State Breach Law

New Jersey Data Breach Notification Law

N.J.S.A. § 56:8-161 et seq. • Effective 2006-01-01

New Jersey has a 30-day hard deadline for breach notification. If you have a breach affecting New Jersey residents, you must notify them within 30 days of confirming the breach occurred. The law covers a broad range of personal information.

Notification deadline: Most expedient time possible, no later than 30 days

Enforcement: New Jersey Attorney General, Division of Consumer Affairs

Overview

New Jersey requires businesses to notify affected residents "in the most expedient time possible" but no later than 30 days after confirming a breach. Recent amendments expanded the scope to include username/password combinations.

Who Must Be Notified

  • Affected New Jersey residents (within 30 days)
  • New Jersey Division of State Police
  • Consumer reporting agencies (if 1,000+ residents affected)

Covered Data Types

Social Security number, Driver's license number, State ID number, Financial account number with access code, Credit/debit card number, Username with password or security questions, Dissociated data if linked together

Notification Requirements

  • Written, electronic, or telephonic notice within 30 days
  • Must notify NJ Division of State Police before notifying residents
  • Description of breach and types of information involved
  • Contact information for business and credit bureaus
  • Notify consumer reporting agencies if 1,000+ residents affected

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Entities in compliance with GLBA, HIPAA
  • Good faith acquisition by employee

Penalties

Civil penalties up to $10,000 for first violation, $20,000 for subsequent violations. AG can seek injunctions and additional penalties.

If You Experience a Breach

  1. 1.

    Be prepared to meet 30-day notification deadline

  2. 2.

    Know procedure to notify NJ State Police first

  3. 3.

    Create notification templates

  4. 4.

    Know how to contact NJ Division of Consumer Affairs

    NJ Consumer Affairs

  5. 5.

    Implement reasonable security measures

  6. 6.

    Train employees on breach detection and 30-day deadline

Official Source

https://www.njconsumeraffairs.gov/

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required