Privacy
New Jersey Data Privacy Act (NJDPA)
The NJDPA applies to controllers that conduct business in New Jersey or target products or services to New Jersey residents and that, during a calendar year, control or process the personal data of at least 100,000 consumers, excluding data processed only to complete a payment transaction, or control or process the personal data of at least 25,000 consumers and derive revenue or receive a discount from selling personal data. There is no minimum revenue share for the second threshold.
What the website needs
- A controller must provide a reasonably accessible, clear and meaningful privacy notice listing the categories of personal data processed, the purposes, the categories of all third parties to which data may be disclosed, the categories of data shared with third parties, how to exercise rights and appeal with the controller's contact information, how the controller notifies consumers of material changes along with the notice's effective date, and an active email address or other online contact method (N.J.S.A. 56:8-166.6(a)).
- A controller that sells personal data or processes it for targeted advertising or significant profiling must clearly and conspicuously disclose that processing and how to opt out (N.J.S.A. 56:8-166.6(b)).
- A controller may not process sensitive data without the consumer's consent, and sensitive data includes precise geolocation, financial account credentials, and status as transgender or non-binary (N.J.S.A. 56:8-166.4, 56:8-166.12).
- A controller may not require a consumer to create a new account to exercise a right, though it may require use of an existing account (N.J.S.A. 56:8-166.6(c)).


