New Jersey Privacy Law (NJDPA): Compliance Guide
The New Jersey Data Privacy Act (SB 332), effective January 15, 2025, widened the net in a subtle but important way: its 25,000-consumer trigger counts businesses that derive “revenue or discounted services” from selling personal data, pulling loyalty-program economics squarely into scope. GPC has been mandatory since July 15, 2025, teens aged 13 to 16 get Montana-style opt-in protection, and violations carry up to $10,000 each.
- Effective
- January 15, 2025
- GPC / universal opt-out
- Required since July 15, 2025
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · New Jersey Data Privacy Act (SB 332)
Applicability
Who must comply with the NJDPA
The New Jersey Data Privacy Act applies to businesses that meet the following criteria:
- Controls or processes the personal data of 100,000 or more New Jersey consumers, or
- Controls or processes the personal data of 25,000 or more New Jersey consumers and derives revenue or discounted services from the sale of personal data
Consumer rights
What New Jersey consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of the sale of personal data, targeted advertising, and profiling
Opt-out mechanics
New Jersey opt-out & GPC requirements
Like every US state privacy law, the NJDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for New Jersey is “Your Privacy Choices”.
Global Privacy Control: Required since July 15, 2025
New Jersey requires covered businesses to honor universal opt-out mechanisms such as Global Privacy Control. The requirement took effect July 15, 2025 — six months after the law itself.
Enforcement
NJDPA penalties & enforcement
- Up to $10,000 per violation
Cure period: Our reference lists no specific cure period for New Jersey; violations carry up to $10,000 each.
State quirks
What makes New Jersey different
New Jersey's “discounted services” language is its signature: a business that trades discounts or perks for personal data can be covered even if it never sells data for cash — a direct challenge to loyalty-program business models. It also joined Montana in requiring opt-in consent for the sale or targeted advertising use of 13-to-16-year-olds' data. The GPC obligation was phased in on July 15, 2025, exactly six months after the law took effect.
“Revenue or discounted services” trigger
The 25,000-consumer prong counts businesses that derive revenue or discounted services from data sales — pulling loyalty-program and discount-for-data economics into scope, not just cash sales.
Minors 13–16 require opt-in
For consumers aged 13 to 16, selling personal data or using it for targeted advertising requires opt-in consent.
Automation
How ConsentKit handles New Jersey
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so New Jersey visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- New Jersey visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Because New Jersey requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for New Jersey visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a New Jersey visitor makes a choice.
ConsentKit's GPC honoring covers New Jersey's July 15, 2025 milestone automatically, and every opt-out lands in your dashboard consent log with full jurisdiction metadata.
FAQ
New Jersey NJDPA FAQ
What does “revenue or discounted services” mean in the NJDPA?
New Jersey's 25,000-consumer trigger covers businesses that derive revenue or discounted services from selling personal data. That phrasing pulls loyalty programs and discount-for-data arrangements into scope — not just businesses that sell data for cash.
Does the NJDPA apply to my business?
It applies if you control or process the personal data of 100,000 or more New Jersey consumers, or 25,000 or more while deriving revenue or discounted services from selling personal data.
Is Global Privacy Control required in New Jersey?
Yes, since July 15, 2025 — six months after the law itself took effect. Covered businesses must honor universal opt-out mechanisms for New Jersey visitors.
How does New Jersey treat teens' data?
Like Montana: for consumers aged 13 to 16, selling personal data or using it for targeted advertising requires opt-in consent rather than a simple opt-out option. Violations of the NJDPA carry up to $10,000 each.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the NJDPA.
Comply with New Jersey's NJDPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.