Law / United States / New Jersey

New Jersey

United States law applies in New Jersey New Jersey is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of New Jersey, described on this page below, applies here too.
New Jersey has 2 local jurisdictions Each local jurisdiction has law of its own, on a page of its own. All 2 are listed below.

13 of 16 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 1 enacted but not yet in force. As of 14 September 2026.

When they take effect13 of 13 carry a date. Earlier is before 2015.
Before 2015: 3 instruments (3 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 8 instruments (8 in force) ’25 2026: 0 instruments 2027: 1 instrument (1 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 2 in force, 1 enacted but not yet in force

Research summary (320 words)

New Jersey's AI-specific criminal law took effect April 2, 2025 with P.L. 2025, c. 40 (A3540), which makes it a crime to generate, solicit, disclose, or use AI-generated deceptive audio or visual media ("deepfakes") for the purpose of furthering an enumerated crime, including endangering the welfare of children, sexual and harassment offenses, and threats or improper influence in official and political matters, and creates a companion civil action; this is New Jersey's coverage of both the CSAM/sexual-deepfake and election-deepfake space, and no separate Title 19 election-specific synthetic-media disclosure statute was located.

The New Jersey Division on Civil Rights adopted final rules effective December 15, 2025 (N.J.A.C. 13:16-3.1(e) and 13:16-3.2) applying the state Law Against Discrimination's disparate-impact framework specifically to "automated employment decision tools," including a rule that a respondent relying on an outside vendor's tool must take reasonable steps to ensure the vendor's tool does not produce a discriminatory outcome; this automated-tool-specific text is confirmed only for employment decisions, not for the chapter's separate housing, lending, or public-accommodation subchapters, which retain a general disparate-impact framework that does not name automated tools.

New Jersey also enacted the Forbidding the Algorithmic Inflation of Rent (FAIR) Act, P.L. 2026, c. 33 (A3497), signed July 20, 2026 and taking effect July 1, 2027, barring a rental property owner, software coordinator, or any person from using an algorithmic device that processes nonpublic, competitively sensitive rent and lease data to set, recommend, or facilitate coordinated pricing among rental property owners, enforced as a violation of the New Jersey Antitrust Act.

A bill that would have created a New Jersey Artificial Intelligence Advisory Board to oversee only state agencies' own AI use (S1438) passed the Senate but lapsed at the end of the 2024-2025 session without being enacted; because it reached only government use of AI, it is not catalogued as an instrument here. No general AI-chatbot consumer-disclosure statute was found enacted as of the date shown.

AI prohibited practices

Deceptive Audio or Visual Media (Deepfake) Criminalization Act

N.J. Stat. §§ 2C:21-17.7 to 2C:21-17.8 (P.L. 2025, c. 40, A3540)official enacted chapter text, New Jersey Legislature (pub.njleg.gov)

In force since 2 April 2025. Binds public and private bodies.

What this law does

A natural person commits a crime of the third degree if, without license or privilege, the person generates, creates, solicits, discloses, or uses a work of deceptive audio or visual media created substantially through technical means, commonly a deepfake, for the purpose of attempting or furthering the commission of an enumerated crime or offense, including sexual offenses, endangering the welfare of children under N.J.S. 2C:24-4, harassment, cyber-harassment, threats or improper influence in official and political matters, false public alarms, and hazing, or with knowledge that the work will be used by another for that purpose; knowingly or recklessly disclosing such a work, without more, is a crime of the fourth degree.

A fine of up to $30,000 may be imposed for a violation in addition to any prison term, and a victim may bring a civil action for actual or liquidated damages, punitive damages, and attorney's fees, without a criminal conviction as a prerequisite.

The Act exempts content a reasonable viewer would understand as criticism, comment, satire, parody, news reporting, teaching, scholarship or research, and exempts interactive computer service providers, cloud services providers, and AI developers or providers protected under 47 U.S.C. section 230.

What it requires

Forbidding the Algorithmic Inflation of Rent (FAIR) Act

P.L. 2026, c. 33 (A3497), supplementing the New Jersey Antitrust Act, N.J. Stat. § 56:9-1 et seq.official Assembly Committee Substitute text (First Reprint), New Jersey Legislature (pub.njleg.gov), for the Act's substantive terms

In force in 281 days, effective 1 July 2027. Binds private bodies.

What this law does

Makes it unlawful, as a violation of the New Jersey Antitrust Act, for a rental property owner to pay for or use the services of a "coordinator," for a coordinator to facilitate a tacit or express pricing agreement among rental property owners including by performing a "coordinating function," for two or more persons to engage in parallel pricing coordination, or for any person to perform a coordinating function.

A "coordinating function" covers using an algorithmic device, other than a plain spreadsheet or an unprocessed-data database, to collect nonpublic, competitively sensitive rental data (prices, lease terms, occupancy) from two or more rental property owners and use it, including to train an algorithm, to set or recommend rental prices, lease terms, or occupancy levels for those owners.

Excluded are collecting such data solely for research, statistical analysis, or testing without using it to set prices, a publicly available free rent estimate, and a real-estate listing database available on equal terms that does not itself set or recommend prices. The Attorney General must establish a complaint intake channel and may adopt implementing rules. Signed by Governor Sherrill on July 20, 2026.

What it requires

AI risk obligations

New Jersey Disparate Impact Discrimination Rules, Automated Employment Decision Tools

N.J.A.C. 13:16-3.1(e), 13:16-3.2official adopted rule text, New Jersey Division on Civil Rights (njoag.gov), New Jersey Register Vol. 57 No. 24 (December 15, 2025)

In force 9 months, effective 15 December 2025. Binds public and private bodies.

What this law does

Final rules adopted by the New Jersey Division on Civil Rights under the Law Against Discrimination define an "automated employment decision tool" as any software, system, or process that aims to automate, aid, or replace human decision-making relevant to employment, including a tool that analyzes data to generate scores, rankings, predictions, classifications, or recommended actions used in advertising, recruiting, screening, interviewing, hiring, or compensation decisions.

The rules state that using such a tool that has not been adequately tested and shown not to adversely affect a protected class before its use, or that limits or screens out applicants based on a schedule requirement without an accommodation mechanism, may have an unlawful disparate impact; a named example is facial analysis technology used to assess personality traits in virtual interviews.

Where an employer's practice relies on an outside vendor's automated tool, the employer must take reasonable steps to ensure the vendor's tool is consistent with the Law Against Discrimination, so an employer cannot avoid liability by pointing to the vendor. The Law Against Discrimination's own definition of employer reaches both government and private employers, so this employment-scoped duty binds a covered New Jersey government employer the same as a private one.

This automated-tool-specific text is confirmed only for the employment subchapter; the rules' separate housing, real estate, and lending subchapter carries the same general disparate-impact framework but does not name automated decision tools specifically.

What it requires

Privacy law5 instruments, 5 in force

Research summary (163 words)

New Jersey's comprehensive private-sector privacy law is the New Jersey Data Privacy Act (NJDPA), N.J. Stat. §§ 56:8-166.4 to 56:8-166.19, enacted as P.L. 2023, c. 266 (S332) and effective January 15, 2025.

NJDPA claws back a recording-derived biometric identifier the moment it is generated to identify a specific individual, and its sensitive-data list is notably broader than most peer states, naming financial account information and pregnancy as their own enumerated categories and enumerating facial mapping, facial geometry, and facial templates specifically within the biometric-data definition.

A universal opt-out mechanism became operative around July 15, 2025, and the Division of Consumer Affairs' notice-and-cure opportunity has already closed (around July 15, 2026). Breach notification is a separate, older statute, the New Jersey Identity Theft Prevention Act, N.J. Stat. § 56:8-163, which requires reporting to the Division of State Police in advance of notifying the customer.

Enforcement of NJDPA runs exclusively through the Attorney General under the Consumer Fraud Act, with no private right of action.

Breach notification

New Jersey Identity Theft Prevention Act, breach notification

N.J. Stat. § 56:8-163official New Jersey session law text, P.L. 2005, c. 226, New Jersey Legislature

In force since 1 January 2006. Binds private bodies.

What this law does

The New Jersey Identity Theft Prevention Act, a separate and older statute enacted as P.L. 2005, c. 226, took effect January 1, 2006, the first January 1 following its September 22, 2005 approval, per the act's own uncodified effective-date section (the breach-notification duty is not among the sections the act separately made effective immediately).

A business conducting business in New Jersey that compiles or maintains computerized records including personal information must disclose a breach of security to an affected New Jersey resident in the most expedient time possible and without unreasonable delay, with no fixed numeric-day deadline. A distinctive New Jersey feature requires reporting the breach to the Division of State Police in advance of notifying the customer.

What it requires

Comprehensive regime

New Jersey Data Privacy Act (NJDPA), general applicability and scope

N.J. Stat. §§ 56:8-166.4 to 56:8-166.19official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

In force since 15 January 2025. Binds private bodies.

What this law does

NJDPA governs private-sector processing of New Jersey residents' personal data, enacted as P.L. 2023, c. 266 (S332), signed January 16, 2024. Its own uncodified section 17 sets the effective date at the 365th day following enactment, January 15, 2025.

A controller must limit collection of personal data to what is adequate, relevant, and reasonably necessary, the ordinary multi-state "reasonably necessary" standard rather than Maryland's stricter "strictly necessary" gate, and enforcement runs through the general Consumer Fraud Act framework.

What it requires

Data subject rights

New Jersey Data Privacy Act, consumer rights and universal opt-out

N.J. Stat. §§ 56:8-166.4 to 56:8-166.19official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

In force since 15 January 2025. Binds private bodies.

What this law does

New Jersey consumers may confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling, with an appeal right for denials. A controller must act within 45 days of receipt, extendable once by 45 additional days, and must communicate a denial within 45 days with appeal instructions.

Beginning around July 15, 2025 (six months after the general effective date), a controller processing personal data for targeted advertising or sale must allow consumers to exercise the opt-out right through a user-selected universal opt-out mechanism, a staged duty confirmed directly from the Act's own text as distinct from the general effective date.

What it requires

Enforcement supervision

New Jersey Data Privacy Act, Division of Consumer Affairs enforcement

N.J. Stat. §§ 56:8-166.4 to 56:8-166.19official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

In force since 15 January 2025. Binds private bodies.

What this law does

A violation of NJDPA is an unlawful practice and violation of the Consumer Fraud Act, N.J. Stat. § 56:8-1 et seq., enforced exclusively by the Division of Consumer Affairs and the Attorney General. Until the 18th month after the effective date (around July 15, 2026, now past as of the date shown), the Division was required to issue a notice of alleged noncompliance and a 30-day cure opportunity before bringing an action if a cure was deemed possible; that window has closed.

The Act expressly forecloses a private right of action under NJDPA itself or under any other law, including the Consumer Fraud Act's own separate private-action mechanism.

What it requires

Sensitive categories

New Jersey Data Privacy Act, sensitive data and biometric definition

N.J. Stat. §§ 56:8-166.4 to 56:8-166.19official New Jersey session law text, P.L. 2023, c. 266, New Jersey Legislature

In force since 15 January 2025. Binds private bodies.

What this law does

NJDPA's sensitive-data list is broader on two axes than most peer states: it names financial information (account number, login, or card number combined with a security code, access code, or password) as its own standalone sensitive category, and it names pregnancy explicitly within the health-condition prong, alongside racial or ethnic origin, religious beliefs, sex life or sexual orientation, citizenship or immigration status, transgender or nonbinary status, genetic or biometric data processed to uniquely identify an individual, a known child's data, and precise geolocation.

"Biometric data" is defined to include fingerprint, voiceprint, retina or iris scan, and facial mapping, facial geometry, or facial templates specifically, the most explicit facial-recognition enumeration, excluding a bare photograph, video, or audio recording but clawing that exclusion back the moment data generated from one is used to identify a specific individual.

Sensitive data may be processed only with the consumer's opt-in consent; New Jersey does not ban its sale outright the way Maryland does.

What it requires

Scraping law3 instruments, 3 in force

Research summary (204 words)

New Jersey diverges from federal scraping law in the computer_misuse, personal_data, and crawl_signals-adjacent families.

Its computer criminal activity statute defines authorization objectively, at N.J. Stat. section 2C:20-23(q): an actor has authorization if a reasonable person would believe that the act was authorized, with no separate statutory carve-out for publicly available data and no notice-based revocation mechanism, so the question for a public, unauthenticated page turns on whether a reasonable person would read an open, unrestricted page as authorized.

The New Jersey Data Privacy Act (NJDPA) defines biometric data unusually explicitly, naming facial mapping, facial geometry, and facial templates outright rather than stopping at fingerprint and voiceprint, and its revenue-from-sale applicability limb carries no percentage floor.

New Jersey's most distinctive scraping-adjacent instrument is the 2019 Bot Disclosure Act, which requires disclosure when an automated account communicates with a New Jersey resident for commercial or election purposes, a genuine state-specific rule none of the other jurisdictions carries. Copyright, text-and-data-mining, and database rights add nothing beyond the federal position.

ToS enforceability and general unfair competition rest on general contract and common-law principles with no New Jersey case applying either to scraping, so neither earns its own instrument here. robots.txt carries no independent legal weight in New Jersey.

Computer misuse

New Jersey Computer Criminal Activity, objective reasonable-person authorization test

N.J. Stat. § 2C:20-25New Jersey Courts' Model Criminal Jury Charge, Computer Criminal Activity, Access (njcourts.gov), quoting the operative statutory text

In force since 14 April 2003. Binds public and private bodies.

What this law does

A person is guilty of computer criminal activity if the person purposely or knowingly and without authorization, or in excess of authorization, accesses data, a database, computer storage medium, computer program, software, equipment, a computer, computer system, or computer network, graded as a crime of the third degree for the general access offense.

N.J. Stat. section 2C:20-23(q) defines authorization objectively: permission, authority or consent given by a person who possesses lawful authority to grant it, and an actor has authorization if a reasonable person would believe that the act was authorized.

There is no separate statutory carve-out for publicly available data and no notice-based revocation concept anywhere in the definitions section, so the operative question for an open, unauthenticated page is whether a reasonable person encountering it, with no login wall, technical block, or other denial signal, would believe access was authorized, which tends to favor treating ordinary public-page crawling as authorized absent such a signal.

No reported New Jersey case applies this reasonable-person test to a scraping or public-page fact pattern; State v. Reid, 194 N.J. 386 (2008), the only related decision located, concerns a state-constitutional subpoena question arising from a stolen-credentials fact pattern and does not resolve the authorization element itself.

Section 4 of the founding act, P.L. 1984, c.184 (C.2C:20-25), was most recently revised by P.L. 2003, c.39 (effective 14 April 2003, per the NJ Division of Criminal Justice's own codification table), which expanded the offense's degree range from third to first and added the mandatory-minimum-sentence provision now at subsection g.; the objective reasonable-person authorization test in section 2C:20-23(q) is unchanged since then.

What it requires

Crawl signals

New Jersey Bot Disclosure Act

N.J. Stat. §§ 56:18-1 to 56:18-5 (P.L. 2019, c. 486)official enacted chapter text, New Jersey Legislature (pub.njleg.state.nj.us)

In force since 19 July 2020. Binds public and private bodies.

What this law does

The Act defines a bot as an automated online account where all or substantially all of the actions or posts of that account are not directly generated by a live natural person, and prohibits using a bot to communicate or interact with a person in New Jersey, in connection with the sale or advertisement of merchandise or real estate, or to solicit election support, unless the person discloses at the outset of the communication or interaction, in clear and conspicuous fashion, that the communication or interaction is being conducted by or through a bot.

