The NJ Data Privacy Act and your small business
Most New Jersey small businesses we speak to believe this applies to somebody larger. It does not, and the grace period is over. This is what it asks of you in plain English.
| Requirement | What it means for a 10-50 person business | Typical gap we find |
|---|---|---|
| Know what you hold | A written record of the personal data you keep and where | No record exists; data is in email and three SaaS tools |
| Reasonable safeguards | MFA, encryption, patching, access control - and documented | MFA on email only, nothing written down |
| Limit who can reach it | Staff see what their job needs, and leavers lose access | Former staff still have live logins |
| Breach notification | Notify affected residents and the Attorney General promptly | No plan, so the clock runs while people decide who to call |
| Vendor responsibility | Your suppliers handling the data are still your problem | Nobody has read a single supplier's terms |
The four questions that decide whether you are exposed
- Can you list, today, every place personal data about a New Jersey resident sits? Most cannot, and that single answer usually predicts the rest.
- Is multi-factor authentication on everything, or just on email? Email-only is the most common half-measure.
- When someone leaves, is their access actually removed the same day - and can you prove it?
- If you found a breach this afternoon, who makes the call, and what is the first hour?
Why 'we are too small' stopped being true
- The June 2026 legislation applies to every business in the state regardless of size. The small-business carve-outs people remember are from other states' laws, and from earlier drafts.
- The thresholds were already low enough to catch an ordinary company with a website and a mailing list.
- The grace period for fixing problems before penalties has closed, so the first thing a regulator sees is your current state, not your plan.
What this costs to fix, honestly
- For most 10-50 person businesses this is weeks, not months, and the bulk of it is documentation rather than new software.
- The expensive version is the one that starts after a breach, when the work happens under a 30-day notification clock and a lawyer's hourly rate.
- If you already have a decent IT provider, much of the technical half may be done - the gap is usually that nobody wrote it down in a form you could show anyone.
Common questions
Does this apply if my business is not in New Jersey?
If you hold personal information about New Jersey residents, yes. The obligation follows the resident, not your office address - which is also how the New York SHIELD Act works, so a business serving both states is in scope for both.
We are a 12-person company. Are we really covered?
Yes. The legislation signed in June 2026 applies to every business in the state regardless of size, and the earlier thresholds were already low enough to include a company with a website and an email list.
What happens if we do nothing?
Nothing, until there is a breach or a complaint. At that point the absence of documented safeguards is the finding, and the notification clock starts whether or not you are ready. The cost of doing this properly beforehand is a fraction of doing it afterwards.
How long does a compliance review take?
A useful first pass takes about a week for a business of this size: find the data, check the controls, write down what exists, and produce a short list of what is missing in priority order.
Book a free 30-minute review
Tell us what is not working. We will look at your setup and tell you what we would change, whether or not you hire us.
Book the review ●●● ●●●-●●●●