New Jersey's Data Broker Law Is Live. The Part That Matters Most Isn't the Registry.
New Jersey's A.5328 data broker law took effect June 30, 2026 with $50,000-per-record penalties for sensitive data violations — and registration isn't required until 2027.
A $50,000-per-record penalty is already enforceable in New Jersey — and most marketing teams haven't audited for it yet.
Governor Mikie Sherrill signed A.5328 on June 30, 2026, just two days after its introduction. The sensitive-data sale restrictions took effect immediately, with no grace period or phase-in.
"This makes the Mactaggart-induced one-week passage of CCPA look downright tame," said Charlie Simon, VP of private advertising at RTB House.
Many teams heard "2027"—the delayed registration deadline—and filed it under future problems. This is a misinterpretation. The registration window and fee collection won't open until the public registry launches, anticipated between April and June 2027, according to a July 10 Division of Consumer Affairs alert. However, the sensitive-data ban is already live, with a severe penalty structure: $50,000 per record.
"That's an easy date to lean on for comfort," said Jason Bier, general counsel and chief privacy officer at Adstra. "But it's the wrong one to watch."
The "Data Collector" Category Changes the Scope
Unlike other state data broker laws that target middlemen—companies buying and reselling data about individuals they haven't interacted with—New Jersey introduced a second statutory category: the "data collector." If you have a direct consumer relationship and then sell or license that data to a third party, you're regulated.
"New Jersey went a step further and pulled in the source," Bier said. "If you're a retailer or platform selling your own customer data to a broker, you're regulated now, too."
For B2B SaaS and adtech companies, this is where operational risk lies. Consider the data supply chain: enrichment vendors, audience products, identity graph providers, and media companies licensing logged-in user data. A first-party relationship with a consumer doesn't exempt you. "You don't have to consider yourself as being in the data business to be in scope," Simon said.
Idara Udofia, a partner and US privacy lead at Reed Smith, stated that companies can't "circumvent compliance" by pointing to a first-party interaction.
The Penalty Math Gets Ugly Fast
The sensitive-data ban covers health information, precise geolocation, financial account details, biometric data, immigration status, and data collected from children. Violations incur a $50,000-per-record penalty with no cap.
"You don't have to work the math far on a segment containing New Jersey residents before you're past any revenue that segment ever produced," Simon said.
For example, a segment of 10,000 NJ residents with even one sensitive data field attached could lead to $500 million in potential exposure. Most audience segments don't generate a fraction of that in lifetime value.
Additionally, registration and reporting violations carry a $2,500-per-day fine once the registry opens. Annual registration fees range from $5,000 (for 100,000 or fewer consumers) to $1.5 million (for over 4.5 million consumers). California, by comparison, charges a flat $6,000 regardless of scale.
"That high end is practically the cost of a compliance team as a sign-up fee," Simon noted.
What to Do This Week
Compliance work splits into two tracks: what's required now (sensitive-data handling) and what's required later (registry and fees). Most teams are ignoring the immediate track.
Start by auditing your data flows from collection through enrichment to activation and sharing. Classify which fields could qualify as sensitive under NJ's definition. Map every downstream partner or vendor receiving that data. If any transfers could be construed as selling or licensing sensitive data, you have immediate exposure.
The "to whom" question matters as much as the "what." Udofia emphasized that controllers are prohibited from selling sensitive data, and partners' noncompliance can become your liability—contractually or otherwise.
"That sounds basic, but most companies probably can't answer it cleanly," Simon said.
For the registry track, compliance details are still developing. Freshfields and other firms have noted that guidance on how to count consumers for fee tiers hasn't been finalized. The state's fiscal estimate was labeled "indeterminate" because regulators don't yet know how many brokers will comply or how many consumer records are in play. Plan with assumptions; refine when guidance drops.
The Signal for Other States
New Jersey is the seventh state to pass a data broker law. The breadth of the "data collector" category and the steep fee structure distinguish it from Vermont, California, and others. Industry groups are already considering constitutional challenges, and Udofia expects early enforcement to be "selective and tempered."
However, don't mistake measured enforcement for inaction. New Jersey has a history of collecting tolls, and other states are watching.
"New Jersey is not the first," Udofia said, "and it most likely will not be the last state to regulate data broker activities."
The registration deadline is 2027, but the legal risk starts in 2026. Teams that treat those as the same date will learn the difference the hard way.
A CMO friend texted me at 11 PM about spending three hours manually adjusting LinkedIn bids. There is a better way, but it's not about replacing human judgment with robots. It's about knowing which levers to automate and which ones still need your fingerprints.
Creating demand from cold audiences costs $187 per lead. Retargeting costs $196. That nine-dollar difference just blew up every budget assumption you've been defending in quarterly reviews, and the real gap worth acting on isn't where you think it is.
Performance Max handles 45% of Google Ads conversions, but most B2B teams can't tell you which AI workflow is actually driving revenue. The question isn't whether to automate, it's which decisions you hand to the model and which you keep.