Skip to main content

New Jersey's $5,000 to $1.5 Million Data Broker Law: What Selling Customer Data Now Costs Small Businesses

15 min readMike ThriftMike Thrift
New Jersey's $5,000 to $1.5 Million Data Broker Law: What Selling Customer Data Now Costs Small Businesses

If you have ever sold a customer list, licensed email addresses to a marketing partner, or passed shopper data to an analytics firm, New Jersey just put a price tag on that transaction — and it starts at $5,000 a year. Even if you only touch a few thousand New Jersey residents' records.

On June 30, 2026, New Jersey enacted A5328 (P.L.2026, c.25), the most expensive data broker registration law in the country. Unlike older laws in California and Vermont that targeted classic third-party data brokers, New Jersey's version reaches any business that sells or licenses personal data of New Jersey residents — including retailers, publishers, apps, and service businesses that have a direct relationship with the consumer. If you monetize data you collected yourself, you are now a regulated "data collector" in New Jersey, subject to the same annual fee, public registry, and sensitive-data ban as a traditional broker.

Here is what changed, what it will cost, who it catches, and how to get your books and operations ready before the registration window opens in mid-2027.

Why This Law Is Different From Every Other State's

Most state data broker laws follow the California model: if you do not have a direct relationship with the consumer and you sell data you bought elsewhere, you register and pay a modest flat fee. California charges about $6,000 a year. Vermont, Texas, and Connecticut charge a few hundred dollars.

New Jersey rewrote that playbook in three ways:

  1. It covers first-party sellers. A "data broker" still means an entity that sells data it did not collect directly from the consumer. But New Jersey added a parallel category, "data collector," for entities that did collect the data directly — from their own customers, subscribers, or website visitors — and then sell or license it downstream. If you run an online store and sell your customer file to a co-op database, you are a data collector.

  2. The fee is tied to volume, not a flat rate. Fees run from 5,000to5,000 to 1.5 million per year based on how many New Jersey consumers' records you handle. California's flat fee looked expensive until this law made it look like a filing fee.

  3. Sensitive data sales are banned outright. The law amends the New Jersey Data Privacy Act (NJDPA) to prohibit the sale or licensing of sensitive data by virtually any entity — not just brokers and collectors, not just large companies, and not with consent as an escape hatch. That ban took effect immediately on June 30.

The bill was also fast-tracked. Introduced June 28, passed both chambers within two days, and signed by Governor Mikie Sherrill on June 30, it went from idea to law faster than most businesses can update a privacy policy.

The 7-Tier Fee Schedule That Starts at $5,000

Covered brokers and collectors must register annually with the New Jersey Division of Consumer Affairs, which will maintain a public registry. Registration requires paying the fee, listing your legal name, physical address, websites, a data-broker history including breaches and cybersecurity events, and clear instructions for how consumers can opt out.

According to the law and subsequent guidance from the Division, the annual fees scale with the number of New Jersey consumers whose personal data you sell or license:

  • $5,000 for 100,000 or fewer New Jersey consumers
  • $10,000–$15,000 for 100,001 to 500,000 consumers
  • $100,000–$200,000 for 500,001 to 1 million consumers
  • $500,000 for 1 million to 2 million consumers
  • $750,000–$1 million for 2 million to 4.5 million consumers
  • $1.5 million for more than 4.5 million consumers

Final tier thresholds have been described with minor variations across law-firm summaries, but the structure is consistent: seven steps, steeply progressive, with the top two tiers reaching seven figures. For context, New Jersey has about 9.5 million residents — a broker handling data on half the state pays the maximum.

Failing to register or pay carries a civil penalty of $2,500 per day. Given that the registry is not expected to be operational until March 27, 2027 (nine months after enactment), with the Attorney General's Division indicating in an early August 2026 alert that it will not require compliance with the registration and fee requirements until June 2027, you have a window to assess exposure — but not to ignore it.

A Quick Cost Comparison

StateAnnual Data Broker Fee
California~$6,000 flat
Vermont, Texas, Oregon$100–$500 flat
Connecticut$500 flat
New Jersey5,000 – \1,500,000 tiered

New Jersey did not just raise the ceiling; it created a new floor that is 10 times higher than most states' entire fee.

Who Actually Qualifies? More Businesses Than You Think

You do not need to think of yourself as a "data broker" to be covered.

You are likely a data broker if: you buy, aggregate, or license personal data from sources other than the consumer directly, and then sell or license that data. Examples include people-search sites, risk-scoring providers, marketing-co-op operators, and lead-generation resellers.

