🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-NJ · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 14 sources retrieved model claude-sonnet-5 ·

United States – New Jersey

US-NJ schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core comprehensive statute is in force with a named enforcement authority and settled effective date; residual amber risk sits in still-pending AG rulemaking and the not-yet-operative data-broker registry.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.)
Traffic-light rationale — GreenCore comprehensive statute is in force with a named enforcement authority and settled effective date; residual amber risk sits in still-pending AG rulemaking and the not-yet-operative data-broker registry.

Sub-modules (5)

Regulator And AuthorityGreen

The Office of the Attorney General, operating through the Division of Consumer Affairs, has sole and exclusive enforcement authority over the NJDPL.

Claims (1):

  • The Office of the Attorney General enforces the NJDPL, and consumers cannot file lawsuits on their own behalf under the law.

Act And InstrumentsGreen

Primary instrument is the NJDPL (P.L.2023, c.266), signed 16 January 2024 and effective 15 January 2025 (365 days after enactment), supplemented by the Identity Theft Prevention Act breach-notification provisions and the 2026 data-broker registration law.

Claims (1):

  • The New Jersey Data Privacy Law, P.L.2023, c.266, guarantees New Jersey consumers certain rights with regard to their personal data and imposes requirements on controllers and processors, taking effect 15 January 2025.

Material ScopeGreen

NJDPL applies to controllers/processors that during a calendar year control or process personal data of at least 100,000 NJ consumers, or at least 25,000 consumers while deriving revenue from data sales.

Claims (1):

  • NJDPL applies to controllers/processors that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and make money from the sale of personal data.

Territorial ScopeAmber

Coverage is defined by reference to New Jersey residents acting in an individual/household context; employment-context data of NJ residents is expressly outside scope, meaning the law's territorial reach turns on the residency of the data subject rather than the controller's location.

Claims (1):

  • A consumer under the NJDPL is a New Jersey resident acting in an individual or household context; a New Jersey resident's data collected in an employment context is not protected under the law.

Regulator Registration And FilingAmber

The NJDPL itself imposes no general controller-registration duty, but a newly signed 2026 data-broker law creates a tiered mandatory annual registration/fee regime (up to $1.5M/year for the largest brokers), with the Division's registry becoming operative 27 March 2027.

Claims (1):

  • New Jersey's 2026 data broker law creates a tiered annual registration-fee structure, with the largest data brokers and collectors required to pay a $1.5 million annual registration fee, and the second fee tier (higher than any other state) triggered at 100,000 consumers; the Division's registry requirement takes effect 270 days after enactment, on 27 March 2027.
Category narrative71 words

New Jersey's comprehensive consumer privacy regime is the New Jersey Data Privacy Law (NJDPL), P.L.2023, c.266, enforced exclusively by the New Jersey Attorney General acting through the Division of Consumer Affairs. It sits atop a pre-existing sectoral patchwork (Identity Theft Prevention Act breach-notification statute, Daniel's Law protecting public officials' personal information, and a newly enacted 2026 data-broker registration law), producing a hybrid state-omnibus-plus-sectoral-overlay structure rather than a single unified DPA-style regulator.

Sources and claims (5)
  1. ConfirmedNew Jersey Division of Consumer AffairsThe Office of the Attorney General enforces the NJDPL, and consumers cannot file lawsuits on their own behalf under the law.observed
  2. ConfirmedNew Jersey Division of Consumer AffairsThe New Jersey Data Privacy Law, P.L.2023, c.266, guarantees New Jersey consumers certain rights with regard to their personal data and imposes requirements on controllers and processors, taking effect 15 January 2025.observed
  3. ConfirmedNew Jersey Division of Consumer AffairsNJDPL applies to controllers/processors that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and make money from the sale of personal data.observed
  4. ConfirmedNew Jersey Division of Consumer AffairsA consumer under the NJDPL is a New Jersey resident acting in an individual or household context; a New Jersey resident's data collected in an employment context is not protected under the law.observed
  5. ConfirmedIAPPNew Jersey's 2026 data broker law creates a tiered annual registration-fee structure, with the largest data brokers and collectors required to pay a $1.5 million annual registration fee, and the second fee tier (higher than any other state) triggered at 100,000 consumers; the Division's registry requirement takes effect 270 days after enactment, on 27 March 2027.observed

#

Sensitive-data consent and consumer opt-out mechanics are well evidenced; the absence of a GDPR-style Art.6 lawful-basis catalogue and of an explicit anonymisation safe-harbour is a structural gap relative to omnibus regimes.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberSensitive-data consent and consumer opt-out mechanics are well evidenced; the absence of a GDPR-style Art.6 lawful-basis catalogue and of an explicit anonymisation safe-harbour is a structural gap relative to omnibus regimes.

