iQ Cookie  State Law Series

State 16 of 25 · New Jersey

Cookie & Privacy Law in New Jersey

Published August 2026
Law in effect
Cure period expired Jul 1, 2026

Educational purposes only — not legal advice. This guide is intended to help you understand New Jersey’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
NJDPA
P.L. 2024, c.1 (S332)
SIGNED
Jan 16, 2024
Effective Jan 15, 2025
CURE PERIOD
Expired
Jul 1, 2026
STATE RANK
#13
To enact a law

The short version

New Jersey’s NJDPA took effect January 15, 2025, and it stands out for covering entities that most peer-state laws exempt: nonprofits and higher education institutions are both in scope. Its 30-day cure period was only ever meant to last 18 months and expired on July 1, 2026, so enforcement discretion now sits entirely with the Attorney General.

New Jersey does not have a separate cookie law. Cookie compliance flows from the NJDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

New Jersey Legislature — Official Text
New Jersey Data Privacy Act — P.L. 2024, c.1 (S332)

Who does it apply to?

The NJDPA covers businesses that conduct business in New Jersey or produce products or services targeted to New Jersey residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more New Jersey consumers during a calendar year (payment-only transaction data excluded).

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives any revenue from selling personal data — no minimum percentage required, unlike Connecticut or Virginia.

GLBA financial institutions and HIPAA-covered entities are exempt at the entity level; FERPA, FCRA, Driver’s Privacy Protection Act, and Farm Credit Act data carry data-level exemptions. Nonprofits and higher-education institutions are NOT categorically exempt — check whether your specific activities trigger the thresholds.

Consumer rights

New Jersey residents whose data is covered by the NJDPA can:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Sale, targeted advertising, and significant profiling
Appeal
Challenge a denied request through an internal process

Businesses must respond within 45 days, extendable once by 45 more — but opt-out requests specifically must be processed within just 15 days, faster than nearly every peer state. There is no private right of action — only the Attorney General can enforce.

What makes New Jersey different

Nonprofits and universities are in scope. Most Virginia-model state privacy laws exempt nonprofit organizations and higher-education institutions outright. New Jersey does not — if a nonprofit or university meets the thresholds, the NJDPA applies to it like any other covered entity.

Financial information can be sensitive data. Beyond the standard sensitive-data categories, New Jersey adds certain financial account information not otherwise covered by GLBA — a broader definition than most comparable states use.

The fastest opt-out timeline in the series. Opt-out requests must be processed within 15 days — compare that to California’s 15 business days for GPC but 45 calendar days generally, or the 45-day standard most other states use across the board.

No revenue percentage on the data-sale threshold. Connecticut and Virginia require a meaningful share of revenue from data sales before the lower consumer-count tier applies. New Jersey requires only that some revenue come from data sales at all.

Minors’ protection runs all the way to 17. Consumers under 17 need affirmative opt-in consent before sale or targeted advertising — one of the broader age bands in the series, extending well past the more common 13-to-16 range.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health conditions
Sexual orientation
Citizenship / immigration status
Genetic / biometric data
Precise geolocation
Certain financial account info
Children’s data (under 13)

For known children under 13, COPPA protections apply and their data is sensitive by default. For ages 13–16, opt-in consent is required before any processing of their personal data at all — not just sale or targeted ads. Sale and targeted advertising for anyone under 17 require affirmative consent.

What this means for your cookies

Cookie / data typeRequirementWhat to do
Sensitive data cookies (health, biometric, financial)Opt-in requiredGate these behind affirmative consent before they fire.
Sale / targeted advertising cookiesOpt-out required (opt-in under 17)Provide a fast opt-out mechanism; honor within 15 days.
GPC / opt-out signalsRequired since Jul 15, 2025Confirm your consent tool honors GPC automatically.
Profiling cookies (legal/significant effects)Opt-out requiredOffer an opt-out for profiling that materially affects consumers.
Any cookies — users 13–16Opt-in requiredConsent needed for any processing, not just sale or ads.

Enforcement

$10k / $20k
First / subsequent violation
Expired
Cure period ended Jul 1, 2026
AG only
No private right of action

The New Jersey Attorney General’s Division of Consumer Affairs has exclusive enforcement authority, with penalties escalating from $10,000 for a first violation to $20,000 for each subsequent one. With the cure period now expired, businesses should not assume they will get advance warning before an enforcement action begins.

Your action checklist

With no cure period left, these need to be handled now:

1

Check your thresholds — including if you’re a nonprofit or university. Do you process data on 100,000+ New Jersey consumers, or 25,000+ while earning any revenue from data sales? If yes, you are in scope regardless of tax status.

2

Speed up your opt-out processing. New Jersey requires opt-out requests be honored within 15 days — confirm your workflow can meet that window.

3

Audit financial data cookies. Certain financial account information counts as sensitive data here, unlike in most peer states.

4

Confirm GPC recognition is live. Required since July 15, 2025, six months after the law’s effective date.

5

Update age-gating for the 13-16 and under-17 bands. Consent requirements are broader here than in most states — verify your logic covers both thresholds correctly.

6

Update your privacy policy. Cover data categories, processing purposes, third-party recipients, and how to exercise every right, including the appeal process.

7

Review vendor contracts. Any processor handling New Jersey resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with New Jersey?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 16 of 25  ·  Next: Oregon →