Faegre Drinker Biddle & Reath LLP, a Delaware limited liability partnership | This website contains attorney advertising.
July 23, 2026

New Jersey Enacts Sweeping Data Broker and Data Collector Registration Law

Businesses Must Assess Data Disclosure Practices and Prepare for New Registration Requirements and an Immediate Ban on Sensitive Data Sales

At a Glance

  • On June 30, 2026, New Jersey enacted A5328, P.L.2026, c.25, a law that significantly expands regulatory oversight of businesses that sell consumers’ personal data.
  • The law establishes the most comprehensive data broker and data collector regime adopted in the US to date, covering not only “data brokers” (entities that sell personal data about consumers with whom they have no direct relationship) but also “data collectors” (businesses that collect personal data directly from consumers and later sell it to data brokers).
  • As of June 30, 2026, the sale of sensitive personal data of New Jersey consumers is prohibited for all entities, regardless of whether they are otherwise covered by the New Jersey Data Privacy Act. No consent exception applies.
  • Annual data broker and data collector registration fees range from $5,000 to $1.5 million, depending on the volume of consumer data sold, far exceeding fees in other states. There is a $2,500 fee per day for failure to register and a $50,000 per record fee for selling sensitive data.
  • The registration provisions remain inoperative until March 27, 2027. The Division of Consumer Affairs indicated on July 10, 2026 that it plans to launch the registry in spring 2027 and will issue additional enforcement guidance in the coming months.

Data Broker and Data Collector Registration

The new data broker law requires two categories of entities to register annually with the New Jersey Division of Consumer Affairs in the Department of Law (the Division): data brokers and data collectors.

Data brokers are entities that sell personal data about consumers with whom they do not have a direct relationship. This aligns with the traditional definition of “data broker.” Data collectors are businesses that collect personal data directly from consumers (i.e., their own customers) and subsequently sell or provide that data to data brokers.

Existing data broker laws, including those in California, Texas, and Vermont, generally apply only to data brokers that sell personal data of consumers they do not have a direct relationship with. However, New Jersey’s law is substantially broader: by also covering “data collectors,” it reaches businesses that have a direct relationship with consumers and make their personal data available to third-party data brokers. This means businesses that were never subject to data broker registration requirements in other states may now be within scope in New Jersey if they disclose customer data to third parties that qualify as data brokers.

The law adopts the same definition of “personal data” as the New Jersey Data Privacy Act: any information that is linked or reasonably linkable to an identified or identifiable person.1 Critically, this includes data collected via cookies, pixels, and other tracking technologies deployed on businesses’ websites. Businesses must therefore review both traditional offline data disclosures (e.g., customer lists shared with third parties) and disclosures via online tracking technologies to determine whether any recipients qualify as data brokers.

Disclosures of personal data to service providers acting solely as processors (entities that process personal data only on behalf of and at the direction of the disclosing company) are not considered disclosures to data brokers. This distinction is critical for assessing whether a particular vendor relationship triggers registration obligations.

The law also contains several exemptions for certain information regulated under other federal frameworks, including for protected health information regulated under HIPAA, information regulated under the Gramm-Leach-Bliley Act, and information collected as part of human subjects research regulated under clinical trial regulations.

The annual registration fees range from $5,000 to $1.5 million, depending on the number of consumers whose personal data is sold. By contrast, California’s annual data broker registration fee is currently $6,000, while the fees in other states are lower, ranging from $100 in Vermont to $2,500 in Connecticut.

In addition to the registration and fee requirements, data brokers and data collectors must also submit detailed annual reports to the Division that include:

  • The registrant’s name, physical address, email address, and website
  • Whether and how consumers may opt out of the sale of their personal data, including the method for opting out, the type of opt-out, whether third parties may exercise opt-out rights on behalf of consumers, and whether the opt-out is limited to certain activities or sales
  • Whether and how consumers may request deletion of their data
  • A statement specifying the data collection, databases, or sales activities from which an individual may not opt out
  • Any credentialing process used to vet data purchasers, with an explanation of the process
  • History of data breaches and cybersecurity events, including the number of individuals affected
  • Data collection and sales activities and opt-out methods specific to personal data of individuals under age 18, including whether the registrant has actual knowledge it possesses data of minors
  • A list of the registrant’s data processors
  • Any additional information required by the Division

Entities that fail to register, pay the required fee, or submit required reporting are subject to a civil penalty of $2,500 per day of noncompliance.

Prohibition on the Sale of Sensitive Data

In addition to creating the data broker and data collector registry, the law amends the New Jersey Data Privacy Act to prohibit the sale of sensitive data. Notably, this prohibition applies to all entities, regardless of whether they are otherwise within the scope of the New Jersey Data Privacy Act. This prohibition also applies to data brokers and data collectors. Moreover, there is no consent exception. Even if a consumer provides affirmative consent, the sale of their sensitive data remains unlawful.

