New Jersey adopted its own comprehensive privacy statute, the New Jersey Data Privacy Act, effective 15 January 2025. This page sets out what that law actually covers, where it draws its line around business-to-business data, and why lead.box is built to the stricter EU standard as its baseline rather than the New Jersey minimum.
At a glance
- Framework
- New Jersey Data Privacy Act (NJDPA), N.J. Stat. §56:8-166.4 et seq. (S332), effective 15 January 2025
- Supervision
- New Jersey Attorney General via the Division of Consumer Affairs, with rulemaking authority for future regulations
- Usual legal basis
- Legitimate business purpose; identification stays at company level and falls outside the NJDPA's consumer-focused definitions
- Processing location
- ISO-certified EU data centres
The New Jersey Data Privacy Act
Regulation at a glance
- FrameworkNew Jersey Data Privacy Act (NJDPA), N.J. Stat. §56:8-166.4 et seq. (S332), effective 15 January 2025
- SupervisionNew Jersey Attorney General via the Division of Consumer Affairs, with rulemaking authority for future regulations
- Usual legal basisLegitimate business purpose; identification stays at company level and falls outside the NJDPA's consumer-focused definitions
- Processing locationISO-certified EU data centres
The New Jersey Data Privacy Act, codified at N.J. Stat. §56:8-166.4 et seq. and originally enacted as S332, took effect on 15 January 2025. It applies to controllers that conduct business in New Jersey or produce products or services targeted at New Jersey residents, and that either control or process the personal data of at least 100,000 New Jersey consumers in a calendar year (excluding data processed solely to complete a payment transaction), or control or process the personal data of at least 25,000 consumers while deriving revenue from selling personal data or using it for targeted advertising. Unlike Virginia or Connecticut, the NJDPA sets no percentage-of-revenue floor on that second threshold, which means a comparatively small New Jersey-facing site that sells or advertises with visitor data can trigger coverage well before it would under those neighbouring statutes.
Enforcement rests solely with the New Jersey Attorney General, acting through the Division of Consumer Affairs; there is no private right of action. For the first 18 months after the effective date, the Attorney General was required to consider a 30-day cure period before initiating an enforcement action, but that cure right sunsets afterward and becomes purely discretionary. The Division also holds rulemaking authority under the statute, so businesses operating in New Jersey should expect implementing regulations to refine definitions and obligations over time rather than treating the statutory text as the final word.
The NJDPA also carries a notably broad definition of sensitive data: alongside the usual categories, it expressly names financial information — an account number, log-in credential, or credit or debit card number combined with any required access code — and transgender or non-binary status as sensitive data requiring opt-in consent to process. It further requires consent before processing the personal data of a known 13-to-17-year-old for targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects, a narrower carve-out than the blanket protections some other states apply only to under-13s.
Where B2B data sits outside the NJDPA
The NJDPA defines a 'consumer' as a New Jersey resident acting only in an individual or household context, and it explicitly excludes a person acting in a commercial or employment context — for example, an employee submitting a work email to a vendor's demo request form, or a company purchasing agent whose business contact details are exchanged during a sales process. That carve-out places purely business-to-business contact data outside the statute's consumer rights and most of its obligations, a structural feature the NJDPA shares with Virginia's VCDPA and Connecticut's CTDPA rather than with California.
California is the deliberate counterexample worth naming here: the CCPA/CPRA's temporary exemptions for B2B and employment-context personal information expired on 1 January 2023, so California now treats a business card handed over at a trade show, or a work email captured on a form, as personal information subject to the same consumer rights as any other California resident's data. New Jersey took the opposite path and kept its B2B exclusion intact when the NJDPA came into force, which is a meaningful distinction for any company running the same lead-capture forms nationally and assuming one rulebook covers every state.
Layered on top of that statutory question is a separate, third distinction that matters for a tool like lead.box: company-level visitor identification resolves the organisation behind a website visit — a company name, industry and size band derived from network-level signals — rather than a named individual at all. Whether New Jersey's B2B exclusion even needs to be invoked depends first on whether personal data tied to an identifiable person is involved in the first place, and identifying an organisation is a categorically different activity from identifying a person, regardless of which state's consumer definition applies.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
What this means for sales and marketing in New Jersey
New Jersey's economy along the Route 1 and I-95 corridor into New York runs heavily on pharmaceutical, life-sciences and logistics companies, sectors where procurement teams are accustomed to detailed vendor due diligence because their own regulatory environment — FDA-adjacent compliance, cold-chain and customs documentation — already demands it. A New Jersey buyer evaluating a visitor identification tool will typically ask the same questions their compliance team asks of any data vendor: what is collected, whether anything is sold or shared for targeted advertising under the NJDPA's now-broader 25,000-consumer threshold, and whether a data processing agreement is available.
New Jersey also joins the group of states requiring recognition of an opt-out preference signal, such as a browser-level universal opt-out mechanism, from six months after the NJDPA's effective date. That obligation is aimed at consumer-facing sale and targeted-advertising opt-outs and does not extend automatically to company-level identification that does not sell or share personal data, but sales and marketing teams building New Jersey-facing sites should still document how their broader tracking stack, if any, honours such signals.
In practice, a New Jersey sales team gets the most value from identification during the long, quiet research phase common to complex B2B and life-sciences sales cycles — when a buying committee reviews technical documentation and pricing across several sessions before a single form is submitted. Surfacing the company name during that window lets a rep reach out while the evaluation is still open, which matters more in a corridor where competing vendors are often only a short drive or a train ride away.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
The NJDPA governs personal data tied to a New Jersey consumer acting in an individual or household context, with thresholds around controllers processing 100,000 or more New Jersey consumers' data annually, or 25,000 or more where the controller sells personal data or uses it for targeted advertising — notably with no revenue-percentage floor on that second prong, unlike Virginia or Connecticut. lead.box resolves the visiting company from network-level signals such as IP address ranges, returning an organisation name, industry and size band rather than identifying a named person, cookie identifier, or advertising profile. Because that output is not tied to an identified or identifiable individual, it sits outside the category of data the NJDPA's consumer rights provisions were written to address. Confirming that against your own broader data flows remains your responsibility as controller; lead.box provides documentation to support that review but this is not legal advice.
No, and this is one of the sharper contrasts between New Jersey and California privacy law. The NJDPA defines 'consumer' as a New Jersey resident acting only in an individual or household context and expressly excludes a person acting in a commercial or employment context, so a work email submitted on a demo request form or a purchasing manager's business card generally falls outside the statute's consumer rights obligations. California took the opposite route: its temporary B2B and employee exemptions under the CCPA/CPRA expired on 1 January 2023, so equivalent business contact data is now fully in scope there. A national sales organisation running the same lead-capture forms in both states needs to track that difference rather than assume one privacy policy answers for every state, since New Jersey's B2B carve-out and California's full coverage produce genuinely different obligations from the same underlying data.
The NJDPA is built around personal data linked to an identified or identifiable natural person — name, device identifiers, precise geolocation and the like — and around a defined 'consumer' acting in a personal, non-commercial capacity. lead.box operates one layer up from that: it maps network-level signals from a website visit to the visiting organisation, producing a company name, industry and size band without resolving, storing or exporting any named individual's identity. That is a categorically different exercise from identifying a person, and it holds regardless of whether the visitor happens to be acting in a personal or business context, or whether the NJDPA's B2B exclusion would apply to them individually. Distinguishing 'which company visited' from 'which person visited' is the cleanest way to explain the tool to a legal reviewer working through New Jersey's statutory definitions, and it is a distinction worth stating explicitly in any internal privacy assessment.
The NJDPA's definition of sensitive data is broader than several comparable state statutes: alongside racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, and precise geolocation, it expressly includes financial information — an account number, log-in credential, or a credit or debit card number combined with a required access code — and transgender or non-binary status, all of which require opt-in consent before processing. lead.box does not collect financial account details, login credentials, health information or any of the other sensitive categories the NJDPA names; it works from network-level identifiers to resolve a visiting organisation. That said, any sensitive data your own site collects elsewhere — through checkout flows, account portals or intake forms — falls squarely under this heightened consent requirement, and it is worth reviewing those separate flows against the NJDPA's sensitive-data list independently of any visitor identification tooling.
In one specific respect, yes. Virginia's VCDPA and Connecticut's CTDPA both pair a lower 25,000-consumer threshold with a requirement that the controller derive over 50% of gross revenue from selling personal data, which keeps that lower tier narrowly targeted at data-broker-style businesses. The NJDPA drops that revenue-percentage condition entirely: any controller processing 25,000 or more New Jersey consumers' personal data while selling it or using it for targeted advertising can be covered, regardless of how small a share of overall revenue that activity represents. For a marketing or sales operation running paid advertising campaigns using New Jersey visitor data, that means the NJDPA can apply at a meaningfully smaller organisational scale than its regional neighbours, which is worth flagging to counsel specifically rather than assuming the same thresholds apply across all three states.
Enforcement authority sits exclusively with the New Jersey Attorney General, acting through the Division of Consumer Affairs; the NJDPA does not create a private right of action, so individual consumers cannot sue directly under the statute. For the first 18 months after the 15 January 2025 effective date, the Attorney General was directed to consider granting a controller a 30-day cure period before pursuing an enforcement action, but that mandatory consideration period sunsets after those 18 months, after which any cure opportunity becomes fully discretionary. The Division of Consumer Affairs also has rulemaking authority under the statute, so businesses with New Jersey-facing operations should watch for implementing regulations that may refine definitions, consent mechanics, or documentation expectations beyond what the statutory text alone specifies.
Yes — the NJDPA requires controllers to recognize an opt-out preference signal, such as a browser or device-level universal opt-out mechanism, for exercising a consumer's right to opt out of targeted advertising, sale of personal data, or certain profiling, and that requirement took effect six months after the statute's 15 January 2025 effective date. That obligation is directed at consumer-facing tracking used for advertising or sale of personal data. lead.box does not sell personal data or use visitor data for targeted advertising and does not build a persistent individual-level profile, so it sits outside the specific data flows that universal opt-out signals are designed to interrupt. Sites should still review their broader analytics and advertising stack for opt-out-signal compliance independently of any company-level identification tool they run alongside it.
Companies in New Jersey's pharmaceutical, life-sciences and logistics sectors typically run more rigorous vendor due diligence than average, given the regulatory scrutiny already applied to their core operations, so it is reasonable to expect the same rigor applied to a visitor identification tool. Useful questions include: what specific data points are collected from a visit, whether any output is sold or shared for advertising, whether a data processing agreement and sub-processor list are available, and where processing occurs. lead.box resolves visiting organisations rather than named individuals, does not sell or share personal data, processes data in ISO-certified EU data centres, and provides a standard processing agreement on request. Confirming how that fits your specific NJDPA obligations, particularly if you separately collect sensitive data such as financial or health information elsewhere on your site, should still involve your own counsel rather than relying on general product documentation.
See which New Jersey companies are already on your site
Install a first-party snippet, watch the first companies appear, and hand your legal team the same documentation a European customer would ask for.