New Jersey just closed the loophole that let smaller businesses assume its data privacy law didn't apply to them. On June 30, 2026, Governor Mikie Sherrill signed A5328, an amendment to the New Jersey Data Privacy Act that bans the sale of sensitive personal data outright, with no size threshold and no consent exception. If your business processes any New Jersey resident's health, financial, biometric, or location data and shares or sells it to a third party, this law reaches you now, regardless of how many records you handle.
That's a real change from how the original law worked, and a lot of businesses in the 25 to 250 employee range haven't caught up to it yet.
What the Original NJ Data Privacy Act Covered
The New Jersey Data Privacy Act, signed in January 2024 and effective January 15, 2025, only applied to businesses that hit certain volume thresholds. You were covered if you controlled or processed the personal data of at least 100,000 New Jersey consumers in a year, or at least 25,000 consumers while also making money from selling that data.
Those thresholds gave most small and mid-size businesses a reasonable basis to assume the law was someone else's problem. A 60-person marketing agency in Hoboken or a 40-person insurance brokerage in Parsippany typically doesn't touch 100,000 consumer records. Under the original law, that assumption mostly held up.
What A5328 Changed
A5328, sometimes called the NJ Sensitive Data Law, doesn't touch those original thresholds for the broader NJDPA. What it does is carve out a separate, much broader rule specifically for sensitive personal data. That rule applies to "any person or entity," full stop, regardless of consumer volume or revenue.
Sensitive data under the law covers a wide list: racial or ethnic origin, religious beliefs, health conditions and treatment, financial account information, sex life or sexual orientation, citizenship or immigration status, transgender or non-binary status, genetic and biometric identifiers, data collected from a known child, and precise geolocation data.
If your business sells, licenses, shares, or otherwise discloses any of that data for money or something else of value, and you didn't get explicit consent structured the way the law requires, you're exposed. There's no consent workaround built into this particular ban the way there is in a lot of state privacy laws.
The penalty is $50,000 per record. Personal data moves in batches, not one record at a time, so that number scales fast. A single non-compliant transfer involving a modest list can turn into a liability figure that dwarfs the transaction that caused it.
The New Data Broker and Data Collector Rules
A5328 also creates two new categories of regulated entity that didn't exist before in New Jersey: data brokers and data collectors. A data broker collects or buys personal data from people it has no direct relationship with, then sells or licenses it to others. A data collector has a direct relationship with the consumer, collects the data itself, and then sells or licenses it to a broker.
Both categories have to register annually with the New Jersey Division of Consumer Affairs and pay a fee based on how many consumers' data they handle. Fees run from $5,000 at the low end up to $1.5 million for the largest operations. According to a Division alert issued in July 2026, the registration requirement itself won't be enforced until the registry launches, expected around spring 2027. But legal commentary on the law is consistent on one point: businesses should figure out now whether they fall into either category, because the sensitive data sale ban is already enforceable with no grace period.
Who Actually Gets Caught By This
This is where the fine print matters more than the headline. Most businesses in the 25 to 250 employee range don't think of themselves as data brokers. But the definitions in A5328 are broad enough to catch arrangements that don't look like data brokering on the surface.
A staffing firm that shares candidate health screening results with a client. A property management company that sells or licenses tenant application data to a background check vendor for something beyond a direct service fee. A retailer running location-based marketing through a third-party ad platform that resells geolocation data. Any of these could trigger the sensitive data rules even if the business has never thought of itself as being in the data business.
The honest answer for most companies is that they don't know whether any of their current vendor relationships or marketing tools involve a disclosure that counts as a "sale" under this law. That's not a knock on any particular business. It's a genuinely new legal category applied retroactively to arrangements that were set up before anyone was thinking about it this way.
What to Do About It Now
Start with an inventory, not a legal opinion. Before you need a lawyer, you need to know what sensitive data categories you actually collect and where that data goes after it leaves your systems. That means looking at website tracking pixels, marketing platform integrations, vendor contracts that involve any data sharing, and any arrangement where a third party pays you or gives you something of value in exchange for data.
This is exactly the kind of gap that shows up during a managed IT and compliance review, because it sits at the intersection of what your systems actually do and what your contracts say they do. Most businesses don't have a single person who owns both views. An ongoing IT partnership that includes governance and vendor oversight is built to catch this kind of thing before a regulator or a plaintiff's attorney does.
FAQ
Does the New Jersey Data Privacy Act apply to my business if I'm small?
The general NJDPA still applies based on volume thresholds (100,000+ consumers, or 25,000+ with revenue from data sales). But the sensitive data sale ban added by A5328 applies to any business regardless of size, if you sell or share sensitive personal data of New Jersey residents.
What counts as "selling" data under New Jersey's law?
The law defines it broadly to include sharing, disclosing, or transferring personal data in exchange for money or anything else of value. It's not limited to a traditional cash sale.
When do I need to register as a data broker or data collector?
The registration and fee requirements are not being enforced yet. The New Jersey Division of Consumer Affairs has indicated the public registry is expected to launch around spring 2027. The sensitive data sale ban itself, however, is already enforceable with no grace period.
What's the penalty for violating the sensitive data sale ban?
Civil penalties of up to $50,000 per record for unlawful sale, offer for sale, or licensing of sensitive personal data. Registration violations carry a separate penalty of $2,500 per day once that requirement takes effect.
Who enforces this law?
The New Jersey Attorney General, through the Consumer Fraud Act. There's no private right of action, meaning individual consumers can't sue directly, but they can file complaints that trigger AG enforcement.
Figuring out whether your vendor contracts and marketing tools create exposure under New Jersey's expanded privacy law takes someone who understands both your systems and your data flows. Get in touch to talk through where your business stands.