New Jersey can fine a business up to $20,000 per violation of its Data Privacy Act, and as of July 1, 2026 the law's mandatory 30-day cure period has expired, according to the New Jersey Division of Consumer Affairs' own NJDPA guidance. That means the Attorney General's office can now pursue enforcement immediately, without first giving a business a chance to fix the problem. Below is the full set of thresholds, penalty figures, and enforcement data that matter for any business handling New Jersey residents' personal data.

New Jersey Data Privacy Act penalties can reach 20,000 dollars per violation $20K per subsequent violation underthe NJDPA, once the cure period ends

A single NJDPA violation can cost a business up to $20,000 once the Division of Consumer Affairs finds a repeat offense.

What are the New Jersey Data Privacy Act's applicability thresholds?

A business falls under the NJDPA if it controls or processes the personal data of 100,000 or more New Jersey consumers in a calendar year, or the data of 25,000 or more consumers while deriving revenue from selling personal data, according to the New Jersey Division of Consumer Affairs' official NJDPA FAQ. Unlike Virginia's law, New Jersey sets no minimum percentage of revenue that has to come from data sales, so even a small amount of data-sale income alongside 25,000 consumer records is enough to trigger coverage.

Both thresholds look only at New Jersey residents acting in a personal or household capacity, and both exclude data collected in an employment context. Location of the business does not matter. A retailer headquartered in another state or country is covered the moment either count is crossed, the same rule most comprehensive state privacy laws share.

Figure 1: New Jersey's two-track applicability test, with no minimum revenue floor on the second track. Source: New Jersey Division of Consumer Affairs NJDPA FAQ.

A local business with 40,000 New Jersey customers and no data-sale income sits outside the law entirely, while a smaller data broker with 26,000 records for sale and even modest data-sale revenue falls inside it. That gap makes the second threshold the one most small and mid-sized businesses need to check first, since it catches far more of them than the 100,000-consumer count alone. New Jersey's 100,000-consumer bar is also far from the lowest in the country; see how it stacks up against Oregon and Delaware's much lower privacy law thresholds, where Delaware's own bar sits at just 35,000 consumers.

How much can an NJDPA violation actually cost?

Up to $10,000 for a first violation and up to $20,000 for each subsequent violation, enforced by the Attorney General's Division of Consumer Affairs under New Jersey's consumer protection framework. That per-violation structure puts New Jersey's maximum penalty on par with Colorado's, the strictest among the states with a comprehensive privacy law in effect.

Figure 2: New Jersey's subsequent-violation penalty ties Colorado for the highest per-violation maximum among comprehensive state privacy laws. Sources: New Jersey Division of Consumer Affairs, Colorado Revised Statutes 6-1-112, California Privacy Protection Agency 2025 inflation adjustment, Code of Virginia 59.1-584, Connecticut General Statutes 42-110o.

New Jersey does differ from Colorado in one important way: Colorado carries no aggregate cap on the total penalty across violations, while New Jersey's structure is a flat first-offense, subsequent-offense split. A business that fixes a violation before it recurs never sees the higher $20,000 figure. Sites that handle New Jersey resident data at meaningful scale can generate a privacy policy built for the NJDPA that keeps disclosure language, sale opt-outs, and consumer-rights notices aligned with the statute rather than relying on a generic template written for an earlier state law.

New Jersey is one of 20 states with a comprehensive privacy law now in effect nationwide as of 2026; our full state-by-state privacy law tracker covers how the other 19 compare on thresholds and penalties.

What happened when the NJDPA's cure period ended?

New Jersey's mandatory 30-day right-to-cure period ended July 1, 2026, according to the Division of Consumer Affairs. Before that date, the Division had to notify a business of a suspected violation and give it 30 days to fix the problem before pursuing a formal enforcement action. After that date, the Division can act immediately, with no guaranteed warning first.

Figure 3: Six compliance milestones across three years, from signing to the end of guaranteed cure notices. Source: New Jersey Division of Consumer Affairs NJDPA guidance, New Jersey Office of the Attorney General press releases.

The Division published proposed implementing rules on June 2, 2025, and closed the public comment period on August 1, 2025, but the one-year statutory deadline for adopting final rules, June 2, 2026, passed without a Notice of Adoption, based on tracking from New Jersey compliance practitioners. Colorado went through a similar sequence during its own rulemaking; see how Colorado's own penalty structure and deadline timeline compares for a state that has already finished a rulemaking cycle.

How many violations has New Jersey's Division of Consumer Affairs cited so far?

Ten cure letters, all now resolved, were issued between March 24, 2025 and November 13, 2025, citing 37 combined alleged violations, according to Troutman Pepper Locke's analysis of records the New Jersey Attorney General's office released in response to an open records request. New Jersey does not publish its cure letters on its own, so this count reflects what one law firm's records request surfaced rather than an official running tally from the Division itself.

The letters concentrated on public-facing disclosures, appeals processes for consumer rights requests, third-party data-sharing transparency, and consumer rights mechanisms, per that same analysis. Every one of the 10 letters was resolved without further enforcement action during the cure-period years, which is no longer guaranteed for a violation the Division finds after July 1, 2026.

The Division of Consumer Affairs is the same office that separately delayed enforcement of New Jersey's data broker registration fees, a related but distinct law; see our coverage of New Jersey's data broker fee enforcement delay for how that law's registry and fee schedule differ from the NJDPA's consumer-facing disclosure rules.

How does New Jersey's opt-out requirement compare to other states?

New Jersey businesses had to start honoring universal opt-out signals such as Global Privacy Control by July 15, 2025, six months after the NJDPA took effect. New Jersey joins a majority of states that now require this: 12 of the 20 states with a comprehensive privacy law in effect as of 2026 require honoring an opt-out preference signal, according to tracking compiled from state attorney general guidance and enacted privacy statutes.

Figure 4: New Jersey sits in the 12-state majority that requires machine-readable opt-out signals rather than opt-out links alone. Source: state attorney general guidance and enacted privacy statutes, compiled 2026.

For a business already honoring GPC signals in California or Colorado, extending the same handling to New Jersey is mostly a configuration step, since GPC operates as a single browser-level signal rather than a state-specific format.

Where does New Jersey sit on threshold breadth versus penalty size?

New Jersey pairs a moderate applicability threshold with the highest tier of per-violation penalty, a combination only Colorado currently matches among comprehensive state privacy laws. California sits apart from both on threshold structure, since its coverage test runs on revenue and processing volume rather than a flat consumer count.

Figure 5: New Jersey and Colorado cluster in the high-penalty, narrower-threshold quadrant, while California's revenue-based test places it on the broader-coverage side. Source: state statutes and agency guidance cited throughout this post.

A business already tracking California's revenue-based thresholds should not assume New Jersey's flat consumer count is automatically covered by the same compliance work. The two tests measure different things, and a business can clear one while missing the other.

NJDPA vs. other comprehensive state privacy laws

LawMax penalty per violationConsumer thresholdCure period status (2026)
New Jersey NJDPA$10,000 first / $20,000 subsequent100,000, or 25,000 with data salesEnded July 1, 2026
Colorado CPA$20,000, no aggregate cap100,000, or 25,000 with data salesEnded January 1, 2025
Virginia CDPA$7,500100,000, or 25,000 with 50%+ revenue from salesPermanent 30-day cure
Connecticut CTDPA$5,000100,000, or 25,000 with data salesDiscretionary as of 2025
California CCPA/CPRA$2,663 standard, $7,988 intentional or minorsRevenue or volume-based, not a flat consumer countNo mandatory cure period

Sources: New Jersey Division of Consumer Affairs NJDPA FAQ, Colorado Revised Statutes 6-1-112, Code of Virginia 59.1-584, Connecticut General Statutes 42-110o, California Privacy Protection Agency 2025 inflation adjustment announcement.

New Jersey's flat first-offense, subsequent-offense structure is closer to a traditional consumer protection penalty than Colorado's uncapped per-violation model, but the $20,000 ceiling on repeat violations puts the two states within reach of each other at the top end.

The Bottom Line

New Jersey's $10,000-to-$20,000 penalty structure, combined with the July 1, 2026 end of its mandatory cure period, means the NJDPA has moved from a law with a built-in grace window to one the Division of Consumer Affairs can enforce on first notice. Ten resolved cure letters citing 37 violations in the law's first enforcement year show the Division was already active well before that grace window closed, concentrated on disclosure, appeals, and data-sharing transparency gaps that a current privacy policy addresses directly. For any business meeting the 100,000 or 25,000-consumer threshold, the practical risk this data points to is treating the NJDPA as a one-time setup task rather than a standing disclosure obligation now enforced without warning.

Frequently Asked Questions

What are the New Jersey Data Privacy Act's applicability thresholds? A business must control or process the personal data of 100,000 or more New Jersey consumers in a calendar year, or 25,000 or more consumers while deriving revenue from selling personal data, according to the New Jersey Division of Consumer Affairs' official NJDPA FAQ.

How much can an NJDPA violation cost? Up to $10,000 for a first violation and up to $20,000 for each subsequent violation, enforced by the New Jersey Attorney General's Division of Consumer Affairs, per the state's own NJDPA guidance and corroborated by Baker Donelson's 2026 compliance guide.

When did the NJDPA's cure period end? July 1, 2026, according to the New Jersey Division of Consumer Affairs. Before that date, the Division had to give a business 30 days' notice and a chance to fix a violation before pursuing enforcement. After it, the Division can act immediately.

When did New Jersey's universal opt-out mechanism requirement take effect? July 15, 2025, six months after the NJDPA's January 15, 2025 effective date. From that date on, covered businesses had to honor consumer opt-out signals sent through mechanisms such as Global Privacy Control.

Where the Numbers Come From

  1. New Jersey Division of Consumer Affairs. "New Jersey Data Privacy Law FAQ." Effective date, applicability thresholds, penalty amounts, cure period end date, and universal opt-out mechanism deadline.
  2. New Jersey Office of the Attorney General. Press release on proposed NJDPA implementing rules, published June 2, 2025, with a 60-day public comment period.
  3. White & Case. "New Jersey Enacts Comprehensive Data Privacy Law." Signing date of January 16, 2024, and New Jersey's position as the 13th state to enact a comprehensive privacy law.
  4. Troutman Pepper Locke, cited via Captain Compliance's summary of that analysis. Ten resolved cure letters citing 37 combined alleged violations, issued March 24 to November 13, 2025, based on records obtained through a New Jersey open records request.
  5. Baker Donelson. "Consumer Data Privacy Law Guide: New Jersey." Penalty structure corroboration.
  6. Justia, Colorado Revised Statutes. Section 6-1-112, civil penalties, for the Colorado comparison figures.
  7. California Privacy Protection Agency. 2025 CCPA fine inflation adjustment, for the California comparison figures.
  8. IAPP. US State Privacy Legislation Tracker, for the 20-state count of comprehensive privacy laws in effect as of 2026.

Note: All figures verified as of August 2026. The Division of Consumer Affairs had not published a Notice of Adoption for final NJDPA rules as of this post's publication, so the rulemaking status will be updated once final rules are adopted. This post's figures are refreshed at least twice a year as New Jersey publishes new enforcement and rulemaking updates.