Bill
Bill > A4093
NJ A4093
NJ A4093Requires certain persons and business entities to maintain comprehensive information security program.
summary
Introduced
02/19/2026
02/19/2026
In Committee
02/19/2026
02/19/2026
Crossed Over
Passed
Dead
Introduced Session
2026-2027 Regular Session
Bill Summary
This bill requires any person, corporation, association, partnership or other legal entity that owns or licenses personal information about a resident of this State to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are necessary to protect the personal information. The bill provides that it would be an unlawful practice under the consumer fraud act, P.L.1960, c.39 (C.56:8-1 et seq.), to willfully, knowingly or recklessly violate the provisions of the bill. An unlawful practice is punishable by a monetary penalty of not more than $10,000 for a first offense and not more than $20,000 for any subsequent offense. Additionally, a violation can result in ceaseand desist orders issued by the Attorney General, the assessment of punitive damages, and the awarding of treble damages and costs to those injured as a result of the violation.
AI Summary
This bill requires any person or business entity that owns or licenses personal information about a resident of the State to establish and maintain a comprehensive information security program. This program must include administrative, technical, and physical safeguards appropriate to the business's size, resources, and the amount of data it handles, and must be designed to protect the confidentiality and integrity of personal information. Key components of the program include designating employees to oversee security, identifying and assessing risks, providing employee training, implementing security policies for remote work, imposing disciplinary measures for violations, preventing terminated employees from accessing data, overseeing service providers through contracts and due diligence, restricting physical access to records, regularly monitoring systems, annually reviewing security measures, and documenting responses to security incidents. For electronic data, the program must also include secure user authentication, access controls, encryption of data transmitted wirelessly or over public networks, encryption of data on laptops and portable devices, firewall protection, up-to-date security software, and employee education on computer security. Violating these provisions will be considered an unlawful practice under the consumer fraud act, punishable by monetary penalties, cease and desist orders, and potential damages for those harmed.
Committee Categories
Business and Industry
Sponsors (1)
Last Action
Introduced, Referred to Assembly Commerce and Economic Development Committee (on 02/19/2026)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
| Document Type | Source Location |
|---|---|
| State Bill Page | https://www.njleg.state.nj.us/bill-search/2026/A4093 |
| BillText | https://pub.njleg.gov/Bills/2026/A4500/4093_I1.HTM |
Loading...