The Act does not impose a duty on a service provider of an online platform, including an Internet web hosting service provider or an Internet service provider, so the disclosure duty falls on the bot's operator, not the host. Civil penalties run $2,500 for a first offense, $5,000 for a second, and $10,000 for each subsequent offense, enforced by the Superior Court, with injunctive relief also available to the Attorney General.

This is a genuine automated-interaction-specific state law that none of the other jurisdictions researched carries: it does not regulate reading public pages, but it directly regulates deploying an automated account to interact with New Jersey residents.

What it requires

Personal data

New Jersey Data Privacy Act (NJDPA), publicly available information exemption and biometric definition

N.J. Stat. §§ 56:8-166.4 et seq. (P.L. 2023, c. 266, S332)official enacted chapter text, New Jersey Legislature (pub.njleg.state.nj.us)

In force since 15 January 2025. Binds private bodies.

What this law does

Personal data excludes de-identified data and publicly available information, defined as information lawfully made available from government records or widely distributed media, or that a controller reasonably believes a consumer lawfully made available to the public and did not restrict to a specific audience, the ordinary exemption with no biometric carve-back.

The Act applies to a controller conducting business in New Jersey or targeting New Jersey residents that controls or processes personal data of at least 100,000 consumers, or of at least 25,000 consumers where the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data; notably, unlike several peer states, this second limb carries no percentage threshold on how much revenue must come from data sales, a lower bar than most comparable state acts.

Biometric data is defined unusually explicitly to include, but not be limited to, fingerprint, voiceprint, eye retinas, irises, facial mapping, facial geometry, facial templates, or other unique biological, physical, or behavioral patterns or characteristics used to identify a specific individual, naming facial mapping, geometry, and templates outright where several peer states' definitions stop at fingerprint and voiceprint, directly relevant to a scraper harvesting faces from public photos for facial-recognition purposes.

Approved January 16, 2024, effective on the 365th day following enactment, January 15, 2025, per the Act's own enactment clause. Enforcement is by the Division of Consumer Affairs in the Office of the Attorney General with sole and exclusive authority; the statute expressly creates no private right of action.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (670 words)

New Jersey's one enacted, standalone product-security or baseline-security duty on a private business is a secure-disposal requirement, not a full data-security-program statute: N.J. Stat. Ann. 56:8-162 (Identity Theft Prevention Act, L. 2005, c.226, s.11, approved September 22, 2005, effective January 1, 2006) requires a business or public entity to destroy, or arrange for the destruction of, a customer's records within its custody or control containing personal information, once no longer retained, by shredding, erasing, or otherwise modifying the personal information to make it unreadable, undecipherable, or non-reconstructable through generally available means.

A violation of that duty is deemed an unlawful practice under the Consumer Fraud Act, N.J. Stat. Ann. 56:8-166, enforceable both by the Attorney General (Consumer Fraud Act penalty and injunctive process, N.J. Stat. Ann. 56:8-13 and 56:8-14) and, because the Consumer Fraud Act carries its own private right of action, N.J. Stat. Ann. 56:8-19, by a consumer for an ascertainable loss, trebled with attorney's fees.

New Jersey has no broader, standalone "reasonable security program" statute of the shape New York's SHIELD Act 899-bb, Massachusetts's 201 CMR 17.00, or California's Civil Code 1798.81.5 impose: the state's comprehensive privacy statute, the New Jersey Data Privacy Act (N.J. Stat. Ann. 56:8-166.4 et seq., P.L. 2023, c.266), does carry its own security-of-processing clause requiring a controller to take reasonable measures to establish, implement, and maintain administrative, technical, and physical data security practices, but that clause lives inside the comprehensive regime rather than as a standalone statute, so under this topic's Test 2 it stays with New Jersey's privacy row, which already researches the Act, rather than being refiled here.

No enacted New Jersey statute sets security requirements a connected device, IoT product, or other software product with digital elements must meet before or after it reaches the market; no bill of the shape of California's or Oregon's connected-device statutes was located as introduced or enacted in New Jersey.

