New Jersey’s New Data Broker Law: Why Companies Must Follow Their Data Before Regulators Do
Written by Jason Vigeant
In state privacy enforcement, the decisive question is increasingly definitional: which companies qualify as data brokers, and which businesses are the ones supplying them. New Jersey has just redrawn both lines. On June 30, 2026, Governor Mikie Sherrill signed Assembly Bill 5328 into law, and it took effect immediately.[i] New Jersey businesses that sell or license consumer personal data (and a larger population of businesses that supply data to another entity who resells it) are now operating under one of the costliest data broker regimes in the country.
For many organizations, the greatest risk will not be an intentional decision to operate as a data broker. Instead, it will be discovering that a longstanding vendor relationship or data-sharing arrangement quietly placed the organization inside a regulatory framework it never expected to enter. Answering that question typically takes less legal interpretation than operational reconstruction.
A Law With Broad Reach
A5328 does three things. First, it bans the sale of “sensitive data” outright, with no consent exception and no applicability threshold. An entity that sells the sensitive data of a single New Jersey resident can be liable under the ban, whether or not it is otherwise within scope of the state’s privacy law.[i] Sensitive data covers consumer health information, biometric and genetic data, sexual orientation, citizenship or immigration status, racial or ethnic origin, religious beliefs, transgender or non-binary status, financial account-access credentials, data from a known child, and precise geolocation data, defined as location known to within 1,750 feet.[i] Violating the ban carries a penalty of $50,000 for each record sold, offered for sale, or licensed, which is an amount that scales quickly against a larger volume of data.[i]
Second, the law creates a new registered category that most companies haven’t considered previously: the “data collector.” Data brokers, which are entities that buy or collect data on people they have no direct relationship with and resell it, are a familiar target in other states. New Jersey has added a second, broader category covering any business that does have a direct relationship with its own customers or users but sells or licenses that data downstream to a data broker. A retailer, publisher, or subscription service with an ordinary customer base could fall into this second category without ever operating anything resembling a traditional data-broker business.[i]
Third, registration fees for covered data brokers and data collectors are tiered by the number of New Jersey consumers involved, from $5,000 at the lowest tier (100,000 consumers or fewer) up to $1.5 million for entities handling more than 4.5 million New Jersey consumers’ data[i]. Missing a registration deadline or letting disclosures go stale adds a penalty of $2,500 per day.[i],[ii] The public registry itself does not go live until March 27, 2027, 270 days after enactment, but the sensitive-data sale prohibitions are already in force.[i]
The law does exclude established categories: protected health information under HIPAA, data held by GLBA-regulated financial institutions and insurance companies, certain FCRA-governed consumer reporting activity, specified human-subjects research, government entities, and transfers incidental to operating a third-party e-commerce platform or providing directory-assistance services.[i] Nothing in A5328’s broker and data collector provisions obligates a company to offer consumers a way to opt out of sale or request deletion, and nothing in the statute requires registrants to post a bond or other financial security.[i]
Beyond Data Brokers
Consider an ordinary consumer-facing business that licenses customer information to a marketing or analytics partner as part of a broader monetization strategy (e.g., a subscription platform, loyalty program, or retail app). That partner may combine the data with other datasets, grant access to additional parties, or sell portions of it downstream. The originating company likely never thought of the arrangement as a sale; its contracts probably describe it as a marketing service, data partnership, or licensing agreement.
Under New Jersey’s law, those labels do not resolve the issue. The statute defines a sale as sharing, disclosing, or transferring personal data for monetary or other valuable consideration, which is a test that turns on the substance of what changed hands, not on what the contract calls it.[i] Companies may need to look past their agreements and reconstruct what happened operationally: what data left the organization, how often, and where it ultimately went.
These engagements rarely begin with a complete understanding of where data resides or how it moves through the organization. The work looks less like a legal review than a forensic investigation: follow the data, reconcile inconsistencies, validate the evidence, and document conclusions that can withstand scrutiny. The compliance question is no longer limited to whether a company is a data broker, but whether any of its data ends up with one. And answering this question requires forensic reconstruction.
