New Jersey has enacted one of the most aggressive data broker statutes in the country, and it did so in seventy-two hours. Assembly Bill A5328 was introduced on June 28, 2026, amended and passed by both houses on June 30 and signed by Governor Sherrill the same day as P.L.2026, c.25. For any business that buys, sells or licenses personal data about New Jersey residents, the compliance clock is already running.
The New Law Builds on the New Jersey Data Privacy Act
A5328 amends the New Jersey Data Privacy Act, P.L.2023, c.266, the comprehensive privacy statute that took effect in January 2025. The NJDPA generally applies only to controllers that process the personal data of at least 100,000 New Jersey consumers, or 25,000 consumers where the controller derives revenue from selling data. A5328 removes that floor for one category of conduct. Under the amended statute, the prohibition on selling sensitive data now applies to all individuals and legal entities regardless of the number of consumers whose data they control or process. The amendment also adds a consent mechanic worth noting: controllers must give consumers a way to revoke consent that is at least as easy as the way consent was given, and must stop processing within 15 days of revocation.

Data Brokers and Data Collectors Are Now Defined Categories
The statute creates two new regulated classes. A “data broker” is a person or entity that knowingly collects or purchases the personal data of consumers with whom it has no direct relationship and sells or licenses that data to third parties. A “data collector” is a business that collects personal data from its own customers, employees, investors or donors and then sells or licenses that data to a data broker. The second definition is the sleeper. Plenty of ordinary operating companies that would never call themselves brokers monetize customer lists, loyalty program data or app telemetry. If any of that flows to a data broker for consideration, the seller is a data collector and the statute applies.
The Sensitive Data Ban Is Absolute
The core prohibition is short: in no case shall a data broker or data collector sell or license sensitive data. There is no consent exception. “Sensitive data” covers personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, financial account credentials, sex life or sexual orientation, citizenship or immigration status, transgender or non-binary status, genetic or biometric data used for identification, personal data collected from a known child and precise geolocation data, defined as location within a radius of 1,750 feet. Much of the commercial location data economy operates well inside that radius.
Registration Fees Scale to $1.5 Million
Data brokers and data collectors that sell or license New Jersey consumer data must register annually with the Division of Consumer Affairs, which will maintain a public registry. The fees are tiered by volume and they climb steeply: $5,000 for entities handling data of 100,000 or fewer New Jersey consumers, $10,000 up to 500,000 consumers, $100,000 up to one million, $500,000 up to 1.5 million, $750,000 up to 2.5 million, $1,000,000 up to 4.5 million and $1,500,000 above that. Registrants must also disclose their opt-out and deletion practices, whether they credential purchasers of data, their history of data breaches, their practices concerning data of persons under 18 and the processors acting on their behalf. The legislative fiscal estimate anticipates the fee revenue will fund administration of the registry.
Penalties Are Designed to Get Attention
An entity that fails to register or pay the fee owes the back fees plus a civil penalty of $2,500 for each day of noncompliance, with a separate $2,500 daily penalty for failing to submit or update the required disclosures. Selling or licensing sensitive data in violation of the statute carries a civil penalty of $50,000 for each record sold, offered for sale or licensed. On a per-record basis, a single file of a few thousand consumers is an existential number. Penalties are enforced by the Division in summary proceedings under the Penalty Enforcement Law of 1999.
Exemptions Track the Federal Regimes
The statute carves out data and entities already regulated elsewhere, including protected health information under HIPAA, financial institutions subject to the Gramm-Leach-Bliley Act, consumer reporting activity governed by the Fair Credit Reporting Act, insurance institutions regulated under New Jersey law, Motor Vehicle Commission disclosures permitted by the federal Driver’s Privacy Protection Act, regulated human subjects research and registered national securities associations. There are also carve-outs for entities whose third-party data sales are merely incidental to activities such as operating an e-commerce platform, providing directory assistance, publishing professional or real estate information, or providing regulated title and settlement services. The exemptions are narrower than they look. A GLBA institution is exempt, but its marketing affiliate handling non-GLBA data may not be, and the Senate committee statement makes clear the Legislature intended the new obligations to apply in addition to, not in place of, the NJDPA.
Effective Dates and the Business Pushback
The act took effect immediately upon signing, except that the public registry provision remains inoperative for 270 days following enactment, which lands in late March 2027. The sensitive data ban is therefore already law. The bill passed the Assembly 53 to 21 over opposition from the New Jersey Business & Industry Association, the New Jersey Retail Merchants Association and the New Jersey Food Council, which pointed out that the top registration fee of $1.5 million dwarfs the registration charges in other data broker registry states. Vermont, California, Texas and Oregon all maintain registries; none charges fees remotely approaching New Jersey’s upper tiers. Expect the fee schedule to feature prominently in any dormant commerce clause or preemption challenge that follows.
What Businesses Should Do Now
The first task is classification. Map your data flows and determine honestly whether any line of business collects and sells data about consumers you have no relationship with, or sells your own customer data to someone who does. The second task is triage on sensitive data. Because the ban is already effective and carries a $50,000 per record penalty, any sale or license of health, location, biometric, immigration or children’s data touching New Jersey residents should stop pending legal review. The third task is preparation for registration. Assemble the disclosure package now, including breach history and processor lists, and watch for Division of Consumer Affairs rulemaking, which the statute directs the Director to adopt. New Jersey has spent two years layering privacy obligations onto businesses one statute at a time. A5328 is the first one with a price list attached.
You may also enjoy:

- Apple Promised a Smarter Siri. What iPhone Buyers May Be Owed.
- What New Jersey Lawyers Must Know About AI and Professional Responsibility
- New Jersey’s Comprehensive Privacy Law
- Safeguarding Privacy in the Age of AI
and, if you lke what you’ve read, please subscribe below or in the right hand column.