PrivacySignal
News

New Jersey’s New Data Broker Law Imposes Compliance Obligations on Entities That Provide Personal Data to Data Brokers, Prohibits the Sale of Sensitive Data

Morrison Foerster · · International · Privacy Law

New Jersey has enacted a data broker law that places compliance obligations not only on data brokers themselves but also on companies that supply personal data to them. The law separately bans the sale of certain sensitive personal data categories.

Why this matters: Most state privacy laws go after the broker. New Jersey is also going after whoever feeds the broker. That is a meaningful shift. A company that sells, shares, or hands off personal data to a broker is now on the hook too, not just the middleman. And sensitive data — the kind that can expose health conditions, location patterns, or financial stress — cannot be sold at all. If you operate anywhere in the data supply chain touching New Jersey residents, this law is not someone else's problem.

Who should care: Lawyers · Compliance · General readers · Privacy officers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

News
The Guardian — Tech · · International

Amazon to launch Ring ‘neighbourhood watch’ app in UK amid US privacy fears

Doorbell firm aims to replace WhatsApp or Facebook groups with platform where people can post about safety or lost pets Amazon’s doorbell camera maker Ring is to launch its Neighbours community app in the UK in an attempt to supplant neighbourhood WhatsApp or Facebook groups. The service is intended as a modern equivalent of a community message board, where neighbours can post about safety, community matters or lost pets. Continue reading...

Who should care: General readers · Privacy officers · Policy

News
Inside Privacy (Covington) · · International

Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences

On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country. The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and... Continue Reading…

Who should care: Lawyers · Compliance · General readers · Privacy officers · Policy

#regulation#privacy Read original →