Charter Data PrivacyJurisdictional Research

NJDPA

New Jersey Data Privacy Act

Statute
N.J.S.A. 56:8-166.4 et seq.
Regulations
None specified
Enacted / Last Major Amendment
P.L. 2023, c.266 (S332); signed Jan 16, 2024; effective Jan 15, 2025
Jurisdictional Layer
New Jersey (state)

Summary

NJ's comprehensive consumer privacy law (the 13th state to enact one). Controller/processor model with consumer rights (access, correction, deletion, portability, opt-out of sale, targeted advertising, and profiling), data-protection assessments for heightened-risk processing, and a universal opt-out mechanism (effective Jul 15, 2025). Applies to controllers doing business in NJ or targeting NJ residents that process 100,000+ consumers (or 25,000+ where data is sold).

Key Terms

Controller
Entity that determines the purpose and means of processing personal data.
Processor
Entity that processes personal data on behalf of the controller (the MSP/vendor role).
Sensitive data
Racial or ethnic origin, religion, health, financial info, sex life or orientation, immigration status, genetic or biometric data, data from a known child, and precise geolocation.
Data protection assessment
Required documented assessment for targeted advertising, sale, certain profiling, and processing of sensitive data.

School-side obligations

  • A charter operator is unlikely to hit the 100K-consumer threshold itself, but must ensure vendor contracts reflect NJDPA processor obligations
  • Where acting as a controller of staff and family data at scale, honor consumer rights and conduct data-protection assessments

Vendor-side obligations

  • Limit collection to what is reasonably necessary
  • Maintain reasonable administrative, technical, and physical security
  • Conduct and document data-protection assessments for heightened-risk processing
  • Operate under a binding controller-processor contract and flow obligations to sub-processors
  • Honor consumer rights within 45 days and support the universal opt-out (eff Jul 15, 2025)
  • Obtain consent before processing sensitive data

Breach notification

Governed by the NJ data breach notification law (N.J.S.A. 56:8-161 et seq.).

Enforcement

NJ Attorney General / Division of Consumer Affairs (sole and exclusive). 30-day cure period until roughly 18 months after the effective date. No private right of action.

NCSC AI Toolkit — Scanner Fields

These fields in the NCSC AI Toolkit derive from this statute:

state_primary_law_generalrequires_data_protection_assessmentprohibits_sale_of_student_data

Case Law — Verification Queue

Pending vLex verification. Never cite these without verification.

  • NJDPA construction
    TBD
    vLex query: '56:8-166' OR 'Data Protection Act' /s privacy

Open Questions / Unsettled Law

  • Vendor-of-vendor (sub-processor) flow is the highest-risk operational area for an MSP
  • When a multi-district edtech vendor crosses the 100K-consumer threshold