Protect Your Business: What the NJDPA 2025 Means for You

Since January 2024, the state of New Jersey has demonstrated a growing commitment to the rights of New Jersey consumers in respect to data privacy. This growing commitment helped to foster the enactment and put into effect the New Jersey Data Privacy Act, or the NJDPA. The NJDPA, which was put into effect on January 15, 2025, is modeled after similar privacy laws in states such as California and the European GDPR and applies to entities that conduct business in New Jersey or target its residents. Furthermore, the NJDPA is a privacy law that was designed to protect the personal data of New Jersey residents while simultaneously providing transparency, control, and security regarding how businesses collect and process peoples’ personal data. The policy follows a framework that includes detailed writing on the purpose of the act:

  • Who must comply with the new data privacy rules;
  • The rights of the consumers; and
  • The obligations of controllers, or businesses
HOW COMPANIES CAN ACHIEVE COMPLIANCE

In June 2025, we conducted a thorough analysis of the NJDPA. Here we identify eleven key points which companies need to follow to comply with NJDPA.

The first key point determines who must comply under the NJDPA. Per the NJDPA, any business that controls or processes the personal data of 100,000+ NJ consumers or any business with 25,000+ NJ consumers that derives revenue from selling data must fall into compliance. However, there are stipulations within the act that call for schools, government agencies, and other entities that find themselves in connection with these two types of businesses to practice these newly enforced privacy laws. Given the requirements set forth by the New Jersey Data Privacy Act (NJDPA), it is important to understand how the law may apply indirectly to your organization. For example, through business relationships with entities that are subject to NJDPA compliance, if your operations involve handling or processing the personal data of New Jersey residents on behalf of or in partnership with such entities, you may be contractually obligated to uphold certain privacy standards under the NJDPA.

The second key point outlines the rights of New Jersey consumers that companies must honor under the NJDPA. To understand the rights of New Jersey consumers under the NJDPA, please refer to the appendix at the bottom of this document or the New Jersey Data Privacy Law itself. For companies to act in compliance with these rights, companies should look to:

  • Create a Privacy Request Portal on your website or app;
  • Add an “opt-out” button to your website/app;
  • Honor browser privacy signals that say “opt me out” or “block”;
  • Create a simple way for users to submit a request to see their data either through a contact us page, or web form/portal link within the Privacy Request Portal; and/or
  • Provide consumer data in a common and easy-to-use format such as a PDF so it can be downloaded (data portability).

The third key point highlights the amount of transparency companies need to have with their consumers as well as how they are to construct any notice requirements when it comes to beginning the process of collecting a consumer’s personal data. To see what the specific requirements are, please refer to the appendix at the bottom of this document or the New Jersey Data Privacy Law itself. For companies to act in compliance with these requirements, companies should look to:

  • Create a clear privacy notice asking for consumer information such as name and email address that helps to answer the questions listed on our reference sheet;
  • Put links to the Privacy Notice in key spots, such as the footer of every webpage, and label the link clearly;
  • Add a visible button that reads “Do Not Sell or Share My Personal Information” in the event a consumer would like to opt out of that practice; and
  • Create a consumer rights request process either through a simple web form or an email address.

The fourth key point sets the precedent for obtaining a consumer’s consent. To learn more details on how to obtain consent, please refer to the appendix at the bottom of this document or the New Jersey Data Privacy Law itself. For companies to act in compliance with these requirements, companies should look to:

  • Set up checkboxes in which the user must manually click the box to acknowledge consent in receiving any form of notice or use of data;
  • Create a space in which a company can keep a log of when and how users gave consent; and
  • Allow users to withdraw consent at any time by adding an unsubscribe link or a “manage privacy” hyperlink at the bottom of notices such as emails and SMS messages as well as one a company’s privacy page.

The fifth key point highlights the importance of a universal opt-out mechanism. To learn more about the specifics of the universal opt-out mechanism, please refer to the appendix at the bottom of this document or the New Jersey Data Privacy Law itself. For companies to act in compliance with the universal opt-out mechanism, companies should look to:

  • Install technology to detect opt-out signals like GPC;
  • Automatically apply opt-out without asking the user to do more; and
  • Apply the opt-out to ALL data linked to that user/device/browser, not just future data.

The sixth key point describes how a company should operate if they offer loyalty programs. To learn more about loyalty programs under the NJDPA, please refer to the appendix at the bottom of this document or the New Jersey Data Privacy Law itself. For companies with loyalty programs to act in compliance under the NJDPA, companies should look to:

  • Create an easy-to-understand disclosure explaining if joining the loyalty program requires sharing personal data;
  • Place the explanation where customers sign up;
  • Build an “Opt Out of Data Sharing/Sale” link on the company\’s homepage; and
  • Include a list of all third parties within the company’s privacy policy.

The seventh key point describes how companies should only collect necessary data from consumers. To learn more about the specifics regarding data minimization and how to uphold its purpose, please refer to the appendix at the bottom of this document or the New Jersey Data Privacy Law itself. For companies to act in compliance with data minimization, companies should look to:

  • Add a section into one’s privacy notice that states what data was collected and why; and
  • Use pop-ups or banners to alert users when your purpose for collecting data changes.

The eighth key point highlights the different ways in which companies can implement data security and protections for their consumers. To learn more about data security and protections, please refer to the appendix at the bottom of this document, the white paper at the bottom of this document, and/or the New Jersey Data Privacy Law itself. For companies to act in compliance with data security and protection, companies should look to:

  • Require strong passwords for accounts as well as two-factor authentication for login and other access points; and
  • Create and maintain a Data Security Policy, explaining how a company protects the data of its users, and an Incident Response Plan, explaining a step-by-step plan for what to do if a company experiences a data breach.

The ninth key point discusses the collection and use of children’s data and the process in which both components must follow. To learn more about the collection and use of children’s data and their respective processes, please refer to the appendix at the bottom of this document, or the New Jersey Data Privacy Law itself. For companies to act in compliance with the collection and use of children’s data, companies should look to:

  • Ask for the user’s Date of Birth at Sign-Up or Visit by adding a screen that asks for the user’s birthday and if under 13 takes them to a parental consent page; and
  • Ask the child’s parents to sign and return a consent form.

The tenth key point highlights how companies should have contracts in place with their vendors or processors. To learn more about the specific requirements of consumer processor contracts, please refer to the appendix at the bottom of this document, or the New Jersey Data Privacy Law itself. For companies to act in compliance with the specific requirements of consumer processor contracts, companies should look to:

  • Update your privacy policy list the categories of third parties who process user data along with what they are to do with personal user data by instruction only; and
  • Add a “Third-Party Vendors” section on your website that lists the names and roles/titles of the processors that will be handling personal user data.

The eleventh and final point discusses the concept of record keeping and the intricacy in which records are to be collected and kept. To learn more about the specifics of collecting and keeping records under the NJDPA, please refer to the appendix at the bottom of this document, or the New Jersey Data Privacy Law itself. For companies to act in compliance with the specific requirements of record keeping, companies should look to:

  • Create a spreadsheet that logs what consumer requests and the company’s response;
  • Create a Data Inventory Sheet that logs why data was collected and if consent was obtained;
  • Add a “Consumer Rights” Request Form to your website;
  • Use consent checkboxes for when the user is prompted with questions about data collection; and
  • Create a clear link to the company’s privacy policy.

—————————————————————————————————————————————————————————————————————————————-

DISCLAIMER: We “TNTMAX’ are not attorneys, and the information provided herein is for general informational purposes only. Our interpretation of the New Jersey Data Privacy Act (NJDPA) is not intended to constitute legal advice or recommendations. You should not rely on this content as a substitute for legal counsel. For guidance specific to your organization or circumstances, please consult a qualified attorney familiar with data privacy laws.

REFERENCE:

New Jersey Enacts Comprehensive Data Privacy Law

CREDIT:

 

For all your Information Technology, Cybersecurity, and Compliance needs, TNTMAX delivers reliable, tailored solutions that keep your business running smoothly and securely. Our team helps you stay ahead of evolving cyber threats while ensuring compliance with the latest regulatory requirements. Operate with confidence knowing your risk exposure is proactively managed with TNTMAX as your trusted partner.
[email protected]
(201) 891-8686

more News