What NJDPA says about fingerprinting
New Jersey Senate Bill 332 (2024) was signed into law and codified at N.J.S.A. 56:8-166.4 through 56:8-166.20. It took effect on 15 January 2025, making New Jersey one of the last large-population states to enact a comprehensive privacy law - and one of the strictest. NJDPA is not a copy of the Virginia template. Where VCDPA narrowed the sensitive-data list and CCPA broadened opt-out rights, NJDPA synthesised the most expansive provisions of both and added three differentiators found in no other state law.
The statute does not use the word 'fingerprinting'. It defines personal data at N.J.S.A. 56:8-166.5 as 'any information that is linked or reasonably linkable to an identified or identifiable natural person'. A browser or device fingerprint hash - composed of canvas output, GPU strings, font enumeration, audio context, time zone, screen resolution, and similar device signals - satisfies that test the moment a controller uses it to recognise a returning New Jersey consumer. Linkability, not formal identification, is the test.
What distinguishes NJDPA from every other state law is what happens next. The sensitive-data regime, the minor-protection rule, and the applicability threshold each operate at a different level of strictness than any comparable jurisdiction. Controllers that have mapped their obligations for VCDPA or CPA and assumed NJDPA is similar will find material gaps.
When NJDPA applies to you
N.J.S.A. 56:8-166.6 applies the law to controllers that conduct business in New Jersey or produce products or services targeted to New Jersey consumers, and meet one of two thresholds: (a) control or process the personal data of 100,000 or more New Jersey consumers in a calendar year, OR (b) control or process the personal data of 25,000 or more New Jersey consumers AND derive revenue, or a discount on the price of goods or services, from the sale of personal data.
The second leg is where NJDPA diverges from VCDPA and matches Colorado's CPA. VCDPA requires that more than 50% of gross revenue come from selling personal data. NJDPA and CPA require only any revenue from sale. A vendor that earns 3% of its revenue selling fingerprint-derived audience segments and touches 30,000 New Jersey consumers is inside NJDPA, outside VCDPA, and on the same footing as Colorado.
NJDPA defines 'sale' at N.J.S.A. 56:8-166.5 as the exchange of personal data for 'monetary or other valuable consideration' - matching CPA, not VCDPA. Non-monetary data sharing for mutual lift, data-for-services arrangements, and promotional consideration all potentially qualify as sale in New Jersey.
Consumer is defined as a New Jersey resident acting in an individual or household capacity. Employees, B2B contacts, and persons acting in a commercial context are excluded, matching the standard cluster carve-outs.
The opt-in rule for known children up to age 17
The most operationally unusual provision in NJDPA is N.J.S.A. 56:8-166.8, which requires opt-in consent before processing the personal data of a consumer the controller knows or has reason to know is under the age of 18. This is not a COPPA provision - COPPA covers under-13, applied to COPPA-covered operators. NJDPA's rule applies to any fingerprinting controller, covers up to age 17, and is an opt-in requirement, not merely a prohibition on targeted advertising.
In practical terms, this means that a fingerprinting deployment on a consumer-facing platform where some users may be teenagers cannot treat those users on the same basis as adult users. If the controller has any reasonable basis to know that a user is under 18 - account registration data, a self-declared age, an age-gate result, or any contextual signal - the controller must obtain verifiable consent before fingerprinting that user for any regulated purpose.
No other US state law has a comparable provision. CCPA restricts sale and targeted advertising for under-16 (and requires parental consent for under-13), but does not impose a blanket opt-in for all fingerprinting. NJDPA's under-18 rule applies to all regulated processing, not just sale and targeted advertising.
The three opt-out rights and how they apply to fingerprinting
N.J.S.A. 56:8-166.8 grants New Jersey consumers rights to access, correction, deletion, portability, and opt-out. The opt-out right covers three categories: targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects.
