State Breach Law
New Jersey Data Breach Notification Law
N.J.S.A. § 56:8-161 et seq. • Effective 2006-01-01
New Jersey has a 30-day hard deadline for breach notification. If you have a breach affecting New Jersey residents, you must notify them within 30 days of confirming the breach occurred. The law covers a broad range of personal information.
Notification deadline: Most expedient time possible, no later than 30 days
Enforcement: New Jersey Attorney General, Division of Consumer Affairs
Overview
New Jersey requires businesses to notify affected residents "in the most expedient time possible" but no later than 30 days after confirming a breach. Recent amendments expanded the scope to include username/password combinations.
Who Must Be Notified
- • Affected New Jersey residents (within 30 days)
- • New Jersey Division of State Police
- • Consumer reporting agencies (if 1,000+ residents affected)
Covered Data Types
Social Security number, Driver's license number, State ID number, Financial account number with access code, Credit/debit card number, Username with password or security questions, Dissociated data if linked together
Notification Requirements
- • Written, electronic, or telephonic notice within 30 days
- • Must notify NJ Division of State Police before notifying residents
- • Description of breach and types of information involved
- • Contact information for business and credit bureaus
- • Notify consumer reporting agencies if 1,000+ residents affected
Is your business exposed?
Exemptions
- • Encrypted data (if key not compromised)
- • Entities in compliance with GLBA, HIPAA
- • Good faith acquisition by employee
Penalties
Civil penalties up to $10,000 for first violation, $20,000 for subsequent violations. AG can seek injunctions and additional penalties.
If You Experience a Breach
- 1.
Be prepared to meet 30-day notification deadline
- 2.
Know procedure to notify NJ State Police first
- 3.
Create notification templates
- 4.
Know how to contact NJ Division of Consumer Affairs
- 5.
Implement reasonable security measures
- 6.
Train employees on breach detection and 30-day deadline
Official Source
https://www.njconsumeraffairs.gov/Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required