New Jersey’s new data broker law was introduced on June 28. The governor signed it on June 30.
Trade groups managed to push the registration deadline back to 2027, but the rest of it took effect immediately.
“This makes the Mactaggart-induced one-week passage of CCPA look downright tame,” said Charlie Simon, VP of private advertising at RTB House. (For reference, Alastair Mactaggart is the San Francisco real estate attorney who personally bankrolled California’s landmark privacy law, which was negotiated and passed over the course of roughly one week in 2018.)
Back over on the East Coast, a lot of folks in the ad industry quietly breathed a sigh of relief when they heard “2027” and put “compliance with NJ’s sweeping data broker law” in a file labeled “next year’s problem.” Not a good idea.
“That’s an easy date to lean on for comfort,” said Jason Bier, general counsel and chief privacy officer at Adstra. “But it’s the wrong one to watch.”
A wide net
New Jersey is the seventh state to enact a data broker law, but it’s not a carbon copy of Vermont, California, Texas, Oregon or Connecticut.
The most talked-about parts of the new law are the fee structure (we’ll get there) and the sensitive data ban (we’ll get there, too). But the most consequential part – and the bit getting the least attention – is a new statutory category called the “data collector.”
Every other state data broker law goes after middlemen, the companies buying and reselling data about people they’ve never dealt with directly.
“New Jersey went a step further and pulled in the source,” Bier said. “If you’re a retailer or platform selling your own customer data to a broker, you’re regulated now, too.”
For a lot of businesses – retailers with loyalty programs, for example, or media companies – this marks their first encounter with obligations they didn’t think applied to them. “You don’t have to consider yourself as being in the data business to be in scope,” Simon said.
But most consumers don’t realize their data is being sold at all. That’s why this law exists. (Well, that and the revenue it generates for the state.)
A pharmacy customer signing up for a loyalty card, for example, probably isn’t consenting to have their purchase history end up in a broker’s database, and neither is a reader who logs into a news site to access an article.
In other words, a first-party relationship with a consumer isn’t air cover, and companies can’t “circumvent compliance” by pointing to a first-party interaction, said Idara Udofia, a partner and US privacy lead for the emerging technologies group at Reed Smith.
Everything’s fine
Companies also can’t push off their obligations.
Although the registration window doesn’t open until April 2027 – the one concession trade groups successfully lobbied for – and the New Jersey Division of Consumer Affairs has been clear that companies don’t need to file anything until then, the sensitive data ban took effect the moment Governor Mikie Sherrill signed the bill.
But Bier has some advice for free: Don’t confuse the paperwork timeline with the legal timeline.
The sensitive data ban is already in effect and covers everything from health information, precise geolocation and financial account details to biometric data, immigration status and data collected from children. Violations carry a $50,000-per-record penalty, which can add up fast.
“It’s a multiplier with no cap,” Simon said. “You don’t have to work the math far on a segment containing New Jersey residents before you’re past any revenue that segment ever produced.”
And the annual public registration fee will eventually come due, too, and it’s also not cheap. New Jersey’s tiered structure runs from $5,000 to $1.5 million a year, depending on how many NJ residents a company markets to.
For the sake of comparison, California charges a flat $6,000 annual registration fee, which stays the same whether a broker holds several thousand records or several million.
“That high end is practically the cost of a compliance team as a sign-up fee,” Simon said.
For whom the regulator tolls
But in the meantime, the best practices still and always apply. Companies should know exactly what data they sell, to whom they sell it and whether any of the data would count as sensitive.
“That sounds basic, but most companies probably can’t answer it cleanly,” Simon said.
The “to whom” is particularly important.
“Controllers are prohibited from selling sensitive data,” Udofia said. “Therefore controllers, among others, may be held liable, whether contractually or otherwise” – which is another way of saying that a partner’s noncompliance can become your problem fast.
Litigation, meanwhile, is widely expected. Industry and political groups are already floating potential constitutional challenges to the law. For now, though, Udofia thinks enforcement itself will start carefully: “selective and tempered,” they said.
Not that NJ is usually shy about collecting tolls, and other states without their own data broker laws yet are no doubt taking notes.
“New Jersey is not the first,” Udofia said, “and it most likely will not be the last state to regulate data broker activities.”
🙏 Thanks for reading! As always, feel free to drop me a line at allison@adexchanger.com with any comments or feedback. While you’re at it, why not donate to this adorable cat rescue in Asbury Park, NJ?
🍎 🚕 🍕 And since you’ve already got your credit card out, might as well snag a ticket to Programmatic IO New York, too, coming up on September 28 and 29 in New York City. (See what I did there?)