Sub-modules (4)

Lawful BasesAmber

NJDPL is structured around consumer opt-out rights for standard processing (sale, targeted advertising, certain profiling) rather than an enumerated lawful-basis catalogue; no equivalent to GDPR Art.6 was identified.

Claims (1):

  • Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, in lieu of a GDPR-style enumerated lawful-basis requirement for processing.

Special CategoriesGreen

Sensitive data is defined broadly to include racial/ethnic origin, religious beliefs, health condition, financial information, sexual activity/orientation, immigration/citizenship status, transgender/non-binary status, genetic or biometric data, precise geolocation, and any data collected from a known child.

Claims (1):

  • Sensitive data under the NJDPL is a subset of personal data revealing racial or ethnic origin, religious beliefs, health condition, financial information, sexual activity or orientation, immigration or citizenship status, transgender or non-binary status, genetic or biometric data, precise geolocation data, or personal data collected from a known child.

Pseudonymisation And AnonymisationAmber

The NJDPL defines de-identified data (data that cannot be linked to or used to infer information about a specific individual, where the controller takes steps to ensure non-linkability) and treats the potential use of de-identified data as a factor within data protection assessments, but no dedicated pseudonymisation/anonymisation safe-harbour provision separate from this definition was located. Searches of the DCA FAQ and DataGuidance jurisdiction notes did not surface a standalone anonymisation exemption regime.

Claims (1):

  • De-identified data is data that cannot be linked to or used to infer information about a specific individual or a device linked to that individual, and is considered de-identified only if the controller takes steps to ensure it cannot be linked to the consumer.
Category narrative70 words

NJDPL does not adopt a GDPR-style enumerated set of lawful bases; instead it relies on an opt-out model for ordinary processing (sale, targeted advertising, certain profiling) combined with an opt-in consent requirement specifically for sensitive/special-category data and for processing the data of consumers aged 13-16. Anonymisation/de-identification is recognised as a distinct, lower-risk data state relevant to the required data protection assessments, but no separate anonymisation 'safe harbour' provision was located.

Sources and claims (4)
  1. ConfirmedNew Jersey Division of Consumer AffairsConsumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, in lieu of a GDPR-style enumerated lawful-basis requirement for processing.observed
  2. ConfirmedNew Jersey Division of Consumer AffairsThe controller must get the consumer's consent before processing the consumer's sensitive data, and must obtain consent before processing personal data of a consumer the controller knows or willfully disregards as being between 13 and 16 years old.observed
  3. ConfirmedNew Jersey Division of Consumer AffairsSensitive data under the NJDPL is a subset of personal data revealing racial or ethnic origin, religious beliefs, health condition, financial information, sexual activity or orientation, immigration or citizenship status, transgender or non-binary status, genetic or biometric data, precise geolocation data, or personal data collected from a known child.observed
  4. ConfirmedNew Jersey Division of Consumer AffairsDe-identified data is data that cannot be linked to or used to infer information about a specific individual or a device linked to that individual, and is considered de-identified only if the controller takes steps to ensure it cannot be linked to the consumer.observed

#

Rights bundle and response deadlines are directly evidenced by regulator and industry sources; itemised statutory text for rectification specifically was not independently isolated from a single named clause, warranting slightly lower confidence there.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — GreenRights bundle and response deadlines are directly evidenced by regulator and industry sources; itemised statutory text for rectification specifically was not independently isolated from a single named clause, warranting slightly lower confidence there.

Sub-modules (5)

Access RightGreen

Consumers have the right to confirm whether a controller is processing their personal data and to access it.

Claims (1):

  • The NJDPL grants consumers the right to confirm whether a controller is processing their personal data.

Rectification And ErasureAmber

Consumers have a deletion (erasure) right under specified conditions; correction/rectification is understood to form part of the standard rights bundle guaranteed by the NJDPL though the specific operative clause text was not independently isolated.

Claims (1):

  • Consumers may request data erasure (deletion) under specified conditions set out in the NJDPL.

Restriction And ObjectionGreen

Consumers may opt out of (object to) a controller's sale of personal data, use for targeted advertising, and certain profiling activities, including profiling used for loan/mortgage, employment, or insurance decisions.

Claims (1):

  • Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, such as profiling to determine loan, employment, or insurance eligibility.

Data PortabilityGreen

Consumers may obtain their personal data in a portable, machine-readable format.

Claims (1):

  • Consumers may obtain a copy of their personal data in a portable, machine-readable format under the NJDPL.

Deadlines And Response WindowsGreen

Controllers have 45 days to respond to consumer rights requests, with an optional 45-day extension.

