New Jersey’s New Privacy Law Changes the Playing Field: Is Your Business Ready?
A New Privacy Law That Demands Attention
For many businesses, privacy compliance has historically been viewed as an issue for large technology companies, major retailers, data brokers and social media platforms. If you were not collecting millions of consumer records or operating a sophisticated online advertising network, privacy laws often seemed like someone else’s problem.
On Jan. 16, 2024, New Jersey Governor Phil Murphy signed Senate Bill (SB) 332, (N.J.S.A. 56:8-166.4 et seq.), establishing New Jersey’s consumer data privacy law – the New Jersey Data Privacy Act (NJDPA) – which became effective Jan. 15, 2025. Though the NDPA’s provisions had little impact on small and medium-sized businesses in the Garden State.
New Jersey’s newly enacted A5328 may change that calculus.
Signed into law on June 30, 2026, A5328 significantly expands New Jersey’s privacy framework by restricting the sale, licensing, transfer and other disclosure of certain categories of broadly defined “sensitive data.” Unlike many privacy laws that apply only to businesses meeting specific revenue thresholds or processing large volumes of personal data, A5328 applies broadly and can impact organizations regardless of size.
For many New Jersey businesses, the law raises an uncomfortable question: Could activities your organization views as ordinary business practices now create privacy compliance risk? The answer may surprise you.
Why This Law Is Different
Most privacy laws focus on how businesses collect and use personal information. A5328 goes a step further by targeting the commercial transfer and disclosure of certain categories of sensitive personal data.
The law focuses on information such as precise geolocation data, health-related information, immigration status, certain financial account information and specified biometric and genetic data. These categories of information are increasingly viewed by regulators as deserving heightened protection because misuse can create significant risks for consumers.
What makes A5328 particularly noteworthy is that many organizations collect this type of information without ever thinking of themselves as being in the “data business.”
A health care provider obviously maintains health information. A property management company may use technologies that collect location data. Employers increasingly use biometric systems for timekeeping and access control. Financial services companies routinely process account information. Even many small and medium-sized businesses utilize website analytics tools that collect information capable of revealing consumer behavior and location.
As a result, businesses that have never considered themselves subject to privacy regulation may suddenly find themselves facing a new set of compliance obligations.
The “We Don’t Sell Data” Problem
One of the most common statements privacy attorneys hear is: “We don’t sell personal data.”
In many cases, that statement is made in good faith. Businesses often associate data sales with the traditional concept of compiling consumer lists and selling them to third parties. Modern data ecosystems are far more complex. Today, organizations routinely share information with advertising networks, analytics platforms, software vendors, marketing partners, customer relationship management systems and artificial intelligence providers. Information may be transferred as part of service arrangements, strategic partnerships or technology integrations without anyone viewing the transaction as a “sale.”
Under A5328, however, businesses should carefully examine whether certain disclosures, licenses, transfers or sharing arrangements could fall within the law’s scope. The answer is often highly fact-specific and may depend on how information is collected, what agreements are in place, and how the recipient uses the data.
In other words, the question is no longer simply whether a company sells data. The question is whether any business practice could be characterized as commercially transferring sensitive personal information.
A New Registration Regime Is Coming
A5328 also establishes a new registration framework for certain entities involved in the sale or licensing of personal information. The law contemplates annual registration requirements and fees tied to data-processing volumes, and New Jersey expects a public registry for covered entities to become operational in 2027.
Many businesses immediately assume these requirements apply only to traditional data brokers. That may not always be the case. Organizations that collect, aggregate, share, license or otherwise monetize personal information should carefully evaluate whether registration obligations may apply to their operations. Even companies that ultimately determine they are outside the registration framework will likely benefit from conducting that analysis now rather than waiting for enforcement activity to begin.
The public nature of the anticipated registry also creates reputational considerations. Customers, vendors, investors, regulators and plaintiffs’ attorneys may all have increased visibility into how organizations handle personal information.
Financial Exposure Is Significant
Perhaps the most eye-catching aspect of A5328 is its penalty structure. The law authorizes civil penalties of up to $50,000 per record for certain violations involving prohibited sales of sensitive personal data, in addition to penalties associated with registration-related violations.
Whether regulators ultimately pursue aggressive enforcement remains to be seen. Nevertheless, the statutory exposure is substantial enough that businesses should not adopt a “wait and see” approach. Even relatively small incidents involving multiple records could create significant liability. For organizations handling large volumes of customer or employee information, the potential exposure quickly becomes impossible to ignore.
What Businesses Should Be Doing Right Now
The good news is that organizations do not need to wait for regulations, enforcement actions or customer complaints to begin reducing risk. The first step is understanding what information your business actually collects and where it goes. Many organizations lack a current inventory of personal information collected through websites, applications, internal systems, vendors and third-party platforms. Without that understanding, evaluating compliance becomes nearly impossible.
Businesses should also determine whether any information they maintain falls within the law’s sensitive data categories. Once sensitive information is identified, organizations should evaluate how that information is used, who receives it and whether any transfers could trigger obligations under the new law.
Contractual relationships deserve particular attention. Agreements with advertising providers, analytics vendors, marketing partners, software providers and data processors should be reviewed to understand exactly how information is shared and what rights recipients have regarding the data they receive.
Privacy notices, website disclosures, consent mechanisms and internal governance procedures should likewise be reassessed to ensure they accurately reflect current practices and satisfy evolving legal requirements. Organizations should also determine now whether future registration requirements could apply so that they are prepared when implementation deadlines arrive.
Website Technologies May Create Unexpected Risk
For many businesses, one of the greatest sources of privacy risk may be sitting in plain sight: the company website. Modern websites often contain analytics tools, advertising technologies, tracking pixels, customer engagement platforms and behavioral analytics software. These tools can provide valuable business insights, but they also frequently involve the collection and sharing of personal information.
A5328 serves as another reminder that website technologies should not be viewed solely as marketing tools. They may also represent privacy compliance issues that deserve legal review. Organizations that have not recently evaluated what information their websites collect, where that information is transmitted and how third parties use it should consider doing so sooner rather than later.
What This Means for Your Business
A5328 sends a clear message: New Jersey intends to take a more aggressive approach toward the commercialization of sensitive personal information. Businesses that previously believed privacy laws applied only to large technology companies should reconsider that assumption. Whether your organization collects customer information, utilizes website tracking technologies, shares information with service providers, licenses data or processes sensitive information as part of ordinary operations, now is the time to understand how the new law may affect your business.
The most effective compliance strategy is almost always proactive rather than reactive. An early assessment of data collection practices, vendor relationships, website technologies and privacy governance can help identify issues before regulators, customers or plaintiffs’ attorneys do.
If you have questions about New Jersey’s new law, website tracking technologies, data-sharing practices, privacy compliance or cybersecurity obligations, please reach out to Elliott J. Stein, Keith McWha or the Stevens & Lee with whom you regularly work.

