On June 30, 2026, Governor Mikie Sherrill signed P.L. 2026, c.25, expanding New Jersey’s regulation of businesses that collect, share, sell, or license consumers’ personal information. The law creates new compliance obligations for certain businesses that transfer personal information to third parties and amends portions of the New Jersey Data Privacy Act.
Many business owners may assume the law applies only to large technology companies or traditional “data brokers.” That is not necessarily the case. Depending on how a business uses customer information, the law may also apply to companies whose primary business has nothing to do with selling data.
Could This Law Apply to Your Business?
Your business should evaluate the new law if it:
- collects personal information from customers or website visitors;
- shares customer information with marketing companies, advertising platforms, or data analytics providers;
- licenses or sells customer lists or other personal information to third parties;
- participates in lead-generation or referral programs involving consumer information; or
- otherwise receives compensation or other value in exchange for transferring personal information.
Whether the law applies depends on the specific facts and the statutory definitions, not simply on whether a business considers itself to be a “data broker.”
Examples
The law may warrant review if your business:
- provides customer information to an outside marketing company in exchange for advertising or promotional services;
- licenses customer or membership lists to another business;
- participates in a lead-generation program in which customer information is transferred to third parties;
- shares consumer information with affiliates as part of a revenue-generating arrangement; or
- uses third-party vendors that monetize or further distribute customer information.
Not every transfer of information will trigger the law, but these are the types of arrangements that should be reviewed.
What Does the Law Require?
Among other things, the legislation:
- requires certain covered businesses to register annually with the New Jersey Division of Consumer Affairs;
- requires specified information regarding data collection and privacy practices to be disclosed as part of the registration process;
- expands regulation of the sale and licensing of certain categories of personal information;
- strengthens certain obligations under the New Jersey Data Privacy Act; and
- authorizes significant civil penalties for violations.
The Division of Consumer Affairs has announced that it expects to establish the registration system in Spring 2027, with the initial registration period anticipated to begin thereafter.
Registration Fees and Penalties
Annual registration fees are based on the number of New Jersey consumers whose personal information is sold or licensed and range from $5,000 to $1.5 million per year.
The law also authorizes substantial civil penalties, including:
- $2,500 per day for failing to register, pay the required registration fee, or timely update required registration information; and
- Up to $50,000 per record for certain unlawful sales or licensing of sensitive personal information.
What Should Businesses Do Now?
Businesses should consider taking the following steps:
- Inventory what personal information the business collects.
- Identify every third party with whom that information is shared.
- Review contracts with marketing firms, software providers, analytics companies, affiliates, and other vendors.
- Determine whether any customer information is sold, licensed, or otherwise transferred for value.
- Review website privacy policies and internal privacy practices to ensure they accurately describe the business's data practices.
- Consult legal counsel to determine whether the business has registration or other compliance obligations under the new law.
Why This Matters
Privacy regulation continues to expand at both the state and federal levels. Businesses that have historically viewed privacy compliance as an issue for large technology companies should reconsider that assumption. Even companies in traditional industries—including retailers, manufacturers, professional service firms, contractors, healthcare providers, and nonprofit
organizations—may need to evaluate whether their data-sharing practices are subject to New Jersey’s new requirements.
If you have questions about how P.L. 2026, c.25 may affect your business, or would like assistance reviewing your privacy practices, customer agreements, vendor contracts, or website privacy policies, please contact one of the attorneys in our Business Law Group.
The foregoing is not intended, and should not be construed as, legal advice or guidance or an offer to provide legal services by Laddey, Clark & Ryan, LLP. The contents of this communication are for informational purposes only and should not be relied on or considered in making any decisions or taking any actions. If you wish to inquire about legal services, please contact Laddey, Clark & Ryan, LLP, at lcr@lcrlaw.com.


