New Jersey Data Privacy Act (S332) state silhouette

New Jersey Data Privacy Act (S332)

Effective Date: 2025-01-15

The New Jersey Data Privacy Act applies to businesses that control or process personal data of at least 100,000 New Jersey consumers, or 25,000 consumers if the business derives revenue or receives a discount from selling personal data, a lower bar than most states since any sale revenue counts. Financial data is treated as sensitive, and there is no exemption for nonprofits or institutions of higher education.

What the New Jersey Data Privacy Act Requires

Businesses must post a privacy notice, honor access, correction, deletion, and portability rights, get consent for sensitive data, offer opt-outs for targeted advertising, sale, and significant profiling, and conduct data protection assessments. Universal opt-out signal recognition became mandatory in mid-2025.

Enforcement and Penalties

The Attorney General enforces under the Consumer Fraud Act, with penalties up to $10,000 for a first violation and $20,000 for subsequent ones. The 30-day cure period was available only until July 1, 2026, so enforcement can now proceed without a chance to fix problems first.

Source: New Jersey Legislature: S332, P.L. 2023, c. 266

Report a violation: If you believe a business is violating this law, you can file a complaint with the New Jersey Attorney General Division of Consumer Affairs.

More Rules & Regulations