NJDPA
New Jersey Data Privacy Act
- Statute
- N.J.S.A. 56:8-166.4 et seq.
- Regulations
- None specified
- Enacted / Last Major Amendment
- P.L. 2023, c.266 (S332); signed Jan 16, 2024; effective Jan 15, 2025
- Jurisdictional Layer
- New Jersey (state)
Summary
NJ's comprehensive consumer privacy law (the 13th state to enact one). Controller/processor model with consumer rights (access, correction, deletion, portability, opt-out of sale, targeted advertising, and profiling), data-protection assessments for heightened-risk processing, and a universal opt-out mechanism (effective Jul 15, 2025). Applies to controllers doing business in NJ or targeting NJ residents that process 100,000+ consumers (or 25,000+ where data is sold).
Key Terms
- Controller
- Entity that determines the purpose and means of processing personal data.
- Processor
- Entity that processes personal data on behalf of the controller (the MSP/vendor role).
- Sensitive data
- Racial or ethnic origin, religion, health, financial info, sex life or orientation, immigration status, genetic or biometric data, data from a known child, and precise geolocation.
- Data protection assessment
- Required documented assessment for targeted advertising, sale, certain profiling, and processing of sensitive data.
School-side obligations
- A charter operator is unlikely to hit the 100K-consumer threshold itself, but must ensure vendor contracts reflect NJDPA processor obligations
- Where acting as a controller of staff and family data at scale, honor consumer rights and conduct data-protection assessments
Vendor-side obligations
- Limit collection to what is reasonably necessary
- Maintain reasonable administrative, technical, and physical security
- Conduct and document data-protection assessments for heightened-risk processing
- Operate under a binding controller-processor contract and flow obligations to sub-processors
- Honor consumer rights within 45 days and support the universal opt-out (eff Jul 15, 2025)
- Obtain consent before processing sensitive data
Breach notification
Governed by the NJ data breach notification law (N.J.S.A. 56:8-161 et seq.).
Enforcement
NJ Attorney General / Division of Consumer Affairs (sole and exclusive). 30-day cure period until roughly 18 months after the effective date. No private right of action.
NCSC AI Toolkit — Scanner Fields
These fields in the NCSC AI Toolkit derive from this statute:
Case Law — Verification Queue
Pending vLex verification. Never cite these without verification.
- NJDPA constructionTBDvLex query: '56:8-166' OR 'Data Protection Act' /s privacy
Open Questions / Unsettled Law
- Vendor-of-vendor (sub-processor) flow is the highest-risk operational area for an MSP
- When a multi-district edtech vendor crosses the 100K-consumer threshold