A $50,000-per-record penalty is already enforceable in New Jersey — and most marketing teams haven't audited for it yet. Governor Mikie Sherrill signed A.5328 on June 30, 2026, just two days after its introduction. The sensitive-data sale restrictions took effect immediately, with no grace period or phase-in. "This makes the Mactaggart-induced one-week passage of CCPA look downright tame," said Charlie Simon, VP of private advertising at RTB House. Many teams heard "2027"—the delayed registration deadline—and filed it under future problems. This is a misinterpretation. The registration window and fee collection won't open until the public registry launches, anticipated between April and June 2027, according to a July 10 Division of Consumer Affairs alert. However, the sensitive-data ban is already live, with a severe penalty structure: $50,000 per record. "That's an easy date to lean on for comfort," said Jason Bier, general counsel and chief privacy officer at Adstra. "But it's the wrong one to watch."

The "Data Collector" Category Changes the Scope

Unlike other state data broker laws that target middlemen—companies buying and reselling data about individuals they haven't interacted with—New Jersey introduced a second statutory category: the "data collector." If you have a direct consumer relationship and then sell or license that data to a third party, you're regulated. "New Jersey went a step further and pulled in the source," Bier said. "If you're a retailer or platform selling your own customer data to a broker, you're regulated now, too." For B2B SaaS and adtech companies, this is where operational risk lies. Consider the data supply chain: enrichment vendors, audience products, identity graph providers, and media companies licensing logged-in user data. A first-party relationship with a consumer doesn't exempt you. "You don't have to consider yourself as being in the data business to be in scope," Simon said. Idara Udofia, a partner and US privacy lead at Reed Smith, stated that companies can't "circumvent compliance" by pointing to a first-party interaction.

The Penalty Math Gets Ugly Fast

The sensitive-data ban covers health information, precise geolocation, financial account details, biometric data, immigration status, and data collected from children. Violations incur a $50,000-per-record penalty with no cap. "You don't have to work the math far on a segment containing New Jersey residents before you're past any revenue that segment ever produced," Simon said. For example, a segment of 10,000 NJ residents with even one sensitive data field attached could lead to $500 million in potential exposure. Most audience segments don't generate a fraction of that in lifetime value. Additionally, registration and reporting violations carry a $2,500-per-day fine once the registry opens. Annual registration fees range from $5,000 (for 100,000 or fewer consumers) to $1.5 million (for over 4.5 million consumers). California, by comparison, charges a flat $6,000 regardless of scale. "That high end is practically the cost of a compliance team as a sign-up fee," Simon noted.

What to Do This Week

Compliance work splits into two tracks: what's required now (sensitive-data handling) and what's required later (registry and fees). Most teams are ignoring the immediate track. Start by auditing your data flows from collection through enrichment to activation and sharing. Classify which fields could qualify as sensitive under NJ's definition. Map every downstream partner or vendor receiving that data. If any transfers could be construed as selling or licensing sensitive data, you have immediate exposure. The "to whom" question matters as much as the "what." Udofia emphasized that controllers are prohibited from selling sensitive data, and partners' noncompliance can become your liability—contractually or otherwise. "That sounds basic, but most companies probably can't answer it cleanly," Simon said. For the registry track, compliance details are still developing. Freshfields and other firms have noted that guidance on how to count consumers for fee tiers hasn't been finalized. The state's fiscal estimate was labeled "indeterminate" because regulators don't yet know how many brokers will comply or how many consumer records are in play. Plan with assumptions; refine when guidance drops.

The Signal for Other States

New Jersey is the seventh state to pass a data broker law. The breadth of the "data collector" category and the steep fee structure distinguish it from Vermont, California, and others. Industry groups are already considering constitutional challenges, and Udofia expects early enforcement to be "selective and tempered." However, don't mistake measured enforcement for inaction. New Jersey has a history of collecting tolls, and other states are watching. "New Jersey is not the first," Udofia said, "and it most likely will not be the last state to regulate data broker activities." The registration deadline is 2027, but the legal risk starts in 2026. Teams that treat those as the same date will learn the difference the hard way.