The term “data broker” sounds, understandably, very specific. So specific that most people assume the label only applies to tech companies, marketing firms, or similar businesses. But New Jersey passed a new law in June 2026 that applies the definition to any businesses that sells or licenses personal data. That means a plumber in Union County with a customer list, or an online retailer based in Morristown who share email addresses with an ad partner, are now data brokers in the eyes of the law.
What New Jersey’s Data Privacy Act Now Regulates
New Jersey’s data privacy act already covered how businesses collect and use consumer data. This new law, A5328, adds two things on top of what already existed.
First, it creates a public registry. Figuring out whether your business belongs on it is a regulatory compliance question.
Second, it bans the sale of sensitive data outright, even for a small business.
The registry and the sensitive data ban do not have the same reach. Only certain businesses fall under the registry. The sensitive data ban applies to everyone.
Are You a “Data Collector” Without Realizing It?
The law creates two categories, and only one of them immediately sounds like a business problem.
A “data broker” buys or collects data from people it has no direct relationship with, then sells it. A company dealing only with its own customers might read that definition and assume it doesn’t apply to them. But it does. A “data collector” is a business with a direct link to its own customers. It then sells or licenses that data to a data broker.
That covers a lot of ordinary deals.
- Rented email lists
- Customer databases sold to ad networks
- Referral deals that share contact information for a fee
If your business does any of that, the law treats you like the data broker on the other end.
The Sensitive Data Ban That Applies to Every Business
Separate from the registry, A5328 bans selling or licensing “sensitive data” entirely. This part has no size threshold and no consumer-count minimum. It applies regardless of how many records are involved.
The category is broader than a basic customer name or email address. Precise location data, health information, immigration status, and certain financial account details all count.
A vendor agreement that lets a partner resell any of that data can violate the ban. That’s true even if your business never registers as anything.
Registration: Who Has to Sign Up, and When
Data brokers and data collectors must register every year with the Division of Consumer Affairs. Registration fees range from $5,000 to $1.5 million, based on how many consumers are involved. Failure to register can mean a civil penalty of $2,500 per day.
Here’s the part that catches people off guard: the public registry itself doesn’t take effect until March 27, 2027.
Businesses might see that and think the law won’t go into effect until then. But that date only applies to the registry. The sensitive data ban has no such delay and applies now.
Where This Fits Into New Jersey’s Broader Data Privacy Act
A5328 amends New Jersey’s current data privacy act rather than replacing it.
That underlying law already applies to any business controlling or processing the data of 100,000 New Jersey consumers. It also applies at a lower threshold, 25,000 consumers, if the business gets any revenue from selling personal data. There’s no revenue percentage floor, which is unusual among state privacy laws.
A5328 removes even that lower bar for the sensitive data ban specifically. Size and revenue make no difference once sensitive data is involved.
What to Do Before March 2027
Start by mapping what your business shares with outside partners. Look at vendor contracts, referral arrangements, and advertising relationships. Also check any other agreement that lets customer information move outside the company.
A business agreement attorney can help compare those arrangements against the new registration and sensitive-data rules. Find out whether customer information is being sold, licensed, or passed along in a way A5328 now regulates.
Then pull the older agreements that were written before this law existed. An NDA deserves another look, as do referral terms and non-solicitation agreements that govern customer lists or contact information.
A business contract attorney can flag contract language that no longer matches the current rules. The same reason businesses use a contract attorney for other agreements applies here too: the actual text controls. Read what you’re really promising, not what a vendor’s summary says you’re promising.
New Jersey Data Privacy Act FAQs
Does this law only apply to companies that call themselves data brokers?
No. If your business sells or licenses customer data to someone else, you may count as a data collector. That’s true even if you’ve never used that label.
When do I need to register?
The public registry takes effect March 27, 2027. The sensitive data sale ban does not wait. It’s already in force.
What counts as sensitive data under New Jersey law?
Precise location data, health information, immigration status, and certain financial account details are among the types covered. The category reaches well beyond the basic contact information businesses usually think of as customer data.
Could a small business really be caught by this?
Yes. New Jersey has surprised small businesses with broad rules before. The ABC test caught employers who never meant to misclassify anyone in a similar way. Size does not get a business out of the sensitive data rule either.
Why This Law Surprises So Many Businesses
New Jersey built this law around actual data flows. How a business describes itself doesn’t change whether the law applies. A company that has never used the words “data broker” can still fall inside the registration rule.
The Division of Consumer Affairs hasn’t published its registration forms yet, so the practical starting point isn’t paperwork. It’s the contract review.
Reviewing existing vendor and referral agreements now is the fastest way to find out where the exposure sits. That’s true well before the registry opens in 2027.
Sources
P.L. 2026, c.25 (A5328): An Act Concerning Personal Data, Data Brokers, Data Collectors
N.J.S.A. 56:8-166.4: New Jersey Data Privacy Act, Definitions

