A 3339 New Jersey General Assembly · 2026-2027 Regular Session

Revises requirements for disclosure of a breach of security of certain computerized records containing personal information.

This New Jersey bill (A 3339) revises disclosure rules for security breaches involving personal information. It requires businesses and public entities handling New Jersey residents' data to notify affected customers within five business days of discovering a breach - unless law enforcement needs a delay or further investigation is needed. The bill clarifies that businesses may skip notification only after a proper investigation and consultation with law enforcement, and specifies acceptable notification methods (written, electronic, or substitute notice for large-scale breaches). It also mandates notifying national credit bureaus if over 1,000 people are affected. The law directly affects any company or government entity maintaining computerized personal records in New Jersey.
Bill status in committee 1 of 4 stages cleared
Introduction
Jan 2026
Committee Review
Floor Vote
Governor
Introduced Jan 13, 2026 Last action Jan 13, 2026
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
1
Key actions
0
Committee
0
Jan 13, 2026
Introduced
Introduced, Referred to Assembly Consumer Affairs Committee
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Sterley Stanley
Sterley Stanley
DDemocratic
NJ
18