EnglishEspañol
New Jersey flag

New Jersey

What Is the NJDPA? New Jersey Data Privacy Act

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 8, 2026. · 8 primary sources cited on this page. How we verify our legal content

What Is the NJDPA? New Jersey Data Privacy Act

Frequently Asked Questions

What is the NJDPA?

The NJDPA, or New Jersey Data Privacy Act, is New Jersey's comprehensive consumer data privacy law codified at N.J.S.A. 56:8-166.4 et seq. It was enacted as Senate Bill S332, signed by Governor Phil Murphy on January 16, 2024, and took effect January 15, 2025. It gives New Jersey residents rights over their personal data and requires covered controllers to be transparent about how they collect, use, and disclose it.

When did the NJDPA take effect?

The NJDPA took effect on January 15, 2025. A controller must recognize a universal opt-out mechanism such as Global Privacy Control no later than six months after that date, by approximately July 15, 2025. The 30-day right to cure sunset on July 1, 2026, the first day of the 18th month after the effective date.

What are the NJDPA's coverage thresholds?

Under N.J.S.A. 56:8-166.5, the NJDPA covers any controller doing business in New Jersey or targeting New Jersey residents that, during a calendar year, controlled or processed the personal data of at least 100,000 consumers (excluding data used solely to complete a payment transaction), or of at least 25,000 consumers while deriving any revenue, or a discount on goods or services, from the sale of personal data. The second trigger has no percentage-of-revenue floor.

Does the NJDPA treat financial information as sensitive data?

Yes. Under N.J.S.A. 56:8-166.4, sensitive data includes financial information, defined as a consumer's account number, account log-in, financial account, or credit or debit card number in combination with any required security code, access code, or password that would permit access to the financial account. Most state privacy laws do not classify financial information as sensitive, so this is a distinctive feature, and processing sensitive data requires opt-in consent.

What counts as sensitive data under the NJDPA?

Under N.J.S.A. 56:8-166.4, sensitive data includes data revealing racial or ethnic origin, religious beliefs, mental or physical health condition, treatment, or diagnosis, financial information, sex life or sexual orientation, citizenship or immigration status, status as transgender or nonbinary, genetic or biometric data, personal data collected from a known child, and precise geolocation data. Processing any sensitive data requires the consumer's opt-in consent.

Does the NJDPA require recognizing a universal opt-out signal?

Yes. The NJDPA requires controllers to recognize a universal opt-out mechanism, such as Global Privacy Control, that lets consumers opt out of targeted advertising and the sale of their personal data through a browser or device setting. That obligation took effect no later than six months after the law's effective date, by approximately July 15, 2025.

How is the NJDPA different from the CCPA?

Key differences: New Jersey's lower-tier trigger of 25,000 consumers requires only any revenue or a discount from data sales, with no percentage floor, while California's lower trigger requires deriving 50 percent of revenue from selling or sharing data; New Jersey treats financial information as sensitive data subject to opt-in consent; California also treats a financial account, debit card, or credit card number combined with a required access code as sensitive personal information, but handles it with an opt-out right to limit rather than an opt-in requirement, consistent with the broader pattern that New Jersey uses an opt-in consent model for sensitive data while California uses an opt-out right to limit. Neither law gives consumers a general private right of action.

Who enforces the NJDPA?

The New Jersey Attorney General and the Division of Consumer Affairs enforce the NJDPA under the New Jersey Consumer Fraud Act. There is no private right of action. A violation can carry civil penalties of up to $10,000 for a first violation and $20,000 for each subsequent violation. A 30-day right to cure applied through June 30, 2026, but sunset on July 1, 2026, the first day of the 18th month after the effective date.

Updates

Updated the 2026 amendment section to track the enacted text of P.L.2025, c.367, clarifying the broadened HIPAA and human-subjects research exemptions and the expanded de-identified-data definition.

Corrected the NJDPA-vs-CCPA comparison to reflect that California also treats a financial account or card number combined with an access code as sensitive personal information (it uses an opt-out right to limit, not an opt-in requirement); added coverage of the January 20, 2026 A5017 amendment, which added new exemptions and expanded the de-identified-data definition; and restored the statutory qualifier on the teen-consent profiling trigger.

Independently fact-checked against the cited primary sources

Corrected the NJDPA right-to-cure sunset date and fixed a now-stale framing. The enacted law (P.L. 2023, c.266, Section 14.b) sunsets the Division of Consumer Affairs' pre-enforcement cure notice 'on the first day of the 18th month next following the effective date' -- effective date January 15, 2025, so the sunset is July 1, 2026, not 'around July 15, 2026.' The article also described the cure window as 'in its final weeks' as of mid-2026, which is now wrong on any reading since the audit date is well past July 1, 2026 -- the window has already closed.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.J.S.A. 56:8-166.4: Definitions (Sensitive Data, Financial Information)(pub.njleg.state.nj.us).gov
  2. N.J.S.A. 56:8-166.5: Applicability and Thresholds(pub.njleg.state.nj.us).gov
  3. N.J.S.A. 56:8-166.6: Privacy Notice and Consumer Rights Exercise(pub.njleg.state.nj.us).gov
  4. N.J.S.A. 56:8-166.19: Authority and Enforcement(pub.njleg.state.nj.us).gov
  5. New Jersey Legislature: S332 bill page (2022-2023 session)(njleg.state.nj.us).gov
  6. New Jersey Division of Consumer Affairs(njconsumeraffairs.gov).gov
  7. NJCCIC: New Jersey Enacts Comprehensive Data Privacy Law(cyber.nj.gov).gov
  8. A5017 (P.L.2025, c.367) - NJDPA amendments: exemptions and de-identified data definition(pub.njleg.state.nj.us).gov
Share: