Privacy Law Library

Internet-Connected Baby Monitor Security Requirements

NJ Baby Monitor Security Law

Data security · Children

Internet-connected baby monitors sold in New Jersey must include end-to-end encryption, certificate-based authentication, a ban on unauthenticated access, and security settings that consumers cannot disable. Selling a non-compliant monitor is a consumer fraud violation.

Where
New Jersey
Citation
N.J.S.A. 56:8-207; P.L.2017, c.81 (A3581)
Status
In force
In force since
2018-12-01
Enforced by
New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
People can sue
Limited
Penalties
Violations are unlawful practices under the Consumer Fraud Act, with civil penalties of up to $10,000 for a first offense and $20,000 for each later offense (56:8-13) and injunctive relief; a person with an ascertainable loss may sue for treble damages and attorney's fees (56:8-19).
Applies to
  • Anyone who manufactures, sells, offers for sale, or distributes in New Jersey a baby monitor that broadcasts audio or video over the Internet; multi-function devices such as smartphones and security cameras are excluded (56:8-207(a), (d))

What a privacy notice must say

  • Include conspicuous, easily understood manufacturer instructions on proper use and security features.N.J.S.A. 56:8-207(a)(5)

Security duties

  • Provide end-to-end encryption and certificate-based authentication for manufacturer access when updating, registering, or relaying audio or video.N.J.S.A. 56:8-207(a)(1)-(2)
  • Prohibit unauthenticated access (including implied third-party trusted access) and prevent consumers from disabling security measures.N.J.S.A. 56:8-207(a)(3)-(4)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective date computed as the first day of the 19th month after May 11, 2017 (December 1, 2018).

Research reference, not legal advice.