This bill establishes privacy protections for sensitive consumer health data in New Jersey, directly affecting residents, healthcare providers, and entities handling health information. It requires explicit, informed consent for collecting or using health data (prohibiting deceptive designs or broad terms of service) and defines "consumer health data" to include medical conditions, genetic information, biometrics, reproductive health details, and location data tied to health services. Key provisions mandate that businesses must authenticate requests to exercise privacy rights and prohibit sharing data without consent, while excluding research data processed under institutional review board oversight. The law applies to all entities collecting health data from New Jersey residents or processing data linked to New Jersey consumers.
This New Jersey bill prohibits public and private entities from collecting, storing, or sharing biometric data (like facial recognition, fingerprints, or voice patterns) without clear notice. It requires entities to post plain-language signs at all entry points if they use biometric systems, directly affecting businesses, schools, and government agencies that currently use such technology. Violations carry $5,000 fines for first offenses, $10,000 for repeat violations, and repeated offenses (five or more in 30 days) may become criminal charges punishable by fines up to $15,000 or imprisonment. The bill defines "biometric identifier information" as data from systems identifying people via unique physical traits.
This resolution establishes the Assembly Select Committee on COVID-19 Contact Tracing Data Privacy to examine how personal data collected through contact tracing during the pandemic is handled. The committee, made up of nine Assembly members (five appointed by the Speaker, four by the Minority Leader), will study data collection, storage, usage, and privacy safeguards to balance public health needs with individual privacy rights. It must submit findings and recommendations within 60 days of organizing, with the resolution ending 30 days after the report is delivered. The committee’s work will inform potential future policies on protecting contact tracing data privacy.
This bill prohibits health care providers, mobile app developers, and third parties from collecting or sharing New Jersey residents' personal health data - including biometric information like heart rate, sleep patterns, or menstrual cycles, and health records - without explicit consent. It requires consent before initial collection and within three days before each disclosure, though ongoing consent covers repeated collection if previously authorized. Exceptions apply for medical treatment between health providers. Violations could result in $1,000 penalties per violation, without affecting existing HIPAA protections.
This proposed bill (A 3065) would establish a legal right for New Jersey residents to control how their name, image, likeness, or voice is used commercially. It grants individuals (living or deceased) the ability to sue businesses or others who use these elements without permission for advertising, fundraising, or other commercial purposes - including digital uses like AI-generated voice replicas. After death, these rights would pass to heirs for 10 years (unless extended), allowing them to enforce the ban on unauthorized use. The law would require explicit consent from the individual, their guardian (for minors), or their estate (for deceased persons) before commercial use can occur.
This bill requires Internet service providers (ISPs) in New Jersey to keep subscribers' personally identifiable information confidential unless the subscriber provides written authorization to share it. It defines "personally identifiable information" broadly to include names, addresses, phone numbers, browsing history, location data, and communication contents. ISPs must notify subscribers in writing about this requirement and cannot deny service for refusing to authorize disclosure. Exceptions apply for routine business activities (like order fulfillment) or disclosures required by law under New Jersey's wiretapping regulations.
This bill amends New Jersey's data breach law to require businesses and public entities to disclose security breaches involving geolocation data. It adds "geolocation" (the location of an individual determined by electronic devices like phones or tablets) to the legal definition of "personal information," which already includes Social Security numbers and financial account details. Under the change, if a breach compromises geolocation data, the entity must notify affected consumers, just as they currently must for other personal information breaches. This expands existing disclosure requirements to cover location data collected by apps, services, or devices.
This bill, the New Jersey Disclosure and Accountability Transparency Act (NJ DaTA), creates new rules for how businesses handle personal data in New Jersey. It requires businesses (called "controllers") to get clear, active permission ("affirmative opt-in") from New Jersey residents before collecting or processing their personal information, and gives residents the right to access, correct, or delete their data. The bill also establishes a new Office of Data Protection within the Division of Consumer Affairs to enforce these rules and ensure businesses comply. It directly affects businesses that collect personal data from New Jersey residents, including online services, apps, and other entities handling consumer information.
This bill prohibits mobile service providers and app developers from sharing customers' GPS location data with third parties without explicit consent. To obtain consent, app developers must provide a clear, bold notice requiring users to actively agree ("I agree to allow my location data to be disclosed"). Exceptions apply for legal requirements like law enforcement requests, and third parties accessing the data cannot sell it or share it beyond the purpose of the consent. Violations would violate New Jersey's consumer fraud law, potentially resulting in fines up to $20,000 per offense. The bill is pending in the Assembly Consumer Affairs Committee.
The "Digital Impersonation Prevention Act" (A4422) makes it a crime to knowingly impersonate a real person online without their consent, specifically when done to harm others, send unsolicited spam or ads, or access their personal contact list. It criminalizes creating fake email or social media accounts in someone else's name, altering digital messages to appear as if they came from another person, or using impersonation to transmit unsolicited commercial messages. Violators face fines up to $1,000, up to one year in jail, or both. Victims can also sue for $500 per incident plus additional damages and seek court orders to stop the impersonation. The law does not hold internet service providers liable unless they personally commit the impersonation.