Effective Date: January 15, 2025
New Jersey is set to implement robust privacy protections for consumers with the enactment of the New Jersey Data Protection Act (NJDPA), effective January 15, 2025. The NJDPA provides comprehensive safeguards for personal data, aligning with the growing trend of state-led privacy initiatives and enhancing consumer rights in the digital age.
This article provides a breakdown of the key provisions of the NJDPA, including its scope, consumer rights, and business obligations.
The NJDPA applies to businesses that:
Important Note: Unlike some privacy laws, the NJDPA does not include a revenue threshold for applicability. It also applies to non-profit organizations but exempts state entities, along with certain types of data governed by federal laws (such as health information under HIPAA).
New Jersey residents will have the following rights under the NJDPA:
Consumers can submit requests to businesses using the methods specified in the privacy notice, without needing to create an account. For those with existing accounts, businesses may request that they use their accounts for submitting requests. Additionally, consumers can appoint an authorized agent to make opt-out requests on their behalf, including through universal opt-out signals (when such technology becomes available).
Businesses (controllers) must:
Limit Data Collection: Only collect personal data that is relevant and necessary for the stated processing purposes.
Obtain Consent: Controllers must obtain explicit consent to process personal data for purposes not necessary to nor compatible with those originally disclosed, process sensitive data, or process personal data of individuals between 13 and 17 for purposes of targeted advertising, sale of personal data, or profiling.
Privacy Notice Requirements: Businesses must provide a clear and accessible privacy notice that includes, among others:
Contract with Data Processors: Businesses must ensure that their data processors are also aligned with NJDPA provisions.
Data Protection Assessments: Businesses must perform and document data protection assessments for activities that present a higher risk of harm to consumers’ privacy, such as the processing of sensitive data or the sale of personal data.
Security Practices: Businesses must implement reasonable data security measures to protect personal data from unauthorized access, both during storage and use.
Businesses must respond to consumer requests within 45 days. If more time is needed, businesses may extend this period by an additional 45 days, but consumers must be informed of the delay. Information must be provided free of charge for one request per consumer every 12 months. If a request is manifestly unfounded, excessive, or repetitive, businesses may charge a reasonable fee to cover administrative costs.
Consumers have the right to appeal decisions made by businesses regarding their requests. The appeal process must be easy to access and similar to the process for submitting the initial request. Businesses must respond to appeals within 45 days. If an appeal is denied, consumers can contact the New Jersey Division of Consumer Affairs to file a complaint.
The New Jersey Attorney General will have exclusive authority to enforce the NJDPA. Businesses that fail to comply with the law will be subject to civil penalties, which could result in significant financial consequences. Until July 1, 2026, violators have 30 days to remedy any violations after receiving written notice.
By July 15, 2025, businesses will need to provide consumers with an option to opt out of the sale of personal data, targeted advertising, and profiling through universal opt-out signals.
The New Jersey Consumer Data Protection Act represents a major step toward protecting consumer privacy in the state. With its strong emphasis on transparency, consumer control over personal data, and business accountability, the NJDPA ensures that consumers in New Jersey can exercise their rights over their personal information.
Businesses operating in New Jersey must begin preparing to comply with the law ahead of its January 15, 2025 effective date. This includes revising privacy policies, implementing data protection practices, and ensuring that consumer rights processes are in place.
Act now to mitigate compliance risks and demonstrate your commitment to consumer privacy under the NJDPA.