惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
Netflix TechBlog - Medium
IT之家
IT之家
博客园_首页
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
小众软件
小众软件
博客园 - 叶小钗
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
月光博客
月光博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure
New Jersey Adopts New Data Broker Registration Regime and...
2026-07-17 · via Privacy & Cybersecurity Law Blog

New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions

On June 30, 2026, New Jersey Governor Mikie Sherrill signed into law A.5328 (“the Act”), requiring data brokers and data collectors to register annually, pay a fee, make specified disclosures, and refrain from selling or licensing sensitive data.

The law took effect immediately, with the exception of provisions requiring the New Jersey Division of Consumer Affairs to establish and maintain a public registry of covered data brokers and collectors, which remain inoperative for 270 days after enactment. On July 10, the Division announced that the initial registration period for covered data brokers and data collectors will run from April 1 through June 30, 2027, and that it will provide additional guidance before that period begins.

The law creates requirements for both “data brokers” and “data collectors:”

  • A “data broker” is a person or legal entity that knowingly collects or purchases the personal data of a consumer with whom it does not have a direct relationship and sells or licenses that data to a third party.
  • A “data collector” is a business, or a unit of a business, that knowingly collects the personal data of a consumer with whom it has a direct relationship and sells or licenses that personal data to a data broker.

As a result, the law may apply not only to traditional data brokers, but also to entities that sell or license personal data obtained through a direct consumer relationship, if that data is sold to data brokers. In addition to registration and annual fee requirements, data brokers and data collectors must disclose certain information as part of the registration process and, like controllers (discussed further below), are prohibited from selling or licensing sensitive data subject to applicable statutory exemptions.

The law establishes an annual registration fee structure based on the number of New Jersey consumers whose personal data a data broker sells or licenses, or whose personal data a data collector collects and sells or licenses to a data broker. Fees start at $5,000 annually for 100,000 consumers or fewer and increase to $1.5 million annually for more than 4.5 million consumers.

The law also creates significant penalties for noncompliance. A data broker or data collector that fails to register or pay the required registration fee is liable for the unpaid registration fees for each applicable year, plus a civil penalty of $2,500 for each day of noncompliance. Failure to submit or update required registration information likewise carries a civil penalty of $2,500 per day. A data broker, controller, or data collector that unlawfully sells, offers for sale, or licenses sensitive data is liable for a civil penalty of $50,000 per record.

The law also amends New Jersey’s comprehensive privacy law to prohibit controllers from selling sensitive data. The statute defines sensitive data to include personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition, treatment, or diagnosis, certain financial information, sex life or sexual orientation, citizenship or immigration status, transgender or nonbinary status, genetic or biometric data used to uniquely identify an individual, personal data collected from a known child, and precise geolocation data. The law does not include a consent-based exception to this prohibition, and the prohibition applies to all individuals and legal entities regardless of the number of consumers whose data the individual or entity controls or processes.