Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Age-appropriate design code
Requires a controller that has actual knowledge, or willfully disregards, that a consumer is at least 13 but younger than 17 years of age to obtain the consumer's own opt in consent before processing personal data for targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects, and treats personal data collected from a known child under 13 as sensitive data that must be processed in accordance with COPPA.
Note and primary source →
Breach notification
cite N.J. Stat. § 56:8-163
stage IN FORCE in force since 2006-01-01
source official New Jersey session law text, P.L. 2005, c. 226, New Jersey Legislature
The New Jersey Identity Theft Prevention Act, a separate and older statute enacted as P.L. 2005, c. 226, took effect January 1, 2006, the first January 1 following its September 22, 2005 approval, per the act's own uncodified effective-date section (the breach-notification duty is not among the sections the act separately made effective immediately).
A business conducting business in New Jersey that compiles or maintains computerized records including personal information must disclose a breach of security to an affected New Jersey resident in the most expedient time possible and without unreasonable delay, with no fixed numeric-day deadline. A distinctive New Jersey feature requires reporting the breach to the Division of State Police in advance of notifying the customer.
What it asks of an app →
Comprehensive regime
NJDPA governs private-sector processing of New Jersey residents' personal data, enacted as P.L. 2023, c. 266 (S332), signed January 16, 2024. Its own uncodified section 17 sets the effective date at the 365th day following enactment, January 15, 2025.
A controller must limit collection of personal data to what is adequate, relevant, and reasonably necessary, the ordinary multi-state "reasonably necessary" standard rather than Maryland's stricter "strictly necessary" gate, and enforcement runs through the general Consumer Fraud Act framework.
What it asks of an app →
Data subject rights
New Jersey consumers may confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling, with an appeal right for denials. A controller must act within 45 days of receipt, extendable once by 45 additional days, and must communicate a denial within 45 days with appeal instructions.
Beginning around July 15, 2025 (six months after the general effective date), a controller processing personal data for targeted advertising or sale must allow consumers to exercise the opt-out right through a user-selected universal opt-out mechanism, a staged duty confirmed directly from the Act's own text as distinct from the general effective date.
What it asks of an app →
Enforcement supervision
A violation of NJDPA is an unlawful practice and violation of the Consumer Fraud Act, N.J. Stat. § 56:8-1 et seq., enforced exclusively by the Division of Consumer Affairs and the Attorney General. Until the 18th month after the effective date (around July 15, 2026, now past as of this brief's as_of_date), the Division was required to issue a notice of alleged noncompliance and a 30-day cure opportunity before bringing an action if a cure was deemed possible; that window has closed.
The Act expressly forecloses a private right of action under NJDPA itself or under any other law, including the Consumer Fraud Act's own separate private-action mechanism.
What it asks of an app →
Sensitive categories
NJDPA's sensitive-data list is broader on two axes than most peer states: it names financial information (account number, login, or card number combined with a security code, access code, or password) as its own standalone sensitive category, and it names pregnancy explicitly within the health-condition prong, alongside racial or ethnic origin, religious beliefs, sex life or sexual orientation, citizenship or immigration status, transgender or nonbinary status, genetic or biometric data processed to uniquely identify an individual, a known child's data, and precise geolocation.
"Biometric data" is defined to include fingerprint, voiceprint, retina or iris scan, and facial mapping, facial geometry, or facial templates specifically, the most explicit facial-recognition enumeration in this wave, excluding a bare photograph, video, or audio recording but clawing that exclusion back the moment data generated from one is used to identify a specific individual.
Sensitive data may be processed only with the consumer's opt-in consent; New Jersey does not ban its sale outright the way Maryland does.
What it asks of an app →