Charter Data PrivacyJurisdictional Research
Home/New Jersey

New Jersey

state

State layer above federal baseline. NJ stacks a student-specific operator law (SOPPA-NJ) and a comprehensive consumer privacy law (NJDPA) on top of FERPA.

Applies to: All NJ charter schools (e.g., North Star Academy in Newark, Camden Prep). Subject to NJ Public School Contracts Law plus NJ student and consumer data privacy law.

Layered legal regime

A charter in this jurisdiction is subject to all of the following layers stacked:

  1. Layer 1Federal Baseline5 laws
  2. Layer 2New Jersey2 laws

New Jersey — Laws & Regulations

SOPPA-NJ

New Jersey Student Online Personal Protection Act

Full detail →
Statute: N.J.S.A. 56:8-215 et seq.
Regs:

Student-side operator privacy law. Prohibits operators of K-12 online services from selling student data, using it for targeted advertising, or building non-educational student profiles. Requires reasonable security and deletion on request. Schools must execute written agreements with edtech vendors defining data-protection duties.

School-side obligations

  • Execute written agreements with operators that define data-protection duties
  • Maintain an inventory of operators with which the school has agreements

Vendor-side obligations

  • Do not sell, rent, or trade student covered information
  • Do not use student covered information for targeted advertising
  • Do not create non-K-12 student profiles
  • Maintain reasonable security procedures and practices
  • Delete student covered information on school request or at contract termination
  • + 1 more on detail page
Breach notification: Governed by the NJ data breach notification law (N.J.S.A. 56:8-161 et seq.): notice in the most expedient time possible without unreasonable delay.
Enforcement: NJ Division of Consumer Affairs (Department of Law and Public Safety); Commissioner of Education consulted on rulemaking.

NJDPA

New Jersey Data Privacy Act

Full detail →
Statute: N.J.S.A. 56:8-166.4 et seq.
Regs:

NJ's comprehensive consumer privacy law (the 13th state to enact one). Controller/processor model with consumer rights (access, correction, deletion, portability, opt-out of sale, targeted advertising, and profiling), data-protection assessments for heightened-risk processing, and a universal opt-out mechanism (effective Jul 15, 2025). Applies to controllers doing business in NJ or targeting NJ residents that process 100,000+ consumers (or 25,000+ where data is sold).

School-side obligations

  • A charter operator is unlikely to hit the 100K-consumer threshold itself, but must ensure vendor contracts reflect NJDPA processor obligations
  • Where acting as a controller of staff and family data at scale, honor consumer rights and conduct data-protection assessments

Vendor-side obligations

  • Limit collection to what is reasonably necessary
  • Maintain reasonable administrative, technical, and physical security
  • Conduct and document data-protection assessments for heightened-risk processing
  • Operate under a binding controller-processor contract and flow obligations to sub-processors
  • Honor consumer rights within 45 days and support the universal opt-out (eff Jul 15, 2025)
  • + 1 more on detail page
Breach notification: Governed by the NJ data breach notification law (N.J.S.A. 56:8-161 et seq.).
Enforcement: NJ Attorney General / Division of Consumer Affairs (sole and exclusive). 30-day cure period until roughly 18 months after the effective date. No private right of action.