Claims (1):

  • Organizations have 45 days to respond to a consumer rights request under the NJDPL, with an optional 45-day extension.
Category narrative54 words

The NJDPL grants New Jersey consumers rights to confirm whether a controller is processing their personal data and to access it, to correct/delete data, to obtain a portable copy, and to opt out of targeted advertising, data sales, and certain profiling. Controllers generally have 45 days to respond, extendable by a further 45 days.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe NJDPL grants consumers the right to confirm whether a controller is processing their personal data.observed
  2. ProbableDataGuidanceConsumers may request data erasure (deletion) under specified conditions set out in the NJDPL.observed
  3. ConfirmedNew Jersey Division of Consumer AffairsConsumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, such as profiling to determine loan, employment, or insurance eligibility.observed
  4. ProbableDataGuidanceConsumers may obtain a copy of their personal data in a portable, machine-readable format under the NJDPL.observed
  5. ConfirmedDataGuidanceOrganizations have 45 days to respond to a consumer rights request under the NJDPL, with an optional 45-day extension.observed

#

DPIA-equivalent, processor-contract, and breach-notification duties are well evidenced and binding; DPO appointment and formal ROPA requirements are not evidenced and are flagged as gaps rather than fabricated.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; New Jersey Identity Theft Prevention Act, N.J.S.A. 56:8-161 et seq.
Traffic-light rationale — AmberDPIA-equivalent, processor-contract, and breach-notification duties are well evidenced and binding; DPO appointment and formal ROPA requirements are not evidenced and are flagged as gaps rather than fabricated.

Sub-modules (7)

Accountability And DpiaGreen

Section 9 of the NJDPL requires controllers to conduct and document a data protection assessment prior to processing that presents a heightened risk of harm, including all sensitive-data processing, considering risks/benefits, consumer expectations, and potential use of de-identified data.

Claims (2):

  • Section 9 of the NJDPA requires controllers to conduct and document a data protection assessment prior to initiating any processing activity that presents a heightened risk of harm to consumers.
  • Processing presents a heightened risk of harm when there is risk of unfair treatment, illegal discrimination, or financial or physical injury, or when the controller processes sensitive data, triggering the DPA requirement.

Dpo RequirementsRed

No explicit statutory DPO-appointment threshold or independence requirement analogous to GDPR Art.37-39 was located in the NJDPL FAQ, DataGuidance jurisdiction notes, or NJDPL infographic reviewed for this run.

Ropa RequirementsRed

No explicit Records of Processing Activities obligation equivalent to GDPR Art.30 was identified in the sources reviewed; the NJDPL's transparency obligations run instead through privacy notices and data protection assessments.

Joint Controller ArrangementsGreen

Processors may only process personal data at the controller's direction, under a contract specifying processing instructions, the data to be processed, duration, and requiring return or deletion of data once processing is complete.

Claims (1):

  • A processor may only process personal data at the request and under the direction of a controller, and must enter into a contract with the controller containing processing instructions, identifying the data processed and retention duration, and requiring return or deletion of the data once processing is complete.

Security MeasuresGreen

Controllers must implement robust administrative, technical, and physical safeguards, limit collection to essential purposes (data minimisation), and enforce contractual compliance with NJDPL vendor-management standards.

Claims (1):

  • Controllers are required to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.

Breach NotificationGreen

Under the Identity Theft Prevention Act, businesses conducting business in NJ must disclose any breach of security of computerized records to affected NJ residents in the most expedient time possible without unreasonable delay, and must report the breach to the NJ State Police Division in advance of customer notification.

Claims (2):

  • Any business conducting business in New Jersey must disclose a breach of security of computerized records to any affected New Jersey resident in the most expedient time possible and without unreasonable delay.
  • A business or public entity must, in advance of disclosing a breach to affected customers, report the breach and related information to the Division of State Police in the Department of Law and Public Safety.

Retention And DisposalAmber

Processor contracts must require return or deletion of personal data once processing is complete; no separate general data-retention-limit statute beyond this processor-contract duty was located.

Claims (1):

  • Processor contracts under the NJDPL must require the processor to return or delete personal data once processing is complete.
Category narrative77 words

Controllers must complete and document a data protection assessment ('DPA') before processing that presents a heightened risk of harm (including all sensitive-data processing, and processing for targeted advertising, sale, or significant-effect profiling). Processor obligations run through a mandatory data-processing contract. Security-of-processing and breach-notification duties derive substantially from the pre-existing Identity Theft Prevention Act rather than from the NJDPL itself. No explicit DPO-appointment threshold or GDPR-style Records of Processing Activities (ROPA) obligation was located in the sources reviewed.

Sources and claims (7)
  1. ConfirmedDataGuidanceSection 9 of the NJDPA requires controllers to conduct and document a data protection assessment prior to initiating any processing activity that presents a heightened risk of harm to consumers.observed
  2. ConfirmedNew Jersey Division of Consumer AffairsProcessing presents a heightened risk of harm when there is risk of unfair treatment, illegal discrimination, or financial or physical injury, or when the controller processes sensitive data, triggering the DPA requirement.observed
  3. ConfirmedNew Jersey Division of Consumer AffairsA processor may only process personal data at the request and under the direction of a controller, and must enter into a contract with the controller containing processing instructions, identifying the data processed and retention duration, and requiring return or deletion of the data once processing is complete.observed
  4. ProbableDataGuidanceControllers are required to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.observed
  5. ConfirmedNew Jersey Division of Consumer AffairsAny business conducting business in New Jersey must disclose a breach of security of computerized records to any affected New Jersey resident in the most expedient time possible and without unreasonable delay.observed
  6. ConfirmedNew Jersey Division of Consumer AffairsA business or public entity must, in advance of disclosing a breach to affected customers, report the breach and related information to the Division of State Police in the Department of Law and Public Safety.observed
  7. ConfirmedNew Jersey Division of Consumer AffairsProcessor contracts under the NJDPL must require the processor to return or delete personal data once processing is complete.observed

#

No transfer-mechanism, adequacy, or localisation provisions exist in the NJDPL or ancillary NJ statutes reviewed; module is populated with an explicit absence finding rather than left silently empty.

Traffic-light rationale — RedNo transfer-mechanism, adequacy, or localisation provisions exist in the NJDPL or ancillary NJ statutes reviewed; module is populated with an explicit absence finding rather than left silently empty.

Sub-modules (6)

Transfer MechanismsRed

No statutory cross-border transfer mechanism (adequacy, SCCs, BCRs, derogations) exists under the NJDPL; searched DCA FAQ, DataGuidance NJ jurisdiction notes, and NJDPL infographic without finding transfer-specific provisions.

Adequacy ReceivedRed

Not applicable — New Jersey, as a US state, is not a party to adequacy findings under any foreign comprehensive privacy regime.

Adequacy GrantedRed

New Jersey has no authority to grant adequacy determinations; this sits with the federal government, and no NJ-specific mechanism was found.

Sccs And BcrsRed

No SCC or BCR framework exists under the NJDPL.

Transfer Impact AssessmentRed

No transfer impact assessment requirement was identified under the NJDPL; the statute's assessment obligation (data protection assessment) is tied to heightened-risk processing generally, not cross-border transfer specifically.

Data LocalisationRed

No data-localisation mandate (partial or absolute) was identified in the NJDPL or ancillary NJ statutes reviewed.

Category narrative50 words

The NJDPL is a domestic US state consumer-privacy statute and contains no GDPR-style cross-border transfer mechanism regime (no adequacy findings, SCCs, BCRs, or transfer-impact-assessment requirement), and no data-localisation mandate was identified. This is a legitimate structural gap consistent with the US state omnibus model rather than an omission of research.

#

Financial, health, and credit-sector carve-outs are well evidenced; education and insurance-specific overlay detail beyond the general GLBA/HIPAA/FCRA exclusions was not independently verified.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; Gramm-Leach-Bliley Act (federal, as applied in NJ); HIPAA (federal, as applied in NJ)
Traffic-light rationale — AmberFinancial, health, and credit-sector carve-outs are well evidenced; education and insurance-specific overlay detail beyond the general GLBA/HIPAA/FCRA exclusions was not independently verified.

Sub-modules (7)

Financial Sector OverlayGreen

Data collected by certain financial and insurance institutions is excluded from the NJDPL, and GLBA-mandated annual privacy notices and opt-out rights continue to apply to financial institutions operating in New Jersey, administered with DCA involvement.

Claims (2):

  • Data collected by certain financial and insurance institutions is excluded from the NJDPL.
  • Financial institutions must provide consumers an annual privacy notice regarding nonpublic personal information, and consumers may opt out of disclosure of that information at any time.

Health Sector OverlayGreen

Health information protected by HIPAA is excluded from the NJDPL, leaving HIPAA as the operative federal health-privacy instrument for covered entities in New Jersey.

Claims (1):

  • Health information protected by HIPAA is excluded from the NJDPL.

Telecoms And EprivacyAmber

No dedicated New Jersey ePrivacy/telecoms-specific cookie-consent statute distinct from the NJDPL's general opt-out and universal-opt-out-mechanism provisions was identified.

Employment DataGreen

Personal data collected from a New Jersey resident in an employment context (e.g., a job applicant) is expressly excluded from NJDPL protection.

Claims (1):

  • A New Jersey resident whose personal data is collected by a potential employer while applying for a job is not protected under the NJDPL.

Credit And ScoringGreen

Data processed under the federal Fair Credit Reporting Act is excluded from the NJDPL; separately, the Identity Theft Prevention Act gives NJ consumers the right to place a security freeze on their consumer/credit report.

Claims (2):

  • Data that can be processed under the federal Fair Credit Reporting Act is excluded from the NJDPL.
  • New Jersey consumers have the right to place a security freeze on their consumer report under the Identity Theft Prevention Act, preventing release of report information without express authorization.

EducationAmber

DataGuidance notes that New Jersey Revised Statutes and Administrative Code provisions create sector-specific obligations for education-sector data collection, but no education-specific statute name or citation was independently isolated in this run.

Claims (1):

  • Various privacy-related provisions in the New Jersey Revised Statutes and New Jersey Administrative Code create obligations for data collected by companies in the education sector, in addition to the NJDPL.

InsuranceGreen

Data collected by certain insurance institutions is excluded from the NJDPL under the same carve-out as financial institutions; GLBA-style privacy-notice obligations apply to insurance disclosures of nonpublic personal information.

Claims (1):

  • Nonpublic personal information collected by insurance companies is subject to GLBA-style annual privacy-notice and opt-out requirements administered with New Jersey Division of Consumer Affairs involvement.
Category narrative50 words

The NJDPL carves out several federally regulated sectors entirely: HIPAA-covered health information, FCRA-covered consumer-reporting data, and data collected by certain financial and insurance institutions (GLBA-aligned exclusion). Employment-context data is also excluded. Pre-existing sectoral statutes (Identity Theft Prevention Act, GLBA annual privacy-notice obligations enforced via DCA) continue to apply in parallel.

Sources and claims (8)
  1. ConfirmedNew Jersey Division of Consumer AffairsData collected by certain financial and insurance institutions is excluded from the NJDPL.observed
  2. ProbableNew Jersey Division of Consumer AffairsFinancial institutions must provide consumers an annual privacy notice regarding nonpublic personal information, and consumers may opt out of disclosure of that information at any time.observed
  3. ConfirmedNew Jersey Division of Consumer AffairsHealth information protected by HIPAA is excluded from the NJDPL.observed
  4. ConfirmedNew Jersey Division of Consumer AffairsA New Jersey resident whose personal data is collected by a potential employer while applying for a job is not protected under the NJDPL.observed
  5. ConfirmedNew Jersey Division of Consumer AffairsData that can be processed under the federal Fair Credit Reporting Act is excluded from the NJDPL.observed
  6. ConfirmedNew Jersey Division of Consumer AffairsNew Jersey consumers have the right to place a security freeze on their consumer report under the Identity Theft Prevention Act, preventing release of report information without express authorization.observed
  7. UncertainDataGuidanceVarious privacy-related provisions in the New Jersey Revised Statutes and New Jersey Administrative Code create obligations for data collected by companies in the education sector, in addition to the NJDPL.observed
  8. ProbableNew Jersey Division of Consumer AffairsNonpublic personal information collected by insurance companies is subject to GLBA-style annual privacy-notice and opt-out requirements administered with New Jersey Division of Consumer Affairs involvement.observed

#

Opt-out and UOOM obligations are binding and in force; dark-patterns, clean-room, and direct-marketing-specific sub-modules lack dedicated statutory findings and are flagged amber/red accordingly.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — GreenOpt-out and UOOM obligations are binding and in force; dark-patterns, clean-room, and direct-marketing-specific sub-modules lack dedicated statutory findings and are flagged amber/red accordingly.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie-consent statute exists separate from the NJDPL's general sale/targeted-advertising opt-out and UOOM mechanics; the DCA's non-binding Cyber Safe NJ guidance discusses browser cookie controls but is educational rather than a compliance obligation.

Dark PatternsAmber

No standalone dark-patterns prohibition was identified in the NJDPL text reviewed; the law's requirement that privacy notices clearly state how consumers may exercise their rights functions as an indirect anti-obfuscation measure.

Claims (1):

  • A controller's privacy notice must clearly state how consumers may exercise their rights under the NJDPL.

Opt Out SignalsGreen

By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms such as Global Privacy Control.

Claims (1):

  • By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms, such as Global Privacy Control, which allow automatic opt-out across websites, platforms, or devices.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rule was identified under the NJDPL.

Cross Context AdvertisingGreen

NJDPL's UOOM provisions uniquely extend to opt-outs for consumer profiling in furtherance of decisions producing legal or similarly significant effects, not just targeted advertising and data sales as in most peer state laws.

Claims (1):

  • Under the NJDPL, universal opt-out mechanisms must support consumer opt-outs for profiling in furtherance of decisions that produce legal or similarly significant effects, in addition to targeted advertising and sales of personal data, a scope broader than most peer state laws.

Direct MarketingAmber

Direct-marketing consent/suppression is addressed indirectly through the general targeted-advertising and sale opt-out mechanism; no standalone direct-marketing statute distinct from the NJDPL was identified.

Category narrative65 words

The NJDPL's principal adtech mechanism is a consumer opt-out right covering targeted advertising, sale of personal data, and — unusually among state laws — significant-effect profiling, reinforced by a universal-opt-out-mechanism (UOOM) requirement effective 15 July 2025 requiring controllers to honor signals such as Global Privacy Control. No dedicated dark-patterns statute, clean-room/data-collaboration-room rule, or standalone direct-marketing consent statute distinct from the general opt-out regime was identified.

Sources and claims (3)
  1. ConfirmedNew Jersey Division of Consumer AffairsA controller's privacy notice must clearly state how consumers may exercise their rights under the NJDPL.observed
  2. ConfirmedNew Jersey Division of Consumer AffairsBy 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms, such as Global Privacy Control, which allow automatic opt-out across websites, platforms, or devices.observed
  3. ConfirmedIAPPUnder the NJDPL, universal opt-out mechanisms must support consumer opt-outs for profiling in furtherance of decisions that produce legal or similarly significant effects, in addition to targeted advertising and sales of personal data, a scope broader than most peer state laws.observed

#

Profiling opt-out and sensitive-data (biometric/genetic) consent duties are binding and evidenced; dedicated AI-risk-assessment and biometric-specific statutory regimes are not evidenced for New Jersey and are flagged as gaps.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberProfiling opt-out and sensitive-data (biometric/genetic) consent duties are binding and evidenced; dedicated AI-risk-assessment and biometric-specific statutory regimes are not evidenced for New Jersey and are flagged as gaps.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling in furtherance of decisions producing legal or similarly significant effects, with statutory examples including denial/provision of financial or lending services, housing, insurance, education enrollment, criminal justice, employment, health care, or essential goods and services.

Claims (1):

  • Under the NJDPL, universal opt-out mechanisms cover profiling 'in furtherance of decisions that produce legal or similarly significant effects concerning a consumer,' with examples including denial or provision of financial, lending, housing, insurance, education, criminal justice, employment, health care, or essential goods/services decisions.

Automated Decision Making TransparencyAmber

Controllers must complete a data protection assessment before engaging in significant-effect profiling, functioning as an indirect ADM-transparency mechanism, though no explicit individual right to an explanation of automated decisions was located.

Claims (1):

  • The NJDPL requires completed data protection assessments before a significant-effect profiling activity is carried out.

Ai Risk AssessmentsAmber

New Jersey has not been identified as having a dedicated AI-specific risk-assessment statute (distinct from Colorado's AI Act model); the NJDPL's general data protection assessment is the closest analogue but is not AI-specific.

Absence provenance: not recorded. Searched: njconsumeraffairs.gov FAQ, iapp.org New Jersey privacy law coverage.

Biometric RegimeAmber

Biometric data is classified as sensitive data under the NJDPL, requiring consumer consent and a data protection assessment before processing; no standalone biometric-privacy statute (of the Illinois BIPA type) was identified for New Jersey.

Claims (1):

  • Biometric data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.

Genetic DataGreen

Genetic data is classified as sensitive data under the NJDPL, requiring consumer consent and a data protection assessment before processing.

Claims (1):

  • Genetic data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.

State Surveillance CarveoutsAmber

Personal data collected by New Jersey state agencies is excluded from the NJDPL entirely; the scope and limits of this carve-out relative to law-enforcement/surveillance use were not further detailed in the sources reviewed.

Claims (1):

  • Data collected by state agencies is excluded from the NJDPL.
Category narrative74 words

The NJDPL treats genetic and biometric data as sensitive data requiring consent and a data protection assessment, and grants consumers an opt-out right over profiling that produces legal or similarly significant effects (e.g., lending, housing, insurance, employment, healthcare, criminal justice, essential goods/services decisions). There is no dedicated biometric-specific statute (unlike Illinois's BIPA) and no NJ-specific AI risk-assessment statute distinct from the general data protection assessment; state-agency data is carved out of the NJDPL entirely.

Sources and claims (5)
  1. ConfirmedIAPPUnder the NJDPL, universal opt-out mechanisms cover profiling 'in furtherance of decisions that produce legal or similarly significant effects concerning a consumer,' with examples including denial or provision of financial, lending, housing, insurance, education, criminal justice, employment, health care, or essential goods/services decisions.observed
  2. ConfirmedIAPPThe NJDPL requires completed data protection assessments before a significant-effect profiling activity is carried out.observed
  3. ConfirmedNew Jersey Division of Consumer AffairsBiometric data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.observed
  4. ConfirmedNew Jersey Division of Consumer AffairsGenetic data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.observed
  5. ConfirmedNew Jersey Division of Consumer AffairsData collected by state agencies is excluded from the NJDPL.observed

#

Age-13-16 consent threshold and 'known child' sensitive-data treatment are binding and evidenced; age-verification mechanics, education-settings specifics, and dependent-adult protections are not evidenced and flagged as gaps.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; federal COPPA (as applied to NJ residents under 13)
Traffic-light rationale — AmberAge-13-16 consent threshold and 'known child' sensitive-data treatment are binding and evidenced; age-verification mechanics, education-settings specifics, and dependent-adult protections are not evidenced and flagged as gaps.

Sub-modules (5)

Age VerificationAmber

No explicit statutory age-verification mechanism was identified in the NJDPL; the consent obligation is triggered by the controller's actual knowledge or willful disregard of a consumer's age rather than a mandated verification process.

Minor Profiling BansAmber

Personal data collected from a known child is treated as sensitive data requiring consent under the NJDPL; this extends the general sensitive-data consent and profiling opt-out protections to minors rather than establishing a standalone profiling ban.

Claims (1):

  • Personal data collected from a known child is included within the NJDPL's definition of sensitive data, requiring the controller to obtain consent before processing.

Education SettingsRed

New Jersey Administrative Code provisions reportedly create education-sector data obligations, but no specific education-settings statute citation was independently isolated in this run.

Absence provenance: not recorded. Searched: dataguidance.com New Jersey jurisdiction notes.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) specific data-protection provision was identified in the sources reviewed for New Jersey.

Absence provenance: not recorded. Searched: njconsumeraffairs.gov NJ Data Privacy Law FAQ, dataguidance.com New Jersey jurisdiction notes.

Category narrative78 words

Children under 13 are governed by the federal COPPA regime; New Jersey layers an additional opt-in consent requirement for processing personal data of consumers aged 13-16 when the controller knows or willfully disregards the consumer's age, and treats any personal data collected from a known child as sensitive data requiring consent. No NJ-specific statutory age-verification mandate, minor-profiling ban distinct from the general profiling opt-out, dedicated education-settings privacy statute, or dependent-adult protection provision was independently verified in this run.

Sources and claims (2)
  1. ConfirmedNew Jersey Division of Consumer AffairsFederal law regulates the online privacy of children under age 13, and in New Jersey, when a controller knows or willfully disregards that a consumer is between 13 and 16 years old, the controller must obtain the consumer's consent before processing the consumer's personal data.observed
  2. ConfirmedNew Jersey Division of Consumer AffairsPersonal data collected from a known child is included within the NJDPL's definition of sensitive data, requiring the controller to obtain consent before processing.observed

#

Core enforcement architecture (AG-only, no PRA, penalty caps, cure period) is well evidenced and now largely operative post-July-2026; recent legislative activity (data broker law) and limited public track record of concluded NJDPL enforcement actions keep this amber rather than green.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberCore enforcement architecture (AG-only, no PRA, penalty caps, cure period) is well evidenced and now largely operative post-July-2026; recent legislative activity (data broker law) and limited public track record of concluded NJDPL enforcement actions keep this amber rather than green.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require violators to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses; the new 2026 data-broker/sensitive-data-sale law adds a separate $50,000-per-record fine for prohibited sensitive-data sales.

Claims (2):

  • The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require a violator to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses.
  • New Jersey's 2026 data-broker law amends the NJDPL to prohibit the sale of sensitive data, with violations carrying a $50,000-per-record fine.

Enforcement Activity IndexAmber

New Jersey's AG has created a privacy-focused subunit and joined a bipartisan Consortium of Privacy Regulators with California, Colorado, Connecticut, Delaware, Indiana, and Oregon to collaborate on state privacy-law enforcement; no major concluded public NJDPL enforcement decision was identified as of this run, consistent with the law's recent effective date and cure-period history.

Claims (1):

  • Attorneys general in California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon, along with the California Privacy Protection Agency, have formed the bipartisan Consortium of Privacy Regulators to collaborate on enforcing their respective state privacy laws.

Regulator Funding And CapacityGreen

New Jersey is among the states that have created a privacy-focused subunit within the Attorney General's office, signaling dedicated enforcement capacity.

Claims (1):

  • New Jersey is among the states, including California, Connecticut, New Hampshire, Oregon, Texas and Virginia, that have created privacy-focused subunits within their Attorney General's office.

Collective Redress And Class ActionsAmber

The NJDPL itself provides no class-action or collective-redress mechanism for consumers, but the separate Daniel's Law (protecting public officials' personal information) has driven dozens of private lawsuits, including proposed class actions against data brokers.

