Core comprehensive statute is in force with a named enforcement authority and settled effective date; residual amber risk sits in still-pending AG rulemaking and the not-yet-operative data-broker registry.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.)
Traffic-light rationale — GreenCore comprehensive statute is in force with a named enforcement authority and settled effective date; residual amber risk sits in still-pending AG rulemaking and the not-yet-operative data-broker registry.
Sub-modules (5)
Regulator And AuthorityGreen
The Office of the Attorney General, operating through the Division of Consumer Affairs, has sole and exclusive enforcement authority over the NJDPL.
Claims (1):
The Office of the Attorney General enforces the NJDPL, and consumers cannot file lawsuits on their own behalf under the law.
Act And InstrumentsGreen
Primary instrument is the NJDPL (P.L.2023, c.266), signed 16 January 2024 and effective 15 January 2025 (365 days after enactment), supplemented by the Identity Theft Prevention Act breach-notification provisions and the 2026 data-broker registration law.
Claims (1):
The New Jersey Data Privacy Law, P.L.2023, c.266, guarantees New Jersey consumers certain rights with regard to their personal data and imposes requirements on controllers and processors, taking effect 15 January 2025.
Material ScopeGreen
NJDPL applies to controllers/processors that during a calendar year control or process personal data of at least 100,000 NJ consumers, or at least 25,000 consumers while deriving revenue from data sales.
Claims (1):
NJDPL applies to controllers/processors that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and make money from the sale of personal data.
Territorial ScopeAmber
Coverage is defined by reference to New Jersey residents acting in an individual/household context; employment-context data of NJ residents is expressly outside scope, meaning the law's territorial reach turns on the residency of the data subject rather than the controller's location.
Claims (1):
A consumer under the NJDPL is a New Jersey resident acting in an individual or household context; a New Jersey resident's data collected in an employment context is not protected under the law.
Regulator Registration And FilingAmber
The NJDPL itself imposes no general controller-registration duty, but a newly signed 2026 data-broker law creates a tiered mandatory annual registration/fee regime (up to $1.5M/year for the largest brokers), with the Division's registry becoming operative 27 March 2027.
Claims (1):
New Jersey's 2026 data broker law creates a tiered annual registration-fee structure, with the largest data brokers and collectors required to pay a $1.5 million annual registration fee, and the second fee tier (higher than any other state) triggered at 100,000 consumers; the Division's registry requirement takes effect 270 days after enactment, on 27 March 2027.
Category narrative71 words
New Jersey's comprehensive consumer privacy regime is the New Jersey Data Privacy Law (NJDPL), P.L.2023, c.266, enforced exclusively by the New Jersey Attorney General acting through the Division of Consumer Affairs. It sits atop a pre-existing sectoral patchwork (Identity Theft Prevention Act breach-notification statute, Daniel's Law protecting public officials' personal information, and a newly enacted 2026 data-broker registration law), producing a hybrid state-omnibus-plus-sectoral-overlay structure rather than a single unified DPA-style regulator.
Sources and claims (5)
ConfirmedNew Jersey Division of Consumer Affairs — The Office of the Attorney General enforces the NJDPL, and consumers cannot file lawsuits on their own behalf under the law.observed
ConfirmedNew Jersey Division of Consumer Affairs — The New Jersey Data Privacy Law, P.L.2023, c.266, guarantees New Jersey consumers certain rights with regard to their personal data and imposes requirements on controllers and processors, taking effect 15 January 2025.observed
ConfirmedNew Jersey Division of Consumer Affairs — NJDPL applies to controllers/processors that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and make money from the sale of personal data.observed
ConfirmedNew Jersey Division of Consumer Affairs — A consumer under the NJDPL is a New Jersey resident acting in an individual or household context; a New Jersey resident's data collected in an employment context is not protected under the law.observed
ConfirmedIAPP — New Jersey's 2026 data broker law creates a tiered annual registration-fee structure, with the largest data brokers and collectors required to pay a $1.5 million annual registration fee, and the second fee tier (higher than any other state) triggered at 100,000 consumers; the Division's registry requirement takes effect 270 days after enactment, on 27 March 2027.observed
Sensitive-data consent and consumer opt-out mechanics are well evidenced; the absence of a GDPR-style Art.6 lawful-basis catalogue and of an explicit anonymisation safe-harbour is a structural gap relative to omnibus regimes.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberSensitive-data consent and consumer opt-out mechanics are well evidenced; the absence of a GDPR-style Art.6 lawful-basis catalogue and of an explicit anonymisation safe-harbour is a structural gap relative to omnibus regimes.
Sub-modules (4)
Lawful BasesAmber
NJDPL is structured around consumer opt-out rights for standard processing (sale, targeted advertising, certain profiling) rather than an enumerated lawful-basis catalogue; no equivalent to GDPR Art.6 was identified.
Claims (1):
Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, in lieu of a GDPR-style enumerated lawful-basis requirement for processing.
Consent ThresholdsGreen
Controllers must obtain the consumer's consent before processing sensitive data, and opt-in consent before processing the personal data of a consumer aged 13-16 when the controller knows or willfully disregards the consumer's age.
Claims (1):
The controller must get the consumer's consent before processing the consumer's sensitive data, and must obtain consent before processing personal data of a consumer the controller knows or willfully disregards as being between 13 and 16 years old.
Special CategoriesGreen
Sensitive data is defined broadly to include racial/ethnic origin, religious beliefs, health condition, financial information, sexual activity/orientation, immigration/citizenship status, transgender/non-binary status, genetic or biometric data, precise geolocation, and any data collected from a known child.
Claims (1):
Sensitive data under the NJDPL is a subset of personal data revealing racial or ethnic origin, religious beliefs, health condition, financial information, sexual activity or orientation, immigration or citizenship status, transgender or non-binary status, genetic or biometric data, precise geolocation data, or personal data collected from a known child.
Pseudonymisation And AnonymisationAmber
The NJDPL defines de-identified data (data that cannot be linked to or used to infer information about a specific individual, where the controller takes steps to ensure non-linkability) and treats the potential use of de-identified data as a factor within data protection assessments, but no dedicated pseudonymisation/anonymisation safe-harbour provision separate from this definition was located. Searches of the DCA FAQ and DataGuidance jurisdiction notes did not surface a standalone anonymisation exemption regime.
Claims (1):
De-identified data is data that cannot be linked to or used to infer information about a specific individual or a device linked to that individual, and is considered de-identified only if the controller takes steps to ensure it cannot be linked to the consumer.
Category narrative70 words
NJDPL does not adopt a GDPR-style enumerated set of lawful bases; instead it relies on an opt-out model for ordinary processing (sale, targeted advertising, certain profiling) combined with an opt-in consent requirement specifically for sensitive/special-category data and for processing the data of consumers aged 13-16. Anonymisation/de-identification is recognised as a distinct, lower-risk data state relevant to the required data protection assessments, but no separate anonymisation 'safe harbour' provision was located.
Sources and claims (4)
ConfirmedNew Jersey Division of Consumer Affairs — Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, in lieu of a GDPR-style enumerated lawful-basis requirement for processing.observed
ConfirmedNew Jersey Division of Consumer Affairs — The controller must get the consumer's consent before processing the consumer's sensitive data, and must obtain consent before processing personal data of a consumer the controller knows or willfully disregards as being between 13 and 16 years old.observed
ConfirmedNew Jersey Division of Consumer Affairs — Sensitive data under the NJDPL is a subset of personal data revealing racial or ethnic origin, religious beliefs, health condition, financial information, sexual activity or orientation, immigration or citizenship status, transgender or non-binary status, genetic or biometric data, precise geolocation data, or personal data collected from a known child.observed
ConfirmedNew Jersey Division of Consumer Affairs — De-identified data is data that cannot be linked to or used to infer information about a specific individual or a device linked to that individual, and is considered de-identified only if the controller takes steps to ensure it cannot be linked to the consumer.observed
Rights bundle and response deadlines are directly evidenced by regulator and industry sources; itemised statutory text for rectification specifically was not independently isolated from a single named clause, warranting slightly lower confidence there.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — GreenRights bundle and response deadlines are directly evidenced by regulator and industry sources; itemised statutory text for rectification specifically was not independently isolated from a single named clause, warranting slightly lower confidence there.
Sub-modules (5)
Access RightGreen
Consumers have the right to confirm whether a controller is processing their personal data and to access it.
Claims (1):
The NJDPL grants consumers the right to confirm whether a controller is processing their personal data.
Rectification And ErasureAmber
Consumers have a deletion (erasure) right under specified conditions; correction/rectification is understood to form part of the standard rights bundle guaranteed by the NJDPL though the specific operative clause text was not independently isolated.
Claims (1):
Consumers may request data erasure (deletion) under specified conditions set out in the NJDPL.
Restriction And ObjectionGreen
Consumers may opt out of (object to) a controller's sale of personal data, use for targeted advertising, and certain profiling activities, including profiling used for loan/mortgage, employment, or insurance decisions.
Claims (1):
Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, such as profiling to determine loan, employment, or insurance eligibility.
Data PortabilityGreen
Consumers may obtain their personal data in a portable, machine-readable format.
Claims (1):
Consumers may obtain a copy of their personal data in a portable, machine-readable format under the NJDPL.
Deadlines And Response WindowsGreen
Controllers have 45 days to respond to consumer rights requests, with an optional 45-day extension.
Claims (1):
Organizations have 45 days to respond to a consumer rights request under the NJDPL, with an optional 45-day extension.
Category narrative54 words
The NJDPL grants New Jersey consumers rights to confirm whether a controller is processing their personal data and to access it, to correct/delete data, to obtain a portable copy, and to opt out of targeted advertising, data sales, and certain profiling. Controllers generally have 45 days to respond, extendable by a further 45 days.
Sources and claims (5)
ConfirmedDataGuidance — The NJDPL grants consumers the right to confirm whether a controller is processing their personal data.observed
ProbableDataGuidance — Consumers may request data erasure (deletion) under specified conditions set out in the NJDPL.observed
ConfirmedNew Jersey Division of Consumer Affairs — Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, such as profiling to determine loan, employment, or insurance eligibility.observed
ProbableDataGuidance — Consumers may obtain a copy of their personal data in a portable, machine-readable format under the NJDPL.observed
ConfirmedDataGuidance — Organizations have 45 days to respond to a consumer rights request under the NJDPL, with an optional 45-day extension.observed
DPIA-equivalent, processor-contract, and breach-notification duties are well evidenced and binding; DPO appointment and formal ROPA requirements are not evidenced and are flagged as gaps rather than fabricated.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; New Jersey Identity Theft Prevention Act, N.J.S.A. 56:8-161 et seq.
Traffic-light rationale — AmberDPIA-equivalent, processor-contract, and breach-notification duties are well evidenced and binding; DPO appointment and formal ROPA requirements are not evidenced and are flagged as gaps rather than fabricated.
Sub-modules (7)
Accountability And DpiaGreen
Section 9 of the NJDPL requires controllers to conduct and document a data protection assessment prior to processing that presents a heightened risk of harm, including all sensitive-data processing, considering risks/benefits, consumer expectations, and potential use of de-identified data.
Claims (2):
Section 9 of the NJDPA requires controllers to conduct and document a data protection assessment prior to initiating any processing activity that presents a heightened risk of harm to consumers.
Processing presents a heightened risk of harm when there is risk of unfair treatment, illegal discrimination, or financial or physical injury, or when the controller processes sensitive data, triggering the DPA requirement.
Dpo RequirementsRed
No explicit statutory DPO-appointment threshold or independence requirement analogous to GDPR Art.37-39 was located in the NJDPL FAQ, DataGuidance jurisdiction notes, or NJDPL infographic reviewed for this run.
Ropa RequirementsRed
No explicit Records of Processing Activities obligation equivalent to GDPR Art.30 was identified in the sources reviewed; the NJDPL's transparency obligations run instead through privacy notices and data protection assessments.
Joint Controller ArrangementsGreen
Processors may only process personal data at the controller's direction, under a contract specifying processing instructions, the data to be processed, duration, and requiring return or deletion of data once processing is complete.
Claims (1):
A processor may only process personal data at the request and under the direction of a controller, and must enter into a contract with the controller containing processing instructions, identifying the data processed and retention duration, and requiring return or deletion of the data once processing is complete.
Security MeasuresGreen
Controllers must implement robust administrative, technical, and physical safeguards, limit collection to essential purposes (data minimisation), and enforce contractual compliance with NJDPL vendor-management standards.
Claims (1):
Controllers are required to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.
Breach NotificationGreen
Under the Identity Theft Prevention Act, businesses conducting business in NJ must disclose any breach of security of computerized records to affected NJ residents in the most expedient time possible without unreasonable delay, and must report the breach to the NJ State Police Division in advance of customer notification.
Claims (2):
Any business conducting business in New Jersey must disclose a breach of security of computerized records to any affected New Jersey resident in the most expedient time possible and without unreasonable delay.
A business or public entity must, in advance of disclosing a breach to affected customers, report the breach and related information to the Division of State Police in the Department of Law and Public Safety.
Retention And DisposalAmber
Processor contracts must require return or deletion of personal data once processing is complete; no separate general data-retention-limit statute beyond this processor-contract duty was located.
Claims (1):
Processor contracts under the NJDPL must require the processor to return or delete personal data once processing is complete.
Category narrative77 words
Controllers must complete and document a data protection assessment ('DPA') before processing that presents a heightened risk of harm (including all sensitive-data processing, and processing for targeted advertising, sale, or significant-effect profiling). Processor obligations run through a mandatory data-processing contract. Security-of-processing and breach-notification duties derive substantially from the pre-existing Identity Theft Prevention Act rather than from the NJDPL itself. No explicit DPO-appointment threshold or GDPR-style Records of Processing Activities (ROPA) obligation was located in the sources reviewed.
Sources and claims (7)
ConfirmedDataGuidance — Section 9 of the NJDPA requires controllers to conduct and document a data protection assessment prior to initiating any processing activity that presents a heightened risk of harm to consumers.observed
ConfirmedNew Jersey Division of Consumer Affairs — Processing presents a heightened risk of harm when there is risk of unfair treatment, illegal discrimination, or financial or physical injury, or when the controller processes sensitive data, triggering the DPA requirement.observed
ConfirmedNew Jersey Division of Consumer Affairs — A processor may only process personal data at the request and under the direction of a controller, and must enter into a contract with the controller containing processing instructions, identifying the data processed and retention duration, and requiring return or deletion of the data once processing is complete.observed
ProbableDataGuidance — Controllers are required to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.observed
ConfirmedNew Jersey Division of Consumer Affairs — Any business conducting business in New Jersey must disclose a breach of security of computerized records to any affected New Jersey resident in the most expedient time possible and without unreasonable delay.observed
ConfirmedNew Jersey Division of Consumer Affairs — A business or public entity must, in advance of disclosing a breach to affected customers, report the breach and related information to the Division of State Police in the Department of Law and Public Safety.observed
ConfirmedNew Jersey Division of Consumer Affairs — Processor contracts under the NJDPL must require the processor to return or delete personal data once processing is complete.observed
No transfer-mechanism, adequacy, or localisation provisions exist in the NJDPL or ancillary NJ statutes reviewed; module is populated with an explicit absence finding rather than left silently empty.
Traffic-light rationale — RedNo transfer-mechanism, adequacy, or localisation provisions exist in the NJDPL or ancillary NJ statutes reviewed; module is populated with an explicit absence finding rather than left silently empty.
Sub-modules (6)
Transfer MechanismsRed
No statutory cross-border transfer mechanism (adequacy, SCCs, BCRs, derogations) exists under the NJDPL; searched DCA FAQ, DataGuidance NJ jurisdiction notes, and NJDPL infographic without finding transfer-specific provisions.
Adequacy ReceivedRed
Not applicable — New Jersey, as a US state, is not a party to adequacy findings under any foreign comprehensive privacy regime.
Adequacy GrantedRed
New Jersey has no authority to grant adequacy determinations; this sits with the federal government, and no NJ-specific mechanism was found.
Sccs And BcrsRed
No SCC or BCR framework exists under the NJDPL.
Transfer Impact AssessmentRed
No transfer impact assessment requirement was identified under the NJDPL; the statute's assessment obligation (data protection assessment) is tied to heightened-risk processing generally, not cross-border transfer specifically.
Data LocalisationRed
No data-localisation mandate (partial or absolute) was identified in the NJDPL or ancillary NJ statutes reviewed.
Category narrative50 words
The NJDPL is a domestic US state consumer-privacy statute and contains no GDPR-style cross-border transfer mechanism regime (no adequacy findings, SCCs, BCRs, or transfer-impact-assessment requirement), and no data-localisation mandate was identified. This is a legitimate structural gap consistent with the US state omnibus model rather than an omission of research.
Financial, health, and credit-sector carve-outs are well evidenced; education and insurance-specific overlay detail beyond the general GLBA/HIPAA/FCRA exclusions was not independently verified.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; Gramm-Leach-Bliley Act (federal, as applied in NJ); HIPAA (federal, as applied in NJ)
Traffic-light rationale — AmberFinancial, health, and credit-sector carve-outs are well evidenced; education and insurance-specific overlay detail beyond the general GLBA/HIPAA/FCRA exclusions was not independently verified.
Sub-modules (7)
Financial Sector OverlayGreen
Data collected by certain financial and insurance institutions is excluded from the NJDPL, and GLBA-mandated annual privacy notices and opt-out rights continue to apply to financial institutions operating in New Jersey, administered with DCA involvement.
Claims (2):
Data collected by certain financial and insurance institutions is excluded from the NJDPL.
Financial institutions must provide consumers an annual privacy notice regarding nonpublic personal information, and consumers may opt out of disclosure of that information at any time.
Health Sector OverlayGreen
Health information protected by HIPAA is excluded from the NJDPL, leaving HIPAA as the operative federal health-privacy instrument for covered entities in New Jersey.
Claims (1):
Health information protected by HIPAA is excluded from the NJDPL.
Telecoms And EprivacyAmber
No dedicated New Jersey ePrivacy/telecoms-specific cookie-consent statute distinct from the NJDPL's general opt-out and universal-opt-out-mechanism provisions was identified.
Employment DataGreen
Personal data collected from a New Jersey resident in an employment context (e.g., a job applicant) is expressly excluded from NJDPL protection.
Claims (1):
A New Jersey resident whose personal data is collected by a potential employer while applying for a job is not protected under the NJDPL.
Credit And ScoringGreen
Data processed under the federal Fair Credit Reporting Act is excluded from the NJDPL; separately, the Identity Theft Prevention Act gives NJ consumers the right to place a security freeze on their consumer/credit report.
Claims (2):
Data that can be processed under the federal Fair Credit Reporting Act is excluded from the NJDPL.
New Jersey consumers have the right to place a security freeze on their consumer report under the Identity Theft Prevention Act, preventing release of report information without express authorization.
EducationAmber
DataGuidance notes that New Jersey Revised Statutes and Administrative Code provisions create sector-specific obligations for education-sector data collection, but no education-specific statute name or citation was independently isolated in this run.
Claims (1):
Various privacy-related provisions in the New Jersey Revised Statutes and New Jersey Administrative Code create obligations for data collected by companies in the education sector, in addition to the NJDPL.
InsuranceGreen
Data collected by certain insurance institutions is excluded from the NJDPL under the same carve-out as financial institutions; GLBA-style privacy-notice obligations apply to insurance disclosures of nonpublic personal information.
Claims (1):
Nonpublic personal information collected by insurance companies is subject to GLBA-style annual privacy-notice and opt-out requirements administered with New Jersey Division of Consumer Affairs involvement.
Category narrative50 words
The NJDPL carves out several federally regulated sectors entirely: HIPAA-covered health information, FCRA-covered consumer-reporting data, and data collected by certain financial and insurance institutions (GLBA-aligned exclusion). Employment-context data is also excluded. Pre-existing sectoral statutes (Identity Theft Prevention Act, GLBA annual privacy-notice obligations enforced via DCA) continue to apply in parallel.
ProbableNew Jersey Division of Consumer Affairs — Financial institutions must provide consumers an annual privacy notice regarding nonpublic personal information, and consumers may opt out of disclosure of that information at any time.observed
ConfirmedNew Jersey Division of Consumer Affairs — A New Jersey resident whose personal data is collected by a potential employer while applying for a job is not protected under the NJDPL.observed
ConfirmedNew Jersey Division of Consumer Affairs — Data that can be processed under the federal Fair Credit Reporting Act is excluded from the NJDPL.observed
ConfirmedNew Jersey Division of Consumer Affairs — New Jersey consumers have the right to place a security freeze on their consumer report under the Identity Theft Prevention Act, preventing release of report information without express authorization.observed
UncertainDataGuidance — Various privacy-related provisions in the New Jersey Revised Statutes and New Jersey Administrative Code create obligations for data collected by companies in the education sector, in addition to the NJDPL.observed
ProbableNew Jersey Division of Consumer Affairs — Nonpublic personal information collected by insurance companies is subject to GLBA-style annual privacy-notice and opt-out requirements administered with New Jersey Division of Consumer Affairs involvement.observed
Opt-out and UOOM obligations are binding and in force; dark-patterns, clean-room, and direct-marketing-specific sub-modules lack dedicated statutory findings and are flagged amber/red accordingly.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — GreenOpt-out and UOOM obligations are binding and in force; dark-patterns, clean-room, and direct-marketing-specific sub-modules lack dedicated statutory findings and are flagged amber/red accordingly.
Sub-modules (6)
Cookies And TrackersAmber
No dedicated cookie-consent statute exists separate from the NJDPL's general sale/targeted-advertising opt-out and UOOM mechanics; the DCA's non-binding Cyber Safe NJ guidance discusses browser cookie controls but is educational rather than a compliance obligation.
Dark PatternsAmber
No standalone dark-patterns prohibition was identified in the NJDPL text reviewed; the law's requirement that privacy notices clearly state how consumers may exercise their rights functions as an indirect anti-obfuscation measure.
Claims (1):
A controller's privacy notice must clearly state how consumers may exercise their rights under the NJDPL.
Opt Out SignalsGreen
By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms such as Global Privacy Control.
Claims (1):
By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms, such as Global Privacy Control, which allow automatic opt-out across websites, platforms, or devices.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room-specific rule was identified under the NJDPL.
Cross Context AdvertisingGreen
NJDPL's UOOM provisions uniquely extend to opt-outs for consumer profiling in furtherance of decisions producing legal or similarly significant effects, not just targeted advertising and data sales as in most peer state laws.
Claims (1):
Under the NJDPL, universal opt-out mechanisms must support consumer opt-outs for profiling in furtherance of decisions that produce legal or similarly significant effects, in addition to targeted advertising and sales of personal data, a scope broader than most peer state laws.
Direct MarketingAmber
Direct-marketing consent/suppression is addressed indirectly through the general targeted-advertising and sale opt-out mechanism; no standalone direct-marketing statute distinct from the NJDPL was identified.
Category narrative65 words
The NJDPL's principal adtech mechanism is a consumer opt-out right covering targeted advertising, sale of personal data, and — unusually among state laws — significant-effect profiling, reinforced by a universal-opt-out-mechanism (UOOM) requirement effective 15 July 2025 requiring controllers to honor signals such as Global Privacy Control. No dedicated dark-patterns statute, clean-room/data-collaboration-room rule, or standalone direct-marketing consent statute distinct from the general opt-out regime was identified.
Sources and claims (3)
ConfirmedNew Jersey Division of Consumer Affairs — A controller's privacy notice must clearly state how consumers may exercise their rights under the NJDPL.observed
ConfirmedNew Jersey Division of Consumer Affairs — By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms, such as Global Privacy Control, which allow automatic opt-out across websites, platforms, or devices.observed
ConfirmedIAPP — Under the NJDPL, universal opt-out mechanisms must support consumer opt-outs for profiling in furtherance of decisions that produce legal or similarly significant effects, in addition to targeted advertising and sales of personal data, a scope broader than most peer state laws.observed
Profiling opt-out and sensitive-data (biometric/genetic) consent duties are binding and evidenced; dedicated AI-risk-assessment and biometric-specific statutory regimes are not evidenced for New Jersey and are flagged as gaps.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberProfiling opt-out and sensitive-data (biometric/genetic) consent duties are binding and evidenced; dedicated AI-risk-assessment and biometric-specific statutory regimes are not evidenced for New Jersey and are flagged as gaps.
Sub-modules (6)
Profiling RestrictionsGreen
Consumers may opt out of profiling in furtherance of decisions producing legal or similarly significant effects, with statutory examples including denial/provision of financial or lending services, housing, insurance, education enrollment, criminal justice, employment, health care, or essential goods and services.
Claims (1):
Under the NJDPL, universal opt-out mechanisms cover profiling 'in furtherance of decisions that produce legal or similarly significant effects concerning a consumer,' with examples including denial or provision of financial, lending, housing, insurance, education, criminal justice, employment, health care, or essential goods/services decisions.
Automated Decision Making TransparencyAmber
Controllers must complete a data protection assessment before engaging in significant-effect profiling, functioning as an indirect ADM-transparency mechanism, though no explicit individual right to an explanation of automated decisions was located.
Claims (1):
The NJDPL requires completed data protection assessments before a significant-effect profiling activity is carried out.
Ai Risk AssessmentsAmber
New Jersey has not been identified as having a dedicated AI-specific risk-assessment statute (distinct from Colorado's AI Act model); the NJDPL's general data protection assessment is the closest analogue but is not AI-specific.
Absence provenance: not recorded. Searched: njconsumeraffairs.gov FAQ, iapp.org New Jersey privacy law coverage.
Biometric RegimeAmber
Biometric data is classified as sensitive data under the NJDPL, requiring consumer consent and a data protection assessment before processing; no standalone biometric-privacy statute (of the Illinois BIPA type) was identified for New Jersey.
Claims (1):
Biometric data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.
Genetic DataGreen
Genetic data is classified as sensitive data under the NJDPL, requiring consumer consent and a data protection assessment before processing.
Claims (1):
Genetic data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.
State Surveillance CarveoutsAmber
Personal data collected by New Jersey state agencies is excluded from the NJDPL entirely; the scope and limits of this carve-out relative to law-enforcement/surveillance use were not further detailed in the sources reviewed.
Claims (1):
Data collected by state agencies is excluded from the NJDPL.
Category narrative74 words
The NJDPL treats genetic and biometric data as sensitive data requiring consent and a data protection assessment, and grants consumers an opt-out right over profiling that produces legal or similarly significant effects (e.g., lending, housing, insurance, employment, healthcare, criminal justice, essential goods/services decisions). There is no dedicated biometric-specific statute (unlike Illinois's BIPA) and no NJ-specific AI risk-assessment statute distinct from the general data protection assessment; state-agency data is carved out of the NJDPL entirely.
Sources and claims (5)
ConfirmedIAPP — Under the NJDPL, universal opt-out mechanisms cover profiling 'in furtherance of decisions that produce legal or similarly significant effects concerning a consumer,' with examples including denial or provision of financial, lending, housing, insurance, education, criminal justice, employment, health care, or essential goods/services decisions.observed
ConfirmedIAPP — The NJDPL requires completed data protection assessments before a significant-effect profiling activity is carried out.observed
ConfirmedNew Jersey Division of Consumer Affairs — Biometric data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.observed
ConfirmedNew Jersey Division of Consumer Affairs — Genetic data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.observed
Age-13-16 consent threshold and 'known child' sensitive-data treatment are binding and evidenced; age-verification mechanics, education-settings specifics, and dependent-adult protections are not evidenced and flagged as gaps.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; federal COPPA (as applied to NJ residents under 13)
Traffic-light rationale — AmberAge-13-16 consent threshold and 'known child' sensitive-data treatment are binding and evidenced; age-verification mechanics, education-settings specifics, and dependent-adult protections are not evidenced and flagged as gaps.
Sub-modules (5)
Age VerificationAmber
No explicit statutory age-verification mechanism was identified in the NJDPL; the consent obligation is triggered by the controller's actual knowledge or willful disregard of a consumer's age rather than a mandated verification process.
Parental ConsentGreen
Federal COPPA governs online privacy of children under 13; for consumers aged 13-16, the NJDPL requires the controller to obtain the consumer's own consent (opt-in) when the controller knows or willfully disregards their age, rather than mandating parental consent specifically.
Claims (1):
Federal law regulates the online privacy of children under age 13, and in New Jersey, when a controller knows or willfully disregards that a consumer is between 13 and 16 years old, the controller must obtain the consumer's consent before processing the consumer's personal data.
Minor Profiling BansAmber
Personal data collected from a known child is treated as sensitive data requiring consent under the NJDPL; this extends the general sensitive-data consent and profiling opt-out protections to minors rather than establishing a standalone profiling ban.
Claims (1):
Personal data collected from a known child is included within the NJDPL's definition of sensitive data, requiring the controller to obtain consent before processing.
Education SettingsRed
New Jersey Administrative Code provisions reportedly create education-sector data obligations, but no specific education-settings statute citation was independently isolated in this run.
Absence provenance: not recorded. Searched: dataguidance.com New Jersey jurisdiction notes.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated) specific data-protection provision was identified in the sources reviewed for New Jersey.
Absence provenance: not recorded. Searched: njconsumeraffairs.gov NJ Data Privacy Law FAQ, dataguidance.com New Jersey jurisdiction notes.
Category narrative78 words
Children under 13 are governed by the federal COPPA regime; New Jersey layers an additional opt-in consent requirement for processing personal data of consumers aged 13-16 when the controller knows or willfully disregards the consumer's age, and treats any personal data collected from a known child as sensitive data requiring consent. No NJ-specific statutory age-verification mandate, minor-profiling ban distinct from the general profiling opt-out, dedicated education-settings privacy statute, or dependent-adult protection provision was independently verified in this run.
Sources and claims (2)
ConfirmedNew Jersey Division of Consumer Affairs — Federal law regulates the online privacy of children under age 13, and in New Jersey, when a controller knows or willfully disregards that a consumer is between 13 and 16 years old, the controller must obtain the consumer's consent before processing the consumer's personal data.observed
ConfirmedNew Jersey Division of Consumer Affairs — Personal data collected from a known child is included within the NJDPL's definition of sensitive data, requiring the controller to obtain consent before processing.observed
Core enforcement architecture (AG-only, no PRA, penalty caps, cure period) is well evidenced and now largely operative post-July-2026; recent legislative activity (data broker law) and limited public track record of concluded NJDPL enforcement actions keep this amber rather than green.
Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberCore enforcement architecture (AG-only, no PRA, penalty caps, cure period) is well evidenced and now largely operative post-July-2026; recent legislative activity (data broker law) and limited public track record of concluded NJDPL enforcement actions keep this amber rather than green.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require violators to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses; the new 2026 data-broker/sensitive-data-sale law adds a separate $50,000-per-record fine for prohibited sensitive-data sales.
Claims (2):
The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require a violator to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses.
New Jersey's 2026 data-broker law amends the NJDPL to prohibit the sale of sensitive data, with violations carrying a $50,000-per-record fine.
Enforcement Activity IndexAmber
New Jersey's AG has created a privacy-focused subunit and joined a bipartisan Consortium of Privacy Regulators with California, Colorado, Connecticut, Delaware, Indiana, and Oregon to collaborate on state privacy-law enforcement; no major concluded public NJDPL enforcement decision was identified as of this run, consistent with the law's recent effective date and cure-period history.
Claims (1):
Attorneys general in California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon, along with the California Privacy Protection Agency, have formed the bipartisan Consortium of Privacy Regulators to collaborate on enforcing their respective state privacy laws.
Regulator Funding And CapacityGreen
New Jersey is among the states that have created a privacy-focused subunit within the Attorney General's office, signaling dedicated enforcement capacity.
Claims (1):
New Jersey is among the states, including California, Connecticut, New Hampshire, Oregon, Texas and Virginia, that have created privacy-focused subunits within their Attorney General's office.
Collective Redress And Class ActionsAmber
The NJDPL itself provides no class-action or collective-redress mechanism for consumers, but the separate Daniel's Law (protecting public officials' personal information) has driven dozens of private lawsuits, including proposed class actions against data brokers.
Claims (1):
New Jersey's Daniel's Law, protecting personal information of judges, law enforcement personnel and other public officials, has driven a substantial wave of private lawsuits and constitutional challenges against data brokers and consumer-facing businesses.
Private Right Of ActionRed
Consumers cannot file lawsuits on their own behalf under the NJDPL; enforcement is exclusively vested in the Attorney General/Division of Consumer Affairs.
Claims (1):
Consumers cannot file lawsuits on their own behalf under the NJDPL; the Office of the Attorney General enforces the law exclusively.
Recent Developments 180DGreen
On 30 June 2026, Governor Sherrill signed A 5328 into law, making New Jersey the seventh state (and second in 2026) to enact a data-broker registration law, with the registry itself becoming operative 27 March 2027; the law also amends the NJDPL to prohibit the sale of sensitive data, carrying up to $50,000-per-record fines.
Claims (1):
On 30 June 2026, Governor Mikie Sherrill signed A 5328 into law, making New Jersey the seventh state to enact a data broker law and the second state to do so in 2026, following Connecticut.
Category narrative111 words
Enforcement authority rests exclusively with the New Jersey Attorney General/Division of Consumer Affairs; the NJDPL carries no private right of action. A statutory notice-and-cure period applied until 1 July 2026, after which the Division may proceed directly to enforcement for uncured violations. Maximum civil penalties are $10,000 for a first offense and $20,000 for subsequent offenses, alongside injunctive and restitutionary relief. New Jersey's AG has joined a multistate 'Consortium of Privacy Regulators' for enforcement collaboration. Separately, Daniel's Law (protecting public officials' personal information) has generated a substantial wave of private litigation against data brokers, and a costly new 2026 data-broker registration/sensitive-data-sale-prohibition law (up to $50,000-per-record fines) was enacted 30 June 2026.
Sources and claims (7)
ConfirmedNew Jersey Division of Consumer Affairs — The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require a violator to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses.observed
ConfirmedIAPP — New Jersey's 2026 data-broker law amends the NJDPL to prohibit the sale of sensitive data, with violations carrying a $50,000-per-record fine.observed
ConfirmedIAPP — Attorneys general in California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon, along with the California Privacy Protection Agency, have formed the bipartisan Consortium of Privacy Regulators to collaborate on enforcing their respective state privacy laws.observed
ConfirmedIAPP — New Jersey is among the states, including California, Connecticut, New Hampshire, Oregon, Texas and Virginia, that have created privacy-focused subunits within their Attorney General's office.observed
ConfirmedIAPP — New Jersey's Daniel's Law, protecting personal information of judges, law enforcement personnel and other public officials, has driven a substantial wave of private lawsuits and constitutional challenges against data brokers and consumer-facing businesses.observed
ConfirmedNew Jersey Division of Consumer Affairs — Consumers cannot file lawsuits on their own behalf under the NJDPL; the Office of the Attorney General enforces the law exclusively.observed
ConfirmedIAPP — On 30 June 2026, Governor Mikie Sherrill signed A 5328 into law, making New Jersey the seventh state to enact a data broker law and the second state to do so in 2026, following Connecticut.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – New Jersey
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 14 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress are all populated with a mix of T1 (njconsumeraffairs.gov FAQ, homepage, Identity Theft Prevention Act statute PDF, GLBA consumer brief) and T2/T3 (IAPP, DataGuidance) sourcing. cross_border_and_adequacy carries zero claims with an explicit absent_field_provenance narrative, reflecting the genuine absence of a transfer/adequacy regime in the NJDPL rather than a research gap. Sub-modules for DPO appointment, ROPA, AI-specific risk assessment, biometric-specific statute, education-settings-specific statute, and dependent-adult protections likewise carry explicit absent_field_provenance rather than fabricated obligations, as these were not located in T1/T2/T3 sources reviewed for New Jersey.
Unresolved questions (5):
Has the NJ Division of Consumer Affairs finalized implementing regulations under NJDPL Section 9 (data protection assessments) since the 'forthcoming in 2025' status noted in the DCA FAQ, and if so, what is the citation?
Does the NJDPL contain an explicit statutory right to rectification/correction with independently citable clause text, or is correction handled solely via deletion-and-recollection in practice?
Has the NJ AG brought any concluded public enforcement action specifically under the NJDPL (as distinct from Daniel's Law litigation) since the cure period lapsed on 1 July 2026?
What NJ Administrative Code provisions specifically govern education-sector and dependent-adult data protection, referenced only generically in DataGuidance jurisdiction notes?
Is there an NJ-specific biometric privacy statute analogous to Illinois BIPA beyond the NJDPL's sensitive-data consent treatment of biometric data?