What Is the New Jersey Data Privacy Act?
NJDPA applies to controllers that conduct business in New Jersey or target New Jersey residents and meet its 100,000-consumer or 25,000-consumer-plus-sale-revenue/discount threshold, subject to scope and exemptions. It grants rights to delete, correct, access, port, and opt out of sale, targeted advertising, and profiling. Controllers generally have 45 days to respond, with a possible 45-day extension when permitted. Covered controllers must allow a user-selected universal opt-out mechanism for targeted advertising or sale; the Attorney General has sole and exclusive enforcement authority, and the original 30-day cure period sunset July 1, 2026. Daniel's Law remains a separate route for covered people and information.
At a glance
- Full name
- New Jersey Data Privacy Act
- Short code
- NJDPA
- Effective date
- January 15, 2025
- Response reference
- 45 days in this snapshot
- Cure period
- None recorded in this snapshot
- Private right of action
- No
- Enforcement
- New Jersey Attorney General. Division of Consumer Affairs
- Penalty reference
- Up to $10,000 for the first violation; up to $20,000 for each subsequent violation under the NJ Consumer Fraud Act
- Statutory citation
- N.J. Stat. Ann. §§ 56:8-166.4–56:8-166.19
Who NJDPA applies to
A business is covered if it meets the applicability thresholds set out in N.J. Stat. Ann. §§ 56:8-166.4–56:8-166.19. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.
- Conducts business in New Jersey or targets New Jersey residents and, during a calendar year, controls or processes the personal data of at least 100,000 consumers, excluding data processed solely for payment transactions
- Conducts business in New Jersey or targets New Jersey residents and, during a calendar year, controls or processes the personal data of at least 25,000 consumers and derives revenue or receives a discount on goods or services from the sale of personal data
Consumer rights under NJDPA
NJDPA: delete, access, correct, port, opt-out
Daniel's Law: generally 10 business days for qualifying private-internet notices, with a separate OIP government-site route
Attorney General enforcement with Division of Consumer Affairs implementation
Penalties up to $20,000 per subsequent violation
Notable features (vs. CCPA)
NJDPA requires consent before processing the personal data of a consumer the controller knows, or willfully disregards, is at least 13 but younger than 17 for targeted advertising, sale, or profiling. Covered controllers must allow a user-selected universal opt-out mechanism for targeted advertising or sale no later than July 15, 2025; the Division of Consumer Affairs may issue implementation rules.
Enforcement and penalty reference
Enforcing agency: New Jersey Attorney General. Division of Consumer Affairs
Penalty reference: Up to $10,000 for the first violation; up to $20,000 for each subsequent violation under the NJ Consumer Fraud Act
Cure period: The NJDPA's separate 30-day enforcement notice-and-cure opportunity ended July 1, 2026, under N.J.S.A. 56:8-166.17(b)'s 18th-month sunset. As of this review, the statute does not provide a general automatic cure right; the Division/AG's current enforcement procedure and the facts of a matter still govern.
Private right of action: NJDPA has no private right of action. The New Jersey Office of the Attorney General has sole and exclusive enforcement authority, with the Division of Consumer Affairs administering implementation provisions.
Where to file a complaint: New Jersey Attorney General. Division of Consumer Affairs
How to exercise your NJDPA rights
- 1
Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.
- 2
Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable New Jersey residency, scope, exemption, and verification rules before sending.
- 3
This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.
- 4
If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the New Jersey Attorney General. Division of Consumer Affairs complaint route at https://www.njconsumeraffairs.gov/File-a-Complaint. A complaint route does not itself guarantee deletion or a particular enforcement result.
Generate requests in under 60 seconds
Generate a NJDPA privacy request, $9 one-time
FAQ
What is New Jersey's data privacy law?+
New Jersey's comprehensive data privacy law is the New Jersey Data Privacy Act (NJDPA), effective January 15, 2025. It gives qualifying consumers rights to access, correct, delete, and port personal data and to opt out of sale, targeted advertising, and certain profiling, subject to the law's thresholds, exemptions, and verification rules. A covered controller generally has 45 days to respond and may extend that period by 45 days when the statute permits; review the enacted law for the current details.
Does NJDPA overlap with Daniel's Law?+
They are separate mechanisms. Daniel's Law is narrower and applies to covered individuals, covered information, and qualifying requests under New Jersey law; current private-internet provisions generally use a 10-business-day period after written notice, while the Office of Information Privacy handles a separate government-site redaction route. The NJDPA is a broader controller privacy law with its own scope, exemptions, and response framework. Which route applies depends on the person, information, recipient, and request.
How do I use Daniel's Law if I qualify?+
Review the current New Jersey procedure and submit a compliant written notice under P.L. 2021, c. 371, as amended by P.L. 2023, c. 113, when that route applies. Current private-internet provisions generally use a 10-business-day period after qualifying notice; the OIP portal and government-site redaction process are separate. Keep the request, proof of delivery, and the provider response; available enforcement options depend on the facts and the statute.
Official sources & citations
Compare with sibling state laws
NJDPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:
