New Jersey Joins the State Privacy Law Patchwork

New Jersey's Consumer Data Privacy Law, formally cited as PL 2023, c. 266 (NJDPL), places the state among a growing number of jurisdictions giving residents formal control over their personal data. According to legal analysis from Stauss PLLC, the statute generally mirrors the structure of Virginia's privacy law, one of the earliest and most widely copied templates in the country. But the same analysis notes something worth paying attention to: entire paragraphs and provisions found in laws like Connecticut's are missing from New Jersey's version.

That distinction matters. As more states pass their own consumer data privacy law, the details of who is covered, what rights exist, and how strictly those rights are enforced vary significantly from state to state. New Jersey's approach shows how even laws built on the same basic framework can diverge in important ways once they're finalized. States continue to join this patchwork at a steady pace. Louisiana recently became the 22nd state to enact comprehensive privacy legislation, underscoring how quickly this area of law is expanding and how uneven compliance obligations have become for businesses operating across multiple states.

Who Must Comply: Thresholds That Trigger the Law

Like most state privacy statutes, New Jersey's law does not apply to every business. It sets specific thresholds that determine whether a company qualifies as a "controller" subject to the law's requirements. Generally, the law applies to entities that process the personal data of at least 100,000 New Jersey consumers, excluding data processed solely to complete a payment transaction. It also applies to smaller companies, those processing data for at least 25,000 consumers, if they derive revenue from selling that personal data.

One notable feature: New Jersey's law does not include a revenue threshold for controllers, unlike California's privacy law, which sets a specific dollar figure for coverage. That means a company's total revenue is not, by itself, a factor in determining whether the New Jersey law applies. Instead, the focus stays on the volume of consumer data being processed and whether that data is being sold.

Consumer Rights Under the NJDPL, and What's Missing

New Jersey consumers under this law generally gain rights that echo other state privacy statutes: the ability to confirm whether a company is processing their data, access that data, correct inaccuracies, request deletion, and obtain a portable copy of their information. Consumers can also typically opt out of having their data used for targeted advertising, sold to third parties, or used in certain kinds of profiling that carry legal or similarly significant effects.

Where things get more nuanced is in the details Stauss PLLC's analysis flags as absent compared to Connecticut's statute. Connecticut's law is often cited by privacy attorneys as containing more granular consumer protections and procedural requirements than some of its peer states. The fact that New Jersey's law leaves out provisions Connecticut includes suggests that, while New Jersey consumers do have meaningful rights, the enforcement mechanisms and specific protections may not be as comprehensive as what residents in other states with newer or more detailed laws receive.

What This Means For You

If you live in New Jersey, this law gives you real, usable rights over your personal data for the first time at the state level. You can ask companies what they're doing with your information, request corrections or deletion, and opt out of having your data sold or used for targeted ads, provided the company meets the thresholds described above. Smaller businesses that don't sell data and don't hit the 100,000-consumer mark may fall outside the law's scope entirely, so not every company you interact with will be obligated to respond to these requests.

It's also worth understanding that New Jersey's protections, while real, are not the strongest version of a consumer data privacy law currently in effect nationally. If you're comparing your rights here to what a friend or family member has in a state like Connecticut, don't be surprised if their law spells out more specific procedures or protections. The patchwork nature of U.S. privacy law means your rights can genuinely differ depending on your zip code, at least until federal legislation, if it ever arrives, standardizes the baseline.

Actionable Takeaways

For New Jersey residents, the most useful step is simply learning what to ask for: request access to your data, ask companies to delete what they no longer need, and opt out of data sales or targeted advertising where a company is legally required to honor that request. For businesses operating in New Jersey, now is the time to confirm whether you meet either processing threshold and to review how your practices compare against the Virginia-style framework the law follows, since gaps compared to stricter states like Connecticut don't necessarily mean lighter compliance obligations elsewhere. As more states pass their own versions of a consumer data privacy law, staying informed about your specific state's provisions, and their limits, remains the best way to actually use the rights you've been given.