Skip to content

Cyber Liability by state

New Jersey data breach notification law and cyber insurance

Direct answer

What is New Jersey's data breach notification law?

New Jersey's breach notification law (N.J. Stat. sect. 56:8-161 et seq.) requires businesses to notify affected residents in the most expedient time possible and without unreasonable delay after a breach of personal information. New Jersey requires businesses to notify affected residents of breaches of unencrypted personal information without unreasonable delay, and to notify the State Police before consumers are informed.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

New Jersey requires businesses to notify affected residents of breaches of unencrypted personal information without unreasonable delay, and to notify the State Police before consumers are informed. Cyber liability insurance typically covers the forensics, notification, and legal review this statute drives.

Consumer notification deadline
In the most expedient time possible and without unreasonable delay
Regulator notice
Notify the New Jersey State Police, Division of State Police in the Department of Law and Public Safety, before notifying residents.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 1,000 residents.
Safe harbor
Notification is not required if the compromised data was encrypted or secured, or where an investigation finds misuse of the information is not reasonably possible.
Enforcement
Violations are unlawful practices under the state's consumer fraud law, enforceable by the Attorney General.

Statutes and sources

  • New Jersey Consumer Fraud, Security Breach Disclosure Law

    N.J. Stat. sect. 56:8-161 et seq.

Regulator: New Jersey Division of Consumer Affairs . Last verified 2026-07-29 from the official source .

Get New Jersey coverage handled

Share a few details and an agent will respond within one business day.