US Privacy Law New Jersey, USA

New Jersey NJDPA: Data Privacy Act Requirements

New Jersey's Data Privacy Act: no revenue threshold, financial data as sensitive, minors to 17, rulemaking authority, and Division of Consumer Affairs enforcement.

Regulation

New Jersey Data Privacy Act (S332, 2024), N.J.S.A. 56:8-166.4 et seq., effective January 15, 2025

Max Penalty

Up to $10,000 for a first violation and $20,000 for subsequent violations (Consumer Fraud Act)

Enforcing Authority

New Jersey Attorney General / Division of Consumer Affairs

Official Source

www.njconsumeraffairs.gov

Executive Summary

  • The NJDPA (effective January 15, 2025) covers controllers processing personal data of 100,000+ New Jersey consumers annually (excluding payment-only data), or 25,000+ where the controller derives revenue or discounts from selling personal data, with no minimum revenue percentage.
  • Its sensitive-data list is the broadest in the Virginia lineage: it adds financial information (account numbers, log-ins, card numbers with codes) to the usual categories, all requiring opt-in consent.
  • Minors' protections run to 17: targeted advertising, sale, and profiling of consumers known (or willfully disregarded) to be 13-16 require consent.
  • Universal opt-out recognition became mandatory July 15, 2025 (six months after effectiveness), and the Division of Consumer Affairs holds express rulemaking authority, rare among states, so binding regulations can expand the details.
  • Enforcement runs through the Consumer Fraud Act at $10,000 (first) / $20,000 (subsequent) per violation; a 30-day cure right applies only during the act's first 18 months, through mid-2026.

New Jersey closed the January 2025 wave with the sharpest law of the cohort: a threshold that collapses to 25,000 consumers for anyone monetizing data, the only sensitive-data list that captures ordinary payment credentials, teen protections to 17, and a regulator with the power to write binding rules. Programs that filed the NJDPA under “another Connecticut clone” mis-scoped it; on financial data and minors it is closer to a fourth strict-tier anchor beside Colorado, Oregon, and Texas.

LawNJDPA, N.J.S.A. 56:8-166.4 et seq.
EffectiveJanuary 15, 2025 (UOOM July 15, 2025)
Thresholds100,000 consumers, or 25,000 + any sale revenue
Max penalty$10,000 first / $20,000 subsequent (CFA)
RegulatorNJ Division of Consumer Affairs
StatuteS332 (2024)

The New Jersey deltas

Financial-data consent analysis. Map where account numbers, log-ins, and card-plus-code data are processed beyond strict necessity for the requested service: fraud-scoring vendors, analytics on transaction patterns, marketing segmentation by spend. Each use needs consent, an exemption, or elimination. GLBA-regulated institutions keep only a data-level exemption for that data.

Teen ad-targeting to 16 inclusive. Combine with Delaware’s under-18 rule and Connecticut’s provisions: the practical multistate setting is no targeted advertising, sale, or profiling for any user under 17-18 absent affirmative consent. See the children’s matrix.

Rulemaking watch. Subscribe to the Division’s proposals; UOOM specifications and verification rules can impose Colorado-style technical detail on six months’ notice. The GPC pipeline you run nationally should already satisfy the July 2025 mandate.

Everything else inherits. Sensitive-data consent flows, 45-day DSARs with appeals, assessments for heightened-risk processing, and processor contracts transfer from the strict-tier build documented in the multi-state strategy guide and state comparison.

Check the visible surface, notices, opt-outs, trackers, GPC response, with a free scan.

Frequently Asked Questions

What makes New Jersey's applicability test unusual?

The second prong: 25,000+ consumers plus deriving any revenue or discount from selling personal data, no percentage floor. A single paid data-sharing arrangement, or ad-tech participation meeting the sale definition, drops the threshold to 25,000 residents of an 9.3-million-person state. Nonprofits are not exempt as a class either. Most national consumer businesses are covered.

Why does financial data as 'sensitive' matter so much?

No other Virginia-lineage state includes ordinary financial information (account or card numbers with access codes) in its consent-gated sensitive list. E-commerce, fintech, and subscription businesses that treat stored payment credentials as routine operational data need a New Jersey consent analysis, or must rely on processing being strictly necessary for the requested service, and data-level GLBA exemptions only reach GLBA-regulated data.

What are the minors' rules?

Where a controller has actual knowledge or willfully disregards that a consumer is 13 to 16, processing for targeted advertising, sale, or profiling requires the consumer's consent (parental below 13 via COPPA). This extends the teen ad-consent model past Connecticut's 13-15 to include 16-year-olds. Age signals in your data (birthdates, grade levels, content skew) defeat a claimed lack of knowledge.

What could the rulemaking authority change?

The Division of Consumer Affairs may promulgate regulations to effectuate the act, authority most states withheld from their AGs (Colorado and California being the exceptions). Draft rules can specify UOOM technical standards, notice content, and verification procedures with binding force. Programs should monitor the Division's docket the way they monitor the Colorado AG's, New Jersey is one of three states where the rules can move under you.

How is the NJDPA enforced?

By the AG through the Consumer Fraud Act: $10,000 for a first violation, $20,000 for subsequent ones, plus the CFA's injunctions and costs, with no private right of action. For the first 18 months (through mid-2026) the AG offers a 30-day cure for curable violations; afterward none is required. New Jersey's Division of Consumer Affairs has an active history of data-security enforcement (its HIPAA-adjacent actions against health networks), so expect real cases, not just sweep letters.

Regulatory Crosswalk

Colorado CPAConnecticut CTDPACCPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.