top of page

BLOG

The New Jersey Data Privacy Act Is Not Just a Big Tech Problem

  • Writer: Peter Lamont, Esq.
    Peter Lamont, Esq.
  • 17 hours ago
  • 11 min read

By Peter J. Lamont, Esq.

New Jersey Data Privacy Act compliance: outline of New Jersey over a data center with padlocks and a gavel

Most small business owners in New Jersey hear "comprehensive data privacy law" and assume it describes somebody else's problem, a Silicon Valley issue for companies with chief privacy officers and a compliance department. That assumption is wrong, and expensive. The New Jersey Data Privacy Act has been in force since January 15, 2025, its thresholds are low enough to sweep in ordinary companies with a website and an email list, the grace period for fixing problems before penalties has closed, and legislation signed in June 2026 added obligations that apply to every business in this State regardless of size.


What the New Jersey Data Privacy Act Is and When It Took Effect


The statute was enacted as P.L. 2023, c.266, signed on January 16, 2024, and codified at N.J.S.A. 56:8-166.4 et seq. By its own terms it took effect on the 365th day following enactment, which was January 15, 2025. The framework sorts businesses into "controllers," which decide why and how personal data is processed, and "processors," which handle data on a controller's instructions. Controllers carry the substantive obligations.


Two structural points matter most. There is no private right of action, and under N.J.S.A. 56:8-166.19 the Office of the Attorney General has sole and exclusive authority to enforce the law. The Division of Consumer Affairs, which sits within the Department of Law and Public Safety under the Attorney General, is the body that issued cure notices and that receives data protection assessments. And a violation is treated as an unlawful practice under the New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 et seq. That matters because the Consumer Fraud Act penalty provision, N.J.S.A. 56:8-13, authorizes civil penalties of not more than $10,000 for a first offense and not more than $20,000 for the second and each subsequent offense. In a data context, an offense can be counted in ways that make the arithmetic uncomfortable.


The Applicability Thresholds Are Lower Than Most New Jersey Business Owners Assume


Under N.J.S.A. 56:8-166.5, the law reaches any controller that conducts business in New Jersey or produces products or services targeted to New Jersey residents and that, during a calendar year, either:


  • controls or processes the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction; or

  • controls or processes the personal data of at least 25,000 consumers and derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data.


Read that second prong again, because it is where the New Jersey Data Privacy Act departs from expectations. Most state privacy laws pair a lower consumer count with a requirement that the business derive a meaningful percentage of revenue, often 25 or 50 percent, from selling data. New Jersey has no percentage floor. Any revenue, or even a discount received in exchange for personal data, satisfies it.


"Consumer" means a New Jersey resident acting in an individual or household context, so data about people acting in a commercial or employment capacity does not count toward the thresholds. But "consumer" is not a synonym for "customer." Personal data includes information reasonably linkable to an identifiable person, which captures IP addresses, device identifiers, and cookies collected from visitors who never buy anything. A busy e-commerce site can cross 100,000 in a calendar year without ever having 100,000 customers. In our Bergen County practice, we run this analysis as part of general counsel work for New Jersey businesses, and owners are routinely surprised by what their own analytics dashboard shows.


The exemptions at N.J.S.A. 56:8-166.13 are entity based and data based, not size based, and the difference between those two matters more than anything else in the section. Some are entity level: Gramm-Leach-Bliley financial institutions and their affiliates, insurance institutions, State agencies and political subdivisions, secondary market institutions, and sales of data by the New Jersey Motor Vehicle Commission that the federal Driver's Privacy Protection Act permits. Others are only data level, and this is where New Jersey departs sharply from its peers. The State did not adopt the entity level HIPAA exemption most privacy statutes grant. What is carved out is protected health information collected by a covered entity or business associate, which leaves that same organization's marketing analytics, website tracking, and other non-PHI consumer data fully in scope. The Fair Credit Reporting Act carve-out works the same way, covering data used only as the FCRA authorizes rather than exempting the reporting agency itself. There is no small business, revenue, or headcount exemption, and unlike most states there is no exemption for nonprofits or institutions of higher education either. If you are not on the list and you cross a threshold, you are covered.


Consumer Rights, the Universal Opt-Out Mechanism, and Sensitive Data


Covered controllers must honor consumer requests to confirm and access personal data, correct inaccuracies, delete it, obtain a portable copy where technically feasible, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. Controllers must also maintain an appeal process for denied requests. It has to be conspicuously available, similar to the process for submitting the underlying request, and answered within 45 days.


