The New Jersey data privacy law gives state residents the right to see, correct, delete, and take back their personal information from companies that hold it, and to stop those companies from selling that data or using it for targeted advertising. It took effect on January 15, 2025, and is enforced by the state Attorney General, who can seek civil penalties of up to $10,000 for a first violation and up to $20,000 for each repeat offense.1New Jersey Division of Consumer Affairs. New Jersey Data Privacy Law FAQs The formal name is the New Jersey Data Protection Act, codified at N.J.S.A. 56:8-166.4 et seq.
The rights below apply when you are acting as an individual or on behalf of your household. If a company is dealing with you in your role as an employee or in another commercial capacity, this law does not cover that interaction.2New Jersey Legislature. P.L. 2023, c. 266
Your Rights Over Your Personal Data
The act gives New Jersey residents six core rights against any business that meets the coverage thresholds.3New Jersey Legislature. Senate No. 332 Bill Text
- Confirm and access. You can ask whether a company is processing your personal data and get a copy of what it holds.
- Correct. You can require the company to fix information that is wrong.
- Delete. You can require the company to erase your personal data from its records.
- Data portability. You can obtain your data in a portable, readily usable format so you can move it to a different service.
- Opt out of sales and targeted advertising. You can tell the company to stop selling your data or using it to target ads at you.
- Opt out of profiling. You can refuse automated profiling that produces legal or similarly significant effects, such as decisions tied to housing, employment, or insurance eligibility.
“Personal data” is defined broadly. It covers any information linked or reasonably linkable to you, from your name and email address to browsing behavior and purchase history. Data that has been de-identified, and public records lawfully obtained from the government, are not covered.2New Jersey Legislature. P.L. 2023, c. 266
Stronger Protection for Sensitive Data
For a narrower category the law calls “sensitive,” the default flips. A company cannot process this data at all without your affirmative consent up front. Sensitive data includes information about racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, precise geolocation, and any personal data collected from a known child.2New Jersey Legislature. P.L. 2023, c. 266
Biometric data is treated as sensitive. That means data generated from automated processing of biological, physical, or behavioral characteristics, including fingerprints, voiceprints, retina scans, and facial mapping. Ordinary photographs and audio or video recordings are not biometric data unless they were specifically created to identify a person.4Justia Law. New Jersey Revised Statutes 56:8-166.12
Children and Teenagers
For data about a known child under 13, the business must follow the federal Children’s Online Privacy Protection Act, which generally requires verifiable parental consent. Teens between 13 and 16 get their own layer of protection: a company that knows or willfully disregards a consumer’s age in that range cannot process the teen’s data for targeted advertising, data sales, or consequential profiling without the teen’s consent.4Justia Law. New Jersey Revised Statutes 56:8-166.12
Taking Back Consent
If you already gave a company consent, you can revoke it. Every controller has to offer a revocation method that is at least as easy to use as the way you originally consented, and once you revoke, the company must stop processing that data within 15 days. Closing a browser window or simply continuing to use a site does not count as consent in the first place.4Justia Law. New Jersey Revised Statutes 56:8-166.12
How to Submit a Request
Start with the company’s privacy notice, which is required to describe the specific methods you can use. In practice this is usually a web form or a dedicated email address. State clearly which right you are exercising, and provide enough information for the company to find your records and verify who you are. That normally means your full name and the email or account identifier tied to your relationship with the business.
The company has 45 days to respond. If your request is unusually complex, it can extend that deadline once by another 45 days, but only if it tells you about the extension and explains why.2New Jersey Legislature. P.L. 2023, c. 266
You can also let someone else handle the process. The law allows you to designate an authorized agent to submit opt-out requests on your behalf, provided the business can verify both your identity and the agent’s authority to act for you.1New Jersey Division of Consumer Affairs. New Jersey Data Privacy Law FAQs
If the Company Says No
A denial is not the end of the road. Any company that turns down your request must offer an internal appeal process, and the appeal decision has to come with a written explanation. If that appeal is also denied, the company must give you a way to contact the Division of Consumer Affairs to file a complaint.3New Jersey Legislature. Senate No. 332 Bill Text The law does not give individual consumers the right to sue directly, so the Division is the channel that matters if a company refuses to comply.
Universal Opt-Out Signals
Since July 15, 2025, covered controllers have been required to honor universal opt-out mechanisms such as Global Privacy Control. These are browser-based signals that automatically tell every website you visit that you are opting out of data sales and targeted advertising. Turn one on in your browser or through a privacy extension, and businesses covered by the law have to treat it as a valid opt-out. No individual request required, no per-company forms.1New Jersey Division of Consumer Affairs. New Jersey Data Privacy Law FAQs
Which Businesses Have to Comply
The law reaches any organization that does business in New Jersey or targets products and services to New Jersey residents and hits one of two data-volume thresholds. The first captures any controller that processes the personal data of at least 100,000 New Jersey consumers in a calendar year, regardless of whether any sales are involved. The second applies to smaller operations that process data on at least 25,000 consumers and also earn revenue or receive discounts from selling personal data.2New Jersey Legislature. P.L. 2023, c. 266
A company that does not meet either threshold is not covered, which means many small local businesses fall outside the law entirely. A few categories are also carved out even when the thresholds are met. State agencies, political subdivisions, and boards or commissions created by a political subdivision are exempt. Financial institutions subject to the Gramm-Leach-Bliley Act get an entity-level exemption, meaning the whole institution is excluded rather than just certain files. The HIPAA carve-out is narrower: it exempts only the health data already governed by HIPAA, not the hospital or insurer as a whole. Data those entities handle outside HIPAA still falls under the New Jersey act.2New Jersey Legislature. P.L. 2023, c. 266
Two gaps are worth knowing about. There is no exemption for institutions of higher education or for records governed by the Family Educational Rights and Privacy Act, so colleges and universities that meet the thresholds must comply. Nonprofits also get no special treatment; if one processes enough New Jersey consumer data to hit either threshold, it faces the same obligations as a for-profit company.
Enforcement and Penalties
The New Jersey Attorney General has exclusive enforcement authority. Consumers cannot file private lawsuits under the act; the Division of Consumer Affairs within the Attorney General’s office investigates complaints and brings enforcement actions.2New Jersey Legislature. P.L. 2023, c. 266
The Attorney General can seek injunctions to stop ongoing violations, recover compensation for affected consumers, and impose civil penalties of up to $10,000 per initial violation. Subsequent violations carry fines of up to $20,000 each.1New Jersey Division of Consumer Affairs. New Jersey Data Privacy Law FAQs
The Cure Period Ends July 15, 2026
During the law’s initial rollout, the Division of Consumer Affairs can give a business 30 days to fix a problem after issuing a notice of violation, avoiding penalties if the business cures the issue in time. That grace period is scheduled to sunset 18 months after the effective date, on July 15, 2026. After that, the Division has no obligation to offer a fix-it window before pursuing penalties.1New Jersey Division of Consumer Affairs. New Jersey Data Privacy Law FAQs