Following the Data
Consumer data rarely lives in one system or follows one centrally managed path, but is dispersed across CRM platforms, marketing tools, data warehouses, and vendor feeds, with contracts and invoices needed to explain why it moved and what the recipient could do with it. Reconstructing the picture usually requires identifying which systems hold consumer data, deduplicating records across platforms, then tracing outbound transfers against vendor files and contracts to see where the data went.
Key questions related to A5328:
- How many New Jersey consumers are in the dataset? The registration fee schedule is a step function of New Jersey consumer counts, not total records or revenue. That requires isolating New Jersey residency within a larger dataset, deduplicating across systems, and being able to defend the count if the Division of Consumer Affairs challenges it. Getting the tier wrong can have financial consequences.
- Where does the data go after it leaves our systems? Determining data collector status requires mapping vendor and licensee relationships contract by contract, feed by feed, to establish whether personal data sold or licensed to a third party ultimately reaches a data broker.
- Does any of the data sold or licensed qualify as sensitive data? Categories such as precise geolocation and financial account data do not always stand out in a schema. A record-level analysis is often needed to determine whether a dataset that was sold or licensed contains sensitive fields, and to quantify exposure if it did.
- Can the registration disclosures be produced on demand? The law requires registrants to disclose breach history, opt-out mechanics, credentialing processes for data purchasers, and data practices specific to minors, updated at least annually.[i] That is a recurring data governance exercise, not a one-time filing.
- Are we prepared to defend our numbers if challenged? Since fees and penalties both rely on precise counts, a well-documented methodology for arriving at those statistics matters as much as the counts themselves.
Why This Matters
The ability to answer the underlying data questions quickly becomes critical the moment a regulator asks. Can the company identify every New Jersey consumer whose data was sold or licensed? Can it trace where that data went after it left the company’s systems? Can it show, record by record, whether any of it met the statutory definition of sensitive data? Can it reproduce and defend the consumer count behind its registration fee tier?
Each of those questions demonstrates a precise, defensible fact about data that a legal or compliance read of the statute cannot answer on its own. Forensic analytics closes this gap, as follows:
- Enterprise-wide data inventory reconstruction and vendor-flow mapping to establish contract by contract and feed by feed whether the company is a data broker, a data collector, or both (or neither).
- Consumer count validation to size the population accurately, defend the registration fee tier, and avoid both underpayment penalties and unnecessary overpayment.
- Record-level sensitive-data identification, classification, and validation across any dataset that has been sold or licensed, to identify potential exposure.
- Penalty exposure quantification that models potential liability across historical data sales, supporting both remediation prioritization and settlement or defense strategy.
- Proactively build and maintain a defensible registration-disclosure record, including breach history, opt-out mechanics, and minor-specific data practices, with evidentiary support for annual updates.
- Regulatory investigations, litigation support, and expert analytics if the Division of Consumer Affairs opens an inquiry or there are allegations of violations.
These same analyses often become central evidence in regulatory investigations and litigation. Organizations may need to show not just that a policy existed, but precisely which records moved, when, to whom, and in a form that can be independently reproduced. No single source usually answers that alone: customer systems identify the affected population but not where the data went; transfer and access logs show a file left but not its commercial purpose; contracts describe permitted uses, but not what fields moved.
A5328 was introduced on June 28, 2026, and signed within days.[i] Companies with any New Jersey consumer footprint should not wait for the March 2027 registry to start asking the harder question: not “are we a data broker?” but “where does our data go once it leaves our hands, and can we prove it?” The businesses most exposed here are not the obvious data-broker players who already have compliance infrastructure. Instead, they are the ordinary consumer-facing companies that never thought of themselves as being in the data business at all.
[i] https://pub.njleg.state.nj.us/Bills/2026/A5500/5328_R1.PDF