New Jersey's $50K-Per-Record Data Broker Law Is Live Now

The Sensitive Data Sales Ban Is Already Enforceable — Act This Quarter
What changed: New Jersey enacted the costliest data broker law in the country with almost no runway. Assembly Bill A5328, formally P.L.2026, c.25, was introduced on June 28, 2026, passed the Democrat-controlled legislature on June 30, 2026, and was signed the same day by Governor Mikie Sherrill, taking effect immediately upon enactment.
What counsel must do this quarter: separate the two clocks. The sensitive data sales ban and its civil penalties are live now. The public registration requirement is not — it depends on a registry the Division of Consumer Affairs must build.
Do not treat this as a future compliance project. If your client sells or licenses sensitive personal data about New Jersey consumers, the exposure exists today. Map that data flow before you draft anything else.
The Numbers That Should Reset Your Risk Model
The penalty structure is what makes A5328 different from every state law that preceded it. According to the Future of Privacy Forum's analysis, A5328 imposes a civil penalty of $50,000 per record for each prohibited sale of sensitive data, and a civil penalty of $2,500 per day for failure to register or submit required information.
Read the per-record figure carefully. $50,000 per record is not a per-incident cap — it scales with the size of the dataset. A single prohibited sale of a moderately sized file produces catastrophic arithmetic.
The registration fees are equally aggressive. Per Troutman's advisory, A5328 imposes tiered annual registration fees ranging from $5,000 up to $1,500,000 — the highest such fees of any state data broker law in the country. For comparison, Connecticut's data broker registration fee is $2,500 per year.
A practical note on the tiers: the $5,000 floor and $1,500,000 ceiling are confirmed, but public sources conflict on the exact consumer-count breakpoints that trigger each tier. Do not build a fee-budget model on an unverified breakpoint. Confirm the enrolled bill text before you commit a number to a board memo.
The 'Data Collector' Category Extends the Law to Companies That Are Not Brokers
Why direct-relationship businesses are now in scope
Here is the feature that will surprise most compliance teams. Per Troutman's analysis, New Jersey is the only state whose data broker law requires 'data collectors' — businesses that collect personal data directly from consumers with whom they have a direct relationship and then sell or license that data to a data broker — to register alongside traditional data brokers.
Every other state data broker statute exempts businesses with a direct consumer relationship. That exemption is why most retailers, app developers, and loyalty programs have historically ignored broker registration entirely. A5328 removes that shelter.
The consumer-protection logic
The drafters closed the most common loophole in state broker law: the practice of collecting data under a consumer-facing relationship and then quietly selling it downstream. From a consumer-protection standpoint, the individual never sees the broker who ultimately holds the data. New Jersey now attaches registration and disclosure duties at the point of that first commercial transfer.
The practitioner mistake: assuming 'we are not a data broker' resolves the question. Under A5328, the operative question is whether you sell or license consumer data to a broker — not whether you call yourself one. That distinction will not fly with a regulator who reads the statutory definition.
A5328 amends the New Jersey Data Privacy Act, enacted as Senate Bill S332, signed January 16, 2024, and effective January 15, 2025. Treat the two regimes as one compliance program, not separate silos.
The Split Effective Date and the Deferral You Cannot Rely On
Two clocks, not one
The timing structure is the trap. As Wiley's alert explains, the sensitive data sales ban and civil penalties took effect immediately on June 30, 2026, while the requirement for the Division of Consumer Affairs to establish and maintain the public registry takes effect on March 27, 2027.
The IAPP's coverage of the enactment frames the July 4 timing as an 'Independence Day surprise' precisely because the enforceable ban arrived with no transition period.
What the deferral does and does not cover
Law firm advisories report that on July 10, 2026, the Division of Consumer Affairs issued an alert stating that data brokers and data collectors will not be required to register or pay annual fees until the public registry launches, expected in spring 2027. There are also unconfirmed reports of an enforcement pause and possible legislative fixes.
Read that carefully. The deferral addresses registration and fees — the registry-dependent obligations. It does not, on its face, unwind the sensitive data sales ban that is already live. Treat any reported enforcement pause as unconfirmed and non-binding until New Jersey publishes an official statement. You cannot advise a client to keep selling sensitive data on the strength of an anonymously sourced pause.
Action Items for the Next 60 Days
Work the sequence in order. Do not draft notices before you understand your data flows.
- Inventory sensitive data flows first. Identify every sale or license of sensitive personal data touching New Jersey consumers. The $50,000-per-record penalty makes this the highest-priority item.
- Test the 'data collector' definition against your business. If you collect consumer data directly and transfer it to any broker, assume you are in scope until you can document otherwise.
- Verify the fee tier, do not estimate it. Confirm the consumer-count breakpoints in the enrolled A5328 text before budgeting registration fees. Public secondary sources conflict.
- Calendar both effective dates. Log June 30, 2026 for the live ban and March 27, 2027 for the registry launch as separate milestones.
- Do not rely on the reported enforcement pause. Document your compliance posture as though the sensitive data ban is enforceable now, because it is.
- Reconcile with your NJDPA program. A5328 amends the underlying New Jersey Data Privacy Act; align consent, opt-out, and vendor-contract controls across both.
Build a control matrix that maps each obligation to its effective date and responsible owner. Draft your registration materials and internal policies against that matrix — not the other way around.
Key Takeaways and How to Prepare
Key takeaways
- The ban is live now; the registry is not. The sensitive data sales ban and penalties took effect June 30, 2026, while the registry launches March 27, 2027 — two separate compliance clocks.
- The per-record math is the real risk. A $50,000-per-record penalty for prohibited sensitive data sales, plus $2,500 per day for registration failures, dwarfs the exposure under earlier state broker laws.
- New Jersey redefined who registers. By pulling 'data collectors' with direct consumer relationships into scope, A5328 reaches companies that every other state broker law exempts.
- The fees are the highest in the country. Tiered annual fees run from $5,000 to $1,500,000 — but the exact tier breakpoints must be verified against the enrolled bill.
- Do not lean on the reported deferral. The Division of Consumer Affairs guidance addresses registration and fees; the enforcement-pause reporting remains unconfirmed.
Closing
A5328 rewards teams that inventory before they draft. Start with your sensitive data sales, then your 'data collector' status, then the registry timeline. If you cannot map it, you cannot govern it — and you cannot defend it in a New Jersey inquiry.
Rikka Law helps companies operationalize this work: data maps, vendor diligence, and registration readiness that survive a regulator's first request. Learn more at fintechlaw.ai, and reach the team directly at fintechlaw.ai/contact.
This post is for general informational purposes only and does not constitute legal advice. Consult qualified counsel regarding your specific circumstances.