New Jersey Data Broker Law: What Businesses Should Know Before 2027

New Jersey enacted a new data-broker and data-collector law in June 2026. The Division of Consumer Affairs (DCA) now says the public registry is planned for spring 2027, with the first registration window set for April 1 through June 30, 2027. For New Jersey organizations, the useful question is not simply whether to put that date on a calendar—it is whether their data practices fit the law’s definitions, and which obligations may apply before registration begins.

This article summarizes the official law and DCA’s current rollout notice as of October 7, 2026. It is general information, not a coverage determination or legal advice.

What New Jersey enacted

On June 30, 2026, the Legislature approved A5328 as P.L. 2026, c. 25. The law amends New Jersey’s Data Privacy Act and adds requirements for data brokers and data collectors, including annual registration with DCA and restrictions on selling or licensing certain sensitive data.[1][2]

The statute defines these roles through specific data activities and relationships—not just the name a company uses. In broad terms, its “data broker” definition concerns knowingly collecting or purchasing a New Jersey consumer’s personal data without a direct relationship and selling or licensing that data to a third party. Its “data collector” definition concerns a business that collects personal data from consumers with whom it has a direct relationship and sells or licenses that data to a data broker. The law also defines “consumer” as a New Jersey resident acting in an individual or household context, rather than in a commercial or employment context, and includes exceptions.[2]

Those definitions are a reason to review actual data flows, not to assume that every employer or business holding customer information must register—or that a company is out of scope because it does not call itself a data broker. A lawyer should assess how the statutory definitions and exceptions fit the organization’s facts.

What DCA says about the 2027 rollout

DCA’s July 10, 2026 alert says the law requires covered data brokers and data collectors to register annually. DCA plans to launch the public registry in spring 2027. Until then, the agency says covered entities will not be required to register under the law or pay registration fees; the first registration period is scheduled for April 1 through June 30, 2027. DCA says it will provide additional registration guidance before the period begins.[1]

The signed text says the act takes effect immediately, except that the subsection requiring DCA to establish the public registry remains inoperative for 270 days after enactment. DCA’s alert also separately notes restrictions on certain sales or licensing of sensitive data. The delayed registry dates should not be treated as a blanket statement that every other provision is postponed; organizations should ask counsel which rules apply to their activities and when.[2]

Timing What the official sources say Practical response
Now, October 2026 DCA says registration and fees are not required before the registry is launched; its alert separately flags sensitive-data restrictions. Map data collection, sale, and licensing practices; get a legal review instead of assuming the registration delay pauses every obligation.
Spring 2027 DCA plans to launch the public registry and issue further guidance. Watch DCA’s official alerts for instructions; do not rely on older summaries for final filing steps.
April 1–June 30, 2027 DCA identifies this as the first registration period for covered data brokers and data collectors. If counsel determines the organization is covered, prepare for the window and confirm requirements against current DCA guidance.

What businesses can review now

  • Map the relevant data flows. Identify personal data that is collected or purchased, where it comes from, who receives it, and whether it is sold or licensed for consideration. Document the organization’s role in each flow rather than relying only on internal labels.
  • Check direct relationships. The law distinguishes data brokers from data collectors partly by whether the organization has a direct relationship with the consumer and whether data is transferred to a broker. Record the facts that counsel will need to assess.
  • Flag sensitive data. The act separately restricts certain sales or licensing of sensitive data. Determine whether relevant information appears in the organization’s data flows and get advice on the statute’s definitions, exceptions, and timing.
  • Review exceptions and partners. The enacted text includes exceptions and addresses entities that process data on another party’s behalf. Do not assume that a vendor contract, a small number of records, or a familiar industry label answers the coverage question without legal review.
  • Track the official timeline. Keep the April–June 2027 window visible, but revisit the DCA alert page for its promised guidance and any changes before filing.
  • Keep retention and deletion separate. A new data-broker law is not a direction to purge files immediately. Check the retention schedule, legal holds, and other applicable duties before deleting or destroying records.

Registration is not document destruction

P.L. 2026, c. 25 concerns personal-data practices, sensitive-data restrictions, and state registration; it does not make shredding a substitute for a privacy-law analysis or create a general shredding schedule. New Jersey’s separate customer-record destruction provision addresses secure destruction of covered personal-information records when they are no longer to be retained. Retention and legal holds come first. For a practical retention-to-destruction sequence, see our guide to New Jersey customer records and secure destruction.[3]

Once paper records are eligible for disposal, organizations can compare handling options and ask what a service includes. Request a quote to discuss a secure destruction project. Any provider’s role is limited to the service it performs; it does not decide whether a company is covered by the data-broker law or whether records may legally be destroyed.

Frequently asked questions

Does every New Jersey business need to register?

Not automatically. The statute sets definitions for data brokers and data collectors and contains exceptions. Whether an organization is covered depends on its actual practices and the statutory terms; seek qualified legal advice.

Can a business wait until April 2027 to think about the law?

DCA says the first registration period is April 1–June 30, 2027, and that covered entities do not have to register or pay fees before registry launch. But the law contains provisions beyond registration, and DCA separately notes sensitive-data restrictions. Review the full law and current agency guidance with counsel rather than treating the filing window as the start date for every obligation.

Does the law require a company to shred records?

No general shredding schedule is stated in this law. Record destruction is a separate issue: confirm that retention has ended and no hold applies, then use a method appropriate to the records and applicable requirements.

Last reviewed October 7, 2026. This article is general information, not legal advice. The statute, DCA guidance, and implementation details may change; confirm current requirements with qualified counsel and the New Jersey Division of Consumer Affairs.

Primary sources

  1. New Jersey Division of Consumer Affairs, Office of Consumer Protection Alerts, “Data Broker Legislation” entry dated July 10, 2026.
  2. New Jersey Legislature, A5328 / P.L. 2026, c. 25; see the signed advance-law text.
  3. New Jersey Division of Consumer Affairs, Identity Theft Prevention Act, including N.J.S.A. 56:8-162.