Law / United States /
New Jersey
New Jersey Identity Theft Prevention Act, breach notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2006.
A breach notification rule binding private bodies.
As of 27 August 2026.
What it requires
- Report a breach of security involving computerized personal records to the New Jersey Division of State Police before notifying the affected customer.
- Disclose the breach to each affected New Jersey resident in the most expedient time possible and without unreasonable delay. New Jersey sets no fixed numeric-day cap.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The New Jersey Identity Theft Prevention Act, a separate and older statute enacted as P.L. 2005, c. 226, took effect January 1, 2006, the first January 1 following its September 22, 2005 approval, per the act's own uncodified effective-date section (the breach-notification duty is not among the sections the act separately made effective immediately).
A business conducting business in New Jersey that compiles or maintains computerized records including personal information must disclose a breach of security to an affected New Jersey resident in the most expedient time possible and without unreasonable delay, with no fixed numeric-day deadline. A distinctive New Jersey feature requires reporting the breach to the Division of State Police in advance of notifying the customer.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
official New Jersey session law text, P.L. 2005, c. 226, New Jersey Legislature
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.