On June 30, 2026, Governor Mikie Sherrill signed A.5328, now P.L.2026, c.25, and the New Jersey data broker law it creates does something most state broker laws don't. It bans the sale or licensing of ten categories of sensitive personal data outright, rather than requiring brokers to disclose the sale and let you opt out. Most state frameworks, California's included, are built around notice and choice. New Jersey's says that some data simply isn't for sale. The law also reaches past "data brokers" as a narrow category to cover "data collectors" (businesses that sell data about their own customers to brokers), and it requires both to register annually, pay a fee that scales with volume, and make a specific list of disclosures public. Most of it is not live yet, and ten days after the signing the Sherrill administration said it would hold off enforcing the rest. Here is what the law does, when each piece kicks in, and what that gap means if you live in New Jersey in September 2026.
What the New Jersey data broker law bans outright
The other state broker registry laws (California, Vermont, Oregon, Texas) all work the same way. A broker has to register and disclose what it does, and in California and Vermont it has to act on deletion requests. The sale itself stays legal. A.5328 breaks that pattern for a defined slice of data. The statute's wording is one sentence: "In no case shall a data broker or data collector sell or license sensitive data to any other individual or entity." No opt-out mechanism is needed because there is nothing to opt out of.
The ten categories are set by the definition of "sensitive data" in section 2 of the chapter law. The right-hand column is the statute's wording.
| Category (P.L.2026, c.25, section 2) | Statutory scope |
|---|---|
| Racial or ethnic origin | Personal data revealing it |
| Religious beliefs | Same |
| Health | "Mental or physical health condition, treatment, or diagnosis" |
| Financial information | Account number, log-in or card number "in combination with any required security code, access code, or password" |
| Sex life or sexual orientation | Same |
| Citizenship or immigration status | Same |
| Gender identity | "Status as transgender or non-binary" |
| Genetic or biometric data | Data "processed for the purpose of uniquely identifying an individual" |
| Children | "Personal data collected from a known child" |
| Precise geolocation | Location "within a radius of 1,750 feet", excluding communications content and utility smart-meter data |
Section 3 has no consent exception. The Future of Privacy Forum notes the New Jersey sensitive data ban carries none of the standard exceptions found in comprehensive privacy laws, and the exemptions in section 3(b) are sectoral (HIPAA, GLBA, FCRA agencies, insurers, research, government). The ban also reaches past brokers. Section 1 adds "not sell sensitive data" to the New Jersey Data Privacy Act's controller duties "regardless of the number of consumers," and section 5 puts the $50,000-per-record penalty on "a data broker, including a controller, or data collector."
Connecticut got there first on one category: its SB 4, signed May 27, bans the sale of precise geolocation from October 1, 2026. New Jersey's list is the broad one, and it is the piece of A.5328 getting the least attention relative to how much it changes the economics for brokers operating in the state. Whitepages or Spokeo can keep selling your address as long as they tell you they're doing it. They cannot sell your immigration status or a health condition to anyone, disclosure or not.
A.5328 New Jersey timeline: passed in two days, registry live in 2027
The bill moved fast even by Trenton's budget-week standards. The Legislature's record and the Governor's release put two days between introduction and signature, in the same batch as the FY2027 budget. IAPP's headline called it an "Independence Day surprise".
The act took effect immediately on signing, with one exception. The registry provisions are inoperative for 270 days after enactment, which lands on March 27, 2027. On July 10 the Division of Consumer Affairs published an alert saying it plans to open the New Jersey data broker registry in spring 2027, with the first New Jersey data broker registration window running April 1 through June 30, 2027. Until then, nobody has to register or pay a fee.
| Date | What happened |
|---|---|
| June 28, 2026 | A.5328 introduced and reported from the Assembly Budget Committee the same day |
| June 30, 2026 | Assembly 52-21, Senate 25-15, signed, in effect on signing (section 8 of c.25) |
| July 10, 2026 | Division alert: registry opens spring 2027, first window April 1 to June 30, 2027. Same day, a senior official says the state will not enforce until the Legislature fixes defects |
| March 27, 2027 | Registry subsection (section 2(b)) becomes operative, 270 days after enactment |
| April 1 to June 30, 2027 | First registration window |
| Not scheduled | Division guidance on the sensitive-data restriction, promised "in the upcoming months" |
Is the New Jersey data broker law in effect right now?
On paper, yes. In practice, the state has said it is not enforcing it. The same day the Division published its registry timeline, a senior administration official told the New Jersey Globe that the state would not enforce the law until the Legislature fixes "certain defects that have come to light." The defect that got the most attention was the law's reach into voter files: as written, the Globe reported, it could have shut down the voter databases that campaigns, parties and advocacy groups rely on. Two days later the Attorney General's press secretary told the Globe the office evaluates enforcement "on a case-by-case basis" and pointed questions to the Division's alert, which says nothing about sensitive-data sales. Assembly Minority Whip Brian Bergen, who voted against the bill, wrote to the Attorney General on July 14 asking for the legal authority behind not enforcing a signed statute, and for the Governor to call a special session to amend it instead.
As of September 15, 2026, we could find no amendment bill introduced and no published guidance from the Division on the sensitive-data restriction, which the July alert said would come "in the upcoming months." The latest public word, a September 10 op-ed relayed by the NJBIA, asks the Legislature to narrow who counts as a data collector and names no bill. So a New Jersey resident wondering whether a particular broker has stopped selling their data gets an awkward answer. The ban is in the statute. The registry that would show who is complying does not exist yet. And the agency that would enforce it has said, for now, that it won't.
Data broker vs data collector: who has to register
Every other registry state aims at one target, a company that sells data about people it has no direct relationship with. A.5328 keeps that as its "data broker" definition and adds a second registrant nobody else has. Both are in section 2(a).
A data broker "knowingly collects or purchases the personal data of a consumer with whom the person or legal entity does not have a direct relationship and sells or licenses that data to a third party." The statute spells out what a direct relationship is: the consumer is or was a customer, subscriber or user, an employee or contractor, an investor, or a donor. A data collector is a business that knowingly collects the personal data of consumers it does have that relationship with, and then sells or licenses it to a data broker. That is the retailer with a loyalty programme or the publisher with a subscriber list. Neither is a data broker in the ordinary sense, and in every other state neither has a registry duty. In New Jersey they register, pay the same fees and file the same disclosures. It is also the provision the business lobby is now asking the Legislature to cut back.
Section 2(e) exempts companies whose brokering is "incidental" to one of five activities: e-commerce or app platforms, carrier 411 directories, professional and real-estate listings, real-time safety alerts, and regulated title services, plus nonprofits reporting college enrollment data. Section 2(f) pulls anyone back in once their data sales stop being incidental. Section 2(g) exempts whole sectors from registration: HIPAA health data, GLBA financial institutions, insurers, FCRA consumer reporting agencies, the Motor Vehicle Commission's DPPA sales, government, human-subjects research and securities associations. One drafting detail worth knowing: the sale ban in section 3 repeats the sector exemptions but not the incidental-activity list, so a 411 directory that never registers is still barred from selling sensitive data.
Fees that scale, and disclosures that go deeper than most states
New Jersey data broker registration fees are tiered by how many New Jersey consumers' data a broker sells or licenses, or a collector collects and sells. The bands are in section 2(c)(2).
| New Jersey consumers whose data is sold or licensed | Annual fee |
|---|---|
| 100,000 or fewer | $5,000 |
| More than 100,000 and fewer than 500,000 | $10,000 |
| More than 500,000 and fewer than 1 million | $100,000 |
| More than 1 million and fewer than 1.5 million | $500,000 |
| More than 1.5 million and fewer than 2.5 million | $750,000 |
| More than 2.5 million and fewer than 4.5 million | $1,000,000 |
| More than 4.5 million | $1,500,000 |
There is no floor, so one New Jersey consumer's data costs $5,000 to register, and the bands are written so that a company at exactly 500,000 consumers falls into none of them. That top tier is why Troutman Privacy called it "the nation's costliest data broker law yet" and IAPP's headline settled on "costly." California charges a flat $6,000.
The disclosures are more granular than peer states too. Registrants provide entity name, address, email and websites, then a description of how consumers can opt out of collection, whether consumers can direct deletion and authorise a third party to request it on their behalf, the processors handling data for the broker, and whether the broker runs a credentialing process to vet who is allowed to buy its data. That last one means a broker has to state publicly whether it checks who is purchasing your information or whether anyone with a card number qualifies. Brokers also disclose their history of breaches and security incidents, and how they handle data on people under 18.
One thing New Jersey did not build is a central deletion portal. California's DROP lets a consumer file one request that reaches every registered broker, and by August 25, 2026, more than 500,000 Californians had signed up. New Jersey relies on each broker disclosing its own deletion process, so the job of finding and using dozens of different mechanisms stays with the consumer even after the NJ data broker registry goes live.
Penalties: $2,500 a day, plus $50,000 a record
A.5328 sets penalties at up to $2,500 per day for each day a broker or collector fails to register, pay its fee, or submit or update required information. That is a flat per-company rate, and it looks smaller than California's structure, which is $200 a day for non-registration plus $200 per unprocessed deletion request per day under SB 361.
| Violation | Penalty | Who collects it | Section of c.25 |
|---|---|---|---|
| Not registering or not paying the fee | $2,500 per day, plus the unpaid fee for each year missed | Division of Consumer Affairs, summary proceeding under the Penalty Enforcement Law of 1999 | 4(a), 4(c) |
| Not filing or updating the disclosures | $2,500 per day | Division, same procedure | 4(b), 4(c) |
| Selling, offering or licensing sensitive data | $50,000 per record | Section 5 does not say. The parallel NJDPA duty is enforced by the Attorney General alone (c.266 section 16) | 5 |
| Cure period | None in c.25. The NJDPA's 30-day cure notice lapsed in July 2026 | c.266 section 14 |
The $2,500 figure is not the whole cost, though. The $50,000-per-record penalty for a prohibited sensitive-data sale is the one that reprices the business. A flat daily fine is something a company can budget around. A law that forecloses a category of sales, with a five-figure penalty for every record that slips through, is lost revenue rather than a line item.
How A.5328 differs from Daniel's Law
People searching for a New Jersey data broker law often land on Daniel's Law, which is a different statute with a narrower job. Daniel's Law, enacted in November 2020 after the murder of Judge Esther Salas's son at her home, lets a defined group demand that any person or business stop publishing their home address and unlisted phone number. The state's Daniel's Law FAQ lists them: active, formerly active or retired judicial officers, prosecutors, law enforcement officers, child protective investigators, and immediate family in the same household. Per Womble Bond Dickinson's summary, the penalty is actual damages, with a floor of $1,000 in liquidated damages per violation. Covered people can assign their claims to a third party, which is how Atlas Data Privacy Corporation came to file hundreds of suits against people-search sites on behalf of tens of thousands of officers. A federal district court in New Jersey rejected a First Amendment challenge to the law on April 22, 2026, and on August 12 the New Jersey Supreme Court held, on a question from the Third Circuit, that a business still publishing a covered address ten business days after a valid notice is liable without any showing of intent or negligence. The constitutional question went back to the federal court.
Daniel's Law has also produced the most drastic remedy yet used against a people-search site. On August 27, 2026, a Middlesex County judge entered a default judgment for Atlas against Radaris.com, Rehold.com and Trustoria.com and ordered the radaris.com domain transferred to Atlas, which now uses it to post the judgment. The injunction covers only the officers and relatives in the case, and Radaris has moved to vacate it. We walk through the Radaris seizure and what it does not do.