You are likely a data collector if: you have a direct relationship with the consumer — they made an account, bought a product, signed up for a newsletter — and you sell or license their personal data to someone else. Examples that catch ordinary small businesses:

  • An e-commerce brand that monetizes its customer file by selling it to a data co-op or sharing it with non-affiliated advertisers for compensation.
  • A local media site or app that licenses its subscriber or visitor data to an ad network beyond the service-provider context.
  • A loyalty program operator that sells purchase history to a third-party analytics firm.
  • A B2B service that collects small business contact data and licenses it as a prospect list.

What does not trigger registration? If you only use a service provider or processor to handle data on your behalf — for example, an email platform that sends your own campaigns, or a payment processor that touches transaction data only to complete the sale — and you do not sell or license the underlying data for the vendor's own benefit, you are not selling data under the law. Using data internally to market to your own customers is also not a sale.

The distinction that matters in your books: compensation. A "sale" in New Jersey means exchanging personal data for monetary or other valuable consideration. If the data flow is part of providing the contracted service and the recipient cannot reuse it for its own commercial purposes, it is more likely a service-provider arrangement than a sale.

The Sensitive Data Ban That Applies to Everyone

Separate from the broker/collector registration, New Jersey now prohibits the sale or licensing of sensitive data by any entity, regardless of whether you are a broker, collector, or just a small business that once shared a sensitive list with a partner:

  • Personal data revealing racial or ethnic origin
  • Health-related data and genetic data
  • Financial information (beyond what is needed to process a payment)
  • Sexual orientation, transgender/intersex status, and related data
  • Citizenship and immigration status
  • Religious beliefs
  • Biometric and genetic identifiers
  • Precise geolocation
  • Data about children

Unlike Connecticut's narrower geolocation ban or other states that allow sensitive data sales with opt-in consent, New Jersey prohibits the sale even with consent. Violations carry $50,000 per record sold, offered for sale, or licensed. That is not per breach or per consumer file — it is per record. A 1,000-row list of geolocation-tagged customer records offered for $500 could theoretically trigger a $50 million penalty exposure.

This part of the law took effect immediately. If you currently have any data-sharing arrangement that touches one of these categories for New Jersey residents, you should have already paused it and re-examined it with counsel.

What the Public Registry Will Show About Your Business

Once operational, the Division will publish a searchable registry listing for each broker and collector:

  • Legal name, primary physical and mailing address, and website
  • Whether the entity permits consumers to opt out of personal data sales and how to do it
  • Metrics for opt-out requests received and completed
  • History of data breaches and cybersecurity events
  • Contact for consumer inquiries

This is more disclosure than California requires. For small businesses, the reputational point is as important as the fee: if you end up on a public data broker list, customers and partners will find you there.

A 6-Step Checklist Before June 2027

You have roughly 10 months from enactment to the expected compliance deadline. Use them to make a defensible call about whether you are in scope and to clean up your data flows.

1. Map where personal data leaves your company for value

Pull your last 12 months of vendor and income records. Look for any line where you received payment (cash, credits, discounted services, revenue share) and shared personal data in return. Common culprits:

  • "Data licensing" or "audience extension" revenue
  • Co-op database participation fees
  • List rental income
  • Referral payments tied to sharing contact data
  • Analytics partnerships where you provide raw customer data beyond the scope of the service

If the payment is tied to data itself — not to the service of sending an email or processing a payment — flag it.

2. Count New Jersey records separately

The fee is per New Jersey consumer, not per total records. Segment your data by state. Even if you sell a national file of 2 million records, only the subset who are New Jersey residents counts toward the tier. That may be 2–3% for a typical national list, but if you are New Jersey–heavy, it could be much higher.

If you cannot currently segment by state, that is your first engineering task. You cannot calculate a tier or argue you are below a threshold without it.

3. Halt any sensitive data sales now

Run every outgoing data feed against the sensitive categories above. Remember that inferences count: a purchase history that reveals health conditions or a zip-code plus ethnicity file can be treated as sensitive even if you did not label it that way.

If you find sensitive data in a sale pipeline, stop the sale, document the stop date, and do not rely on an old consent form to justify continuing. New Jersey's ban does not have a consent exception for this use.

4. Re-paper vendor relationships that are really service-provider relationships

If a vendor is a true processor, make sure your contract says so: the data may only be used to provide the service to you, must be deleted or returned when the contract ends, and cannot be sold, retained, or used to build the vendor's own products. Absent that language, regulators may treat the hand-off as a sale.

5. Budget the fee and decide if the revenue is worth it

Do a hard P&L on every data-sale line:

  • Gross revenue from the data sale
  • Annual New Jersey registration fee for your tier
  • Legal and audit costs to maintain compliance (privacy counsel, data inventory, opt-out infrastructure)
  • Risk reserve for penalties if your classification is wrong

Many small businesses will discover that a $3,000 annual list rental that pushes them into the $5,000 tier is already unprofitable, before counting the compliance overhead. Some are exiting the side business entirely. Others are restructuring to stay a service provider — for example, by letting the advertiser only target audiences through your platform without ever transferring underlying records.

6. Prepare registry inputs early

If you conclude you are in scope, you will need:

  • A written data-breach and security-event history going back several years
  • Opt-out mechanism documentation and counts of requests honored
  • Alternate fee calculation support (your New Jersey consumer count methodology)
  • Bookkeeping that proves the fee was paid and the registration renewed annually

Keep these as a compliance package, not scattered emails. Examiners will want to see methodology, not just a number.

Bookkeeping and Tax Treatment: Do Not Bury the Fee

The New Jersey fee is an annual, recurring cost of doing business if you remain a broker or collector, not a one-time filing charge. How you book it matters for both internal decisions and external reporting.

Create a separate compliance cost center. Do not lump the registration fee into "licenses and permits" with your local business license or LLC annual report fee. Create a distinct general-ledger account such as Compliance: Data Broker Registration – NJ and book the full tier amount there each year. That makes the profitability test in step 5 above honest: you can see in one line whether data-sale revenue covers its own regulatory cost.

Treat it as an ordinary and necessary business expense, but track deductibility assumptions. For federal income tax, annual registration fees that are ordinary and necessary to operate in a jurisdiction are generally deductible as business expenses in the year paid or accrued. That is not tax advice; state fees can interact with capitalization rules if tied to a 15-year intangible or with Section 162(f) if they are technically a penalty. Keep the invoice and the statute citation with the entry and have your CPA confirm the treatment before filing. If any portion is a penalty for late registration ($2,500 per day), that portion is not deductible.

Do not net the fee against data-sale revenue. Book gross revenue from data sales as Revenue: Data Licensing and the fee as an operating expense. Netting them understates both and breaks the reconciliation between your 1099-related records (if applicable) and your bank deposits. It also hides how close you are to the next fee tier if your New Jersey count grows.

Reconcile to your data-sales log monthly. Maintain a simple table: month, counterparty, records shared, New Jersey records within that share, compensation received, contract type (sale vs. service provider). Reconcile that log to your revenue account and to cash receipts. If you are ever examined, the question will be "how did you get to 87,000 New Jersey consumers?" and you will need the source query, not an estimate.

If you stop selling data to exit the regime: book a final year fee if required for the year you were active, write a dated memo to file stating the business decision and the date sales ceased, and retain the underlying data-flow diagrams. Dropping below the threshold does not retroactively erase fee liability for a year you were over it.

What Happens If You Do Nothing

Three risks converge:

  • Immediate liability for sensitive data sales — there is no grace period for that ban, and the per-record penalty is designed to make even small sales painful.
  • Daily penalties for missed registration — once the registry is live and the enforcement delay lifts in June 2027, every day without registration is a separate $2,500 penalty, irrespective of how much data you sold that day.
  • Contract and payment fallout — data buyers who learn their New Jersey supplier is unregistered may terminate or demand indemnification. Some master data-license agreements already require the seller to represent that it complies with applicable data broker laws.

None of those risks requires New Jersey to prove intent. They are strict compliance obligations, and New Jersey's Attorney General has explicit authority to enforce them.

Should You Exit the Data-Sale Business?

For many small businesses, the answer will be yes — not because the law bans your core product, but because it turns a side revenue line into a regulated activity with six-figure audit tails.

Ask yourself:

  • Is data-sale revenue material — say, more than 5% of gross profit — or is it opportunistic?
  • Could you achieve the same marketing outcome by keeping data in-house and selling access rather than raw records? For example, letting partners advertise to your audiences inside your environment without exporting the underlying personal data.
  • Do you have the engineering capacity to segment by state, honor opt-outs, and maintain breach-history disclosures for a public registry?

If the answer to the first is "no" and the next two are "not easily," exiting is the lower-cost compliance posture. That exit itself should be documented: terminate or amend the data-sale contracts, update your privacy notice to remove the "we sell data" disclosure for New Jersey, and retain the amended agreements as proof of your changed status.

If data sales are core to your model — a list business, a marketing co-op, an audience-data platform — treat New Jersey as the high-water mark and prepare for other states to copy it. California's $6,000 fee looked like the ceiling for a decade; New Jersey moved it to $1.5 million in one bill.

Simplify Your Financial Management

Whether you stay in the data business or exit it, the New Jersey law is a reminder that a small revenue line can create outsized compliance costs if you cannot see its true margin. Keeping data-licensing revenue, registration fees, legal costs, and penalty reserves in separate, version-controlled books makes that margin visible before a renewal notice or an examiner does.

Beancount.io gives you plain-text, double-entry accounting that is fully transparent and AI-ready — no black boxes, no vendor lock-in. Track compliance expenses by jurisdiction, reconcile data-sale income to cash, and keep a complete history of every reclassification in git. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article