New Jersey Data Privacy Act (P.L. 2023, c. 266; N.J.S.A. 56:8-166.4 et seq.)
Below is what the official text of New Jersey Data Privacy Act (P.L. 2023, c. 266; N.J.S.A. 56:8-166.4 et seq.) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in New Jersey and $30 million revenue: Scope not stated.
- The same business with 8,000 people in New Jersey: Scope not stated.
- A US business with no users in New Jersey: Scope not stated.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | The NJDPA (P.L. 2023, c.266) grants consumers certain rights regarding their personal data and imposes duties on the operators, called controllers, that collect it.Official wordingThe proposed rules establish a comprehensive regulatory framework for the implementation of the NJDPA, a law that grants consumers certain rights regarding their personal data | www.njoag.gov read 2026-10-06 |
| When it applies to a business | Not stated on the official pages we read. statute text and Division of Consumer Affairs FAQ not reachable (pub.njleg.state.nj.us timed out, njconsumeraffairs.gov page blocked); the press release gives no thresholds | — |
| In force from | Not stated on the official pages we read. the press release states only that the Act was signed in January 2024; the effective date is not in an official page we read | — |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Not stated on the official pages we read. the page describes consent rules only as proposed regulations (N.J.A.C. 13:45L-7.1), not as the statute's duties | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text we read does not say whether a data protection officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Not stated on the official pages we read. statute text not reachable; the press release does not list privacy-notice contents | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here