If you are not a judge, prosecutor, officer or one of their relatives, Daniel's Law does nothing for you. A.5328 is the law that reaches ordinary residents, and it does so through the registry and the sale ban rather than through a takedown right you can exercise yourself. For everyone else, the only takedown right on the books is the deletion right in the New Jersey Data Privacy Act, exercised one broker at a time.
Where the New Jersey data broker law sits on the map right now
As of September 2026, four states are building broker-specific rules on top of their general privacy laws, and each is on a different clock:
- California's DROP has been live for consumers since January 1, 2026, and brokers have been required to process requests since August 1. CalPrivacy has already fined brokers for missing registration and for obstructive opt-out flows. Our DROP explainer tracks the enforcement record.
- Connecticut opens its registry on January 1, 2027, and takes until July 1, 2028 to build a central deletion mechanism that brokers do not have to act on until October 1, 2028 (full timeline in our Connecticut comparison).
- New Jersey: registry in spring 2027, April-to-June registration window, no central deletion portal planned, sale ban on the books but unenforced.
- Vermont, whose broker registry dates to 2018, rewrote it in June 2026 (H.211, signed June 16): a $900 fee, a $20,000 surety bond, and from January 1, 2027, a duty to delete on individual request within 30 days. A central portal was stripped out in the Senate and replaced with a feasibility study due in December 2028.
Four states, and no two of them on the same schedule.
What a New Jersey resident can do today under the NJDPA
The New Jersey Data Privacy Act rights in P.L.2023, c.266 have been live since January 15, 2025 and do not depend on the registry. This is the route that works now.
- Check the company is covered. Section 2 reaches controllers processing data on at least 100,000 New Jersey consumers a year, or 25,000 if they profit from selling it. Any people-search site of consequence clears both.
- Use the request channel in the privacy notice, which section 3 requires to say how you exercise rights and how you appeal. Name the rights: section 7 gives you access, correction, deletion, a portable copy, and an opt-out from sale, targeted advertising and profiling.
- Turn on Global Privacy Control. Since July 15, 2025, a controller that sells data or runs targeted ads must honour a universal opt-out signal (section 8(b)). In our removal work it does nothing to a people-search listing, because the listing is the product rather than an ad-tracking sale, so it supplements step 2 rather than replacing it.
- Wait 45 days. Section 4 gives the controller 45 days from receipt, extendable by 45 more if it tells you why inside the first window, free once in any 12 months.
- Appeal a refusal. The controller must explain and give appeal instructions inside the same 45 days, decide the appeal in writing within 45 more, and on a denial hand you a way to complain to the Division of Consumer Affairs (section 4(f)).
- File with the Division through its General Consumer Complaint form, attaching the request, refusal and appeal decision. The Division decides whether to investigate, since section 16 gives the Attorney General "sole and exclusive authority." The form warns that an anonymous filing gets no status updates.
- For people-search sites, the site's own opt-out flow beats a 45-day clock. Our opt-out guides cover Whitepages, Spokeo and the rest, with the screens each one shows.
Frequently asked questions
Is the NJ data broker registry open yet?
No. Section 8 of c.25 keeps the registry subsection inoperative until March 27, 2027, and the Division's alert set the first registration window at April 1 through June 30, 2027. Until brokers file, there is no list to search.
Does the New Jersey data broker law apply to small businesses?
Yes, more completely than the NJDPA does. The NJDPA stops at the 100,000-consumer and 25,000-plus-revenue thresholds in c.266 section 2. C.25 has none: its lowest fee band starts at one consumer, and its NJDPA amendment applies the sale ban "regardless of the number of consumers." A two-person firm that sells a customer list to a broker is a data collector under section 2(a) and owes $5,000 to register.
Are political campaigns and voter files exempt?
