Skip to content

Evidence request lists

New Jersey Data Privacy Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consumer Rights

NJDPA-2
Consumer Rights - Access, Correct, Delete, Portability, Appeal

Honour consumer rights per NJ DPA including: confirm processing + access + correct + delete + data portability + appeal denial within 60 days. Respond within 45 days (extendable by 45 days). Recognise authorised agents with reasonable verification. NJ Division of Consumer Affairs rulemaking authority granted to establish implementing regulations covering verification + format + delivery methods.

Artefacts an auditor will ask for
  • Consumer rights portal
  • Verification procedures
  • 45-day response tracking
  • 60-day appeal handling
  • Authorised agent register
  • NJ DCA rulemaking compliance
Where this commonly fails
  • Late responses
  • No appeal process
  • No verification
  • Non-compliant with NJ DCA rules

Enforcement and Compliance

NJDPA-8
AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs

Acknowledge enforcement by New Jersey Attorney General Matthew Platkin (in office since February 2022) via the Division of Consumer Affairs (DCA). No private right of action. Penalties up to USD 10,000 first violation + USD 20,000 subsequent under NJ Consumer Fraud Act (N.J.S.A. 56:8). 18-MONTH cure period available through 15 July 2026 (sunsets - no cure period after). AG and DCA have rulemaking authority to issue implementing regulations including verification of consumer requests + UOOM technical specifications + processor contracts. Effective 15 January 2025. Maintain compliance documentation + AG/DCA notification readiness + executive accountability.

Artefacts an auditor will ask for
  • AG/DCA notification readiness
  • 18-month cure response template
  • DCA rulemaking compliance tracking
  • Executive accountability matrix
  • 15 July 2026 cure sunset readiness
  • Annual compliance review
Where this commonly fails
  • No AG/DCA readiness
  • Missing cure response
  • No DCA rulemaking tracking
  • Unprepared for cure sunset

Opt-Out Rights

NJDPA-3
Opt-Out Rights and Universal Opt-Out Mechanism (UOOM)

Provide opt-out rights for: (a) targeted advertising, (b) sale of personal data, (c) profiling that produces legal or similarly significant effects. NJ DPA REQUIRES Universal Opt-Out Mechanism (UOOM) recognition by 16 July 2025 (six months after effective date) including Global Privacy Control (GPC) signals. NJ DPA defines sale broadly including monetary AND other valuable consideration (similar to California CCPA). Process opt-out within 15 days. Apply to authenticated consumer requests + browser/device signals + authorised agent submissions.

Artefacts an auditor will ask for
  • Privacy choices page
  • UOOM honour configuration (effective 16 July 2025)
  • GPC signal detection
  • Sale identification register (monetary AND valuable consideration)
  • 15-day processing tracking
Where this commonly fails
  • No UOOM by July 2025
  • Narrow sale definition
  • Late opt-out processing
  • No GPC detection

Privacy Notice and Data Hygiene

NJDPA-5
Privacy Notice, Data Minimisation, and Purpose Limitation

Provide a reasonably accessible + clear + meaningful privacy notice including: (1) categories of personal data processed, (2) purposes of processing, (3) how consumers exercise rights and appeal, (4) categories of personal data shared with third parties, (5) categories of third parties + active link to opt-out request page, (6) email address or other online mechanism for consumer contact. Apply data minimisation + purpose limitation per NJ DPA.

Artefacts an auditor will ask for
  • Privacy Notice covering 6 mandatory elements
  • Annual notice review
  • Data inventory tied to purposes
  • Minimisation justification
  • Consumer contact mechanism
Where this commonly fails
  • Missing notice elements
  • Stale notice
  • No minimisation justification
  • No clear consumer contact

Risk and Vendor Management

NJDPA-7
Data Protection Assessments and Processor Contracts

Conduct and document Data Protection Assessments (DPAs) for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data, (e) processing for which the risk of harm is reasonably foreseeable. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts with required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).

Artefacts an auditor will ask for
  • DPA register
  • Risk vs benefit analysis
  • Processor contract template with NJ DPA clauses
  • Subprocessor list with consent
  • Annual processor audit
Where this commonly fails
  • No DPA register
  • Missing risk analysis
  • Processor contracts missing clauses
  • No subprocessor visibility

Scope and Applicability

NJDPA-1
Applicability, Thresholds, and Scope

Determine applicability of New Jersey Data Privacy Act (NJ DPA) per Senate Bill S332 signed by Governor Phil Murphy 16 January 2024 + effective 15 January 2025. NJ DPA applies to controllers conducting business in NJ or targeting NJ residents that: (a) controlled or processed personal data of 100,000+ NJ consumers (excluding payment transactions), OR (b) controlled or processed personal data of 25,000+ NJ consumers AND derived revenue or received discount from sale of personal data. Document exemptions: HIPAA covered entities + GLBA financial institutions + FERPA + nonprofits + state/local government + air carriers + B2B limited exemption.

Artefacts an auditor will ask for
  • Applicability memo
  • NJ resident consumer count
  • Revenue analysis
  • Exemption documentation
  • Annual applicability review
  • NJ business registration
Where this commonly fails
  • No applicability memo
  • Stale consumer counts
  • Missing exemption docs
  • No annual review

Security and Incident Response

NJDPA-6
Reasonable Data Security and Incident Response

Establish + implement + maintain reasonable administrative + technical + physical data security practices to protect the confidentiality + integrity + accessibility of personal data appropriate to the volume + nature of the personal data. Align with NIST Cybersecurity Framework or equivalent. Comply with New Jersey breach notification law (N.J.S.A. 56:8-163.4) requiring notification to NJ State Police + AG + affected residents in most expeditious time possible (typically 30 days). Maintain incident response plan covering preparation + detection + containment + eradication + recovery + lessons learned + breach reporting.

Artefacts an auditor will ask for
  • Written security programme
  • NIST CSF alignment
  • Incident response plan
  • Annual tabletop exercise
  • NJ State Police + AG notification readiness
  • 56:8-163.4 compliance
Where this commonly fails
  • No written programme
  • Missing NIST alignment
  • No NJ State Police notification readiness
  • Inadequate breach procedures

Sensitive Data and Minors

NJDPA-4
Sensitive Data, Children, and Adolescents 13-17 Opt-In

Obtain affirmative opt-in consent before processing sensitive data including racial or ethnic origin + religious beliefs + mental or physical health condition or diagnosis + sex life or sexual orientation + citizenship or immigration status + genetic data + biometric data + precise geolocation + financial information that includes account number/credit/debit card number with required security code/access code/password + status as transgender or non-binary + data of known children under 13. NJ DPA UNIQUE: financial account information is sensitive data + transgender/non-binary status protected as sensitive (strongest such protection in US state privacy laws). Process children under 13 per COPPA + parental consent. Adolescents 13 to under 17 require opt-in for sale of personal data + targeted advertising + profiling.

Artefacts an auditor will ask for
  • Sensitive data inventory including NJ-unique categories
  • Opt-in consent records
  • Age verification
  • COPPA compliance
  • Adolescent 13-17 opt-in tracking
  • Financial info handling procedures
Where this commonly fails
  • Missing NJ-unique sensitive categories
  • No financial info opt-in
  • No adolescent opt-in
  • Missing transgender/non-binary protection
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the New Jersey Data Privacy Act framework page.