Claims (1):

  • New Jersey's Daniel's Law, protecting personal information of judges, law enforcement personnel and other public officials, has driven a substantial wave of private lawsuits and constitutional challenges against data brokers and consumer-facing businesses.

Private Right Of ActionRed

Consumers cannot file lawsuits on their own behalf under the NJDPL; enforcement is exclusively vested in the Attorney General/Division of Consumer Affairs.

Claims (1):

  • Consumers cannot file lawsuits on their own behalf under the NJDPL; the Office of the Attorney General enforces the law exclusively.

Recent Developments 180DGreen

On 30 June 2026, Governor Sherrill signed A 5328 into law, making New Jersey the seventh state (and second in 2026) to enact a data-broker registration law, with the registry itself becoming operative 27 March 2027; the law also amends the NJDPL to prohibit the sale of sensitive data, carrying up to $50,000-per-record fines.

Claims (1):

  • On 30 June 2026, Governor Mikie Sherrill signed A 5328 into law, making New Jersey the seventh state to enact a data broker law and the second state to do so in 2026, following Connecticut.
Category narrative111 words

Enforcement authority rests exclusively with the New Jersey Attorney General/Division of Consumer Affairs; the NJDPL carries no private right of action. A statutory notice-and-cure period applied until 1 July 2026, after which the Division may proceed directly to enforcement for uncured violations. Maximum civil penalties are $10,000 for a first offense and $20,000 for subsequent offenses, alongside injunctive and restitutionary relief. New Jersey's AG has joined a multistate 'Consortium of Privacy Regulators' for enforcement collaboration. Separately, Daniel's Law (protecting public officials' personal information) has generated a substantial wave of private litigation against data brokers, and a costly new 2026 data-broker registration/sensitive-data-sale-prohibition law (up to $50,000-per-record fines) was enacted 30 June 2026.

Sources and claims (7)
  1. ConfirmedNew Jersey Division of Consumer AffairsThe Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require a violator to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses.observed
  2. ConfirmedIAPPNew Jersey's 2026 data-broker law amends the NJDPL to prohibit the sale of sensitive data, with violations carrying a $50,000-per-record fine.observed
  3. ConfirmedIAPPAttorneys general in California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon, along with the California Privacy Protection Agency, have formed the bipartisan Consortium of Privacy Regulators to collaborate on enforcing their respective state privacy laws.observed
  4. ConfirmedIAPPNew Jersey is among the states, including California, Connecticut, New Hampshire, Oregon, Texas and Virginia, that have created privacy-focused subunits within their Attorney General's office.observed
  5. ConfirmedIAPPNew Jersey's Daniel's Law, protecting personal information of judges, law enforcement personnel and other public officials, has driven a substantial wave of private lawsuits and constitutional challenges against data brokers and consumer-facing businesses.observed
  6. ConfirmedNew Jersey Division of Consumer AffairsConsumers cannot file lawsuits on their own behalf under the NJDPL; the Office of the Attorney General enforces the law exclusively.observed
  7. ConfirmedIAPPOn 30 June 2026, Governor Mikie Sherrill signed A 5328 into law, making New Jersey the seventh state to enact a data broker law and the second state to do so in 2026, following Connecticut.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – New Jersey
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 14 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress are all populated with a mix of T1 (njconsumeraffairs.gov FAQ, homepage, Identity Theft Prevention Act statute PDF, GLBA consumer brief) and T2/T3 (IAPP, DataGuidance) sourcing. cross_border_and_adequacy carries zero claims with an explicit absent_field_provenance narrative, reflecting the genuine absence of a transfer/adequacy regime in the NJDPL rather than a research gap. Sub-modules for DPO appointment, ROPA, AI-specific risk assessment, biometric-specific statute, education-settings-specific statute, and dependent-adult protections likewise carry explicit absent_field_provenance rather than fabricated obligations, as these were not located in T1/T2/T3 sources reviewed for New Jersey.

Unresolved questions (5):

  • Has the NJ Division of Consumer Affairs finalized implementing regulations under NJDPL Section 9 (data protection assessments) since the 'forthcoming in 2025' status noted in the DCA FAQ, and if so, what is the citation?
  • Does the NJDPL contain an explicit statutory right to rectification/correction with independently citable clause text, or is correction handled solely via deletion-and-recollection in practice?
  • Has the NJ AG brought any concluded public enforcement action specifically under the NJDPL (as distinct from Daniel's Law litigation) since the cure period lapsed on 1 July 2026?
  • What NJ Administrative Code provisions specifically govern education-sector and dependent-adult data protection, referenced only generically in DataGuidance jurisdiction notes?
  • Is there an NJ-specific biometric privacy statute analogous to Illinois BIPA beyond the NJDPL's sensitive-data consent treatment of biometric data?

Escalate to primary-source review: yes