New Jersey Data Privacy Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Rights
Honour consumer rights per NJ DPA including: confirm processing + access + correct + delete + data portability + appeal denial within 60 days. Respond within 45 days (extendable by 45 days). Recognise authorised agents with reasonable verification. NJ Division of Consumer Affairs rulemaking authority granted to establish implementing regulations covering verification + format + delivery methods.
- Consumer rights portal
- Verification procedures
- 45-day response tracking
- 60-day appeal handling
- Authorised agent register
- NJ DCA rulemaking compliance
- Late responses
- No appeal process
- No verification
- Non-compliant with NJ DCA rules
Enforcement and Compliance
Acknowledge enforcement by New Jersey Attorney General Matthew Platkin (in office since February 2022) via the Division of Consumer Affairs (DCA). No private right of action. Penalties up to USD 10,000 first violation + USD 20,000 subsequent under NJ Consumer Fraud Act (N.J.S.A. 56:8). 18-MONTH cure period available through 15 July 2026 (sunsets - no cure period after). AG and DCA have rulemaking authority to issue implementing regulations including verification of consumer requests + UOOM technical specifications + processor contracts. Effective 15 January 2025. Maintain compliance documentation + AG/DCA notification readiness + executive accountability.
- AG/DCA notification readiness
- 18-month cure response template
- DCA rulemaking compliance tracking
- Executive accountability matrix
- 15 July 2026 cure sunset readiness
- Annual compliance review
- No AG/DCA readiness
- Missing cure response
- No DCA rulemaking tracking
- Unprepared for cure sunset
Opt-Out Rights
Provide opt-out rights for: (a) targeted advertising, (b) sale of personal data, (c) profiling that produces legal or similarly significant effects. NJ DPA REQUIRES Universal Opt-Out Mechanism (UOOM) recognition by 16 July 2025 (six months after effective date) including Global Privacy Control (GPC) signals. NJ DPA defines sale broadly including monetary AND other valuable consideration (similar to California CCPA). Process opt-out within 15 days. Apply to authenticated consumer requests + browser/device signals + authorised agent submissions.
- Privacy choices page
- UOOM honour configuration (effective 16 July 2025)
- GPC signal detection
- Sale identification register (monetary AND valuable consideration)
- 15-day processing tracking
- No UOOM by July 2025
- Narrow sale definition
- Late opt-out processing
- No GPC detection
Privacy Notice and Data Hygiene
Provide a reasonably accessible + clear + meaningful privacy notice including: (1) categories of personal data processed, (2) purposes of processing, (3) how consumers exercise rights and appeal, (4) categories of personal data shared with third parties, (5) categories of third parties + active link to opt-out request page, (6) email address or other online mechanism for consumer contact. Apply data minimisation + purpose limitation per NJ DPA.
- Privacy Notice covering 6 mandatory elements
- Annual notice review
- Data inventory tied to purposes
- Minimisation justification
- Consumer contact mechanism
- Missing notice elements
- Stale notice
- No minimisation justification
- No clear consumer contact
Risk and Vendor Management
Conduct and document Data Protection Assessments (DPAs) for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data, (e) processing for which the risk of harm is reasonably foreseeable. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts with required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).
- DPA register
- Risk vs benefit analysis
- Processor contract template with NJ DPA clauses
- Subprocessor list with consent
- Annual processor audit
- No DPA register
- Missing risk analysis
- Processor contracts missing clauses
- No subprocessor visibility
Scope and Applicability
Determine applicability of New Jersey Data Privacy Act (NJ DPA) per Senate Bill S332 signed by Governor Phil Murphy 16 January 2024 + effective 15 January 2025. NJ DPA applies to controllers conducting business in NJ or targeting NJ residents that: (a) controlled or processed personal data of 100,000+ NJ consumers (excluding payment transactions), OR (b) controlled or processed personal data of 25,000+ NJ consumers AND derived revenue or received discount from sale of personal data. Document exemptions: HIPAA covered entities + GLBA financial institutions + FERPA + nonprofits + state/local government + air carriers + B2B limited exemption.
- Applicability memo
- NJ resident consumer count
- Revenue analysis
- Exemption documentation
- Annual applicability review
- NJ business registration
- No applicability memo
- Stale consumer counts
- Missing exemption docs
- No annual review
Security and Incident Response
Establish + implement + maintain reasonable administrative + technical + physical data security practices to protect the confidentiality + integrity + accessibility of personal data appropriate to the volume + nature of the personal data. Align with NIST Cybersecurity Framework or equivalent. Comply with New Jersey breach notification law (N.J.S.A. 56:8-163.4) requiring notification to NJ State Police + AG + affected residents in most expeditious time possible (typically 30 days). Maintain incident response plan covering preparation + detection + containment + eradication + recovery + lessons learned + breach reporting.
- Written security programme
- NIST CSF alignment
- Incident response plan
- Annual tabletop exercise
- NJ State Police + AG notification readiness
- 56:8-163.4 compliance
- No written programme
- Missing NIST alignment
- No NJ State Police notification readiness
- Inadequate breach procedures
Sensitive Data and Minors
Obtain affirmative opt-in consent before processing sensitive data including racial or ethnic origin + religious beliefs + mental or physical health condition or diagnosis + sex life or sexual orientation + citizenship or immigration status + genetic data + biometric data + precise geolocation + financial information that includes account number/credit/debit card number with required security code/access code/password + status as transgender or non-binary + data of known children under 13. NJ DPA UNIQUE: financial account information is sensitive data + transgender/non-binary status protected as sensitive (strongest such protection in US state privacy laws). Process children under 13 per COPPA + parental consent. Adolescents 13 to under 17 require opt-in for sale of personal data + targeted advertising + profiling.
- Sensitive data inventory including NJ-unique categories
- Opt-in consent records
- Age verification
- COPPA compliance
- Adolescent 13-17 opt-in tracking
- Financial info handling procedures
- Missing NJ-unique sensitive categories
- No financial info opt-in
- No adolescent opt-in
- Missing transgender/non-binary protection
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the New Jersey Data Privacy Act framework page.