Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. A Fresh Take
  4. New Jersey’s New Data Privacy Rules: What Organizations Need to Know
6MIN

New Jersey’s New Data Privacy Rules: What Organizations Need to Know

Subscribe
Jul 20 2026

What’s Happened?

If your organization buys, sells, or licenses consumers’ personal data, new rules in New Jersey may require you to register with the state and pay an annual registration fee. On June 30, 2026, New Jersey Governor Mikie Sherrill signed into law Bill A5328, a sweeping legislative framework amending the state’s existing data privacy law and establishing a new regulatory framework for data brokers and data collectors. 

Why Does It Matter? 

The new obligations imposed by the Act on “data brokers” and “data collectors” are stringent and costly. The new data collector category is broad, and organizations should immediately assess whether they fall under the new definitions. 

Who Does This Apply To?

The Act introduces two new types of entities: 

  • A data broker is any person or entity that knowingly collects or purchases personal data about consumers with whom it has no direct relationship and then sells or licenses that data to third parties.
  • A data collector is a business that does have a direct relationship with the consumer and knowingly collects that data to then sell or license it to a data broker.

A direct relationship can be with past or present (1) customers, (2) employees, (3) investors in the person or organization, or (4) donors.

What Are the New Obligations? 

A5328 imposes onerous reporting requirements on newly defined data brokers and data collectors. They include, among others:

  1. Annual registration and registration fee – both data brokers and data collectors must register with the Division of Consumer Affairs in the Department of Law and Public Safety.
    1. To satisfy registration requirements, organizations must pay a tiered annual registration fee to the Division dependent on the number of New Jersey residents whose data they hold.
    2. 07/13/2026 Update: The DCA issued an alert that data brokers and data collectors will not be required to register or pay any fees until the DCA launches this registry in the spring of 2027.[1]
    3. The registration fee schedule is as follows:
ConsumersAnnual Fee
≤100,000$5,000
100,001–499,999$10,000
500,000–999,999$100,000
1,000,000–1,499,999$500,000
1,500,000–2,499,999$750,000
2,500,000–4,499,999$1,000,000
≥4,500,000$1,500,000
  1. Disclosure requirements – upon registration, data brokers and data collectors must submit detailed disclosures, including:
    1. Basic contact details such as name, primary physical address, email, and website.
    2. How consumers can opt out of data sales including the method available, any limitations, and whether third parties can opt out on a consumer’s behalf.
    3. Whether consumers may direct deletion of their personal data.
    4. A statement identifying any data activities from which consumers cannot opt out.
    5. Information on how purchasers of data are vetted (if applicable).
    6. A history of data breaches and cybersecurity events, including the number of individuals affected.
    7. A separate statement on data practices relating to individuals under 18, including whether the organization has actual knowledge of possessing minors’ data.
    8. The identity of any processors processing data on the organization’s behalf.
  2. Complete prohibition on selling or licensing sensitive data – the Act imposes a complete ban on the selling or licensing of sensitive data. This applies to data brokers, data collectors, and data controllers alike, expanding existing State privacy legislation.

Are There Any Exemptions? 

While the obligations imposed by the Act are broad, the regulatory framework continues to provide the same set of statutory exemptions as the existing New Jersey Data Protection Act. This includes federal healthcare privacy law (HIPAA), financial privacy law (Gramm-Leach-Bliley), credit reporting law (FCRA), and the Driver’s Privacy Protection Act. Research data, consumer reporting agencies, and state agencies are also exempt.  

Additionally, certain narrow data broker activities fall outside of the Act’s scope, including: 411 directory assistance, publicly available business/professional information, real-time health or safety alerts, and nonprofit post-secondary enrollment data reporting. 

What Happens If You Don’t Comply? 

The Act introduces three new civil penalties enforceable via summary proceeding. A failure to register or pay the annual fee can result in a penalty of $2,500 per day in addition to the unpaid fees. A failure to submit or update the required disclosures can similarly result in a $2,500 per day penalty. Lastly, any unlawful sale, offer for sale, or licensing of sensitive data can result in a penalty of $50,000 per record. 

Is Your Organization Ready? Steps To Take Now

While A5328’s obligations are effective immediately, a senior official of the governor’s office reportedly has stated that the governor will not enforce the Act until the legislature fixes “defects” in the law.[2] Additionally, on July 10, 2026, the DCA issued an alert that data brokers and data collectors will not be required to register or pay a registration fee until spring of 2027. Nevertheless, to strengthen readiness for compliance requirements, organizations should: 

  1. Determine your status. Assess whether your organization qualifies as a data broker or data collector.
  2. Audit your data flows. Audit all existing data-sharing agreements, vendor contracts, and CRM export configurations to confirm none involve the transfer of sensitive data for consideration, including non-monetary consideration.
  3. Calculate your fee tier. Work out how many New Jersey residents’ records you hold. Note that regulatory guidance on counting methodology is pending.
  4. Identify your processors. Map all third parties that handle and process personal data on your behalf, as these must be disclosed. Review existing data licensing, sharing, and sale agreements for compliance with the sensitive data prohibition and opt-out disclosure requirements.
  5. Assess your exposure to minors’ data. Establish whether your organization has actual knowledge that it holds data relating to individuals under 18, as a separate disclosure will be required.
  6. Prepare your registry submission. Draft the required opt-out methodology, disclosure statements, and any statements identifying activities from which opt-out is not available. 

Contact Us

A5328 represents a meaningful addition to New Jersey’s existing data privacy framework. If you have any questions about the Act and its potential implications for your organization, our team is here to help. Please reach out to the key contacts below. 

 

The authors thank Summer Associate Denise Choi for assistance with the research and preparation of this blog post.

 


[1] https://www.njconsumeraffairs.gov/ocp/Pages/Alerts.aspx

[2] https://newjerseyglobe.com/governor/sherrill-administration-will-suspend-enforcement-of-new-data-law/

 

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.

Tags

cybersecuritydata protectionus

Authors

San Francisco, Silicon Valley

Megan M. Kayo

Partner
San Francisco

Christine Chong

Senior Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome