Law / New Jersey

New Jersey

age

New Jersey has not enacted an adult content age verification law, a social media minor access law, or an app store age verification law.

Bills requiring age verification for sexually explicit websites (S1826, introduced January 2026, successor to S4455 which died in January 2026) and requiring parental consent and age verification before a minor can hold a social media account (S3993, introduced March 2026) remain in Senate committee without passing either chamber, as does an app store age verification bill (S4669) that died in January 2026.

New Jersey's one enacted age gating instrument is the New Jersey Data Protection Act (S332, 2023), in effect since January 15, 2025, which requires opt in consent before processing the data of a known minor at least 13 and younger than 17 for targeted advertising, sale, or significant profiling.

privacy

New Jersey's comprehensive private-sector privacy law is the New Jersey Data Privacy Act (NJDPA), N.J. Stat. §§ 56:8-166.4 to 56:8-166.19, enacted as P.L. 2023, c. 266 (S332) and effective January 15, 2025.

NJDPA claws back a recording-derived biometric identifier the moment it is generated to identify a specific individual, and its sensitive-data list is notably broader than most peer states, naming financial account information and pregnancy as their own enumerated categories and enumerating facial mapping, facial geometry, and facial templates specifically within the biometric-data definition.

A universal opt-out mechanism became operative around July 15, 2025, and the Division of Consumer Affairs' notice-and-cure opportunity has already closed (around July 15, 2026). Breach notification is a separate, older statute, the New Jersey Identity Theft Prevention Act, N.J. Stat. § 56:8-163, which requires reporting to the Division of State Police in advance of notifying the customer.

Enforcement of NJDPA runs exclusively through the Attorney General under the Consumer Fraud Act, with no private right of action.

15 instruments named 6 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Age-appropriate design code

S332, New Jersey Data Protection Act

cite N.J. Stat. Ann. section 56:8-166.4 et seq. (P.L. 2023, c. 266) stage IN FORCE in force since 2025-01-15 source official New Jersey Legislature final bill text (Sixth Reprint, enacted as P.L. 2023, c. 266)

Requires a controller that has actual knowledge, or willfully disregards, that a consumer is at least 13 but younger than 17 years of age to obtain the consumer's own opt in consent before processing personal data for targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects, and treats personal data collected from a known child under 13 as sensitive data that must be processed in accordance with COPPA.

Note and primary source

Breach notification

New Jersey Identity Theft Prevention Act, breach notification

cite N.J. Stat. § 56:8-163 stage IN FORCE in force since 2006-01-01 source official New Jersey session law text, P.L. 2005, c. 226, New Jersey Legislature

The New Jersey Identity Theft Prevention Act, a separate and older statute enacted as P.L. 2005, c. 226, took effect January 1, 2006, the first January 1 following its September 22, 2005 approval, per the act's own uncodified effective-date section (the breach-notification duty is not among the sections the act separately made effective immediately).

A business conducting business in New Jersey that compiles or maintains computerized records including personal information must disclose a breach of security to an affected New Jersey resident in the most expedient time possible and without unreasonable delay, with no fixed numeric-day deadline. A distinctive New Jersey feature requires reporting the breach to the Division of State Police in advance of notifying the customer.

What it asks of an app

Comprehensive regime

New Jersey Data Privacy Act (NJDPA), general applicability and scope

cite N.J. Stat. §§ 56:8-166.4 to 56:8-166.19 stage IN FORCE in force since 2025-01-15 source official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

NJDPA governs private-sector processing of New Jersey residents' personal data, enacted as P.L. 2023, c. 266 (S332), signed January 16, 2024. Its own uncodified section 17 sets the effective date at the 365th day following enactment, January 15, 2025.

A controller must limit collection of personal data to what is adequate, relevant, and reasonably necessary, the ordinary multi-state "reasonably necessary" standard rather than Maryland's stricter "strictly necessary" gate, and enforcement runs through the general Consumer Fraud Act framework.

What it asks of an app

Data subject rights

New Jersey Data Privacy Act, consumer rights and universal opt-out

cite N.J. Stat. §§ 56:8-166.4 to 56:8-166.19 stage IN FORCE in force since 2025-01-15 source official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

New Jersey consumers may confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling, with an appeal right for denials. A controller must act within 45 days of receipt, extendable once by 45 additional days, and must communicate a denial within 45 days with appeal instructions.

Beginning around July 15, 2025 (six months after the general effective date), a controller processing personal data for targeted advertising or sale must allow consumers to exercise the opt-out right through a user-selected universal opt-out mechanism, a staged duty confirmed directly from the Act's own text as distinct from the general effective date.

What it asks of an app

Enforcement supervision

New Jersey Data Privacy Act, Division of Consumer Affairs enforcement

cite N.J. Stat. §§ 56:8-166.4 to 56:8-166.19 stage IN FORCE in force since 2025-01-15 source official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

A violation of NJDPA is an unlawful practice and violation of the Consumer Fraud Act, N.J. Stat. § 56:8-1 et seq., enforced exclusively by the Division of Consumer Affairs and the Attorney General. Until the 18th month after the effective date (around July 15, 2026, now past as of this brief's as_of_date), the Division was required to issue a notice of alleged noncompliance and a 30-day cure opportunity before bringing an action if a cure was deemed possible; that window has closed.

The Act expressly forecloses a private right of action under NJDPA itself or under any other law, including the Consumer Fraud Act's own separate private-action mechanism.

What it asks of an app

Sensitive categories

New Jersey Data Privacy Act, sensitive data and biometric definition

cite N.J. Stat. §§ 56:8-166.4 to 56:8-166.19 stage IN FORCE in force since 2025-01-15 source official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

NJDPA's sensitive-data list is broader on two axes than most peer states: it names financial information (account number, login, or card number combined with a security code, access code, or password) as its own standalone sensitive category, and it names pregnancy explicitly within the health-condition prong, alongside racial or ethnic origin, religious beliefs, sex life or sexual orientation, citizenship or immigration status, transgender or nonbinary status, genetic or biometric data processed to uniquely identify an individual, a known child's data, and precise geolocation.

"Biometric data" is defined to include fingerprint, voiceprint, retina or iris scan, and facial mapping, facial geometry, or facial templates specifically, the most explicit facial-recognition enumeration in this wave, excluding a bare photograph, video, or audio recording but clawing that exclusion back the moment data generated from one is used to identify a specific individual.

Sensitive data may be processed only with the consumer's opt-in consent; New Jersey does not ban its sale outright the way Maryland does.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.