Who Is Covered?
Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information. N.J. Stat. § 56:8-163(a).
What Information Is Protected?
“Personal information” means an individual’s first name or first initial and last name linked with any one or more of the following data elements:
- Social security number;
- Driver’s license number or State identification card number;
- Account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
- User name, email address, or any other account holder identifying information, in combination with any password or security question and answer that would permit access to an online account. N.J. Stat. § 56:8-161.
What Is A “Breach”?
“Breach of security” means unauthorized access to electronic files, media or data containing personal information that compromises the security, confidentiality or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable. N.J. Stat. § 56:8-161.
What Triggers Notification?
Discovery or notification of a breach of a New Jersey resident’s personal information that was, or is reasonably believed to have been, accessed by an unauthorized person. N.J. Stat. § 56:8-163(a).
Likelihood of Harm Analysis: Disclosure of a breach of security to a customer shall not be required under this section if the business or public entity establishes that misuse of the information is not reasonably possible. Any determination shall be documented in writing and retained for five years. N.J. Stat. § 56:8-163(a).
How Is Notice Provided To Individuals?
Timing: Following notice to the government described below, in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. N.J. Stat. § 56:8-163(a).
Delivery: Notification may be by:
- Written notice;
- Electronic notice, if the notice provided is consistent with the provisions of the E-Sign Act; or
- Substitute notice, if the business or public entity demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or the business or public entity does not have sufficient contact information. Substitute notice shall consist of all of the following: (a) Email notice when the business or public entity has an email address; (b) Conspicuous posting of the notice on the Internet web site page of the business or public entity, if the business or public entity maintains one; and (c) Notification to major statewide media. N.J. Stat. § 56:8-163(d).
In the case of a breach of security involving a user name or password, in combination with any password or security question and answer that would permit access to an online account, the business or public entity may provide the notification in electronic or other form that directs the customer whose personal information has been breached to promptly change any password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the business or public entity and all other online accounts for which the customer uses the same user name or email address and password or security question or answer. N.J. Stat. § 56:8-163(g)(1).
Content: None specified.
Is Notice To The Government Required?
Yes. Any business or public entity required under this section to disclose a breach of security of a customer’s personal information shall, in advance of the disclosure to the customer, report the breach of security and any information pertaining to the breach to the Division of State Police in the Department of Law and Public Safety for investigation or handling, which may include dissemination or referral to other appropriate law enforcement entities. N.J. Stat. § 56:8-163(c).
Is Notice To Credit Reporting Agencies Required?
Yes. In addition to any other disclosure or notification required under this section, in the event that a business or public entity discovers circumstances requiring notification pursuant to this section of more than 1,000 persons at one time, the business or public entity shall also notify, without unreasonable delay, all consumer reporting agencies of the timing, distribution and content of the notices. N.J. Stat. § 56:8-163(f).
Are There Security Measure Standards?
No. However, a separate section provides that a business or public entity shall destroy, or arrange for the destruction of, a customer’s records within its custody or control containing personal information, which is no longer to be retained by the business or public entity, by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable, undecipherable or nonreconstructable through generally available means. N.J. Stat. § 56:8-162.
What Are The Possible Consequences Of A Violation?
Willfully, knowingly or recklessly violating these provisions is an unlawful practice and a violation of N.J. Stat. § 56:8-1, et seq. N.J. Stat. § 56:8-166.
Are There Any Exemptions/Exceptions?
A business or public entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and is otherwise consistent with the requirements of this section, shall be deemed to be in compliance with the notification requirements of this section if the business or public entity notifies subject customers in accordance with its policies in the event of a breach of security of the system. N.J. Stat. § 56:8-163(e).
