Requires controller or processor to de-identify personal data and prohibits re-identification of de-identified data.
This bill (S 4315) requires businesses that collect personal data (called "controllers" or "processors" under the law) to de-identify personal data before selling it. It prohibits these businesses from re-identifying de-identified data themselves or providing third parties with means to re-identify such data. The bill mandates the New Jersey Division of Consumer Affairs to establish standards for de-identification, with limited exceptions allowed only for medical research or environmental protection purposes. These requirements apply to most businesses handling personal data in New Jersey, with specific exemptions for healthcare, financial services, and government entities.
Bill status
in committee
1 of 4 stages cleared
Introduction
May 2025
Committee Review
Floor Vote
Governor
Introduced May 12, 2025
Last action May 12, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
1
Key actions
0
Committee
0
May 12, 2025
Introduced
Introduced in the Senate, Referred to Senate Commerce Committee
upper
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Joe Pennacchio
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about S 4315
Scope: NJ
Hi! I can help you understand S 4315. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline