New Jersey Data Privacy Act (NJDPA) Compliance: The Cure Period Is Gone and the Clock Is 45 Days
The New Jersey Data Privacy Act gives New Jersey residents the right to access, correct, delete, and port their personal data and to opt out of its sale. A verified request starts a 45-day clock, and a denial has to carry an appeal route answered within 60 days. On July 15, 2026 the mandatory 30-day cure period sunset, so the Division of Consumer Affairs no longer has to warn you before acting. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks both clocks.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The New Jersey Data Privacy Act (NJDPA) took effect January 15, 2025. It applies to a controller that conducts business in New Jersey or targets New Jersey residents and, in a calendar year, either controls or processes the personal data of at least 100,000 consumers, excluding data processed solely to complete a payment transaction, or controls or processes the data of at least 25,000 consumers while deriving any revenue or any discount on goods or services from selling personal data. That second test has no percentage floor at all: one dollar of revenue from a data sale is enough, which makes New Jersey broader than Virginia, Connecticut, or Colorado on that path. New Jersey consumers can confirm and access their personal data, correct inaccuracies, delete it, obtain a portable copy, and opt out of sale, targeted advertising, and profiling with legal or similarly significant effects. You generally must respond within 45 days, extendable once by another 45 days with notice, and if you deny a request you must provide an appeal mechanism and answer the appeal within 60 days. Universal opt-out signals such as Global Privacy Control have been mandatory since July 15, 2025. The most important change for 2026 is enforcement posture: for the first 18 months the Division of Consumer Affairs had to send a notice and allow 30 days to cure before bringing an action, and that window closed on July 15, 2026. A cure is now purely discretionary. Civil penalties run up to $10,000 for a first violation and $20,000 for each subsequent violation, enforced under the New Jersey Consumer Fraud Act, and there is no private right of action. Obtainer handles the operational side: intake, discovery of where the person's data lives, a source-system manifest, a drafted deadline-safe response, and tracking of the 45-day and 60-day clocks. Nothing is disclosed or erased automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.
Why it fits
New Jersey businesses and out-of-state SaaS, ecommerce, adtech, and B2B firms that target New Jersey residents at the NJDPA thresholds, especially any company that takes revenue or a discount from sharing data and therefore falls under the 25,000-consumer test.
The grace period ended on July 15, 2026
For the first 18 months of the NJDPA the Division of Consumer Affairs was required to give notice and 30 days to cure. That obligation expired on July 15, 2026. Whether you get a warning is now someone else's discretionary call, made after they have already reviewed your conduct, with penalties of $10,000 for a first violation and $20,000 for each one after. A missed 45-day deadline is the violation now, not the warning.
Any revenue from a data sale pulls you in at 25,000 consumers
Most state laws require you to derive 25 or 50 percent of revenue from selling data before the lower consumer threshold applies. New Jersey requires only that you derive any revenue, or even a discount on goods or services. If you run an ad partnership, a co-marketing data swap, or a referral arrangement that a regulator would read as a sale, the bar drops to 25,000 New Jersey consumers.
Two clocks, not one
New Jersey runs a 45-day response deadline and a separate 60-day appeal deadline, and the appeal only starts when you deny something. Teams tracking requests in a shared inbox routinely miss the second one because nothing restarts a timer when a denial goes out. Obtainer tracks the request and the appeal as distinct deadlines and keeps the dated record of what you disclosed, refused, and why.
More use cases
Related features
Questions
Common questions about this
Who must comply with the New Jersey Data Privacy Act?
A controller doing business in New Jersey or targeting New Jersey residents that, in a calendar year, processes the personal data of at least 100,000 consumers, excluding payment-transaction-only data, or processes the data of at least 25,000 consumers while deriving any revenue or any discount on goods or services from selling personal data. There is no revenue threshold and no percentage floor on the data-sale test, so even incidental sale revenue can trigger coverage.
Does the NJDPA still have a cure period?
No, not as a right. The statute required the Division of Consumer Affairs to give notice and a 30-day opportunity to cure for the first 18 months after the January 15, 2025 effective date. That window ran through July 15, 2026 and has now closed. The attorney general may still offer an opportunity to cure as a matter of discretion, but you cannot plan around it, and enforcement can begin without any warning.
What are the penalties under the New Jersey Data Privacy Act?
Violations are treated as unlawful practices under the New Jersey Consumer Fraud Act, which carries civil penalties of up to $10,000 for a first violation and up to $20,000 for each subsequent violation. Enforcement rests with the attorney general and the Division of Consumer Affairs, and there is no private right of action, so consumers cannot sue you directly under the NJDPA.
How long do I have to respond to a New Jersey privacy request?
Forty-five days from receipt of a verified request, extendable once by another 45 days when reasonably necessary if you notify the consumer of the extension and the reason. If you refuse a request you must tell the consumer why and give them a way to appeal, and you have 60 days to respond to that appeal. If you deny the appeal you must also provide a method to submit a complaint to the Division of Consumer Affairs.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.