New Jersey signed A5328 into law on June 30, 2026, and most of it took effect immediately. Marketers and marketing technology teams that operate in New Jersey are impacted, and this law goes beyond restrictions on data usage to actually having to register as a data collector depending on the technology in your MarTech stack. This is something we haven’t seen from any regulation and may be flying under the radar with its ramifications.
If your stack contains registered data brokers, you have to register as a data collector
The law creates a “data collector” category no other state has. It covers companies that sell or license personal data to a data broker, including brands with direct customer relationships. Registration fees run $5,000 to $1.5 million per year depending on user data volume.
New Jersey doesn’t have a registry of data brokers yet, with the public launch of the registry targeted for April 1, 2027. In the meantime, we can use California’s data broker registry as a proxy. In a recent review of a customer site, we found ten California-registered data brokers were loading on their properties (IQVIA, Demandbase, and LiveRamp among others).
We see many of these same platforms across other customer websites, suggesting that many of them likely will need to register as data collectors. In many cases, the use of these platforms is to power campaigns or measurement models their agencies are running.
You can compare your own tech stack against California’s registry: https://cppa.ca.gov/data_broker_registry/. If sending data to them counts as a sale under New Jersey’s definition, you may have to register and pay the fee.
Selling sensitive data is banned, and consent will not fix it
New Jersey already required opt-in consent to process sensitive data, so if you run an explicit consent model, your targeting and measurement were largely covered before this. The change implemented by the new law is narrower and harder to work around: you can’t sell sensitive data at all. There is no consent exception.
Sensitive data covers racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, precise geolocation, and financial information.
Potential changes/implications to be aware of:
- Data sharing agreements that were previously approved on the basis of opt-in may be impacted with these new requirements.
- Data monetization, second-party data deals, and co-ops involving sensitive attributes may need to be re-evaluated or reconsidered.
- Selling or licensing location data, since precise geolocation is a sensitive category, may be restricted further.
- Organizations previously exempt from data sharing provisions due to their size/presence in the state may now have to comply with these new requirements as the new law doesn’t specify a size or data volume threshold.
Whether targeted advertising counts as a "sale" is still unresolved
New Jersey defines a sale as “sharing, disclosing, or transferring personal data for monetary or other valuable consideration.” Most comprehensive state privacy laws say “sale or share,” with definitions for “share” explicitly inclusive of sharing data for targeted advertising. The new New Jersey law says only “sale,” then attaches the broad consideration language. Among other things, this is expected to be clarified via guidance from the New Jersey Division of Consumer Affairs in the coming months. For now, there are two arguments for if any disclosure of personal data for targeted advertising would be considered a “sale”:
- Argument for data disclosure for advertising being a “Sale”: you receive campaign performance and audience reach, which reads as other valuable consideration.
- Argument against: elsewhere in the same law, processing for targeted advertising is listed separately from selling personal data in the Data Protection Assessment requirements.
Both readings hold up today and the state hasn’t clarified it (yet). It’s worth gaining clarity from your legal team for their interpretation, considering your organization policies and risk tolerance. Your team can help with this consideration by providing which platforms receive data, from which pages, and under what terms.
Enforcement is paused, but the law stands
On July 10, the New Jersey Division of Consumer Affairs said covered entities will not need to register or pay fees until the first registration period in spring 2027. A senior administration official told the New Jersey Globe the state will not enforce until the legislature addresses defects in the law.
The state has not said the prohibited conduct is now permitted, guidance on the sensitive data restriction is still pending, and the pause itself is being challenged politically. However, much like the leadup to GDPR and CCPA… treat this as time to prepare rather than a reason to ignore it. We consistently see that these laws get implemented with short runways to comply.
What to do now
- Inventory what is loading on your site. Your tag manager shows what should load, which is only a piece of the puzzle. Hard coded tags and third-party tags that load other tags often lead to a lot of surprises. A free audit from Tag Inspector can give you full visibility into all of the tags loading on your website.
- Cross-reference your tag inventory against California’s data broker registry. It’s the best available proxy until New Jersey publishes its own.
- Flag pages where sensitive categories can be inferred. Health content, financial tools, and anything where the URL or title reveals a condition or circumstance.
- Pull the data processing terms for platforms loading on pages with potential sensitive information. Your legal team will probably ask whether each one processes only on your behalf or for its own purposes too.
- Check that your Data Protection Assessment process covers targeted advertising. New Jersey now requires one for sales of personal data and for targeted advertising posing heightened risk.
Find out what your tags are doing
Get a free audit of your website. We will provide you an inventory of the tags and cookies loading across your website, including the ones loaded by third parties, to cross-reference against data broker registries.