Not in the statute. Neither section 2(g) nor 2(e) mentions campaigns, parties or voter files. That is the defect the administration cited: the Globe reported that NGP VAN, the DNC's voter-file platform, was among vendors preparing to leave the state rather than risk $50,000 per record, since voter-targeting models draw on race, religion and location. No bill adding an exemption had been introduced as of September 15, 2026.
Can you sue a data broker under the New Jersey Data Privacy Act or A.5328?
No. C.266 section 16 says the act creates no private right of action, and c.25 adds none, so the remedy is the Division complaint in step 6. Daniel's Law is the exception for its covered persons.
What this means if you live in New Jersey today
Mechanically, nothing changes for you yet. The registry does not exist, so you cannot look up whether a broker has registered, because registration is not required until next spring. The sale ban is in the statute, but there is no public list to check against it, no portal to file through, and an administration that has said it will wait for the Legislature before enforcing.
What you do have is the New Jersey Data Privacy Act, in effect since January 2025, and in our removal work that turns out to matter more than the New Jersey data broker law for now. Some people-search sites decide whether to honour an opt-out based on whether your state has a comprehensive privacy law at all. FastBackgroundCheck, for one, sends automated denials that say the requester "lives in a state that does not have a comprehensive consumer privacy law that applies to our data." New Jersey residents clear that filter. Residents of the 27 states without a comprehensive law (26 on trackers that count Florida, as Privacy World's August tally does) do not. The other thing to know before you start is that a registry entry can hide a family of sites. On California's registry, Mississippi Tornado Alley, LLC covers ten people-search brands on one line, and Spokeo's entry lists ThatsThem and AnyWho as trade names, yet every one of those sites runs its own separate opt-out. Expect the NJ data broker registry to look the same when it opens, and plan for one request per site rather than one per company.
If you want your exposure handled without waiting on any state's registry to spin up, that is the gap we are building for. Delist My Data is in pre-launch. Join the waitlist for founding-member access.
Sources
- A.5328, New Jersey Legislature bill page
- P.L.2026, c.25, chapter law text, New Jersey Legislature
- Governor Sherrill Takes Action on Legislation (June 30, 2026), Office of the Governor
- Data Brokers & Beyond: Navigating New Jersey's Data Broker & "Data Collector" Registration Law, Future of Privacy Forum
- New Jersey Enacts Law Establishing Data Broker Registration Regime and Imposing Prohibitions on Sensitive Data Sales, WilmerHale
- New Jersey Enacts the Nation's Costliest Data Broker Law Yet, Troutman Privacy
- Independence Day surprise: New Jersey's costly new data broker law, IAPP
- Navigating New Jersey's Data Broker Registration and Sensitive Data Restrictions (Division of Consumer Affairs July 10 alert), Frankfurt Kurnit
- Sherrill administration will suspend enforcement of new data law (July 10, 2026), New Jersey Globe
- Bergen to AG: Enforce New Jersey's data law or call lawmakers back to fix it (July 14, 2026), New Jersey Globe
- Court Ruling Signals Continued Privacy Litigation Exposure Under NJ's Daniel's Law, Womble Bond Dickinson
- Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations, Hunton
- Vermont Enacts Significant Amendments to Data Broker Legislation, Hunton
- CalPrivacy: Half a million Californians have signed up for DROP (August 25, 2026)
- Adding to the Count: The latest in state consumer privacy laws (August 17, 2026), Privacy World
- California Data Broker Registry (CSV download)
- P.L.2023, c.266, New Jersey Data Privacy Act chapter law, New Jersey Legislature
- Confusion persists over enforcement of N.J. data privacy law (July 12, 2026), New Jersey Globe
- N.J. Supreme Court says Daniel's Law imposes liability without proof of fault (August 12, 2026), New Jersey Globe
- Daniel's Law FAQs, New Jersey Office of Information Privacy
- File a Complaint, New Jersey Division of Consumer Affairs
- Op-ed: Revisions to NJ Data Broker Law Can Turn a Negative to a Positive (September 11, 2026), NJBIA