The New Jersey Data Privacy Act defines “sensitive data” broadly to include personal data revealing racial or ethnic origin; religious beliefs; mental or physical health condition, treatment, or diagnosis; financial information (account numbers, login credentials, credit/debit card numbers combined with security codes or passwords permitting account access); sex life or sexual orientation; citizenship or immigration status; transgender or non-binary status; genetic or biometric data processed to uniquely identify an individual; personal data collected from a known child; and precise geolocation data.2

Data brokers and data collectors that sell sensitive data face a civil penalty of $50,000 per record sold, offered for sale, or licensed. Given the per-record nature of this penalty, potential exposure for even modest violations could be extraordinary.

New Jersey’s sensitive data sales ban is part of a growing trend in the United States, as state legislators and regulators have grown increasingly concerned and focused on the sale of sensitive data, particularly in the context of online tracking and targeted advertising. For example, Maryland previously imposed a similar prohibition on the sale of sensitive data under the Maryland Online Data Privacy Act. New York’s Health Information Privacy Act — which passed the state legislature in June and is currently pending the governor’s action — would similarly prohibit the sale of regulated health information if enacted. California regulators, including the attorney general and California Privacy Protection Agency, have also focused on this area, as demonstrated by the July 2025 enforcement action against Healthline Media for “selling” and “sharing” personal information, including sensitive health information, collected via cookies and online trackers for cross-context behavioral advertising in violation of the California Consumer Privacy Act.

These developments signal that regulators and legislators across multiple states are increasingly focused on curtailing the use of sensitive personal data for commercial purposes, and businesses should expect continued legislation and enforcement activity in this space.

Effective Date and Implementation

The law took effect immediately upon passage. This means that the prohibition on the sale of sensitive data is in effect now. However, the provisions establishing the data broker and collector registry do not become operative until 270 days after enactment, which is March 27, 2027.

On July 10, the Division issued an alert confirming that it plans to launch the registry in spring 2027 and that data brokers and data collectors need not register or pay fees until then. The alert also states that the Division will issue additional guidance on the sensitive data sales prohibition in the coming months. The Division noted it “will consider how to most effectively and fairly enforce the law, taking into account the need for businesses to have clarity about their obligations and the intrusion imposed by the sale of consumers’ most sensitive information.”

Separately, it has been reported that an anonymous senior official in Governor Sherrill’s administration has indicated that the administration will not enforce the law “until the legislature fixes certain defects that have come to light over the last few days.”3 However, whether and to what extent the legislature may amend the law remains unclear.

What Should Businesses Do Now

While the registration provisions do not become operative until March 2027, businesses should take the following steps now to prepare for compliance and mitigate risk under the immediate sensitive data sales prohibition:

  • Map data flows, including website trackers and cookies. Conduct a comprehensive review of how personal data is collected, used, and disclosed, including data collected through cookies, pixels, and other online tracking technologies. Identify all third parties to whom personal data is disclosed and assess whether any of those recipients qualify as “data brokers” under the law.
  • Distinguish processors from data brokers. Review vendor and partner agreements to determine whether third-party recipients of personal data are acting as processors (processing data solely on behalf of and at the direction of the disclosing company) or whether they are using data independently in ways that may make them “data brokers.”
  • Evaluate all data sharing arrangements involving sensitive data. Given the immediate prohibition on selling sensitive data, businesses should audit their data disclosure practices to identify any arrangements that may constitute a “sale” of sensitive data. This includes reviewing advertising technology arrangements, data licensing agreements, and analytics vendor relationships.
  • Monitor for Division guidance. The Division has indicated it will issue additional guidance regarding registration requirements, the registration process, and the enforcement approach for the sensitive data sales prohibition. Businesses should monitor these developments closely to ensure timely compliance.
  • Budget for registration fees. Businesses that determine they will need to register should begin budgeting for the annual registration fee (up to $1.5 million) and preparing the detailed annual disclosures required by the law.
  1. N.J.S.A. § 56:8-166.4
  2. Id.
  3. David Wildstein, Sherrill administration will suspend enforcement of new data law, New Jersey Globe (July 10, 2026).
The material contained in this communication is informational, general in nature and does not constitute legal advice. The material contained in this communication should not be relied upon or used without consulting a lawyer to consider your specific circumstances. This communication was published on the date specified and may not include any changes in the topics, laws, rules or regulations covered. Receipt of this communication does not establish an attorney-client relationship. In some jurisdictions, this communication may be considered attorney advertising.