image

Articles

New Jersey Joins Growing List of States Enacting Privacy Protection Laws

New Jersey Alert

  • Published On: March 13, 2024

Key Points:

  • New Jersey enacts a consumer data protection law, effective 1/15/25.
  • S. 332 imposes tight constraints on collection and dissemination of biometric data but does not include a private right of action.
  • Businesses should scrutinize current insurance policies and renewals for new exclusions pertaining to biometric liability.
On January 16, 2024, New Jersey Governor Phil Murphy signed into law Senate Bill 332 (S. 332), a consumer data protection bill. The law will take effect on January 15, 2025, with a subsequent eighteen-month grace period.

Courthouse Columns

New Jersey joins a growing contingent of states that have created general data privacy laws. As of February 2024, the following states, along with New Jersey, had enacted some form of consumer privacy laws:  California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah and Virginia. Other states, such as Florida, have enacted more targeted privacy laws that apply to specified entities like large tech companies. However, most of these state laws do not provide a private right of action empowering individuals to pursue damages for data privacy violations, instead reserving enforcement for the state. The New Jersey privacy law does not provide a private right of action, which means enforcement of S. 332 will fall to the state Attorney General.

Overview of New Jersey’s New Privacy Protection LawS. 332 applies to entities conducting business in New Jersey or producing products or services targeting New Jersey residents that during a calendar year control or process the personal data of either:

(a) “100,000 consumers, excluding personal data processed solely for the purpose of completing a payment or transaction;” or

(b) 25,000 consumers if the company “derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data.”

S. 332 requires that for any company processing “sensitive data,” the individual whose data will be processed must either opt-in or provide consent.

“Sensitive data” includes but is not limited to:

  • “precise geolocation data,”
  • “religious beliefs,”
  • “personal data collected from a known child,”
  • “sex life” (undefined),
  • “sexual orientation” and
  • “biometric data.”

A limited number of entities are protected from the effects of S. 332, including state and local government agencies, financial institutions and their affiliates, HIPAA-defined protected health information used in federal clinical research, and personal data sales by the New Jersey Motor Vehicle Commission.

Under the law, a consumer has the right to opt out of personal data processing, including through universal opt-out mechanisms, for targeted advertising, personal data sales, or profiling to support decisions that have legal implications for the consumer. Additionally, an entity may only process personal data for the purpose it disclosed to consumers, unless the business obtains the consumer’s consent.

Critically, the required consumer consent cannot be obtained by actions such as closing a website page or using a site and its services where the Privacy Notice comprises information unrelated to privacy. This requirement necessarily will change the composition of many existing websites, because many companies rely upon a privacy statement in a website notice rather than an affirmative consent or opt-in, which will be required when the New Jersey law becomes effective. Any revocation of consent must be complied with within fifteen days after the receipt of such request, and the website operator may not discriminate against a consumer for revoking or opting out.  The penalties under the New Jersey law are potentially severe, as any violation of S. 332 will be a violation of the New Jersey Consumer Fraud Act, P.L.1960, c.39 (C.56:8-1 et seq.), which assesses a “penalty of not more than $10,000 for the first offense and not more than $20,000 for the second and each subsequent offense.”  N.J. Consumer Fraud Act, P.L.1960, c.39 (C.56:8-13 Penalties).

Businesses must keep track of what types of data they process and sell or provide to other companies in any manner, including in all jurisdictions in which they sell products or offer services.

Biometric Data Is Included in the New Jersey Privacy LawSix of the states mentioned above address the use of biometric data in their data privacy laws:  California, Colorado, Connecticut, New Jersey, Utah and Virginia.  Three other states have enacted specific biometric information privacy laws (BIPA), which limit the use of an individual’s biometric data:  Illinois, Texas and Washington.  Like the existing laws specifically addressing individuals’ biometric data, S. 332 contains a definition for “biometric data,” specifying that it includes “data generated by automatic or technological processing, measurements, or analysis of an individual’s biological, physical, or behavioral characteristics.”  This implicates, and is not limited to, data related to fingerprint, voiceprint, eye retinas, irises, and facial mapping.  However, photographs, audio or video recordings, and data generated from videos and recordings are not considered biometric data under the New Jersey law, unless such materials are generated to identify a specific individual.  The New Jersey privacy law offers protections similar to those contained in other states’ BIPA laws in that it prohibits the “processing” of sensitive data, which is defined to include biometric data.  “Processing” means an operation on personal data, such as its collection, use, storage, disclosure, analysis, deletion, or modification.  Thus, enforcement of the New Jersey law could generate cases similar to cases in Illinois, where employers have been sued for requiring employees to clock in using biometric data without having consented.  The critical difference, however, is that Illinois’ BIPA law includes a private right of action, which has enabled high-stakes class action suits, whereas the New Jersey law will require enforcement by the state Attorney General.

Businesses Must Prepare for Privacy Laws, Including Ensuring Responsive InsuranceWith new laws in New Jersey and elsewhere providing greater data privacy protections, companies will need to be aware of their potential liabilities under these laws.  Businesses must keep track of what types of data they process and sell or provide to other companies in any manner, including in all jurisdictions in which they sell products or offer services.  One key source of liability protection for such businesses are insurance policies that should respond when companies are faced with claims of potential privacy law violations.  The legal battles that have played out with insurance companies regarding existing privacy laws are instructive.

Specifically, courts in Illinois have cleared up early uncertainty by ruling consistently in favor of policyholders where insurance coverage for violations of the Illinois Biometric Information Privacy Act (BIPA) is at issue.  In response, insurance companies have implemented several measures to try to avoid paying for these liabilities going forward, such as adding new exclusionary language to policies.  Thus, companies should be examining not only their use of biometrics and other personal data in the present, but also the terms of their current and renewal insurance policies with respect to privacy violation claims.

At renewal time, companies should be wary of any effort by insurance companies to insert more specific exclusionary language to limit coverage for claims under privacy laws.  As litigation stemming from such laws continues to grow, smart businesses will need to put themselves in the best position to limit these liabilities and increase insurance recovery.

 

About Anderson KillAnderson Kill practices law in the areas of Insurance Recovery, Commercial Litigation, Environmental Law, Estates, Trusts and Tax Services, Corporate and Securities, Antitrust, Banking and Lending, Bankruptcy and Restructuring, Real Estate and Construction, Foreign Investment Recovery, Public Law, Government Affairs, Employment and Labor Law, Captive Insurance, Intellectual Property, Corporate Tax, Hospitality, and Health Reform. Recognized nationwide by Chambers USA, and best-known for its work in insurance recovery, the firm represents policyholders only in insurance coverage disputes — with no ties to insurance companies and has no conflicts of interest. Clients include Fortune 1000 companies, small and medium-sized businesses, governmental entities, and nonprofits as well as personal estates. The firm has offices in New York, NY, Boston, MA, Denver, CO, Los Angeles, CA, Newark, NJ, Philadelphia, PA, Stamford, CT, and Washington, D.C.

ATTORNEY ADVERTISING. This publication was prepared by Anderson Kill P.C. to provide information of interest to readers. Distribution of this publication does not establish an attorney-client relationship or provide legal advice. Prior results do not guarantee a similar outcome. Future developments may supersede this information. We invite you to contact the authors with any questions. © 2024 Anderson Kill P.C.

Related People
image
Cort T. Malone
View Moreimage
Related Practice Areas

© Copyright 2026 by Anderson Kill P.C. ClickySoft - WordPress Development Company