data or processes it for targeted advertising, the notice must clearly disclose that and explain how to opt out, including through a universal opt-out mechanism. The proposed Division of Consumer Affairs rules add detail on clarity, accessibility, and avoiding dark patterns, so build the notice to the higher of the statutory and proposed-rule standards.
Step 3: Stand up consumer-rights and appeal workflows
Covered controllers need a working process to receive and fulfill consumer requests to confirm and access, correct, delete, and port personal data, and to honor the opt-out rights. The response deadline under N.J.S.A. 56:8-166.7 is 45 days, with one 45-day extension where reasonably necessary, so the intake and verification workflow has to move within that window.
Build in an authentication step. A controller is not required to comply with a request it cannot authenticate using commercially reasonable efforts, and it may request additional information to verify the consumer. Keep requests free of charge except where they are manifestly unfounded, excessive, or repetitive, and be ready to bear the burden of proving that standard if a fee is charged or a request declined.
The appeal process is mandatory, not optional. Under N.J.S.A. 56:8-166.6 and 56:8-166.7, a refusal must come with a written justification and a conspicuous appeal mechanism, and a denied appeal must point the consumer to the Division of Consumer Affairs. The NJDPA consumer rights guide walks through each right in detail.

Step 4: Opt-in consent for sensitive data, including financial information
Sensitive data requires opt-in consent before processing under N.J.S.A. 56:8-166.12(a)(4), and New Jersey's definition of sensitive data at N.J.S.A. 56:8-166.4 is broad. Map your data inventory against it carefully, because two categories catch many businesses off guard.
First, financial information is sensitive in New Jersey. That covers a consumer's account number, account log-in, financial account, or credit or debit card number combined with any required security code, access code, or password that would permit access to the account. Many businesses that handle payment credentials for purposes beyond completing a transaction will need consent. Second, status as transgender or nonbinary is sensitive data.
The full list also includes racial or ethnic origin, religious beliefs, health condition, treatment, or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data, data from a known child, and precise geolocation. Consent must be a freely given, specific, informed, and unambiguous affirmative act, cannot be obtained through dark patterns, and must be revocable. Where you cannot get consent, stop processing that sensitive data.
Step 5: Recognize a universal opt-out mechanism
Under N.J.S.A. 56:8-166.11(b)(1), the NJDPA requires controllers to honor a universal opt-out mechanism, such as Global Privacy Control, that lets consumers opt out of targeted advertising and the sale of personal data through a browser or device setting. This obligation took effect no later than six months after the January 15, 2025 effective date, by approximately July 15, 2025, so it is already live as of 2026.
Implement the signal detection so that when a consumer's browser or device sends an opt-out preference, the business treats it as a valid opt-out for that browser or device. Do not condition recognition on the consumer also completing a separate form, and do not let a default setting override the consumer's express choice.
Test the implementation. A common compliance gap is a privacy notice that promises to honor universal signals while the website's ad-tech stack quietly keeps loading targeting tags. The opt-out has to actually take effect downstream.

Step 6: Data protection assessments and processor contracts
Under N.J.S.A. 56:8-166.12(a)(9), a controller must conduct and document a data protection assessment for processing that presents a heightened risk of harm to consumers. N.J.S.A. 56:8-166.12(c) defines heightened risk to include processing for targeted advertising, the sale of personal data, certain profiling, and the processing of sensitive data. Under N.J.S.A. 56:8-166.12(b), the assessment weighs the benefits of the processing against the risks to consumers, as mitigated by safeguards.
Keep these assessments on file. N.J.S.A. 56:8-166.12(b) requires a controller to make a data protection assessment available to the Division of Consumer Affairs on request, so the documentation should be retained and kept current as processing activities change.
Under N.J.S.A. 56:8-166.16(e), controllers must also bind every processor with a written contract. The contract has to set out processing instructions, the nature and purpose of processing, the type of data and duration, confidentiality duties, deletion or return of data, and the processor's duty to assist the controller and to make information available to demonstrate compliance. Review existing vendor agreements and add NJDPA-compliant terms where they are missing.
Step 7: Track the rulemaking and the cure-period sunset
Two timing items deserve a place on every NJDPA compliance calendar. First, the Division of Consumer Affairs is actively writing rules. N.J.S.A. 56:8-166.18 directs the Director to promulgate rules and regulations necessary to effectuate the Act, and proposed rules were published on June 2, 2025, with a comment period that ran through August 1, 2025. Those rules can add obligations beyond the statute, so monitor for the adopted version and adjust.
Second, the right to cure has already ended. Under N.J.S.A. 56:8-166.17(b), the NJDPA gave a controller 30 days to cure an alleged violation after notice from the Division of Consumer Affairs, but that mandatory cure notice applied only until the first day of the 18th month after the effective date, which was July 1, 2026. Since that date, the Attorney General may pursue enforcement directly, without first offering a chance to fix the problem, and issuing a cure notice at all is now entirely at the Division's discretion.
Under N.J.S.A. 56:8-166.17(a), a controller's violation is an unlawful practice under the New Jersey Consumer Fraud Act, which carries civil penalties of up to $10,000 for a first violation and $20,000 for each subsequent violation, plus the other remedies available under that Act. Under N.J.S.A. 56:8-166.19, the Office of the Attorney General has sole and exclusive authority to enforce the Act and there is no private right of action, with the Division of Consumer Affairs acting under that authority.
Compliance checklist at a glance
| Step | Action | Authority |
|---|---|---|
| 1 | Confirm applicability, including the data-sale or discount trigger at 25,000 consumers | N.J.S.A. 56:8-166.5 |
| 2 | Publish a clear privacy notice with rights and appeal information | N.J.S.A. 56:8-166.6 |
| 3 | Build request, verification, and appeal workflows within 45 days | N.J.S.A. 56:8-166.7 |
| 4 | Get opt-in consent for sensitive data, including financial information | N.J.S.A. 56:8-166.12(a)(4) (duty); 56:8-166.4 (definition) |
| 5 | Recognize a universal opt-out mechanism (by approx. July 15, 2025) | N.J.S.A. 56:8-166.11(b)(1) |
| 6 | Document assessments and sign compliant processor contracts | N.J.S.A. 56:8-166.12 (assessments); 56:8-166.16 (processor contracts) |
| 7 | Track the rulemaking; the mandatory cure period ended July 1, 2026 | N.J.S.A. 56:8-166.18 (rules); 56:8-166.17(b) (cure sunset) |
For the underlying law and how it compares to other states, see the What is the NJDPA? overview.
Related guides
- New Jersey data privacy laws parent hub
- What is the NJDPA?
- NJDPA consumer rights
- State data privacy law comparison
- What is the CCPA?
More New Jersey Laws
Frequently Asked Questions
How do I know if the NJDPA applies to my business?
Under N.J.S.A. 56:8-166.5, the NJDPA applies if you conduct business in New Jersey or target New Jersey residents and, during a calendar year, control or process the personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving any revenue, or a discount, from selling personal data. Count only New Jersey residents in an individual or household context; the low trigger has no percentage-of-revenue floor.
Does the NJDPA's data-sale trigger have a revenue percentage floor?
No. New Jersey's 25,000-consumer trigger under N.J.S.A. 56:8-166.5 applies if the controller derives any revenue at all, or even receives a discount on goods or services, from the sale of personal data. Unlike states that require a set share of revenue from data sales, New Jersey has no percentage floor, so a small data sale or a data-for-discount deal can bring a business in.
Do I need consent to process financial information under the NJDPA?
Often, yes. Under N.J.S.A. 56:8-166.4, financial information is sensitive data, meaning a consumer's account number, account log-in, financial account, or credit or debit card number combined with a required security code, access code, or password. Processing sensitive data requires opt-in consent under N.J.S.A. 56:8-166.12(a)(4), so handling payment credentials for purposes beyond completing a transaction generally needs the consumer's affirmative consent.
When did the universal opt-out requirement start?
Under N.J.S.A. 56:8-166.11(b)(1), the NJDPA requires controllers to recognize a universal opt-out mechanism such as Global Privacy Control no later than six months after the January 15, 2025 effective date, by approximately July 15, 2025. As of 2026, businesses must detect and honor these browser or device signals to opt consumers out of targeted advertising and the sale of personal data.
When did the NJDPA cure period end?
Under N.J.S.A. 56:8-166.17(b), the NJDPA gave a controller 30 days to cure an alleged violation after notice from the Division of Consumer Affairs, but that mandatory cure notice applied only until the first day of the 18th month after the effective date, which was July 1, 2026. That date has passed, so the Attorney General may now bring enforcement without first offering a chance to cure.
What are the penalties for violating the NJDPA?
Under N.J.S.A. 56:8-166.17(a), a violation is an unlawful practice under the New Jersey Consumer Fraud Act, which carries civil penalties of up to $10,000 for a first violation and $20,000 for each subsequent violation, along with the other remedies that Act provides. Under N.J.S.A. 56:8-166.19, the Office of the Attorney General has sole and exclusive authority to enforce the law, and there is no private right of action.
Do I need to do data protection assessments?
Yes, for higher-risk processing. Under N.J.S.A. 56:8-166.12(a)(9), a controller must conduct and document a data protection assessment for processing that presents a heightened risk of harm, which N.J.S.A. 56:8-166.12(c) defines to include targeted advertising, the sale of personal data, certain profiling, and processing sensitive data. Keep the assessments on file, because N.J.S.A. 56:8-166.12(b) requires the controller to make an assessment available to the Division of Consumer Affairs on request.
Is New Jersey writing privacy regulations?
Yes. N.J.S.A. 56:8-166.18 directs the Director of the Division of Consumer Affairs to promulgate rules to effectuate the Act, and the Division published proposed privacy regulations on June 2, 2025, with comments due August 1, 2025. The proposed rules address privacy-notice detail, dark patterns, and consent, so businesses should track the rulemaking and comply with the adopted rules in addition to the statute.
Updates
Corrected the statutory citations behind the compliance steps: data protection assessments are required by N.J.S.A. 56:8-166.12, the universal opt-out duty is N.J.S.A. 56:8-166.11(b)(1), sensitive-data consent is N.J.S.A. 56:8-166.12(a)(4), and the cure period and rulemaking are N.J.S.A. 56:8-166.17(b) and 56:8-166.18 rather than 56:8-166.19.
Updated the cure-period section to reflect that New Jersey's mandatory 30-day cure notice already ended on July 1, 2026 (previously stated as an upcoming sunset around July 15, 2026), and added the NJDPA's actual applicability exemptions to Step 1.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Jersey Statutes (Unannotated)
§ 56:8-166.12Controller, personal data, responsibilities, security.In forcecited in 2 of our articles
9. a. A controller shall: (1) limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; (2) except as otherwise provided in P.L.2023, c.266 (C.56:8-166.4 et seq.), not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; (3) take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data and to secure personal data during both storage and use from unauthorized acquisition.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: New Jersey Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 56:8-166.5Applicability; consumers, personal data, control, processing.In forcecited in 2 of our articles
2. Notwithstanding any State law, rule, regulation, or order to the contrary, the provisions of P.L.2023, c.266 (C.56:8-166.4 et seq.) shall only apply to controllers that conduct business in the State or produce products or services that are targeted to residents of the State, and that during a calendar year either: a. control or process the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction; or b. control or process the personal data of at least 25,000 consumers and the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: What Is the NJDPA? New Jersey Data Privacy Act
§ 56:8-166.6Controller, consumer, privacy notice, personal data; disclosure, sale.In forcecited in 3 of our articles
3. a. A controller shall provide to a consumer a reasonably accessible, clear, and meaningful privacy notice that shall include, but may not be limited to: (1) the categories of the personal data that the controller processes; (2) the purpose for processing personal data; (3) the categories of all third parties to which the controller may disclose a consumer's personal data; (4) the categories of personal data that the controller shares with third parties, if any; (5) how consumers may exercise their consumer rights, including the controller's contact information and how a consumer may appeal a controller's decision with regard to the consumer's request; (6) the process by which the controller notifies consumers of material changes to the notification required to be made available pursuant to this subsection, along with the effective date of the notice; and (7) an active electronic mail address or other online mechanism that the consumer may use to contact the controller.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: NJDPA Consumer Rights: New Jersey Privacy Law
§ 56:8-166.7Personal data; controller, verified request, consumer, response period.In forcecited in 2 of our articles
4. a. A controller that receives a verified request from a consumer shall provide a response to the consumer within 45 days of the controller's receipt of the request. The controller may extend the response period by 45 additional days where reasonably necessary, considering the complexity and number of the consumer's requests, provided that the controller informs the consumer of any such extension within the initial 45-day response period and the reason for the extension and shall provide the information for all disclosures of personal data that occurred in the prior 12 months. b. This section shall not apply to personal data collected prior to the effective date of P.L.2023, c.266 (C.56:8-166.4 et seq.) unless the controller continues to process such information thereafter. c. If a controller declines to take action regarding the consumer's request, the controller shall inform the consumer without undue delay, but not later than 45 days after receipt of the request, of the justification for declining to take action and instructions for how to appeal the decision.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
§ 56:8-166.16Controllers, processors, respective obligations.In force
13. a. Controllers and processors shall meet their respective obligations established under P.L.2023, c.266 (C.56:8-166.4 et seq.). b. Processors shall adhere to the instructions of the controller and assist the controller to meet its obligations under this act. Taking into account the nature of processing and the information available to the processor, the processor shall assist the controller by: (1) taking appropriate technical and organizational measures, insofar as possible, for the fulfillment of the controller's obligation to respond to consumer requests to exercise their rights under this act; (2) helping to meet the controller's obligations in relation to the security of processing the personal data and in relation to notification of a breach of the security of the system; and (3) providing information to the controller necessary to enable the controller to conduct and document any data protection assessments required by section 9 of P.L.2023, c.266 (C.56:8-166.12). The controller and processor are each responsible for only the measures allocated to them.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
§ 56:8-166.13Applicability, personal data, exceptions, institutions, certain.In force
10. Nothing in P.L.2023, c.266 (C.56:8-166.4 et seq.) shall apply to: a. protected health information collected by a covered entity or business associate subject to the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the "Health Insurance Portability and Accountability Act of 1996," Pub.L.104-191, and the "Health Information Technology for Economic and Clinical Health Act,"42 U.S.C. s.17921 et seq.; b. a financial institution, data, or an affiliate of a financial institution that is subject to Title V of the federal "Gramm-Leach-Bliley Act," 15 U.S.C. s.6801 et seq., and the rules and implementing regulations promulgated thereunder; c. the secondary market institutions identified in 15 U.S.C. s.6809(3)(D) and 12 C.F.R. s.1016.3(l)(3)(iii); d. an insurance institution subject to P.L.1985, c.179 (C.17:23A-1 et seq.); e. the sale of a consumer's personal data by the New Jersey Motor Vehicle Commission that is permitted by the federal "Drivers' Privacy Protection Act of 1994," 18 U.S.C.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
§ 56:8-166.19Authority, enforcement.In forcecited in 2 of our articles
16. The Office of the Attorney General shall have sole and exclusive authority to enforce a violation of P.L.2023, c.266 (C.56:8-166.4 et seq.). Nothing in P.L.2023, c.266 (C.56:8-166.4 et seq.) shall be construed as providing the basis for, or subject to, a private right of action for violations of P.L.2023, c.266 (C.56:8-166.4 et seq.).
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
§ 56:8-166.4Definitions.In forcecited in 5 of our articles
1. As used in P.L.2023, c.266 (C.56:8-166.4 et seq.): "Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity. For the purposes of this definition, "control" means: the ownership of or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company; the control in any manner over the election of a majority of the directors or individuals exercising similar functions; or the power to exercise a controlling influence over the management or policies of a company. "Biometric data" means data generated by automatic or technological processing, measurements, or analysis of an individual's biological, physical, or behavioral characteristics, including, but not limited to, fingerprint, voiceprint, eye retinas, irises, facial mapping, facial geometry, facial templates, or other unique biological, physical, or behavioral patterns or characteristics that are used or intended to be used, singularly or in combination with each other or with other personal data, to identify a specific individual.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: New Jersey Data Privacy Laws: NJDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.J.S.A. 56:8-166.4: Definitions (Sensitive Data, Financial Information)(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.5: Applicability and Thresholds(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.6: Privacy Notice and Consumer Rights(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.7: Verified Request and 45-Day Response(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.16: Data Protection Assessments and Processor Obligations(pub.njleg.state.nj.us).gov
- N.J.S.A. 56:8-166.19: Authority and Enforcement(pub.njleg.state.nj.us).gov
- New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
- NJCCIC: New Jersey Enacts Comprehensive Data Privacy Law(cyber.nj.gov).gov
- New Jersey Legislature: S332 bill page (2022-2023 session)(njleg.state.nj.us).gov
- NJ Office of the Attorney General: Proposed NJDPA Rules Announced (June 2, 2025; comments due August 1, 2025)(njoag.gov)