The obligation that trips up most businesses is the universal opt-out mechanism. The statute required controllers processing data for targeted advertising or sale to accept opt-out signals through a user-selected universal mechanism no later than six months after the effective date, placing that deadline at July 15, 2025. The statute does not name a particular mechanism, and because the implementing regulations expired New Jersey has no official list of recognized ones. In practice that means honoring the Global Privacy Control signal browsers and extensions transmit automatically, which is the default answer largely because nothing else has been designated. This is a configuration problem, not a drafting problem. A privacy policy promising to honor opt-outs while the site ignores GPC signals is worse than no policy, because it pairs a written misrepresentation with the underlying violation.


Sensitive data requires affirmative consent before processing. The category is broad: racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, status as transgender or non-binary, genetic or biometric data processed for the purpose of uniquely identifying an individual, data from a known child, precise geolocation, and financial information. That last item is narrower than it sounds. New Jersey defines it as an account number, account log-in, financial account, or credit or debit card number combined with a security code, access code, or password that would permit access to the account, so ordinary income, balance, or creditworthiness data does not fall inside it. Consent has to come first, not as a disclosure buried in a policy nobody reads.


Privacy Notices, Assessments, and Enforcement Now That the Cure Period Has Closed


A compliant privacy notice must be reasonably accessible, clear, and meaningful. It must state the categories of personal data processed, the purpose of processing, the categories shared with third parties and the categories of those third parties, how consumers exercise their rights and appeal a denial, how to contact the controller, and how consumers learn of material changes. A controller that sells personal data or processes it for targeted advertising must say so clearly and conspicuously and explain how to opt out.


Separately, N.J.S.A. 56:8-166.12 bars processing that presents a heightened risk of harm without conducting and documenting a data protection assessment. Heightened risk includes targeted advertising, the sale of personal data, certain profiling, and processing sensitive data. These assessments are not decorative: they must be produced to the Division of Consumer Affairs on request, and their absence is itself a violation. The statute does protect them. An assessment is confidential and exempt from public inspection, and handing one to the Division does not waive attorney client privilege or work product protection.


That brings us to the change that reset the risk calculus under the New Jersey Data Privacy Act. The statute obligated the Division of Consumer Affairs to issue notice and allow a 30-day cure before filing an enforcement action, but only until the first day of the 18th month next following the effective date. That date was July 1, 2026. The cure period has expired. The Division may still give a business a chance to fix a problem, but no business is entitled to one, and a Consumer Fraud Act enforcement action is not something you want to be defending after the fact. Practitioners tracking the Division's cure letters during that window report the recurring targets were the issues above: sites that failed to honor Global Privacy Control, and incomplete or inaccurate privacy notices.


The Division did propose implementing regulations on June 2, 2025, published at 57 N.J.R. 1101(a), covering dark patterns, consent refresh, data minimization, and assessment content. They were never adopted, and a New Jersey rule proposal lapses if not adopted within a year of publication. The proposal expired in June 2026, so there are currently no final regulations. That is not relief. The statute is fully enforceable on its own terms, and the expired proposal remains a fair map of how the Division reads it.


The 2026 Data Broker Amendments Reach Ordinary New Jersey Businesses


On June 30, 2026, Governor Sherrill signed A5328, enacted as P.L. 2026, c.25, which layers a data broker regime onto the existing statute and amends it. Two features deserve attention.


The law creates two categories, and both of them have to register. A "data broker," a term the statute says expressly includes a controller, knowingly collects or purchases personal data about consumers with whom it has no direct relationship and sells or licenses that data to a third party. A "data collector" knowingly collects personal data from consumers it does have a direct relationship with and sells or licenses that data to a data broker. The second category is the one that catches ordinary companies: a New Jersey business that monetizes its own customer list by selling or licensing it to a broker is a data collector. Each data broker and each data collector engaged in selling or licensing the personal data of New Jersey consumers owes annual registration with the Division of Consumer Affairs. That provision stays inoperative for 270 days after enactment so the Division can build the registry, which puts the operative date at March 27, 2027 and the first registration window at April 1 through June 30, 2027. Fees are tiered across seven brackets by New Jersey consumer count, from $5,000 at 100,000 consumers or fewer up to $1.5 million above 4.5 million, and failing to register or to keep the registry information current carries a civil penalty of $2,500 per day plus back fees for every year missed.


More consequential for most readers, the amendment adds a flat prohibition on selling sensitive data that, by its express terms, applies to all individuals and legal entities regardless of the number of consumers whose data they control or process. There is no threshold and no consent workaround. Entities already carved out of the Act remain outside it, but an ordinary business does not need to reach 25,000 consumers to be bound. The penalty is $50,000 for each record sold, offered for sale, or licensed, and that middle phrase matters: exposure attaches without a completed transaction. If your company has ever monetized data touching health, financial account credentials, precise location, or children, review that arrangement now, along with the vendor agreements behind it.


A Practical Self-Audit for a New Jersey Small Business


You do not need a consultant. You need an afternoon and an honest inventory.


  • Analytics and advertising pixels. List every tag firing on your site. A conversion tag that shares identifiers with an ad platform is very likely a sale or targeted advertising under the statute, whatever your vendor calls it.

  • Global Privacy Control. Test your own site with a browser transmitting a GPC signal and confirm the signal actually stops the tags. Plenty of consent banners display beautifully and enforce nothing.

  • Email and SMS lists. Trace where every contact came from, what they were told at collection, and whether that data has been appended, enriched, rented, or sold.

  • Chat widgets and session recording. Live chat, chatbots, and session replay tools capture far more than owners expect, sometimes including sensitive information typed into a form. Confirm what the vendor keeps and does with it.

  • Embedded third party scripts. Fonts, maps, video players, review widgets, and scheduling tools all transmit visitor data to someone. Each is a data flow you answer for.

  • Vendor contracts. The statute requires a written contract with each processor containing specific terms, and standard software agreements usually omit them unless you ask. Papering those vendor and processor agreements correctly is ordinary contract work.

  • Your privacy notice. Compare it line by line against the required disclosures. A short accurate notice beats an impressive inaccurate one.


Wyckoff is a long way from Silicon Valley, but the statute does not care. Thresholds are counted in people, not revenue. The businesses that get into trouble are rarely those that weighed the law and found it burdensome. They are the ones that never checked whether it applied.


Contact us today to discuss your business or legal matter. Put our 20+ years of legal experience to work for you.

For detailed insights and legal assistance on topics discussed in this post, including data privacy compliance, contact the Law Offices of Peter J. Lamont at our Bergen County Office. We're here to answer your questions and provide legal advice. Contact us at (201) 904-2211 or email us at info@pjlesq.com.


Interested in More Legal Insights?

Explore our range of resources on business and legal matters. Subscribe to our podcast and YouTube channel for a wealth of information covering various business and legal topics. For specific inquiries or to discuss your legal matter with an attorney from our team, please email me directly at pl@pjlesq.com or call at (201) 904-2211. Your questions are important to us, and we look forward to providing the answers you need.

Litigation Attorney Peter Lamont

About Peter J. Lamont, Esq.

Peter J. Lamont is a nationally recognized attorney with significant experience in business, contract, litigation, and real estate law. With over two decades of legal practice, he has represented a wide array of businesses, including large international corporations. Peter is known for his practical legal and business advice, prioritizing efficient and cost-effective solutions for his clients.


Peter has an Avvo 10.0 Rating and has been acknowledged as one of America's Most Honored Lawyers since 2011. 201 Magazine and Lawyers of Distinction have also recognized him for being one of the top business and litigation attorneys in New Jersey. His commitment to his clients and the legal community is further evidenced by his active role as a speaker, lecturer, and published author in various legal and business publications.


As the founder of the Law Offices of Peter J. Lamont, Peter brings his Wall Street experience and client-focused approach to New Jersey, offering personalized legal services that align with each client's unique needs and goals.

DISCLAIMERS: The contents of this website and post are intended to convey general information only and not to provide legal advice or opinions. The contents of this website and the posting and viewing of the information on this website should not be construed as, and should not be relied upon for, legal or tax advice in any particular circumstance or fact situation. Nothing on this website is an offer to represent you, and nothing on this website is intended to create an attorney-client relationship. An attorney-client relationship may only be established through direct attorney-to-client communication that is confirmed by the execution of an engagement agreement.


As with any legal issue, it is important that you obtain competent legal counsel before making any decisions about how to proceed. Because each situation is different, it may be impossible for this article to address all issues raised by every situation encountered. The information above can give you guidance regarding some common issues, but you should consult with an attorney before taking any actions (or refraining from acts) based on these suggestions. This post also focuses on New Jersey law. If your matter arises in a state other than New Jersey, you should immediately seek the advice of an attorney in your state, as certain rules differ in other states.


Disclaimer: Recognition by Legal Awards

The legal awards and recognitions mentioned above do not constitute an endorsement or guarantee of future performance. These honors reflect an attorney's past achievements and should not be considered as predictors of future results. They are not intended to compare one lawyer's services with those of other lawyers. The process for selecting an attorney for these awards can vary and may not include a review of the lawyer's competence in specific areas of practice. Potential clients should perform their own evaluation when seeking legal representation. No aspect of this advertisement has been approved by the Supreme Court of New Jersey.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page