New Jersey · verified official-source register

New Jersey Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

New Jersey case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Marriott International, Inc.

Date
2024-10-09
Amount
$52 million settlement; New Jersey will receive just over $1.3 million
Legal basis
Data breach laws and consumer protection laws, including the New Jersey Consumer Fraud Act

Why the action was brought

States alleged Marriott misrepresented how it protected consumers’ personal information and failed to use adequate cybersecurity safeguards. Intruders accessed Starwood’s guest reservation database from 2014 to 2018, exposing contact information, gender, dates of birth, reservation information, preferences, passport numbers, and payment-card information. About 131.5 million Americans were impacted; a second incident exposed over 5.2 million guest records.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Blackbaud

Date
2023-10-05
Amount
$49.5 million; New Jersey will receive $1,083,802
Legal basis
state consumer protection laws; breach notification laws; the federal Health Insurance Portability and Accountability Act (“HIPAA”)

Why the action was brought

Blackbaud’s software stored Social Security numbers, driver’s license numbers, donation history, contact and demographic details, and financial, employment, and protected health information. It allegedly failed to implement reasonable security, remediate known gaps, and timely provide complete, accurate breach information after unauthorized network access in a 2020 ransomware attack, delaying or preventing consumer notification.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA)

Date
2021-03-11
Amount
$21 million to the participating states; payment is suspended due to the company’s financial situation unless it violates certain other settlement terms. No New Jersey share stated.
Legal basis
state consumer protection and data privacy laws

Why the action was brought

An unauthorized user accessed AMCA’s internal system from August 2018 through March 2019 and collected Social Security numbers, payment-card information, and sometimes medical-test names and diagnostic codes. AMCA allegedly violated state consumer-protection and data-privacy laws by failing to detect the eight-month intrusion despite warnings from banks, exposing information of more than seven million people, including over 246,000 New Jersey residents.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.