← All jurisdictions
NJ · data breach notification
medNew Jersey
N.J. Stat. §56:8-161 et seq.
Individual deadline
No fixed limit
Trigger standard
Risk of harm
AG / regulator
Required
| Notice to individuals | in the most expedient time possible and without unreasonable delay |
| Risk-of-harm standard | no notice if establishment that misuse is not reasonably possible (written determination retained 5 years) |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | NJ Division of State Police (Dept. of Law & Public Safety), required for any affected resident; in advance of disclosure to customers Sequencing trap: State Police before customer notice. Statute-confirmed (2026-07-18): NO numeric individual deadline in NJ |
| Credit reporting agencies | Notify CRAs above 1,000 residents. |
| Substitute notice | Typically available above $250,000 cost / 500,000 affected (verify). |
| Private right of action | Yes. |
| Notable PI definitions | Includes credentials. |
Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a New Jersey breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →