GRC

NJ data breach notification

Under N.J.S.A. 56:8-163, a New Jersey business that suffers a breach of computerized personal information must notify the state police in advance of notifying customers, and must notify affected individuals "in the most expedient time possible and without unreasonable delay" — the statute sets no fixed day count.

For small firms

Build the state police notification step into your incident response plan now; it's easy to miss because it comes before, not after, customer notice.