Targeted advertising under N.J.S.A. 56:8-166.5 means displaying advertisements selected based on personal data obtained from the consumer's activities across non-affiliated websites or applications over time. A fingerprint used to recognise a returning visitor and serve cross-site behavioural ads is squarely inside this definition. First-party frequency capping, contextual advertising, and on-site retargeting on your own domain are excluded.
Sale of personal data under NJDPA is the 'monetary or other valuable consideration' standard - the same broader definition as Colorado, not Virginia's monetary-only definition. Sharing fingerprint hashes with an ad-tech partner for non-cash consideration - data for service, audience for reciprocal data - is more likely to qualify as sale under NJDPA than under VCDPA.
NJDPA's profiling definition covers automated decisions in employment, education, healthcare, housing, financial services, and, notably, access to essential goods and services including housing, utilities, and food. This 'essential goods' extension is broader than VCDPA's profiling scope. A fingerprint used as one input to a real-time decisioning system that governs access to any essential service falls within the opt-out right for profiling under NJDPA.
Common fingerprinting purposes under NJDPA
| Purpose | Personal data under NJDPA? | DPA required? | Opt-out or opt-in? |
|---|---|---|---|
| Anti-fraud at login or payment | Yes | No (not heightened-risk processing) | No opt-out required |
| Account-takeover detection | Yes | No | No opt-out required |
| Bot mitigation on a public form | Yes | No | No opt-out required |
| Cross-site targeted advertising | Yes | Yes | Opt-out required (GPC honoured) |
| Sharing fingerprint hashes for 'other valuable consideration' | Yes | Yes | Opt-out required (sale under NJDPA) |
| Fingerprint joins to NJ-LAD-protected-class attributes | Yes - sensitive data | Yes | Opt-in consent required |
| Fingerprint joins to financial account numbers or login credentials | Yes - sensitive data | Yes | Opt-in consent required |
| Profiling for credit, housing, utilities, food access, or employment decisions | Yes | Yes | Opt-out required (profiling with significant effect) |
| Processing data of a known user under age 18 | Yes | Yes | Opt-in consent required for all regulated purposes |
| Product analytics on your own service (no sale, no targeting) | Yes | No | No opt-out required |
| Frequency capping on your own site | Yes | No | No (first-party carve-out) |
Data Protection Assessments under NJDPA
N.J.S.A. 56:8-166.13 requires a Data Protection Assessment (DPA) before engaging in targeted advertising, sale of personal data, processing of sensitive data, profiling that presents a reasonably foreseeable risk, and any other processing that presents a heightened risk of harm. The assessment must weigh the benefits of the processing against the risks to the consumer and must be retained and made available to the NJ AG on request.
For a fingerprinting deployment used for targeted advertising, an adequate NJDPA DPA identifies the signal categories collected (canvas, GPU, fonts, audio context, etc.), the hash construction and collision rate, the retention window, the recipients (including any downstream ad-tech partners), whether the fingerprint is joined to any NJDPA-sensitive attribute, the de-identification claim if any, and the consumer-facing transparency and opt-out mechanism. Given the expanded sensitive-data list, the DPA should explicitly confirm which downstream data joins are in scope - a join to a financial account database, for example, converts the fingerprint from standard personal data to sensitive data mid-pipeline.
The 'heightened risk' catch-all in N.J.S.A. 56:8-166.13 is broader than any other state law's DPA trigger. In VCDPA, the DPA is only required for the four named categories. In NJDPA, the AG can interpret 'heightened risk' to cover processing that, for example, combines fingerprint data with location patterns in ways that indirectly reveal a consumer's protected-class membership.
Universal Opt-Out Mechanism and GPC recognition
From 15 July 2025, N.J.S.A. 56:8-166.11 requires controllers that engage in targeted advertising or sale of personal data to recognise Universal Opt-Out Mechanisms. The AG has designated Global Privacy Control (GPC) as a recognised UOOM. A fingerprinting deployment that fires before checking the GPC signal on a New Jersey browser is in violation of N.J.S.A. 56:8-166.11, regardless of whether the consumer ever used an on-site opt-out link.
