Effective January 15, 2025

New Jersey Data Privacy Act (NJDPA)

A practical compliance guide for website owners. Learn what New Jersey's privacy law requires and how to implement it on your site.

Who Must Comply

Conducts business in New Jersey or targets New Jersey residents AND controls/processes personal data of 100K+ consumers, OR controls/processes data of 25K+ consumers and derives revenue from selling personal data

Consent model: Opt-outGPC RequiredSensitive data: Opt-in required

What Your Website Must Do

RequirementStatus
Cookie consent bannerRecommended
Do Not Sell linkRequired
Do Not Share linkRequired
Honor GPC browser signalsRequired
Universal opt-out mechanismRequired
Sensitive data opt-in consentRequired

Checked against the NJDPA on August 29, 2026. Read the source This is a summary, not legal advice.

Required Links & Notices

The NJDPA requires the following links or notices to be visible on your website:

  • 1Do Not Sell or Share My Personal Data
  • 2Privacy Policy

Enforcement & Penalties

Enforcement Body
New Jersey Attorney General + Division of Consumer Affairs
Maximum Penalty
Up to $10,000 for a first violation, $20,000 for subsequent ones. Separately, A5328 (30 Jun 2026) bans the sale of sensitive personal data outright — no consent exception, any entity, $50,000 per record.

Key Things to Know

The New Jersey Data Privacy Act (NJDPA) has applied in New Jersey since January 15, 2025.

Who it covers: Conducts business in New Jersey or targets New Jersey residents AND controls/processes personal data of 100K+ consumers, OR controls/processes data of 25K+ consumers and derives revenue from selling personal data.

Do Not Sell and opt-out rights: residents may opt out of the sale of their personal data and opt out of targeted advertising. NJDPA expects the choice to be reachable from your site under the heading “Do Not Sell or Share My Personal Data”, and you may not degrade the service of someone who exercises it.

Global Privacy Control: NJDPA requires you to honour a universal opt-out mechanism sent by the visitor’s browser. A GPC signal has to be treated as the opt-out itself — not as a request to show someone a banner — and it applies to that browser without any further action from the person.

Cookie banner: NJDPA is an opt-out law, so it does not require the opt-in banner the GDPR does. What it does require is that the tracking you run for advertising can be switched off on request, which in practice means a preference control that actually blocks tags rather than a notice that only records a click. Sensitive data is the exception: that needs consent before you process it.

Recently amended. NJDPA changed on June 30, 2026. The summary above reflects the amended law.

Enforcement: Up to $10,000 for a first violation, $20,000 for subsequent ones. Separately, A5328 (30 Jun 2026) bans the sale of sensitive personal data outright — no consent exception, any entity, $50,000 per record. Enforced by the New Jersey Attorney General + Division of Consumer Affairs.

How to Configure LegalBanner for NJDPA

  1. 1

    Create your site

    Sign up for free and add your website domain in the dashboard.

  2. 2

    Set consent mode to "Opt-out"

    In Settings, select the consent mode that matches New Jersey's requirements.

  3. 3

    Install the snippet

    Add the one-line script tag to your website. The banner, opt-out links, and GPC support are automatic.

  4. 4

    Generate your Privacy Policy

    Use the built-in policy wizard to generate a NJDPA-compliant privacy policy.

Set up NJDPA compliance in 5 minutes

LegalBanner handles New Jersey privacy requirements automatically — cookie banner, opt-out links, and GPC support included.

Frequently Asked Questions

When did the New Jersey Data Privacy Act take effect?

The NJDPA took effect January 15, 2025. It is one of the newest comprehensive state privacy laws.

Does New Jersey require a cookie consent banner?

The NJDPA does not require opt-in cookie consent. However, you must provide clear opt-out mechanisms for targeted advertising, sale, and sharing of personal data.

What makes the NJDPA different from other state privacy laws?

New Jersey has escalating penalties ($10,000 first violation, $20,000 for subsequent) and specifically mentions 'sharing' of personal data in addition to selling. The cure period sunsets 18 months after the effective date.

Does New Jersey require honoring GPC signals?

The NJDPA does not explicitly require honoring GPC signals. However, providing universal opt-out mechanisms is recommended.

Does the NJDPA apply to nonprofits?

No. The NJDPA exempts nonprofits, as well as entities covered by HIPAA, Gramm-Leach-Bliley Act, and several other federal laws.

Disclaimer: This page provides practical implementation guidance only. It does not constitute legal advice. The information is current as of the most recent review date but privacy laws change frequently. Consult a qualified attorney for legal advice specific to your situation. LegalBanner provides compliance tools, not legal counsel.