The New Jersey Data Privacy Act (NJDPA), effective January 1, 2025, was signed into law (as Bill S332) by Governor Phil Murphy in 2024. The NJDPA empowers New Jersey residents with rights to access, correct, delete, and opt out of the sale or targeted use of their personal data.
The New Jersey Data Privacy Act (NJDPA) is a state law protecting consumer data privacy. It grants residents rights like accessing, correcting, and deleting personal data, and opting out of data sales or targeted advertising. Businesses must ensure transparency, consent, and robust data security. The NJDPA was signed in March 2024 and its effective date is January 1, 2025.
The NJDPA was passed to give New Jersey residents greater control over personal data and to ensure responsible, transparent data practices by businesses. It aligns with other state laws to foster consumer trust and promote fair data handling in the digital economy.
"In a rapidly growing digital age, our society has become increasingly dependent on the internet to complete day-to-day tasks from shopping and working to deeply personal tasks such as managing finances and medical care. Mandating certain entities to inform individuals about the management of their personal data represents a crucial step towards enhancing data privacy."
The New Jersey Data Protection Act (NJDPA), effective January 15, 2025, is unique for its 15-day opt-out processing requirement, much shorter than most state privacy laws. It also grants rulemaking authority to the New Jersey Attorney General, enabling evolving regulations. Additionally, the NJDPA applies to nonprofits and educational institutions, expanding its business coverage.
The New Jersey Data Privacy Act (NJDPA) includes several key definitions that outline its scope and application, as outlined in Section 2 of the NJDPA:
Note that the NJDPA's definition of "sensitive data" is broader than in comparable laws, encompassing financial information alongside categories like racial or ethnic origin, health conditions, and precise geolocation.
These definitions establish the framework for the NJDPA's consumer rights and business obligations, ensuring clarity in its implementation.
The New Jersey data privacy law applies to businesses operating in New Jersey or targeting residents, if they:
The New Jersey Data Protection Act (NJDPA) also applies to nonprofit organizations and educational institutions, unlike many state privacy laws that exempt them. This means colleges, universities, and nonprofits handling personal data of New Jersey residents must comply with transparency, consumer rights, and data security requirements, ensuring broader data protection coverage.
“Consumer” means an identified person who is a resident of this State acting only in an individual or household context. “Consumer” shall not include a person acting in a commercial or employment context.”
The New Jersey Data Privacy Act (NJDPA) exempts financial institutions regulated by the Gramm-Leach-Bliley Act (GLBA) and protected health information under the Health Insurance Porta providers.
The New Jersey privacy law provisions ensure robust consumer data protections and promote transparency in business practices.
The NJDPA excludes data that is de-identified or publicly available, though it does not exempt aggregated data.
The New Jersey Data Privacy Act (NJDPA) is primarily opt-out, allowing consumers to opt out of data sales, targeted advertising, and profiling. However, for sensitive data, it requires opt-in consent, meaning businesses must obtain explicit permission before processing such data.
The New Jersey Data Protection Act (NJDPA) grants the New Jersey Attorney General (AG) authority for both enforcement and rulemaking, making it one of the few state privacy laws with this dual regulatory power. This means the AG can issue regulations, clarify compliance requirements, and adapt the law’s application over time, ensuring it stays relevant as data privacy concerns evolve.
In terms of enforcement, the AG can investigate complaints, initiate legal action, and impose penalties for non-compliance. Businesses found violating the NJDPA may face civil penalties, injunctions, and damages, depending on the severity of the breach.
Additionally, the AG's rulemaking authority allows for expanding regulations beyond the initial scope, similar to what’s been done under California's CCPA and Colorado's CPA, creating a more dynamic and adaptive regulatory framework.
This proactive enforcement model ensures that businesses remain accountable and responsive to emerging privacy standards, positioning New Jersey as a leader in consumer protection.
Businesses under the New Jersey Data Privacy Act (NJDPA) must:
The New Jersey Data Protection Act (NJDPA) requires businesses to process consumer opt-out requests within 15 days, making it one of the fastest timelines among U.S. privacy laws. By comparison, California (CCPA) and Virginia (CDPA) allow 30 to 45 days. This strict timeframe ensures consumers regain control of their data quickly and pushes businesses to adopt automated privacy management systems, improving data transparency and accountability.
The NJDPA penalties emphasize the importance of compliance while offering businesses an opportunity to rectify issues before facing financial repercussions.
Businesses face fines of up to $7,500 per violation, enforced by the New Jersey Attorney General.
Under the NJDPA, businesses have a 30-day cure period to address violations after receiving notice from the Attorney General. This provision is available for the first 18 months following the law's effective date of January 1, 2025, and will sunset on July 1, 2026. After this period, the opportunity to cure violations is at the discretion of the Attorney General.
By adhering to the NJDPA, businesses can mitigate risks while fostering transparency and trust with consumers:
The NJDPA empowers consumers with control and safeguards over their data, ensuring transparency and security in the digital age. These include:
The New Jersey Data Privacy Act (NJDPA) shares significant similarities with several other U.S. state privacy laws, particularly the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), and the Connecticut Data Privacy Act (CTDPA).
The New Jersey Data Protection Act introduces several distinctive features:
These provisions position the NJDPA as a comprehensive and stringent data privacy law, emphasizing swift consumer rights processing and broad applicability.
Complying with the NJDPA and other state privacy laws can be simpler than you think. The Ketch Data Permissioning Platform helps businesses stay compliant by:
The New Jersey Data Privacy Act represents a significant step forward in data privacy. By preparing for compliance now, businesses can avoid penalties and build stronger relationships with their customers.
Contact Ketch today to streamline your compliance and future-proof your privacy strategy.
Read further: 2025 U.S. State Privacy Laws: what you need to know