The operational requirement is straightforward: the fingerprint API call for targeted-advertising or sale-flagged purposes must be gated behind a GPC header check at the application layer. The anti-fraud and analytics calls do not require this gate, because those purposes are not targeted advertising or sale, but the data flows must be architecturally separated so the gate on the regulated path does not break the exempt path.
The cure period: sunset on 15 July 2025
NJDPA originally included a 30-day right to cure after the NJ AG issued a notice of violation. That cure period sunset on 15 July 2025. As of the date of this page (June 2026), the NJ AG Division of Consumer Affairs can pursue enforcement immediately on identifying a violation, without first issuing a cure notice.
The sunset brings NJDPA into line with Colorado's post-1-July-2025 enforcement posture. The 'fix it when we get the letter' compliance model no longer applies. Controllers that have not completed their DPAs, installed GPC gating, and audited their sensitive-data pipelines are exposed to first-strike penalties under both the NJDPA and the parallel NJ Consumer Fraud Act.
Enforcement contexts
- The NJ AG Division of Consumer Affairs is the primary NJDPA enforcement body. The Division has long-standing authority under the NJ Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.) and has issued privacy-related enforcement actions under that framework before NJDPA took effect - providing an established institutional posture for consumer data enforcement.
- NJDPA penalties are layered with the NJ Consumer Fraud Act. A fingerprinting violation that also involves deceptive practices - such as claiming in a privacy notice that fingerprints are not collected when they are - can be pursued under both NJDPA and the CFA, with CFA penalties of up to $10,000 per first offense and $20,000 per subsequent offense.
- The NJ Consumer Fraud Act has a private right of action for treble damages when a consumer can demonstrate actual loss. This creates a litigation pathway for fingerprinting-related claims that goes beyond AG-only enforcement, distinguishing NJDPA from VCDPA and CPA where enforcement is AG-exclusive.
- The Division of Consumer Affairs has publicly stated that it will prioritise enforcement of the sensitive-data and minor-protection provisions in the first year of NJDPA enforcement (2025-2026), signalling that financial-data joins and under-18 processing are early targets.
How Benny the Doorman fits into an NJDPA-aware deployment
Benny is a fingerprinting SDK and hosted API. Three integration steps matter specifically for NJDPA.
First, gate all targeted-advertising and sale-purpose Benny calls behind a GPC header check and your own preference-centre flag. From 15 July 2025 this is not optional. The anti-fraud and analytics calls do not need this gate, but they must be implemented as separate data flows with separate retention windows and access scopes so the opt-out on the regulated flow does not break the exempt flow.
Second, audit every downstream pipeline that receives a Benny fingerprint hash. NJDPA's sensitive-data list is longer than any other state law. If the fingerprint hash is later joined to a dataset that includes financial account numbers, login credentials, or any attribute that could reveal a consumer's NJ-LAD-protected-class membership, that downstream join converts the processing to sensitive-data processing and triggers the opt-in consent requirement. The DPA for the targeted-advertising flow should explicitly map every known downstream recipient and join key.
Third, if your platform has any population of known users under 18 - via age-gate data, account registration, or any contextual signal - treat all regulated processing of those users as requiring opt-in consent. Benny's per-call architecture allows the consent flag to be passed at invocation time, so the integration pattern is to check consent before calling the API, not to suppress the signal post-collection.
Frequently asked questions
Is browser fingerprinting illegal under NJDPA?
No. Fingerprinting is not banned under the New Jersey Data Privacy Act. It is regulated as personal data when the fingerprint can be reasonably linked to a New Jersey consumer. Lawful use requires honouring opt-out requests for targeted advertising, sale, and covered profiling; obtaining opt-in consent when the fingerprint pipeline touches sensitive data or involves a known user under age 18; completing a Data Protection Assessment before deploying fingerprinting for regulated purposes; and recognising Global Privacy Control as a valid opt-out signal from 15 July 2025.
Why is NJDPA's sensitive-data definition broader than other state laws?