New Jersey has no general, mandatory private-sector duty to report an exploited vulnerability or a cybersecurity incident to an authority: P.L. 2023, c.19 (S297, signed March 13, 2023, C.52:17B-193.2 et seq.) requires a public agency and, separately, a "government contractor" (an individual or entity performing work for or on behalf of a public agency on a contract basis with access to or hosting of the public agency's network, systems, applications, or information) to report a cybersecurity incident to the New Jersey Office of Homeland Security and Preparedness within 72 hours, and permits but does not require a private entity with no such contract to submit a notification through the same channel; because the bound private party is defined by a contracting relationship with government rather than by any activity the LexLint vocabulary can express, no instrument is filed for it here and it is recorded in this summary so a reader knows it exists (the profile-fact gap tracked by #6740, the same treatment New York's Part 500 receives).

New Jersey's Department of Banking and Insurance separately administers N.J.A.C. 11:1-44, Standards for Safeguarding Customer Information, first adopted in 2004 under the federal Gramm-Leach-Bliley Act, requiring a licensee to implement a written information security program with administrative, technical, and physical safeguards; because its bound party, an insurance licensee, is likewise a role the activity vocabulary cannot yet express, it is deferred on the same basis and not filed as an instrument.

A cybersecurity safe-harbor bill creating an affirmative defense for a business that implements and maintains a written cybersecurity program reasonably conforming to a named industry framework (most recently S1860, 2022-2023 session) has been introduced repeatedly in the New Jersey Legislature and has never been enacted, so this is a researched absence rather than a gap in coverage, unlike the conditioned safe harbors Utah, Ohio, Iowa, and Connecticut have enacted.

New Jersey's breach-notification duty, N.J. Stat. Ann. 56:8-163, the other half of the Identity Theft Prevention Act, is already this jurisdiction's privacy row rather than repeated here: it requires disclosure to an affected New Jersey resident following discovery of a breach of security of computerized records.

Security baseline statutes

Identity Theft Prevention Act, methods of destruction of customer records

N.J. Stat. Ann. § 56:8-162 (L. 2005, c.226, s.11)Official session law text, L. 2005, c.226, New Jersey Legislature

In force since 1 January 2006. Binds public and private bodies.

What this law does

A business or public entity must destroy, or arrange for the destruction of, a customer's records within its custody or control containing personal information, once the records are no longer retained, by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable, undecipherable, or non-reconstructable through generally available means.

A willful, knowing, or reckless violation is deemed an unlawful practice and a violation of the Consumer Fraud Act, enforceable by the Attorney General for a civil penalty and injunctive relief, and actionable by a consumer for an ascertainable loss under the Consumer Fraud Act's private right of action, trebled with reasonable attorney's fees.

What it requires

Age gating law1 instrument, 1 in force

Research summary (135 words)

New Jersey has not enacted an adult content age verification law, a social media minor access law, or an app store age verification law.

Bills requiring age verification for sexually explicit websites (S1826, introduced January 2026, successor to S4455 which died in January 2026) and requiring parental consent and age verification before a minor can hold a social media account (S3993, introduced March 2026) remain in Senate committee without passing either chamber, as does an app store age verification bill (S4669) that died in January 2026.

New Jersey's one enacted age gating instrument is the New Jersey Data Protection Act (S332, 2023), in effect since January 15, 2025, which requires opt in consent before processing the data of a known minor at least 13 and younger than 17 for targeted advertising, sale, or significant profiling.

Age-appropriate design code

S332, New Jersey Data Protection Act

N.J. Stat. Ann. section 56:8-166.4 et seq. (P.L. 2023, c. 266)official New Jersey Legislature final bill text (Sixth Reprint, enacted as P.L. 2023, c. 266)

In force since 15 January 2025. Binds private bodies.

What this law does

Requires a controller that has actual knowledge, or willfully disregards, that a consumer is at least 13 but younger than 17 years of age to obtain the consumer's own opt in consent before processing personal data for targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects, and treats personal data collected from a known child under 13 as sensitive data that must be processed in accordance with COPPA.

Note and primary source

Law in local jurisdictions2 with pages

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.