close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

New Jersey Privacy Law

NJ

New Jersey (NJDPA)

Last updated

NJDPA Enacted, in effect

Who this affects: This page tracks New Jersey’s NJDPA, which governs controllers and processors.

Who it applies to: Controllers that do business in New Jersey or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and any revenue or discount from selling personal data; some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 15, 2025
Effective ↗
Attorney General
Enforced by ↗
$10,000
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

NJDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to verified rights requests within 45 days; if you extend, say so and why within the first 45 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 4 “A controller that receives a verified request from a consumer shall provide a response to the consumer within 45 days of the controller’s receipt of the request” Read the statute P.L.2023, c.266 § 4 “provided that the controller informs the consumer of any such extension within the initial 45-day response period and the reason for the extension and shall provide the information for all disclosures of personal data that occurred in the prior 12 months.” Read the statute
  • Run an appeal process, answer appeals in writing within 45 days, and on denial give a way to complain to the Division. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 4 “A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable” Read the statute P.L.2023, c.266 § 4 “Not later than 45 days after receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions” Read the statute P.L.2023, c.266 § 4 “If the appeal is denied, the controller shall also provide the consumer with an online mechanism, if available, or other method through which the consumer may contact the Division of Consumer Affairs in the Department of Law and Public Safety to submit a complaint.” Read the statute
  • If you sell personal data or use it for targeted ads, let consumers opt out via a user-selected universal opt-out mechanism. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 8 “a controller that processes personal data for purposes of targeted advertising,or the sale of personal data shall allow consumers to exercise the right to opt-out of such processing through a user-selected universal opt-out mechanism” Read the statute

Can't

  • Sell sensitive data at all; the ban applies regardless of how many consumers' data you control or process. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2026, c.25 § 1 (C.56:8-166.12 a.(6)) “not sell sensitive data, which shall apply to all individuals or legal entities regardless of the number of consumers whose data the individual or entity controls or processes” Read the statute
  • Process sensitive data without first obtaining consent, or a known child's personal data other than in accordance with COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 9 “not process sensitive data concerning a consumer without first obtaining the consumer’s consent” Read the statute P.L.2023, c.266 § 9 “personal data concerning a known child, without processing such data in accordance with COPPA” Read the statute
  • Target ads at, sell data of, or profile for significant decisions a known teen at least 13 but younger than 17 without consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 9 “not process the personal data of a consumer for purposes of targeted advertising, the sale of the consumer’s personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer without the consumer’s consent, under circumstances where a controller has actual knowledge, or willfully disregards, that the consumer is at least 13 years of age but younger than 17 years of age” Read the statute

Should

  • Conduct and document a data protection assessment before heightened-risk processing of data acquired since the effective date. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 9 “not conduct processing that presents a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of each of its processing activities that involve personal data acquired on or after the effective date of” Read the statute P.L.2023, c.266 § 17 “This act shall take effect on the 365th day following the date of enactment” Read the statute
  • Sign a contract binding you and each processor that sets processing instructions, nature, purpose, data types and duration. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 13 “Processing by a processor shall be governed by a contract between the controller and the processor that is binding on both parties and that sets forth: (1) the processing instructions to which the processor is bound, including the nature and purpose of the processing; (2) the type of personal data subject to the processing, and the duration of the processing” Read the statute
  • Make revoking consent at least as easy as giving it, and stop processing as soon as practicable, within 15 days of revocation. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. P.L.2023, c.266 § 9 “provide an effective mechanism for a consumer to revoke the consumer’s consent under this section that is at least as easy as the mechanism by which the consumer provided the consumer’s consent and, upon revocation of such consent, cease to process the data as soon as practicable, but not later than 15 days after the receipt of such request” Read the statute

These are the highlights we judge most important, not everything NJDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

New Jersey Data Privacy Act

NJDPA (S332) is New Jersey’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read 17. This act shall take effect on the 365th day following the date of enactment, except that the Director of the Division of Consumer Affairs may take any anticipatory administrative action in advance as shall be necessary for the implementation of this act. Requires notification to consumers of co… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
Effective
January 15, 2025
Archived excerpt — the text we read 17. This act shall take effect on the 365th day following the date of enactment, except that the Director of the Division of Consumer Affairs may take any anticipatory administrative action in advance as shall be necessary for the implementation of this act. Requires notification to consumers of co… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
Signed
January 16, 2024
Archived excerpt — the text we read P.L. 2023, CHAPTER 266, approved January 16, 2024 Senate, No. 332 (Sixth Reprint) AN ACT concerning online services, consumers, and personal data and supplementing Title 56 of the Revised Statutes. BE IT ENACTED by the Senate and General Assembly of the State of New Je… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
Enforced by
Attorney General
Office of the Attorney General Archived excerpt — the text we read 16. The Office of the Attorney General shall have sole and exclusive authority to enforce a violation of P.L. , c. (C. ) (pending before the Legislature as this bill). Nothing in P.L. , c. (C. ) (pending before the Legislature as this bill) shall be construed as providing the basis for, or subject to, a private right of action for violations of P.L. , c. (C. ) (pending before the Legi… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
Maximum penalty per violation
$10,000; up to $20,000 (second or later offense)
Mostly Consumer Fraud Act penalties, plus restitution; a separate $50,000-per-record fine covers sensitive-data sales. Source for each figure$10,000 · N.J.S.A. 56:8-13 $20,000 · N.J.S.A. 56:8-13 Additional $50,000 per record · P.L.2026, c.25 § 5 Additional $10,000 · N.J.S.A. 56:8-14.3 Additional $30,000 · N.J.S.A. 56:8-14.3 “be liable to a penalty of not more than $10,000 for the first offense” View the statute
Right to cure
30 days (lapsed Jun 30, 2026)
A mandatory 30-day cure applied until July 1, 2026; that window has closed. Archived excerpt — the text we read 14. a. It shall be an unlawful practice and violation of P.L.1960, c.39 (C.56:8-1 et seq.) for a controller to violate the provisions of P.L. , c. (C. ) (pending before the Legislature as this bill). b. Until the first day of the 18th month next following the effective date of P.L. , c. (C. ) (pending before the Legislature as this bill), prior to bringing an enforcement action before an administrative law judge or a court of competent jurisdiction in this State, the Division of Consumer Affairs in the Department of Law and Public Safety shall issue a notice to the controller if a cure is deemed possible. If the operator controller fails to cure the alleged violation of P.L. , c. (C. ) (pending before the Legislature as this bill) within 30 days after receiving notice of alleged noncompliance from the division, such enfo… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read 16. The Office of the Attorney General shall have sole and exclusive authority to enforce a violation of P.L. , c. (C. ) (pending before the Legislature as this bill). Nothing in P.L. , c. (C. ) (pending before the Legislature as this bill) shall be construed as providing the basis for, or subject to, a private right of action for violations of P.L. , c. (C. ) (pending before the Legislature as this bill) . Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
Universal opt-out signal
Required
Archived excerpt — the text we read …he consumer and the authorized agent’s authority to act on the consumer’s behalf. b. (1) Beginning not later than six months following the effective date of P.L. , c. (C. ) (pending before the Legislature as this bill), a controller that processes personal data for purposes of targeted advertising,or the sale of personal data shall allow consumers to exercise the right to opt-out of such processing through a user-selected universal opt-out mechanism. (2) The platform, technology, or mechanism shall: (a) not permit its manufacturer to unfairly disadvantage another controller; (b) not make use of a default setting that opts-in a consumer to the processing or sale of … Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source

Who it applies to

Controllers that do business in New Jersey or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and any revenue or discount from selling personal data; some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to access Archived excerpt — the text we read 7. a. A consumer shall have the right to: (1) confirm whether a controller processes the consumer’s personal data and accesses such personal data, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller’s trade secrets; (2) correct inaccuracies in the consumer’s personal d… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to correct Archived excerpt — the text we read …r’s personal data and accesses such personal data, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller’s trade secrets; (2) correct inaccuracies in the consumer’s personal data, taking into account the nature of the information and the purposes of the processing of the information; (3) delete personal data concerning the consumer; (4) obtain a copy of the consumer’s personal data held by the controller in a portable and, to the extent technically feasible, readily usable format that allows the co… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to delete Archived excerpt — the text we read …er that would reveal the controller’s trade secrets; (2) correct inaccuracies in the consumer’s personal data, taking into account the nature of the information and the purposes of the processing of the information; (3) delete personal data concerning the consumer; (4) obtain a copy of the consumer’s personal data held by the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another entity with… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to data portability Archived excerpt — the text we read …s; (2) correct inaccuracies in the consumer’s personal data, taking into account the nature of the information and the purposes of the processing of the information; (3) delete personal data concerning the consumer; (4) obtain a copy of the consumer’s personal data held by the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another entity without hindrance, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …nother entity without hindrance, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller’s trade secrets; and (5) opt out of the processing of personal data for the purposes of (a) targeted advertising; (b) the sale of personal data; or (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. b. A controller that has lawfully obtained personal data about a consumer from a source other than the consumer shall be deemed in compliance with a consumer’s request to delete such data pursuant to this subsection by:… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …nother entity without hindrance, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller’s trade secrets; and (5) opt out of the processing of personal data for the purposes of (a) targeted advertising; (b) the sale of personal data; or (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. b. A controller that has lawfully obtained personal data about a consumer from a source other than the consumer shall be deemed in compliance with a consumer’s request to delete such data pursuant to this subsection by:… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …nother entity without hindrance, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller’s trade secrets; and (5) opt out of the processing of personal data for the purposes of (a) targeted advertising; (b) the sale of personal data; or (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. b. A controller that has lawfully obtained personal data about a consumer from a source other than the consumer shall be deemed in compliance with a consumer’s request to delete such data pursuant to this subsection by:… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Sensitive data: opt-in consent required to process; sale prohibited C.56:8-166.12 a.(6), added by P.L.2026, c.25. Archived excerpt — the text we read …bility of personal data and to secure personal data during both storage and use from unauthorized acquisition. The data security practices shall be appropriate to the volume and nature of the personal data at issue; (4) not process sensitive data concerning a consumer without first obtaining the consumer’s consent, or, in the case of the processing of personal data concerning a known child, without processing such data in accordance with COPPA; (5) not process personal data in violation of the laws of this State and… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right to appeal Archived excerpt — the text we read …e person who made such request disclosing that such controller believes such request is fraudulent, why such controller believes such request is fraudulent and that such controller shall not comply with such request. f. A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision. The appeal process shall be conspicuously available and similar to the process for submitting requests to initiate action pu… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Right against discrimination Also (§5): no discrimination for opting out of sale, targeted ads or significant-decision profiling; discounts, loyalty programs or other incentives for selling personal data are allowed. Archived excerpt — the text we read …ch sale or processing . c. A controller shall not: (1) require a consumer to create a new account in order to exercise a right , but may require a consumer to use an existing account to submit a verified request; or (2) based solely on the exercise of a right and unrelated to feasibility or the value of a service, increase the cost of, or decrease the availability of, the product or service. Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read 16. The Office of the Attorney General shall have sole and exclusive authority to enforce a violation of P.L. , c. (C. ) (pending before the Legislature as this bill). Nothing in P.L. , c. (C. ) (pending before the Legislature as this bill) shall be construed as providing the basis for, or subject to, a private right of action for violations of P.L. , c. (C. ) (pending before the Legislature as this bill) . Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …dark patterns. “Consumer” means an identified person who is a resident of this State acting only in an individual or household context. “Consumer” shall not include a person acting in a commercial or employment context. “Controller” means an individual, or legal entity that, alone or jointly with others determines the purpose and means of processing personal data. “COPPA” means the federal Children’s Online Privacy Protection Act, 15 U.S.C. s.6501 et seq., and any rules, regulations, guidelines, and exceptions thereto, as may be amended from time to time. “Dark pattern” means a u… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Processors Archived excerpt — the text we read …ets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data, and also includes the actions of a controller directing a processor to process personal data. “Processor” means a person, private entity, public entity, agency, or other entity that processes personal data on behalf of the controller. “Profiling” means any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual’s economic situation, health, personal p… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source

