New Jersey Moves Forward With Shopper Privacy Bill
Time 2 Minute Read

On September 15, 2016, the New Jersey Senate unanimously approved a bill that seeks to limit retailers’ ability to collect and use personal data contained on consumers’ driver and non-driver identification cards. The bill, known as the Personal Information and Privacy Protection Act, must now be approved by the New Jersey Assembly.

Under the bill, retail establishments may scan an individual’s identification card (i.e., use an electronic device capable of deciphering, in an electronically readable format, information electronically encoded on the identification card) only for the following purposes:

  • to verify the authenticity of the identification card or to verify the identity of the person if the person pays for goods or services with a method other than cash, returns an item, or requests a refund or an exchange;
  • to verify the person’s age when providing age-restricted goods or services to the person;
  • to prevent fraud or other criminal activity if the person returns an item or requests a refund or an exchange and the business uses a fraud prevention service company or system;
  • to establish or maintain a contractual relationship;
  • to record, retain or transmit information as required by state or federal law;
  • to transmit information to a consumer reporting agency, financial institution or debt collector to be used as permitted by the Fair Credit Reporting Act, the Gramm-Leach Bliley Act and the Fair Debt Collection Practices Act; or
  • to record, retain or transmit information by a covered entity governed by the medical privacy and security rules pursuant to the Health Insurance Portability and Accountability Act of 1996.

The bill also would limit the types of information that retailers may scan from an individual’s identification card to name, address, date of birth, the state issuing the identification card and the identification card number. In addition, the bill (1) places limitations on retaining the relevant information; (2) imposes a data security requirement; (3) reiterates retailers’ obligation under New Jersey’s data breach notification law to notify affected residents and the relevant New Jersey regulator in the event of any breach of the security of the information; and (4) prohibits retailers from selling the relevant information to third parties.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page