Back to the hub

Does the New Jersey Data Privacy Act apply to your business?

New Jersey's Data Privacy Act applies to businesses that operate in New Jersey or target its residents and, in a calendar year, control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving any revenue, or a discount, from selling personal data. It took effect January 15, 2025.

Applies to: Controllers that conduct business in New Jersey or target New Jersey residents and meet either the 100,000-consumer threshold or the 25,000-consumer-plus-any-data-sale threshold.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

New Jersey's privacy law took effect on January 15, 2025, and its applicability test hides a trap in the second trigger. The headline number, 100,000 consumers, looks like every other state. The second prong does not. Where Virginia and Connecticut ask whether data sales make up half your revenue, New Jersey asks only whether you make any money, or take any discount, from selling data.

Who the New Jersey Data Privacy Act covers

Under N.J.S.A. 56:8-166.5, the act applies to controllers that conduct business in New Jersey, or produce products or services targeted to New Jersey residents, and that during a calendar year either control or process the personal data of at least 100,000 consumers, excluding data processed solely to complete a payment transaction, or control or process the personal data of at least 25,000 consumers while deriving revenue, or receiving a discount on the price of any goods or services, from the sale of personal data. A consumer is a New Jersey resident acting in an individual or household context, so employees and business contacts do not count.

The 25,000 prong is broader than most states

This is the number to read carefully. In Virginia, Connecticut, and Iowa, the lower 25,000 trigger only fires when data sales exceed a set share of revenue. New Jersey drops the percentage entirely. If you handle the data of 25,000 New Jersey residents and you derive any revenue, or even accept a discount, from selling personal data, you are in scope. A business that sits comfortably outside Virginia can land inside New Jersey on this prong. The Connecticut Data Privacy Act and the Delaware Personal Data Privacy Act also reach further than the early state laws, which is why the applicability question is worth checking state by state.

No blanket nonprofit exemption

New Jersey is one of the states that does not hand nonprofits or universities an automatic pass. There is no entity-level exemption for nonprofit organizations or institutions of higher education in the act. Instead, N.J.S.A. 56:8-166.13 exempts specific data and institutions: HIPAA protected health information, GLBA financial institutions and their data, insurance institutions, consumer reporting activity under the Fair Credit Reporting Act, state agencies and political subdivisions, and certain research. A nonprofit that processes ordinary customer or supporter data can therefore be covered. The US state privacy laws hub shows which states share that stance.

Next step

Because New Jersey's second trigger fires on any data-sale revenue, a business that assumed it was too small can still be covered. The free 2-minute Obligation Scan runs the 56:8-166.5 thresholds against your business and flags the notice, opt-out, universal opt-out, and consent duties that follow, so you can act on the statute rather than a guess.

Compliance checklist

  • Count the New Jersey consumers whose personal data you controlled or processed over the calendar year, excluding data used only to complete a payment transaction, against the 100,000 figure.
  • If you are near 25,000, check whether you derive any revenue, or receive any discount, from selling personal data, since any amount then triggers coverage.
  • Do not assume a nonprofit or university exemption; confirm whether a data-specific or institutional exemption in N.J.S.A. 56:8-166.13 actually applies to you.
  • If covered, publish a privacy notice and honor rights to access, correct, delete, port, and opt out of sale, targeted advertising, and profiling.
  • Support a universal opt-out mechanism and get consent before processing sensitive data.

Sources

Last verified: 2026-07-23

Informational, not legal advice.