top of page

New Jersey's New Data Broker Law Could Change How Personal Data Is Bought and Sold

When people think about privacy laws in the United States, states like California, Virginia, or Colorado usually come to mind. But in early July 2026, New Jersey quickly became part of that conversation with a new law that could significantly affect companies involved in buying and selling personal information.


On June 30, 2026, Governor Mikie Sherrill signed Assembly Bill 5328 into law, making New Jersey the seventh state to enact a dedicated data broker law. Unlike many privacy laws that take months or even years to move through the legislative process, this bill was introduced and signed within just a few days as lawmakers worked to finalize the state's budget before the end of the fiscal year.


Although the law follows the growing trend of regulating data brokers, it introduces several requirements that make it stand out from similar laws passed in other states.


More Than Just Data Brokers


One of the biggest differences is that the law does not focus only on data brokers.


It also applies to data collectors, organizations that have a direct relationship with consumers but later sell personal information to data brokers. This expands the law's reach beyond companies that specialize in data brokerage and places additional responsibilities on businesses that participate anywhere in the personal data supply chain.


The law recognizes that personal information often changes hands multiple times before reaching its final destination. By covering both data brokers and data collectors, New Jersey is attempting to improve transparency across that entire process.


A Registration Fee That Is Hard to Ignore


Perhaps the most talked-about part of the law is its registration fee structure.


Instead of charging a flat registration fee like many other states, New Jersey introduced a tiered system based on the volume of consumer data involved. Under the law, the largest data brokers and data collectors could pay up to USD 1.5 million each year to remain registered.


The law also includes significant financial penalties for organizations that fail to register or update their registration information. In addition, selling sensitive personal data in violation of the law may result in penalties of USD 50,000 for each record involved.


Those figures make New Jersey's law one of the most expensive data broker regulatory frameworks currently in the United States.


Why States Are Paying More Attention to Data Brokers


Data brokers have become an increasingly important topic in privacy discussions because many consumers are unaware of how much personal information is collected, shared, and sold after they interact with websites, mobile applications, retailers, or other businesses.


Privacy advocates have argued that greater transparency and stronger oversight are needed because individuals often have little visibility into how their personal information moves between organizations.


New Jersey's law reflects that growing concern. Rather than focusing only on consumer rights, it also places greater accountability on organizations that profit from collecting and selling personal information.


The law takes effect immediately, although the official registration system is scheduled to be available by March 27, 2027.


Why This Matters for Privacy Professionals


The New Jersey law is another example of how the United States privacy landscape continues to evolve at the state level.


Instead of waiting for a comprehensive federal privacy law, states continue introducing their own approaches to consumer privacy, data broker regulation, and enforcement. As a result, organizations operating across multiple states are increasingly required to monitor different compliance obligations depending on where they collect, process, or sell personal information.


For privacy professionals, this creates an environment where understanding one state's requirements is no longer enough. Keeping up with legislative developments across the country has become an important part of building and maintaining effective privacy programs.


Why This Matters for CIPP/US Preparation


For professionals preparing for the Certified Information Privacy Professional/United States (CIPP/US) certification, New Jersey's new law offers a practical example of how state privacy legislation continues to develop beyond traditional consumer privacy laws.


The CIPP/US body of knowledge covers the evolving landscape of United States privacy regulation, including state privacy laws, enforcement authorities, consumer rights, and emerging regulatory trends. Data broker laws are becoming an increasingly important part of that discussion as more states adopt their own registration requirements and restrictions on personal data sales.


Following developments like New Jersey's new law helps connect certification concepts to real-world legislative changes. It also highlights how state governments continue shaping privacy regulation while broader discussions around federal privacy legislation remain ongoing.


Looking Ahead


New Jersey's new data broker law demonstrates that states are no longer focused solely on giving consumers more privacy rights. They are also placing greater responsibility on the organizations that collect, share, and monetize personal information.


As more states introduce similar legislation, companies will likely face increasing pressure to understand where personal data comes from, how it is shared, and whether those activities comply with a growing number of state-specific requirements.


For privacy professionals, these developments are another reminder that data governance is becoming just as important as data collection itself.



 
 
 

Comments


bottom of page