New Jersey’s New Data Broker Law Imposes Compliance Obligations on Entities That Provide Personal Data to Data Brokers, Prohibits the Sale of Sensitive Data
New Jersey has enacted a data broker law that places compliance obligations not only on data brokers themselves but also on companies that supply personal data to them. The law separately bans the sale of certain sensitive personal data categories.
Why this matters: Most state privacy laws go after the broker. New Jersey is also going after whoever feeds the broker. That is a meaningful shift. A company that sells, shares, or hands off personal data to a broker is now on the hook too, not just the middleman. And sensitive data — the kind that can expose health conditions, location patterns, or financial stress — cannot be sold at all. If you operate anywhere in the data supply chain touching New Jersey residents, this law is not someone else's problem.
Who should care: Lawyers · Compliance · General readers · Privacy officers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.