🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-NJ v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing14 sources retrieved model claude-sonnet-5 · 2026-08-06

New Jersey, USA

US-NJ schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

New Jersey's data protection regime tightened materially this cycle across four distinct fronts. A new data broker and data collector registration law, A5328 (P.L.2026, c.25), was enacted 30 June 2026, requiring annual registration with the Division of Consumer Affairs at fees ranging from $5,000 to $1.5 million, and prohibiting the sale of sensitive personal data outright, with no consent exception available. On the same date, the New Jersey Data Privacy Act's 30-day right-to-cure period for controllers sunset, meaning the Division may now proceed directly to enforcement without first affording a cure opportunity.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core comprehensive statute is in force with a named enforcement authority and settled effective date; residual amber risk sits in still-pending AG rulemaking and the not-yet-operative data-broker registry.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.)
Traffic-light rationale — GreenCore comprehensive statute is in force with a named enforcement authority and settled effective date; residual amber risk sits in still-pending AG rulemaking and the not-yet-operative data-broker registry.

Sub-modules (5)

Regulator And AuthorityGreen

The Office of the Attorney General, operating through the Division of Consumer Affairs, has sole and exclusive enforcement authority over the NJDPL.

Claims (1):

  • The Office of the Attorney General enforces the NJDPL, and consumers cannot file lawsuits on their own behalf under the law.

Act And InstrumentsGreen

Primary instrument is the NJDPL (P.L.2023, c.266), signed 16 January 2024 and effective 15 January 2025 (365 days after enactment), supplemented by the Identity Theft Prevention Act breach-notification provisions and the 2026 data-broker registration law.

Claims (1):

  • The New Jersey Data Privacy Law, P.L.2023, c.266, guarantees New Jersey consumers certain rights with regard to their personal data and imposes requirements on controllers and processors, taking effect 15 January 2025.

Material ScopeGreen

NJDPL applies to controllers/processors that during a calendar year control or process personal data of at least 100,000 NJ consumers, or at least 25,000 consumers while deriving revenue from data sales.

Claims (1):

  • NJDPL applies to controllers/processors that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and make money from the sale of personal data.

Territorial ScopeAmber

Coverage is defined by reference to New Jersey residents acting in an individual/household context; employment-context data of NJ residents is expressly outside scope, meaning the law's territorial reach turns on the residency of the data subject rather than the controller's location.

Claims (1):

  • A consumer under the NJDPL is a New Jersey resident acting in an individual or household context; a New Jersey resident's data collected in an employment context is not protected under the law.

Regulator Registration And FilingAmber

The NJDPL itself imposes no general controller-registration duty, but a newly signed 2026 data-broker law creates a tiered mandatory annual registration/fee regime (up to $1.5M/year for the largest brokers), with the Division's registry becoming operative 27 March 2027.

Claims (1):

  • New Jersey's 2026 data broker law creates a tiered annual registration-fee structure, with the largest data brokers and collectors required to pay a $1.5 million annual registration fee, and the second fee tier (higher than any other state) triggered at 100,000 consumers; the Division's registry requirement takes effect 270 days after enactment, on 27 March 2027.
Category narrative71 words

New Jersey's comprehensive consumer privacy regime is the New Jersey Data Privacy Law (NJDPL), P.L.2023, c.266, enforced exclusively by the New Jersey Attorney General acting through the Division of Consumer Affairs. It sits atop a pre-existing sectoral patchwork (Identity Theft Prevention Act breach-notification statute, Daniel's Law protecting public officials' personal information, and a newly enacted 2026 data-broker registration law), producing a hybrid state-omnibus-plus-sectoral-overlay structure rather than a single unified DPA-style regulator.

Periodic update · new data 2026-09-28

Regulator & Framework

The New Jersey Attorney General enforces the New Jersey Data Privacy Act through the Division of Consumer Affairs and the Division of Law's Data Privacy and Cybersecurity Section. The most significant framework development this cycle is the enactment on 30 June 2026 of a new data broker and data collector registration law, A5328 (P.L.2026, c.25), which materially expands the regulator's registration and enforcement remit beyond the existing Data Privacy Act. The new law requires annual registration of data brokers and data collectors with the Division, with fees ranging from $5,000 to $1.5 million depending on the registering entity, and directs the Division to establish and maintain a public registry of registered data brokers and data collectors.

A Division alert indicates that registration and fee obligations under the registry will not be operationally required until spring 2027, even though the underlying statutory framework -- including the sensitive-data-sale prohibition discussed below -- took effect on 30 June 2026. This creates a period in which substantive obligations are already binding while the registry mechanism that will formalise registration has not yet launched.

The combination of the existing Data Privacy Act and the new data broker law represents a structural escalation of New Jersey's data protection framework, expanding the categories of entity subject to state oversight and the fee-based revenue base supporting the regulator's enforcement capacity.

Outlook

The registry launch, expected in spring 2027 per current secondary reporting, is the next concrete milestone. Entities within scope of A5328 should expect operational registration mechanics to take effect on that timeline even though the underlying prohibitions and duties are already in force.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedNew Jersey Division of Consumer Affairs — The Office of the Attorney General enforces the NJDPL, and consumers cannot file lawsuits on their own behalf under the law.observed
  2. ConfirmedNew Jersey Division of Consumer Affairs — The New Jersey Data Privacy Law, P.L.2023, c.266, guarantees New Jersey consumers certain rights with regard to their personal data and imposes requirements on controllers and processors, taking effect 15 January 2025.observed
  3. ConfirmedNew Jersey Division of Consumer Affairs — NJDPL applies to controllers/processors that during a calendar year either control or process the personal data of at least 100,000 consumers, or control or process the personal data of at least 25,000 consumers and make money from the sale of personal data.observed
  4. ConfirmedNew Jersey Division of Consumer Affairs — A consumer under the NJDPL is a New Jersey resident acting in an individual or household context; a New Jersey resident's data collected in an employment context is not protected under the law.observed
  5. ConfirmedIAPP — New Jersey's 2026 data broker law creates a tiered annual registration-fee structure, with the largest data brokers and collectors required to pay a $1.5 million annual registration fee, and the second fee tier (higher than any other state) triggered at 100,000 consumers; the Division's registry requirement takes effect 270 days after enactment, on 27 March 2027.observed

#

Sensitive-data consent and consumer opt-out mechanics are well evidenced; the absence of a GDPR-style Art.6 lawful-basis catalogue and of an explicit anonymisation safe-harbour is a structural gap relative to omnibus regimes.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberSensitive-data consent and consumer opt-out mechanics are well evidenced; the absence of a GDPR-style Art.6 lawful-basis catalogue and of an explicit anonymisation safe-harbour is a structural gap relative to omnibus regimes.

Sub-modules (4)

Lawful BasesAmber

NJDPL is structured around consumer opt-out rights for standard processing (sale, targeted advertising, certain profiling) rather than an enumerated lawful-basis catalogue; no equivalent to GDPR Art.6 was identified.

Claims (1):

  • Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, in lieu of a GDPR-style enumerated lawful-basis requirement for processing.

Special CategoriesGreen

Sensitive data is defined broadly to include racial/ethnic origin, religious beliefs, health condition, financial information, sexual activity/orientation, immigration/citizenship status, transgender/non-binary status, genetic or biometric data, precise geolocation, and any data collected from a known child.

Claims (1):

  • Sensitive data under the NJDPL is a subset of personal data revealing racial or ethnic origin, religious beliefs, health condition, financial information, sexual activity or orientation, immigration or citizenship status, transgender or non-binary status, genetic or biometric data, precise geolocation data, or personal data collected from a known child.

Pseudonymisation And AnonymisationAmber

The NJDPL defines de-identified data (data that cannot be linked to or used to infer information about a specific individual, where the controller takes steps to ensure non-linkability) and treats the potential use of de-identified data as a factor within data protection assessments, but no dedicated pseudonymisation/anonymisation safe-harbour provision separate from this definition was located. Searches of the DCA FAQ and DataGuidance jurisdiction notes did not surface a standalone anonymisation exemption regime.

Claims (1):

  • De-identified data is data that cannot be linked to or used to infer information about a specific individual or a device linked to that individual, and is considered de-identified only if the controller takes steps to ensure it cannot be linked to the consumer.
Category narrative70 words

NJDPL does not adopt a GDPR-style enumerated set of lawful bases; instead it relies on an opt-out model for ordinary processing (sale, targeted advertising, certain profiling) combined with an opt-in consent requirement specifically for sensitive/special-category data and for processing the data of consumers aged 13-16. Anonymisation/de-identification is recognised as a distinct, lower-risk data state relevant to the required data protection assessments, but no separate anonymisation 'safe harbour' provision was located.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

As of 30 June 2026, the sale of sensitive personal data in New Jersey is prohibited outright, with no consent-based exception available to permit it. This is a materially stricter position than a consent-gated sale regime: rather than requiring a controller to obtain consent before selling sensitive personal data, the new law removes the sale option for sensitive personal data entirely, regardless of any consent a controller might otherwise seek to obtain from the data subject.

This prohibition arrived as part of the same legislative package, A5328 (P.L.2026, c.25), that created the new data broker and data collector registration regime, enacted on the same date. The prohibition applies to the broad category of sensitive personal data as defined under the state's framework, and its consent-exception-free structure marks a clear tightening relative to the prior baseline in which sensitive-data processing, including sale, could generally proceed on a consent basis.

Outlook

Because this prohibition already took effect on 30 June 2026, entities that previously relied on consent to support the sale of sensitive personal data in New Jersey should treat that consent basis as no longer available going forward. No further change to this rule was identified this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedNew Jersey Division of Consumer Affairs — Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, in lieu of a GDPR-style enumerated lawful-basis requirement for processing.observed
  2. ConfirmedNew Jersey Division of Consumer Affairs — The controller must get the consumer's consent before processing the consumer's sensitive data, and must obtain consent before processing personal data of a consumer the controller knows or willfully disregards as being between 13 and 16 years old.observed
  3. ConfirmedNew Jersey Division of Consumer Affairs — Sensitive data under the NJDPL is a subset of personal data revealing racial or ethnic origin, religious beliefs, health condition, financial information, sexual activity or orientation, immigration or citizenship status, transgender or non-binary status, genetic or biometric data, precise geolocation data, or personal data collected from a known child.observed
  4. ConfirmedNew Jersey Division of Consumer Affairs — De-identified data is data that cannot be linked to or used to infer information about a specific individual or a device linked to that individual, and is considered de-identified only if the controller takes steps to ensure it cannot be linked to the consumer.observed

#

Rights bundle and response deadlines are directly evidenced by regulator and industry sources; itemised statutory text for rectification specifically was not independently isolated from a single named clause, warranting slightly lower confidence there.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — GreenRights bundle and response deadlines are directly evidenced by regulator and industry sources; itemised statutory text for rectification specifically was not independently isolated from a single named clause, warranting slightly lower confidence there.

Sub-modules (5)

Access RightGreen

Consumers have the right to confirm whether a controller is processing their personal data and to access it.

Claims (1):

  • The NJDPL grants consumers the right to confirm whether a controller is processing their personal data.

Rectification And ErasureAmber

Consumers have a deletion (erasure) right under specified conditions; correction/rectification is understood to form part of the standard rights bundle guaranteed by the NJDPL though the specific operative clause text was not independently isolated.

Claims (1):

  • Consumers may request data erasure (deletion) under specified conditions set out in the NJDPL.

Restriction And ObjectionGreen

Consumers may opt out of (object to) a controller's sale of personal data, use for targeted advertising, and certain profiling activities, including profiling used for loan/mortgage, employment, or insurance decisions.

Claims (1):

  • Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, such as profiling to determine loan, employment, or insurance eligibility.

Data PortabilityGreen

Consumers may obtain their personal data in a portable, machine-readable format.

Claims (1):

  • Consumers may obtain a copy of their personal data in a portable, machine-readable format under the NJDPL.

Deadlines And Response WindowsGreen

Controllers have 45 days to respond to consumer rights requests, with an optional 45-day extension.

Claims (1):

  • Organizations have 45 days to respond to a consumer rights request under the NJDPL, with an optional 45-day extension.
Category narrative54 words

The NJDPL grants New Jersey consumers rights to confirm whether a controller is processing their personal data and to access it, to correct/delete data, to obtain a portable copy, and to opt out of targeted advertising, data sales, and certain profiling. Controllers generally have 45 days to respond, extendable by a further 45 days.

Sources and claims (5)
  1. ConfirmedDataGuidance — The NJDPL grants consumers the right to confirm whether a controller is processing their personal data.observed
  2. ProbableDataGuidance — Consumers may request data erasure (deletion) under specified conditions set out in the NJDPL.observed
  3. ConfirmedNew Jersey Division of Consumer Affairs — Consumers may opt out of a controller selling their personal data or using it for targeted advertising and certain types of profiling, such as profiling to determine loan, employment, or insurance eligibility.observed
  4. ProbableDataGuidance — Consumers may obtain a copy of their personal data in a portable, machine-readable format under the NJDPL.observed
  5. ConfirmedDataGuidance — Organizations have 45 days to respond to a consumer rights request under the NJDPL, with an optional 45-day extension.observed

#

DPIA-equivalent, processor-contract, and breach-notification duties are well evidenced and binding; DPO appointment and formal ROPA requirements are not evidenced and are flagged as gaps rather than fabricated.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; New Jersey Identity Theft Prevention Act, N.J.S.A. 56:8-161 et seq.
Traffic-light rationale — AmberDPIA-equivalent, processor-contract, and breach-notification duties are well evidenced and binding; DPO appointment and formal ROPA requirements are not evidenced and are flagged as gaps rather than fabricated.

Sub-modules (7)

Accountability And DpiaGreen

Section 9 of the NJDPL requires controllers to conduct and document a data protection assessment prior to processing that presents a heightened risk of harm, including all sensitive-data processing, considering risks/benefits, consumer expectations, and potential use of de-identified data.

Claims (2):

  • Section 9 of the NJDPA requires controllers to conduct and document a data protection assessment prior to initiating any processing activity that presents a heightened risk of harm to consumers.
  • Processing presents a heightened risk of harm when there is risk of unfair treatment, illegal discrimination, or financial or physical injury, or when the controller processes sensitive data, triggering the DPA requirement.

Dpo RequirementsRed

No explicit statutory DPO-appointment threshold or independence requirement analogous to GDPR Art.37-39 was located in the NJDPL FAQ, DataGuidance jurisdiction notes, or NJDPL infographic reviewed for this run.

Ropa RequirementsRed

No explicit Records of Processing Activities obligation equivalent to GDPR Art.30 was identified in the sources reviewed; the NJDPL's transparency obligations run instead through privacy notices and data protection assessments.

Joint Controller ArrangementsGreen

Processors may only process personal data at the controller's direction, under a contract specifying processing instructions, the data to be processed, duration, and requiring return or deletion of data once processing is complete.

Claims (1):

  • A processor may only process personal data at the request and under the direction of a controller, and must enter into a contract with the controller containing processing instructions, identifying the data processed and retention duration, and requiring return or deletion of the data once processing is complete.

Security MeasuresGreen

Controllers must implement robust administrative, technical, and physical safeguards, limit collection to essential purposes (data minimisation), and enforce contractual compliance with NJDPL vendor-management standards.

Claims (1):

  • Controllers are required to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.

Breach NotificationGreen

Under the Identity Theft Prevention Act, businesses conducting business in NJ must disclose any breach of security of computerized records to affected NJ residents in the most expedient time possible without unreasonable delay, and must report the breach to the NJ State Police Division in advance of customer notification.

Claims (2):

  • Any business conducting business in New Jersey must disclose a breach of security of computerized records to any affected New Jersey resident in the most expedient time possible and without unreasonable delay.
  • A business or public entity must, in advance of disclosing a breach to affected customers, report the breach and related information to the Division of State Police in the Department of Law and Public Safety.

Retention And DisposalAmber

Processor contracts must require return or deletion of personal data once processing is complete; no separate general data-retention-limit statute beyond this processor-contract duty was located.

Claims (1):

  • Processor contracts under the NJDPL must require the processor to return or delete personal data once processing is complete.
Category narrative77 words

Controllers must complete and document a data protection assessment ('DPA') before processing that presents a heightened risk of harm (including all sensitive-data processing, and processing for targeted advertising, sale, or significant-effect profiling). Processor obligations run through a mandatory data-processing contract. Security-of-processing and breach-notification duties derive substantially from the pre-existing Identity Theft Prevention Act rather than from the NJDPL itself. No explicit DPO-appointment threshold or GDPR-style Records of Processing Activities (ROPA) obligation was located in the sources reviewed.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The New Jersey Data Privacy Act's statutory 30-day right-to-cure period for controllers sunset on 1 July 2026. Before this date, a controller found in violation of the Act was entitled to a 30-day window to remedy the violation before the Division of Consumer Affairs could pursue enforcement. That entitlement no longer exists: the Division may now proceed directly to enforcement action against a controller without first issuing a cure notice.

This is a material tightening of the accountability regime applicable to controllers operating in New Jersey. Where a controller previously had a structural opportunity to correct a compliance gap before facing enforcement exposure, that opportunity is no longer guaranteed by statute as of 1 July 2026. The change increases the practical stakes of ongoing compliance monitoring and internal audit for controllers subject to the Act, since a violation identified by the Division can now proceed straight to enforcement.

Outlook

Controllers should expect any violation identified by the Division of Consumer Affairs after 1 July 2026 to be capable of proceeding directly to enforcement, without the notice-and-cure buffer previously available. This is a durable structural change to the enforcement posture of the Act, not a one-off event, and applies to violations identified going forward.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedDataGuidance — Section 9 of the NJDPA requires controllers to conduct and document a data protection assessment prior to initiating any processing activity that presents a heightened risk of harm to consumers.observed
  2. ConfirmedNew Jersey Division of Consumer Affairs — Processing presents a heightened risk of harm when there is risk of unfair treatment, illegal discrimination, or financial or physical injury, or when the controller processes sensitive data, triggering the DPA requirement.observed
  3. ConfirmedNew Jersey Division of Consumer Affairs — A processor may only process personal data at the request and under the direction of a controller, and must enter into a contract with the controller containing processing instructions, identifying the data processed and retention duration, and requiring return or deletion of the data once processing is complete.observed
  4. ProbableDataGuidance — Controllers are required to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.observed
  5. ConfirmedNew Jersey Division of Consumer Affairs — Any business conducting business in New Jersey must disclose a breach of security of computerized records to any affected New Jersey resident in the most expedient time possible and without unreasonable delay.observed
  6. ConfirmedNew Jersey Division of Consumer Affairs — A business or public entity must, in advance of disclosing a breach to affected customers, report the breach and related information to the Division of State Police in the Department of Law and Public Safety.observed
  7. ConfirmedNew Jersey Division of Consumer Affairs — Processor contracts under the NJDPL must require the processor to return or delete personal data once processing is complete.observed

#

No transfer-mechanism, adequacy, or localisation provisions exist in the NJDPL or ancillary NJ statutes reviewed; module is populated with an explicit absence finding rather than left silently empty.

Traffic-light rationale — Not assessedNo transfer-mechanism, adequacy, or localisation provisions exist in the NJDPL or ancillary NJ statutes reviewed; module is populated with an explicit absence finding rather than left silently empty.

Sub-modules (6)

Transfer MechanismsRed

No statutory cross-border transfer mechanism (adequacy, SCCs, BCRs, derogations) exists under the NJDPL; searched DCA FAQ, DataGuidance NJ jurisdiction notes, and NJDPL infographic without finding transfer-specific provisions.

Adequacy ReceivedRed

Not applicable — New Jersey, as a US state, is not a party to adequacy findings under any foreign comprehensive privacy regime.

Adequacy GrantedRed

New Jersey has no authority to grant adequacy determinations; this sits with the federal government, and no NJ-specific mechanism was found.

Sccs And BcrsRed

No SCC or BCR framework exists under the NJDPL.

Transfer Impact AssessmentRed

No transfer impact assessment requirement was identified under the NJDPL; the statute's assessment obligation (data protection assessment) is tied to heightened-risk processing generally, not cross-border transfer specifically.

Data LocalisationRed

No data-localisation mandate (partial or absolute) was identified in the NJDPL or ancillary NJ statutes reviewed.

Category narrative50 words

The NJDPL is a domestic US state consumer-privacy statute and contains no GDPR-style cross-border transfer mechanism regime (no adequacy findings, SCCs, BCRs, or transfer-impact-assessment requirement), and no data-localisation mandate was identified. This is a legitimate structural gap consistent with the US state omnibus model rather than an omission of research.

#

Financial, health, and credit-sector carve-outs are well evidenced; education and insurance-specific overlay detail beyond the general GLBA/HIPAA/FCRA exclusions was not independently verified.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; Gramm-Leach-Bliley Act (federal, as applied in NJ); HIPAA (federal, as applied in NJ)
Traffic-light rationale — AmberFinancial, health, and credit-sector carve-outs are well evidenced; education and insurance-specific overlay detail beyond the general GLBA/HIPAA/FCRA exclusions was not independently verified.

Sub-modules (7)

Financial Sector OverlayGreen

Data collected by certain financial and insurance institutions is excluded from the NJDPL, and GLBA-mandated annual privacy notices and opt-out rights continue to apply to financial institutions operating in New Jersey, administered with DCA involvement.

Claims (2):

  • Data collected by certain financial and insurance institutions is excluded from the NJDPL.
  • Financial institutions must provide consumers an annual privacy notice regarding nonpublic personal information, and consumers may opt out of disclosure of that information at any time.

Health Sector OverlayGreen

Health information protected by HIPAA is excluded from the NJDPL, leaving HIPAA as the operative federal health-privacy instrument for covered entities in New Jersey.

Claims (1):

  • Health information protected by HIPAA is excluded from the NJDPL.

Telecoms And EprivacyAmber

No dedicated New Jersey ePrivacy/telecoms-specific cookie-consent statute distinct from the NJDPL's general opt-out and universal-opt-out-mechanism provisions was identified.

Employment DataGreen

Personal data collected from a New Jersey resident in an employment context (e.g., a job applicant) is expressly excluded from NJDPL protection.

Claims (1):

  • A New Jersey resident whose personal data is collected by a potential employer while applying for a job is not protected under the NJDPL.

Credit And ScoringGreen

Data processed under the federal Fair Credit Reporting Act is excluded from the NJDPL; separately, the Identity Theft Prevention Act gives NJ consumers the right to place a security freeze on their consumer/credit report.

Claims (2):

  • Data that can be processed under the federal Fair Credit Reporting Act is excluded from the NJDPL.
  • New Jersey consumers have the right to place a security freeze on their consumer report under the Identity Theft Prevention Act, preventing release of report information without express authorization.

EducationAmber

DataGuidance notes that New Jersey Revised Statutes and Administrative Code provisions create sector-specific obligations for education-sector data collection, but no education-specific statute name or citation was independently isolated in this run.

Claims (1):

  • Various privacy-related provisions in the New Jersey Revised Statutes and New Jersey Administrative Code create obligations for data collected by companies in the education sector, in addition to the NJDPL.

InsuranceGreen

Data collected by certain insurance institutions is excluded from the NJDPL under the same carve-out as financial institutions; GLBA-style privacy-notice obligations apply to insurance disclosures of nonpublic personal information.

Claims (1):

  • Nonpublic personal information collected by insurance companies is subject to GLBA-style annual privacy-notice and opt-out requirements administered with New Jersey Division of Consumer Affairs involvement.
Category narrative50 words

The NJDPL carves out several federally regulated sectors entirely: HIPAA-covered health information, FCRA-covered consumer-reporting data, and data collected by certain financial and insurance institutions (GLBA-aligned exclusion). Employment-context data is also excluded. Pre-existing sectoral statutes (Identity Theft Prevention Act, GLBA annual privacy-notice obligations enforced via DCA) continue to apply in parallel.

Sources and claims (8)
  1. ConfirmedNew Jersey Division of Consumer Affairs — Data collected by certain financial and insurance institutions is excluded from the NJDPL.observed
  2. ProbableNew Jersey Division of Consumer Affairs — Financial institutions must provide consumers an annual privacy notice regarding nonpublic personal information, and consumers may opt out of disclosure of that information at any time.observed
  3. ConfirmedNew Jersey Division of Consumer Affairs — Health information protected by HIPAA is excluded from the NJDPL.observed
  4. ConfirmedNew Jersey Division of Consumer Affairs — A New Jersey resident whose personal data is collected by a potential employer while applying for a job is not protected under the NJDPL.observed
  5. ConfirmedNew Jersey Division of Consumer Affairs — Data that can be processed under the federal Fair Credit Reporting Act is excluded from the NJDPL.observed
  6. ConfirmedNew Jersey Division of Consumer Affairs — New Jersey consumers have the right to place a security freeze on their consumer report under the Identity Theft Prevention Act, preventing release of report information without express authorization.observed
  7. UncertainDataGuidance — Various privacy-related provisions in the New Jersey Revised Statutes and New Jersey Administrative Code create obligations for data collected by companies in the education sector, in addition to the NJDPL.observed
  8. ProbableNew Jersey Division of Consumer Affairs — Nonpublic personal information collected by insurance companies is subject to GLBA-style annual privacy-notice and opt-out requirements administered with New Jersey Division of Consumer Affairs involvement.observed

#

Opt-out and UOOM obligations are binding and in force; dark-patterns, clean-room, and direct-marketing-specific sub-modules lack dedicated statutory findings and are flagged amber/red accordingly.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — GreenOpt-out and UOOM obligations are binding and in force; dark-patterns, clean-room, and direct-marketing-specific sub-modules lack dedicated statutory findings and are flagged amber/red accordingly.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie-consent statute exists separate from the NJDPL's general sale/targeted-advertising opt-out and UOOM mechanics; the DCA's non-binding Cyber Safe NJ guidance discusses browser cookie controls but is educational rather than a compliance obligation.

Dark PatternsAmber

No standalone dark-patterns prohibition was identified in the NJDPL text reviewed; the law's requirement that privacy notices clearly state how consumers may exercise their rights functions as an indirect anti-obfuscation measure.

Claims (1):

  • A controller's privacy notice must clearly state how consumers may exercise their rights under the NJDPL.

Opt Out SignalsGreen

By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms such as Global Privacy Control.

Claims (1):

  • By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms, such as Global Privacy Control, which allow automatic opt-out across websites, platforms, or devices.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rule was identified under the NJDPL.

