Skip to main content
Explainer · Reviewed September 2026

What Is the New Jersey Data Privacy Act?

NJDPA applies to controllers that conduct business in New Jersey or target New Jersey residents and meet its 100,000-consumer or 25,000-consumer-plus-sale-revenue/discount threshold, subject to scope and exemptions. It grants rights to delete, correct, access, port, and opt out of sale, targeted advertising, and profiling. Controllers generally have 45 days to respond, with a possible 45-day extension when permitted. Covered controllers must allow a user-selected universal opt-out mechanism for targeted advertising or sale; the Attorney General has sole and exclusive enforcement authority, and the original 30-day cure period sunset July 1, 2026. Daniel's Law remains a separate route for covered people and information.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
New Jersey Data Privacy Act
Short code
NJDPA
Effective date
January 15, 2025
Response reference
45 days in this snapshot
Cure period
None recorded in this snapshot
Private right of action
No
Enforcement
New Jersey Attorney General. Division of Consumer Affairs
Penalty reference
Up to $10,000 for the first violation; up to $20,000 for each subsequent violation under the NJ Consumer Fraud Act

Who NJDPA applies to

A business is covered if it meets the applicability thresholds set out in N.J. Stat. Ann. §§ 56:8-166.4–56:8-166.19. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.

  • Conducts business in New Jersey or targets New Jersey residents and, during a calendar year, controls or processes the personal data of at least 100,000 consumers, excluding data processed solely for payment transactions
  • Conducts business in New Jersey or targets New Jersey residents and, during a calendar year, controls or processes the personal data of at least 25,000 consumers and derives revenue or receives a discount on goods or services from the sale of personal data

Consumer rights under NJDPA

NJDPA: delete, access, correct, port, opt-out

Daniel's Law: generally 10 business days for qualifying private-internet notices, with a separate OIP government-site route

Attorney General enforcement with Division of Consumer Affairs implementation

Penalties up to $20,000 per subsequent violation

Notable features (vs. CCPA)

NJDPA requires consent before processing the personal data of a consumer the controller knows, or willfully disregards, is at least 13 but younger than 17 for targeted advertising, sale, or profiling. Covered controllers must allow a user-selected universal opt-out mechanism for targeted advertising or sale no later than July 15, 2025; the Division of Consumer Affairs may issue implementation rules.

Enforcement and penalty reference

Enforcing agency: New Jersey Attorney General. Division of Consumer Affairs

Penalty reference: Up to $10,000 for the first violation; up to $20,000 for each subsequent violation under the NJ Consumer Fraud Act

Cure period: The NJDPA's separate 30-day enforcement notice-and-cure opportunity ended July 1, 2026, under N.J.S.A. 56:8-166.17(b)'s 18th-month sunset. As of this review, the statute does not provide a general automatic cure right; the Division/AG's current enforcement procedure and the facts of a matter still govern.

Private right of action: NJDPA has no private right of action. The New Jersey Office of the Attorney General has sole and exclusive enforcement authority, with the Division of Consumer Affairs administering implementation provisions.

Where to file a complaint: New Jersey Attorney General. Division of Consumer Affairs

How to exercise your NJDPA rights

  1. 1

    Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.

  2. 2

    Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable New Jersey residency, scope, exemption, and verification rules before sending.

  3. 3

    This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.

  4. 4

    If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the New Jersey Attorney General. Division of Consumer Affairs complaint route at https://www.njconsumeraffairs.gov/File-a-Complaint. A complaint route does not itself guarantee deletion or a particular enforcement result.

Generate requests in under 60 seconds

Generate a NJDPA privacy request, $9 one-time

Review the provider route, applicable law, and information you intend to send before dispatch. You remain in control of the request and any evidence kept.

FAQ

What is New Jersey's data privacy law?+

New Jersey's comprehensive data privacy law is the New Jersey Data Privacy Act (NJDPA), effective January 15, 2025. It gives qualifying consumers rights to access, correct, delete, and port personal data and to opt out of sale, targeted advertising, and certain profiling, subject to the law's thresholds, exemptions, and verification rules. A covered controller generally has 45 days to respond and may extend that period by 45 days when the statute permits; review the enacted law for the current details.

Does NJDPA overlap with Daniel's Law?+

They are separate mechanisms. Daniel's Law is narrower and applies to covered individuals, covered information, and qualifying requests under New Jersey law; current private-internet provisions generally use a 10-business-day period after written notice, while the Office of Information Privacy handles a separate government-site redaction route. The NJDPA is a broader controller privacy law with its own scope, exemptions, and response framework. Which route applies depends on the person, information, recipient, and request.

How do I use Daniel's Law if I qualify?+

Review the current New Jersey procedure and submit a compliant written notice under P.L. 2021, c. 371, as amended by P.L. 2023, c. 113, when that route applies. Current private-internet provisions generally use a 10-business-day period after qualifying notice; the OIP portal and government-site redaction process are separate. Keep the request, proof of delivery, and the provider response; available enforcement options depend on the facts and the statute.

Official sources & citations

Compare with sibling state laws

NJDPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:

Related concepts & guides