NJDPA includes several categories not found in VCDPA, CPA, or CCPA. Most notably, it adds financial information (account numbers and login credentials), transgender or non-binary status, and - uniquely - status as a member of a class protected under the New Jersey Law Against Discrimination. NJ LAD covers over a dozen protected characteristics including affectional or sexual orientation, gender identity, marital status, and liability for military service. Any fingerprinting pipeline that joins a fingerprint hash to data revealing any of these characteristics requires opt-in consent, regardless of whether those attributes were the intended collection target.
Does NJDPA require opt-in consent for processing data of teenagers?
Yes. N.J.S.A. 56:8-166.8 requires opt-in consent before processing the personal data of a consumer the controller knows or has reason to know is under 18 years of age. This is broader than COPPA's under-13 rule and broader than any comparable US state law. CCPA restricts sale and targeted advertising for under-16 but does not impose a blanket opt-in for all regulated processing. If your platform has account data, age-gate results, or any contextual signal indicating a user is a teenager, all regulated fingerprinting of that user requires opt-in consent under NJDPA.
How does NJDPA's applicability threshold differ from VCDPA?
The 100,000-consumer leg is the same. The second leg is where they diverge. VCDPA requires that more than 50% of the controller's gross revenue come from selling personal data before the 25,000-consumer threshold applies. NJDPA requires only any revenue from the sale of personal data, matching Colorado's CPA. A vendor that earns 5% of its revenue selling fingerprint-derived audience data and processes 30,000 New Jersey consumers falls inside NJDPA but outside VCDPA.
Do I have to honour Global Privacy Control under NJDPA?
Yes, from 15 July 2025. N.J.S.A. 56:8-166.11 requires controllers that engage in targeted advertising or sale of personal data to recognise Universal Opt-Out Mechanisms. The NJ AG has designated GPC as a recognised UOOM. A fingerprinting deployment that ignores a GPC signal from a New Jersey browser is in violation regardless of whether the consumer ever manually used an on-site opt-out link.
Can the NJ Consumer Fraud Act increase exposure beyond NJDPA penalties?
Yes, and this is one of NJDPA's most significant distinctions from peer state laws. The NJ Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.) allows the AG to pursue civil penalties of up to $10,000 per first offense and $20,000 per subsequent offense, and private plaintiffs can bring CFA claims for treble actual damages. A fingerprinting disclosure violation - for example, claiming in a privacy notice that fingerprints are not collected when they are - can generate concurrent NJDPA and CFA liability, and the CFA's private right of action means class-action exposure that VCDPA and CPA do not carry.
What does a Data Protection Assessment need to cover for NJDPA fingerprinting?
N.J.S.A. 56:8-166.13 requires the assessment to weigh the benefits of the processing against the risks to the consumer. For a fingerprinting deployment, the DPA should identify the signal categories collected, the hash construction and retention window, the downstream recipients of the hash, an explicit check of whether any downstream join produces NJDPA-sensitive data (particularly financial data or NJ-LAD-attribute data), the de-identification claim if any, and the consumer-facing opt-out and consent mechanisms. NJDPA's 'heightened risk' catch-all triggers a DPA for processing beyond the four named categories, so any fingerprint pipeline with novel downstream uses should be assessed individually.
How is NJDPA different from CCPA for fingerprinting?
Three meaningful differences. NJDPA's sensitive-data definition includes NJ-LAD protected classes, financial credentials, and transgender status - none of which are CCPA sensitive categories. NJDPA's under-18 opt-in rule covers all regulated fingerprinting purposes; CCPA's analogous provisions are narrower (under-16 for sale, under-13 for parental consent). NJDPA has no private right of action for data-breach scenarios comparable to CCPA's private right, but the concurrent NJ Consumer Fraud Act provides a private litigation pathway for deceptive-practice fingerprinting claims. Maximum penalties under NJDPA are lower headline numbers than CCPA's $7,500 per intentional violation, but the CFA's per-subsequent-offense $20,000 cap can compound quickly across a large consumer population.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