Cross Context AdvertisingGreen

NJDPL's UOOM provisions uniquely extend to opt-outs for consumer profiling in furtherance of decisions producing legal or similarly significant effects, not just targeted advertising and data sales as in most peer state laws.

Claims (1):

  • Under the NJDPL, universal opt-out mechanisms must support consumer opt-outs for profiling in furtherance of decisions that produce legal or similarly significant effects, in addition to targeted advertising and sales of personal data, a scope broader than most peer state laws.

Direct MarketingAmber

Direct-marketing consent/suppression is addressed indirectly through the general targeted-advertising and sale opt-out mechanism; no standalone direct-marketing statute distinct from the NJDPL was identified.

Category narrative65 words

The NJDPL's principal adtech mechanism is a consumer opt-out right covering targeted advertising, sale of personal data, and — unusually among state laws — significant-effect profiling, reinforced by a universal-opt-out-mechanism (UOOM) requirement effective 15 July 2025 requiring controllers to honor signals such as Global Privacy Control. No dedicated dark-patterns statute, clean-room/data-collaboration-room rule, or standalone direct-marketing consent statute distinct from the general opt-out regime was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedNew Jersey Division of Consumer Affairs — A controller's privacy notice must clearly state how consumers may exercise their rights under the NJDPL.observed
  2. ConfirmedNew Jersey Division of Consumer Affairs — By 15 July 2025, controllers must honor opt-out signals sent by consumers through universal opt-out mechanisms, such as Global Privacy Control, which allow automatic opt-out across websites, platforms, or devices.observed
  3. ConfirmedIAPP — Under the NJDPL, universal opt-out mechanisms must support consumer opt-outs for profiling in furtherance of decisions that produce legal or similarly significant effects, in addition to targeted advertising and sales of personal data, a scope broader than most peer state laws.observed

#

Profiling opt-out and sensitive-data (biometric/genetic) consent duties are binding and evidenced; dedicated AI-risk-assessment and biometric-specific statutory regimes are not evidenced for New Jersey and are flagged as gaps.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberProfiling opt-out and sensitive-data (biometric/genetic) consent duties are binding and evidenced; dedicated AI-risk-assessment and biometric-specific statutory regimes are not evidenced for New Jersey and are flagged as gaps.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling in furtherance of decisions producing legal or similarly significant effects, with statutory examples including denial/provision of financial or lending services, housing, insurance, education enrollment, criminal justice, employment, health care, or essential goods and services.

Claims (1):

  • Under the NJDPL, universal opt-out mechanisms cover profiling 'in furtherance of decisions that produce legal or similarly significant effects concerning a consumer,' with examples including denial or provision of financial, lending, housing, insurance, education, criminal justice, employment, health care, or essential goods/services decisions.

Automated Decision Making TransparencyAmber

Controllers must complete a data protection assessment before engaging in significant-effect profiling, functioning as an indirect ADM-transparency mechanism, though no explicit individual right to an explanation of automated decisions was located.

Claims (1):

  • The NJDPL requires completed data protection assessments before a significant-effect profiling activity is carried out.

Ai Risk AssessmentsAmber

New Jersey has not been identified as having a dedicated AI-specific risk-assessment statute (distinct from Colorado's AI Act model); the NJDPL's general data protection assessment is the closest analogue but is not AI-specific.

Absence provenance: unavailable. Searched: njconsumeraffairs.gov FAQ, iapp.org New Jersey privacy law coverage.

Biometric RegimeAmber

Biometric data is classified as sensitive data under the NJDPL, requiring consumer consent and a data protection assessment before processing; no standalone biometric-privacy statute (of the Illinois BIPA type) was identified for New Jersey.

Claims (1):

  • Biometric data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.

Genetic DataGreen

Genetic data is classified as sensitive data under the NJDPL, requiring consumer consent and a data protection assessment before processing.

Claims (1):

  • Genetic data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.

State Surveillance CarveoutsAmber

Personal data collected by New Jersey state agencies is excluded from the NJDPL entirely; the scope and limits of this carve-out relative to law-enforcement/surveillance use were not further detailed in the sources reviewed.

Claims (1):

  • Data collected by state agencies is excluded from the NJDPL.
Category narrative74 words

The NJDPL treats genetic and biometric data as sensitive data requiring consent and a data protection assessment, and grants consumers an opt-out right over profiling that produces legal or similarly significant effects (e.g., lending, housing, insurance, employment, healthcare, criminal justice, essential goods/services decisions). There is no dedicated biometric-specific statute (unlike Illinois's BIPA) and no NJ-specific AI risk-assessment statute distinct from the general data protection assessment; state-agency data is carved out of the NJDPL entirely.

Sources and claims (5)
  1. ConfirmedIAPP — Under the NJDPL, universal opt-out mechanisms cover profiling 'in furtherance of decisions that produce legal or similarly significant effects concerning a consumer,' with examples including denial or provision of financial, lending, housing, insurance, education, criminal justice, employment, health care, or essential goods/services decisions.observed
  2. ConfirmedIAPP — The NJDPL requires completed data protection assessments before a significant-effect profiling activity is carried out.observed
  3. ConfirmedNew Jersey Division of Consumer Affairs — Biometric data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.observed
  4. ConfirmedNew Jersey Division of Consumer Affairs — Genetic data is included within the NJDPL's definition of sensitive data, requiring consumer consent before processing.observed
  5. ConfirmedNew Jersey Division of Consumer Affairs — Data collected by state agencies is excluded from the NJDPL.observed

#

Age-13-16 consent threshold and 'known child' sensitive-data treatment are binding and evidenced; age-verification mechanics, education-settings specifics, and dependent-adult protections are not evidenced and flagged as gaps.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266; federal COPPA (as applied to NJ residents under 13)
Traffic-light rationale — AmberAge-13-16 consent threshold and 'known child' sensitive-data treatment are binding and evidenced; age-verification mechanics, education-settings specifics, and dependent-adult protections are not evidenced and flagged as gaps.

