What counts as sensitive data under New Jersey's privacy law?
New Jersey defines sensitive data more broadly than most states, including financial account information and status as transgender or non-binary alongside health, religion, race, immigration status, and precise geolocation. Controllers must obtain consent before processing it, and must honor a revocation within 15 days of the request.
Applies to: Controllers subject to New Jersey's data privacy law that collect or process sensitive data about New Jersey residents, and any business relying on a consent-based lawful basis there.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanNew Jersey copied much of the Virginia model and then widened the sensitive data definition in two ways that reach ordinary business data.
The definition
Under C.56:8-166.4, sensitive data means personal data revealing racial or ethnic origin; religious beliefs; mental or physical health condition, treatment, or diagnosis; financial information, which shall include a consumer's account number, account log-in, financial account, or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a consumer's financial account; sex life or sexual orientation; citizenship or immigration status; status as transgender or non-binary; genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data.
Two entries there are unusual. Financial information brings payment credentials into the sensitive category, which most state definitions do not. And status as transgender or non-binary is called out separately from sex life and sexual orientation.
Precise geolocation carries the familiar 1,750-foot radius, and excludes the content of communications and data from advanced utility metering infrastructure.
Consent, not opt-out
Section 56:8-166.12(a)(4) provides that a controller shall not process sensitive data concerning a consumer without first obtaining the consumer's consent, or, for a known child, without processing in accordance with COPPA.
That is a gate, not a preference. And New Jersey's definition of consent rules out the shortcuts: it excludes acceptance of a general or broad terms of use document that mixes data processing descriptions with unrelated information, hovering over, muting, pausing, or closing a piece of content, and agreement obtained through dark patterns.
The 15-day revocation clock
This is the provision most likely to break an existing consent stack. Section 56:8-166.12(a)(6) requires a controller to provide an effective mechanism for a consumer to revoke consent that is at least as easy as the mechanism by which the consumer provided it and, upon revocation, to cease processing the data as soon as practicable but not later than 15 days after receipt of the request.
Fifteen days is the tightest revocation deadline in the state laws verified across this site. It also sits alongside the 45-day general response deadline in section 56:8-166.7, so a single queue running on 45 days will miss it. Revocations need their own path.
The parity requirement matters as much as the number. A one-click consent banner paired with an email-us-to-withdraw process fails the "at least as easy" test regardless of how fast you then act.
Teenagers get a consent gate too
Section 56:8-166.12(a)(7) prohibits processing personal data for targeted advertising, sale, or profiling in furtherance of significant-effect decisions without consent where the controller has actual knowledge, or willfully disregards, that the consumer is at least 13 and younger than 17.
"Willfully disregards" is doing real work in that sentence. Choosing not to ask about age is not a defense.
Sensitive data triggers an assessment
Under section 56:8-166.12(a)(9) a controller must not conduct processing that presents a heightened risk of harm without conducting and documenting a data protection assessment. Subsection (c) defines heightened risk to include targeted advertising, certain profiling, selling personal data, and processing sensitive data.
So in New Jersey, deciding to process sensitive data is also a decision to produce an assessment. The Division of Consumer Affairs may request it, and while assessments are confidential and exempt from public inspection, disclosure to the division does not waive attorney-client privilege or work-product protection.
Enforcement
Section 56:8-166.19 gives the Office of the Attorney General sole and exclusive authority to enforce, and states that nothing in the act provides the basis for a private right of action. A violation is an unlawful practice under the Consumer Fraud Act.
There is a cure period, but a temporary one. Under section 56:8-166.17(b), until the first day of the 18th month following the effective date, the Division of Consumer Affairs must issue a notice before bringing an enforcement action where a cure is deemed possible, and may proceed if the controller fails to cure within 30 days.
Next step
Sensitive data definitions diverge more between states than almost any other provision, so a single global classification usually under-covers somewhere. The free 2-minute Obligation Scan checks which US state privacy laws apply to your business and what each requires. See the New Jersey Data Privacy Act overview for the applicability thresholds, and Texas sensitive data consent for a narrower comparison.
Compliance checklist
- Re-run your sensitive data inventory against New Jersey's list, since financial account credentials and transgender or non-binary status are in scope here even if your existing classification omits them.
- Obtain consent before processing sensitive data; New Jersey uses a consent gate rather than an opt-out, and consent excludes broad terms of use, hovering or pausing, and anything obtained through dark patterns.
- Build a revocation mechanism at least as easy as the mechanism used to collect consent, and stop processing within 15 days of a revocation request.
- Treat data from a known child under COPPA rather than under the general consent rule.
- Get consent before targeted advertising, sale, or significant-effect profiling where you know, or willfully disregard, that the consumer is at least 13 and under 17.
- Run a documented data protection assessment before any processing that presents a heightened risk, which expressly includes processing sensitive data and selling personal data.
Sources
Last verified: 2026-08-23
Informational, not legal advice.