Privacy Law Library

Identity Theft Prevention Act: Data Breach Notification

NJ Breach Notification Law

Breach notification · Data security

New Jersey's breach law requires businesses and public entities to notify New Jersey residents whose unencrypted personal information was, or is reasonably believed to have been, accessed by an unauthorized person, unless misuse is not reasonably possible. The New Jersey State Police must be notified before consumers, and consumer reporting agencies must be notified when more than 1,000 people are affected.

Where
New Jersey
Citation
N.J.S.A. 56:8-161, 56:8-163, 56:8-166; P.L.2005, c.226, ss.10, 12, 15; amended by P.L.2019, c.95
Status
In force
In force since
2006-01-01
Last amended
2019-09-01
Enforced by
New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act); breaches are reported first to the Division of State Police
People can sue
Limited
Penalties
Willful, knowing, or reckless violations are unlawful practices under the Consumer Fraud Act (56:8-166), carrying civil penalties of up to $10,000 for a first offense and $20,000 for each later offense (56:8-13), plus injunctive relief. A person who suffers an ascertainable loss of money or property from a CFA unlawful practice may sue for treble damages and attorney's fees (56:8-19).
Applies to
  • Businesses (including financial institutions, for-profit or not) that conduct business in New Jersey and public entities (State and local, not federal) that compile or maintain computerized records containing personal information (56:8-161, 56:8-163(a))
  • Service providers that maintain computerized personal information on behalf of another business or public entity (56:8-163(b))
  • Personal information: first name or initial and last name plus SSN, driver's license or State ID number, or financial account/card number with any required access code; or (since Sept. 1, 2019) username or email address plus a password or security question and answer for an online account. Encrypted or otherwise unreadable data is outside the breach definition (56:8-161)

Breach duties

  • Notify affected New Jersey residents in the most expedient time possible and without unreasonable delay after discovering a breach, subject to law enforcement needs and measures to determine scope and restore system integrity.N.J.S.A. 56:8-163(a)
  • Notice may be skipped only if misuse is not reasonably possible; that determination must be documented in writing and kept for five years.N.J.S.A. 56:8-163(a)
  • Report the breach to the Division of State Police in the Department of Law and Public Safety before notifying customers.N.J.S.A. 56:8-163(c)(1)
  • Delay notice if a law enforcement agency determines notice would impede a criminal or civil investigation and requests the delay.N.J.S.A. 56:8-163(c)(2)
  • A vendor that maintains records on behalf of another entity must notify that entity immediately after discovering a breach.N.J.S.A. 56:8-163(b)
  • Give notice in writing, electronically (E-SIGN compliant), or by substitute notice (email, website posting, and statewide media) if cost exceeds $250,000, more than 500,000 people are affected, or contact information is insufficient.N.J.S.A. 56:8-163(d)
  • Notify all nationwide consumer reporting agencies of the timing, distribution, and content of notices when more than 1,000 people must be notified at one time.N.J.S.A. 56:8-163(f) · Only if: More than 1,000 persons notified at one time
  • For breaches involving only online account credentials, notice may direct users to change passwords and security questions; an entity that provides the breached email account must not send notice to that account.N.J.S.A. 56:8-163(g) · From 2019-09-01

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Whether a private plaintiff can recover under 56:8-19 for a breach-notification violation depends on proving an ascertainable loss; this is a matter of case law not reviewed here. | The State Police online breach-reporting portal and its current form were not checked.

Research reference, not legal advice.