News Stories
Sponsored by Earth Etch. Regulatory insight and compliance solutions for today’s energy markets.
Data Broker/Collector Bill Passes Both Houses
On June 28, 2026 in New Jersey A5328 and identical bill S2316 were amended. The bills are aimed at regulating data brokers, data collectors, and collection and dissemination of certain sensitive information.
On June 30th the bills passed both houses (56-18-1)
The Senate Budget and Appropriations Committee reports favorably and with committee amendments a Senate Committee Substitute for Senate Bill Nos. 2316.
As amended by the committee, the substitute bill prohibits a controller of a commercial Internet website or online services from selling sensitive data, which prohibition will apply to all individuals or legal entities regardless of the number of consumers whose data the individual or entity controls or processes.
Under the bill, the Division of Consumer Affairs in the Department of Law and Public Safety (division) is to establish and maintain a public registry of “data brokers” and “data collectors,” as these terms are defined in the bill, engaged in processing personal data of New Jersey consumers. The registry is to include, at a minimum, for each data broker and data collector: the data broker’s or data collector’s name and physical address; a general email address that may be used to request information about the data broker’s or data collector’s privacy policies and data collection practices; a general Internet website address for the data broker or data collector; an Internet website address specific to the data broker’s or data collector’s privacy policies; and any relevant opt-out information.
Under the bill, each data broker and data collector is to submit the following information to the division at the time of registration, which information is to be updated by the data broker or data collector at least annually, or at such other frequency as the division may require: (1) the data broker’s or data collector’s name and primary physical, email, and Internet website addresses; (2) whether the data broker or data collector permits individuals to opt out of the data broker’s or data collector’s collection practices, including the method for requesting an opt-out, the type of opt-out, whether the opt-out is limited to certain activities or sales, and whether the data broker or data collector permits individuals to authorize a third party to opt out on the individual’s behalf; (3) whether the data broker or data collector permits individuals to direct the data broker or data collector to delete any personal data in the data broker’s or data collector’s possession; (4) a statement specifying the data collection, databases, or sales activities from which an individual may not opt out; (5) whether the data broker or data collector uses a credentialing process for purchasers of data and, if applicable, a general explanation of that process; (6) a history of data breaches and other cybersecurity events affecting the data broker or data collector and personal identifying information in the data broker’s or data collector’s possession, including the number of individuals affected by each data breach or cybersecurity event; (7) a separate statement detailing the data collection practices, databases, sales activities, and opt-out methods that are applicable to the personal identifying information of persons under the age of 18 and whether the data broker or data collector has actual knowledge that it possesses the personal identifying information of persons under the age of 18; (8) any information the division deems appropriate to implement the purposes of the bill; and (9) the processors who process personal data on behalf of the data broker or data controller.
The bill imposes civil penalties for violations of the bill’s provisions.

