Home › Guides › NJ privacy law
Guide

The NJ Data Privacy Act and your small business

Most New Jersey small businesses we speak to believe this applies to somebody larger. It does not, and the grace period is over. This is what it asks of you in plain English.

The short answerThe New Jersey Data Privacy Act has applied since 15 January 2025, the grace period for fixing problems before penalties has closed, and legislation signed in June 2026 added obligations that apply to every business in the state regardless of size. If you hold personal information about New Jersey residents - a customer list, an email list, employee records - you are in scope. The practical test is not whether you are a big company. It is whether you can show, in writing, what personal data you hold, where it lives, who can reach it, and what you would do in the first 72 hours of a breach.
What the law expects, and what it looks like in practice
RequirementWhat it means for a 10-50 person businessTypical gap we find
Know what you holdA written record of the personal data you keep and whereNo record exists; data is in email and three SaaS tools
Reasonable safeguardsMFA, encryption, patching, access control - and documentedMFA on email only, nothing written down
Limit who can reach itStaff see what their job needs, and leavers lose accessFormer staff still have live logins
Breach notificationNotify affected residents and the Attorney General promptlyNo plan, so the clock runs while people decide who to call
Vendor responsibilityYour suppliers handling the data are still your problemNobody has read a single supplier's terms

The four questions that decide whether you are exposed

Why 'we are too small' stopped being true

What this costs to fix, honestly

Common questions

Does this apply if my business is not in New Jersey?

If you hold personal information about New Jersey residents, yes. The obligation follows the resident, not your office address - which is also how the New York SHIELD Act works, so a business serving both states is in scope for both.

We are a 12-person company. Are we really covered?

Yes. The legislation signed in June 2026 applies to every business in the state regardless of size, and the earlier thresholds were already low enough to include a company with a website and an email list.

What happens if we do nothing?

Nothing, until there is a breach or a complaint. At that point the absence of documented safeguards is the finding, and the notification clock starts whether or not you are ready. The cost of doing this properly beforehand is a fraction of doing it afterwards.

How long does a compliance review take?

A useful first pass takes about a week for a business of this size: find the data, check the controls, write down what exists, and produce a short list of what is missing in priority order.

Book a free 30-minute review

Tell us what is not working. We will look at your setup and tell you what we would change, whether or not you hire us.

Book the review   ●●● ●●●-●●●●