Law note · New Jersey

New Jersey Identity Theft Prevention Act, breach notification

cite N.J. Stat. ยง 56:8-163 stage IN FORCE in force since 2006-01-01 reviewed 2026-08-27

The New Jersey Identity Theft Prevention Act, a separate and older statute enacted as P.L. 2005, c. 226, took effect January 1, 2006, the first January 1 following its September 22, 2005 approval, per the act's own uncodified effective-date section (the breach-notification duty is not among the sections the act separately made effective immediately).

A business conducting business in New Jersey that compiles or maintains computerized records including personal information must disclose a breach of security to an affected New Jersey resident in the most expedient time possible and without unreasonable delay, with no fixed numeric-day deadline. A distinctive New Jersey feature requires reporting the breach to the Division of State Police in advance of notifying the customer.

What it asks of an app

  • Report a breach of security involving computerized personal records to the New Jersey Division of State Police before notifying the affected customer.
  • Disclose the breach to each affected New Jersey resident in the most expedient time possible and without unreasonable delay. New Jersey sets no fixed numeric-day cap.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official New Jersey session law text, P.L. 2005, c. 226, New Jersey Legislature

← Back to the example  ·  Lint your app →