Exemptions

  • Protected health information collected by a HIPAA covered entity or business associate Data-level; no entity-wide HIPAA exemption. Archived excerpt — the text we read 10. Nothing in P.L. , c. (C. ) (pending before the Legislature as this bill) shall apply to: a. protected health information collected by a covered entity or business associate subject to the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the "Health Insurance Portability and Accountability Act of 1996," Pub.L.104-191, and the “Health Information Technology for Eco… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Financial institutions, their affiliates, and data subject to GLBA Title V Entity- and data-level Entity- and data-level, §10 b. Archived excerpt — the text we read …tions, established pursuant to the "Health Insurance Portability and Accountability Act of 1996," Pub.L.104-191, and the “Health Information Technology for Economic and Clinical Health Act,”42 U.S.C. s.17921 et seq.; b. a financial institution ,data, or an affiliate of a financial institution that is subject to Title V of the federal “Gramm-Leach-Bliley Act,” 15 U.S.C. s.6801 et seq., and the rules and implementing regulations promulgated thereunder; c. the secondary market institutions identified in 15 U.S.C. s.6809(3)(D) and 12 C.F.R. s.1016.3(l)(3)(iii); d. an insurance institution subject to P.L.1985, c.179 (C.17:23A-1 et seq.); e. the sale of a consumer’s pers… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Secondary market institutions Archived excerpt — the text we read …ution ,data, or an affiliate of a financial institution that is subject to Title V of the federal “Gramm-Leach-Bliley Act,” 15 U.S.C. s.6801 et seq., and the rules and implementing regulations promulgated thereunder; c. the secondary market institutions identified in 15 U.S.C. s.6809(3)(D) and 12 C.F.R. s.1016.3(l)(3)(iii); d. an insurance institution subject to P.L.1985, c.179 (C.17:23A-1 et seq.); e. the sale of a consumer’s personal data by the New Jersey Motor Vehicle Commission that is permitted by the federal "Drivers' Privacy Prote… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • State-regulated insurance institutions Archived excerpt — the text we read …h-Bliley Act,” 15 U.S.C. s.6801 et seq., and the rules and implementing regulations promulgated thereunder; c. the secondary market institutions identified in 15 U.S.C. s.6809(3)(D) and 12 C.F.R. s.1016.3(l)(3)(iii); d. an insurance institution subject to P.L.1985, c.179 (C.17:23A-1 et seq.); e. the sale of a consumer’s personal data by the New Jersey Motor Vehicle Commission that is permitted by the federal "Drivers' Privacy Protection Act of 1994," 18 U.S.C. s.2721 et seq.; f. personal data collected, pro… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • DPPA-permitted DMV data sales Archived excerpt — the text we read …ations promulgated thereunder; c. the secondary market institutions identified in 15 U.S.C. s.6809(3)(D) and 12 C.F.R. s.1016.3(l)(3)(iii); d. an insurance institution subject to P.L.1985, c.179 (C.17:23A-1 et seq.); e. the sale of a consumer’s personal data by the New Jersey Motor Vehicle Commission that is permitted by the federal "Drivers' Privacy Protection Act of 1994," 18 U.S.C. s.2721 et seq.; f. personal data collected, processed, sold, or disclosed by a consumer reporting agency, as defined in 15 U.S.C. s.1681a(f), if the collection, processing, sale, or disclosure of the personal data is limited, governed… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • FCRA-regulated data of consumer reporting agencies Archived excerpt — the text we read …, c.179 (C.17:23A-1 et seq.); e. the sale of a consumer’s personal data by the New Jersey Motor Vehicle Commission that is permitted by the federal "Drivers' Privacy Protection Act of 1994," 18 U.S.C. s.2721 et seq.; f. personal data collected, processed, sold, or disclosed by a consumer reporting agency, as defined in 15 U.S.C. s.1681a(f), if the collection, processing, sale, or disclosure of the personal data is limited, governed, and collected, maintained, disclosed, sold, communicated, or used only as authorized by the federal “Fair Credit Reporting Act,” 15 U.S.C. s.1681 et seq., and implementing regulations; g. any State agency as defined in section 2 of P.L.1971, c.182 (C.52:13D-13), any political subdivision, and any division, board, bureau, office, commission, or other instrumentality creat… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • State and local government Archived excerpt — the text we read …onal data is limited, governed, and collected, maintained, disclosed, sold, communicated, or used only as authorized by the federal “Fair Credit Reporting Act,” 15 U.S.C. s.1681 et seq., and implementing regulations; g. any State agency as defined in section 2 of P.L.1971, c.182 (C.52:13D-13), any political subdivision, and any division, board, bureau, office, commission, or other instrumentality created by a political subdivision; or h. personal data that is collected, processed, or disclosed, as part of research conducted in accordance with the Federal Policy for the protection of human subjects pursuant to 45 C.F.R. Part 46 or the protection o… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Human subjects research data Archived excerpt — the text we read …y State agency as defined in section 2 of P.L.1971, c.182 (C.52:13D-13), any political subdivision, and any division, board, bureau, office, commission, or other instrumentality created by a political subdivision; or h. personal data that is collected, processed, or disclosed, as part of research conducted in accordance with the Federal Policy for the protection of human subjects pursuant to 45 C.F.R. Part 46 or the protection of human subjects pursuant to 21 C.F.R. Parts 50 and 56. Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Evidentiary privilege (compliance would violate a New Jersey evidentiary privilege) Archived excerpt — the text we read …sures to protect the confidentiality, integrity, and accessibility of the personal data and to reduce reasonably foreseeable risks of harm to consumers relating to such collection, use, or retention of personal data. c. The obligations imposed on controllers or processors under P.L. , c. (C. ) (pending before the Legislature as this bill) shall not apply where compliance by the controller or processor with the provisions of law would violate an evidentiary privilege under the laws of this State. Nothing in P.L. , c. (C. ) (pending before the Legislature as this bill) shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary … Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …ly where compliance by the controller or processor with the provisions of law would violate an evidentiary privilege under the laws of this State. Nothing in P.L. , c. (C. ) (pending before the Legislature as this bill) shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of the State as part of a privileged communication. d. Personal data that are processed by a controller pursuant to an exception provided by this section: (1) shall not be processed for any purpose other than a purpose expressly listed in this section; and … Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source
  • National securities associations Entity-level P.L.2025, c.367 § 1 (C.56:8-166.13) National securities associations registered under section 15A of the Securities Exchange Act of 1934 (added by P.L.2025, c.367, eff. 2026-01-20). Archived excerpt — the text we read …r research conducted in accordance with the protection of human subjects pursuant to 21 C.F.R. Parts 50 and 56; i. an insurance-support organization as defined in section 2 of P.L.1985, c.179 (C.17:23A-2); or j. a national securities association registered pursuant to section 15A of the “Securities Exchange Act of 1934,” 15 U.S.C. s.78a et seq., and any rules or regulations promulgated thereunder. 2. Section 1 of P.L.2023, c.266 (C.56:8-166.4) is amended to read as follows: C.56:8-166.4 Definitions.… Archived from source — captured 2026-09-29 · snapshot 2a4552de Verify at the source
  • Insurance-support organizations as defined in C.17:23A-2 Entity-level P.L.2025, c.367 § 1 (C.56:8-166.13) Added by P.L.2025, c.367, eff. 2026-01-20. Archived excerpt — the text we read …nternational Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use, or research conducted in accordance with the protection of human subjects pursuant to 21 C.F.R. Parts 50 and 56; i. an insurance-support organization as defined in section 2 of P.L.1985, c.179 (C.17:23A-2); or j. a national securities association registered pursuant to section 15A of the “Securities Exchange Act of 1934,” 15 U.S.C. s.78a et seq., and any rules or regulations promulgated thereunder. … Archived from source — captured 2026-09-29 · snapshot 2a4552de Verify at the source
  • Information treated like PHI under HIPAA Data-level P.L.2025, c.367 § 1 (C.56:8-166.13) Information treated like protected health information by a HIPAA covered entity or business associate, when used or disclosed in accordance with HIPAA and given all HIPAA privacy and security protections (data-level; added by P.L.2025, c.367). Archived excerpt — the text we read …blished pursuant to the "Health Insurance Portability and Accountability Act of 1996" (“HIPAA”), Pub.L.104-191, and the "Health Information Technology for Economic and Clinical Health Act," 42 U.S.C. s.17921 et seq.; or information treated like protected health information collected, used, or disclosed by a covered entity or business associate under HIPAA when the information is used or disclosed in accordance with HIPAA and the information is afforded all the privacy protections and security safeguards of the federal laws and implementing regulations under HIPAA; b. a financial institution, data, or an affiliate of a financial institution that is subject to Title V of the federal "Gramm-Leach-Bliley Act," 15 U.S.C. s.6801 et seq., and the rules and implementing regulations … Archived from source — captured 2026-09-29 · snapshot 2a4552de Verify at the source
  • Human subjects research under ICH good clinical practice guidelines Data-level P.L.2025, c.367 § 1 (C.56:8-166.13) Data-level; added by P.L.2025, c.367. Archived excerpt — the text we read …tical subdivision; h. personal data that is collected, processed, or disclosed, as part of research conducted in accordance with the Federal Policy for the protection of human subjects pursuant to 45 C.F.R. Part 46, human subjects research conducted in accordance with good clinical practice guidelines issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use, or research conducted in accordance with the protection of human subjects pursuant to 21 C.F.R. Parts 50 and 56; i. an insurance-support organization as defined in section 2 of P.L.1985, c.179 (C.17:23A-2); or … Archived from source — captured 2026-09-29 · snapshot 2a4552de Verify at the source
  • Employee and B2B data: persons acting in a commercial or employment context are not 'consumers' Data-level Definitional exclusion, §1. Archived excerpt — the text we read …sing, or closing a given piece of content; or agreement obtained through the use of dark patterns. “Consumer” means an identified person who is a resident of this State acting only in an individual or household context. “Consumer” shall not include a person acting in a commercial or employment context. “Controller” means an individual, or legal entity that, alone or jointly with others determines the purpose and means of processing personal data. “COPPA” means the federal Children’s Online Privacy Protection Act, 15 U… Archived from source — captured 2026-09-25 · snapshot d83d93bd Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

NJDPA milestones

This state currently has one dated milestone on the books.

Enforcement January 15, 2025

NJDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026