top of page

The Privacy Patchwork Reaches Main Street: New Jersey’s Data Law and Your Business

dnelson58
Aug 2
2 min read

Updated: Aug 11

Comprehensive data privacy law is no longer a California curiosity. Roughly twenty states now have one, and New Jersey’s is among the broadest. If your business collects data from New Jersey residents, the New Jersey Data Privacy Act (N.J.S.A. 56:8-166.4 et seq.) likely already applies to you.


The Act took effect January 15, 2025. It reaches any business that operates in New Jersey or targets New Jersey residents and meets one of two thresholds: processing the data of at least 100,000 New Jersey consumers, or at least 25,000 consumers while deriving revenue from selling data. There is no general revenue floor, and the law does not exempt nonprofits, so it sweeps in organizations that other states’ laws would leave alone.


What it requires. Covered businesses must post a clear privacy notice; honor consumer rights to access, correct, delete, and port their data; and let consumers opt out of targeted advertising, data sales, and certain profiling. New Jersey requires recognition of universal opt-out signals, meaning your website must respect a browser-level “do not sell” preference. Processing “sensitive data,” which New Jersey defines broadly enough to include much financial information, requires opt-in consent, and data protection assessments are required for higher-risk processing.


Two features make New Jersey stricter than many peers. The sensitive-data definition is unusually wide. And enforcement carries teeth: the Division of Consumer Affairs has rulemaking authority, and the initial grace period that let businesses cure violations sunset in mid-2026. After that window, the Attorney General can proceed to penalties without a mandatory chance to fix the problem first. There is no private right of action, so enforcement comes from the state rather than private plaintiffs, but state enforcement is real.


One clarification that trips people up: the Act protects consumers acting in an individual or household context and excludes data about people acting in an employment or commercial context. The NJDPA is about your customers’ data, not your employees’ data. Employee-privacy obligations come from other sources.


New Jersey has kept moving. A 2026 data-broker measure amended the law to restrict selling sensitive personal data and will require a public data-broker registry. The direction is one way: more obligations, not fewer.


What to do. Run a data inventory: know what personal data you collect, why, from whom, and with whom you share it. Update your privacy notice and build the consumer-rights request process, opt-out signal recognition, and consent flows for sensitive data. If you operate in multiple states, map your practices to the strictest law that applies, because building to that standard usually satisfies the rest.


The compliance lift is real but finite, and the cost of ignoring it climbs every year as the patchwork thickens.


Legal note: This article provides general information and is not legal advice.


Authorities: New Jersey Data Privacy Act, N.J.S.A. 56:8-166.4 et seq. (S. 332; P.L. 2023, c. 266; eff. Jan. 15, 2025); N.J. data-broker amendment (eff. June 30, 2026).


 
 
 

Comments


bottom of page