Sub-modules (5)

Age VerificationAmber

No explicit statutory age-verification mechanism was identified in the NJDPL; the consent obligation is triggered by the controller's actual knowledge or willful disregard of a consumer's age rather than a mandated verification process.

Minor Profiling BansAmber

Personal data collected from a known child is treated as sensitive data requiring consent under the NJDPL; this extends the general sensitive-data consent and profiling opt-out protections to minors rather than establishing a standalone profiling ban.

Claims (1):

  • Personal data collected from a known child is included within the NJDPL's definition of sensitive data, requiring the controller to obtain consent before processing.

Education SettingsRed

New Jersey Administrative Code provisions reportedly create education-sector data obligations, but no specific education-settings statute citation was independently isolated in this run.

Absence provenance: unavailable. Searched: dataguidance.com New Jersey jurisdiction notes.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) specific data-protection provision was identified in the sources reviewed for New Jersey.

Absence provenance: unavailable. Searched: njconsumeraffairs.gov NJ Data Privacy Law FAQ, dataguidance.com New Jersey jurisdiction notes.

Category narrative78 words

Children under 13 are governed by the federal COPPA regime; New Jersey layers an additional opt-in consent requirement for processing personal data of consumers aged 13-16 when the controller knows or willfully disregards the consumer's age, and treats any personal data collected from a known child as sensitive data requiring consent. No NJ-specific statutory age-verification mandate, minor-profiling ban distinct from the general profiling opt-out, dedicated education-settings privacy statute, or dependent-adult protection provision was independently verified in this run.

Sources and claims (2)
  1. ConfirmedNew Jersey Division of Consumer Affairs — Federal law regulates the online privacy of children under age 13, and in New Jersey, when a controller knows or willfully disregards that a consumer is between 13 and 16 years old, the controller must obtain the consumer's consent before processing the consumer's personal data.observed
  2. ConfirmedNew Jersey Division of Consumer Affairs — Personal data collected from a known child is included within the NJDPL's definition of sensitive data, requiring the controller to obtain consent before processing.observed

#

Core enforcement architecture (AG-only, no PRA, penalty caps, cure period) is well evidenced and now largely operative post-July-2026; recent legislative activity (data broker law) and limited public track record of concluded NJDPL enforcement actions keep this amber rather than green.

Primary frameworkNew Jersey Data Privacy Law (NJDPL), P.L.2023, c.266
Traffic-light rationale — AmberCore enforcement architecture (AG-only, no PRA, penalty caps, cure period) is well evidenced and now largely operative post-July-2026; recent legislative activity (data broker law) and limited public track record of concluded NJDPL enforcement actions keep this amber rather than green.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require violators to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses; the new 2026 data-broker/sensitive-data-sale law adds a separate $50,000-per-record fine for prohibited sensitive-data sales.

Claims (2):

  • The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require a violator to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses.
  • New Jersey's 2026 data-broker law amends the NJDPL to prohibit the sale of sensitive data, with violations carrying a $50,000-per-record fine.

Enforcement Activity IndexAmber

New Jersey's AG has created a privacy-focused subunit and joined a bipartisan Consortium of Privacy Regulators with California, Colorado, Connecticut, Delaware, Indiana, and Oregon to collaborate on state privacy-law enforcement; no major concluded public NJDPL enforcement decision was identified as of this run, consistent with the law's recent effective date and cure-period history.

Claims (1):

  • Attorneys general in California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon, along with the California Privacy Protection Agency, have formed the bipartisan Consortium of Privacy Regulators to collaborate on enforcing their respective state privacy laws.

Regulator Funding And CapacityGreen

New Jersey is among the states that have created a privacy-focused subunit within the Attorney General's office, signaling dedicated enforcement capacity.

Claims (1):

  • New Jersey is among the states, including California, Connecticut, New Hampshire, Oregon, Texas and Virginia, that have created privacy-focused subunits within their Attorney General's office.

Collective Redress And Class ActionsAmber

The NJDPL itself provides no class-action or collective-redress mechanism for consumers, but the separate Daniel's Law (protecting public officials' personal information) has driven dozens of private lawsuits, including proposed class actions against data brokers.

Claims (1):

  • New Jersey's Daniel's Law, protecting personal information of judges, law enforcement personnel and other public officials, has driven a substantial wave of private lawsuits and constitutional challenges against data brokers and consumer-facing businesses.

Private Right Of ActionRed

Consumers cannot file lawsuits on their own behalf under the NJDPL; enforcement is exclusively vested in the Attorney General/Division of Consumer Affairs.

Claims (1):

  • Consumers cannot file lawsuits on their own behalf under the NJDPL; the Office of the Attorney General enforces the law exclusively.

Recent Developments 180DGreen

On 30 June 2026, Governor Sherrill signed A 5328 into law, making New Jersey the seventh state (and second in 2026) to enact a data-broker registration law, with the registry itself becoming operative 27 March 2027; the law also amends the NJDPL to prohibit the sale of sensitive data, carrying up to $50,000-per-record fines.

Claims (1):

  • On 30 June 2026, Governor Mikie Sherrill signed A 5328 into law, making New Jersey the seventh state to enact a data broker law and the second state to do so in 2026, following Connecticut.
Category narrative111 words

Enforcement authority rests exclusively with the New Jersey Attorney General/Division of Consumer Affairs; the NJDPL carries no private right of action. A statutory notice-and-cure period applied until 1 July 2026, after which the Division may proceed directly to enforcement for uncured violations. Maximum civil penalties are $10,000 for a first offense and $20,000 for subsequent offenses, alongside injunctive and restitutionary relief. New Jersey's AG has joined a multistate 'Consortium of Privacy Regulators' for enforcement collaboration. Separately, Daniel's Law (protecting public officials' personal information) has generated a substantial wave of private litigation against data brokers, and a costly new 2026 data-broker registration/sensitive-data-sale-prohibition law (up to $50,000-per-record fines) was enacted 30 June 2026.

Periodic update · new data 2026-09-28

Enforcement & Redress

Multiple enforcement-relevant developments converged in New Jersey this cycle. A new Attorney General was confirmed under the Sherrill administration in February 2026 and now holds enforcement authority over the state's data privacy regime. The Data Privacy Act's 30-day right-to-cure period for controllers sunset on 1 July 2026, removing the mandatory notice-and-cure step and allowing the Division of Consumer Affairs to proceed directly to enforcement. Separately, the new data broker and data collector registration law, A5328 (P.L.2026, c.25), was enacted on 30 June 2026, with a registry launch reportedly deferred to spring 2027, expanding the population of entities within the Division's enforcement remit.

On penalty structure, available reporting indicates penalties of up to $10,000 for an initial violation and $20,000 for subsequent violations, along with injunctive relief and victim compensation as available remedies; this penalty figure derives from a secondary compliance-guide source rather than a primary statutory citation and should be read with that sourcing caveat in mind. The Act does not provide a private right of action -- enforcement runs exclusively through the Attorney General, meaning individual data subjects cannot bring a direct civil claim under the statute themselves.

Outlook

With the cure period now sunset and a new data broker law in force, the Division of Consumer Affairs enters the next period with both an expanded population of regulated entities and a lower procedural bar to bringing enforcement action. The confirmation of a new Attorney General in February 2026 places a fresh appointee at the head of this expanded enforcement apparatus going forward.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedNew Jersey Division of Consumer Affairs — The Attorney General may go to court to stop NJDPL violations, seek compensation for victims, and require a violator to pay up to $10,000 for an initial offense and $20,000 for subsequent offenses.observed
  2. ConfirmedIAPP — New Jersey's 2026 data-broker law amends the NJDPL to prohibit the sale of sensitive data, with violations carrying a $50,000-per-record fine.observed
  3. ConfirmedIAPP — Attorneys general in California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon, along with the California Privacy Protection Agency, have formed the bipartisan Consortium of Privacy Regulators to collaborate on enforcing their respective state privacy laws.observed
  4. ConfirmedIAPP — New Jersey is among the states, including California, Connecticut, New Hampshire, Oregon, Texas and Virginia, that have created privacy-focused subunits within their Attorney General's office.observed
  5. ConfirmedIAPP — New Jersey's Daniel's Law, protecting personal information of judges, law enforcement personnel and other public officials, has driven a substantial wave of private lawsuits and constitutional challenges against data brokers and consumer-facing businesses.observed
  6. ConfirmedNew Jersey Division of Consumer Affairs — Consumers cannot file lawsuits on their own behalf under the NJDPL; the Office of the Attorney General enforces the law exclusively.observed
  7. ConfirmedIAPP — On 30 June 2026, Governor Mikie Sherrill signed A 5328 into law, making New Jersey the seventh state to enact a data broker law and the second state to do so in 2026, following Connecticut.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct28.57
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for New Jersey, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 23 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress are all populated with a mix of T1 (njconsumeraffairs.gov FAQ, homepage, Identity Theft Prevention Act statute PDF, GLBA consumer brief) and T2/T3 (IAPP, DataGuidance) sourcing. cross_border_and_adequacy carries zero claims with an explicit absent_field_provenance narrative, reflecting the genuine absence of a transfer/adequacy regime in the NJDPL rather than a research gap. Sub-modules for DPO appointment, ROPA, AI-specific risk assessment, biometric-specific statute, education-settings-specific statute, and dependent-adult protections likewise carry explicit absent_field_provenance rather than fabricated obligations, as these were not located in T1/T2/T3 sources reviewed for New Jersey.

Unresolved questions (5):

  • Has the NJ Division of Consumer Affairs finalized implementing regulations under NJDPL Section 9 (data protection assessments) since the 'forthcoming in 2025' status noted in the DCA FAQ, and if so, what is the citation?
  • Does the NJDPL contain an explicit statutory right to rectification/correction with independently citable clause text, or is correction handled solely via deletion-and-recollection in practice?
  • Has the NJ AG brought any concluded public enforcement action specifically under the NJDPL (as distinct from Daniel's Law litigation) since the cure period lapsed on 1 July 2026?
  • What NJ Administrative Code provisions specifically govern education-sector and dependent-adult data protection, referenced only generically in DataGuidance jurisdiction notes?
  • Is there an NJ-specific biometric privacy statute analogous to Illinois BIPA beyond the NJDPL's sensitive-data consent treatment of biometric data?

Escalate to primary-source review: yes