Loading chat...

NJ A3339

Bill

Status

Introduced

1/13/2026

Primary Sponsor

Sterley Stanley

Click for details

Origin

General Assembly

2026-2027 Regular Session

AI Summary

  • Requires businesses and public entities in New Jersey to notify customers of data breaches within five business days, establishing a specific deadline where current law only requires notification "without unreasonable delay"

  • Maintains existing exceptions allowing delayed notification for legitimate law enforcement needs or when determining the scope of the breach and restoring data system integrity

  • Mandates that businesses or public entities must conduct an appropriate investigation and consult with relevant federal, state, and local law enforcement agencies before determining that breach disclosure is unnecessary due to low risk of information misuse

  • Amends the Identity Theft Prevention Act (P.L.2005, c.226) and applies to any business operating in New Jersey or public entity that maintains computerized records containing personal information

Legislative Description

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

Consumer Affairs

Last Action

Introduced, Referred to Assembly Consumer Affairs Committee

1/13/2026

Committee Referrals

Consumer Affairs1/13/2026

Full Bill Text

No bill text available