Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Data Privacy

New Jersey's A5328 Is the Costliest Data Broker Law in the Country — and It's Already in Effect for Sensitive Data

New Jersey signed A5328 on June 30, 2026, banning the sale of sensitive financial and personal data immediately and creating registration fees up to $1.5 million. GLBA covers some fintechs — but 'financial services' doesn't automatically mean exempt. Here's the analysis every fintech and data aggregator needs to run now.

By Rebecca Leung · July 29, 2026 ·
Table of Contents

TL;DR

  • New Jersey signed A5328 on June 30, 2026 — creating the nation’s highest data broker registration fees (up to $1.5M annually) and immediately banning the sale of sensitive financial and personal data
  • Unlike California’s DROP system deadline (which covered only registered data brokers without a direct consumer relationship), NJ’s law also covers “data collectors” — companies that sell data about their own direct customers
  • The GLBA entity-level exemption exists but requires confirming your fintech is itself a GLBA-covered financial institution — being in financial services is not enough
  • Penalties for selling sensitive data start at $50,000 per record; the ban is in effect now

The Law Nobody Saw Coming Was Already Effective Before Most Teams Noticed

California gets the headlines. Vermont gets the practitioners’ attention because it’s where data broker compliance started. New Jersey just wrote the most expensive version of either.

On June 30, 2026, New Jersey Governor Mikie Sherrill signed A5328 — a data broker and data collector registration and regulation law that does three things no prior state law has done at this scale:

  1. It bans the sale or licensing of “sensitive personal data” immediately on signing — no effective date, no grace period
  2. It creates registration fees that scale to $1.5 million annually for the largest data sellers
  3. It sweeps in “data collectors” — companies that sell consumer data even when they have a direct relationship with those consumers

That third element is what separates New Jersey from the existing framework. California’s Delete Act and Texas’s data broker law both focus on the classic broker model: companies collecting and selling data about people they’ve never interacted with directly. NJ creates a second category that reaches into direct-relationship businesses — and that changes the compliance calculus for a significant portion of the fintech ecosystem.

Two New Registration Requirements: Broker and Collector

A5328 creates two distinct registration obligations:

Data brokers: Businesses that sell or license personal data of New Jersey residents with whom they have no direct relationship. This tracks the standard data broker definition used in California, Vermont, and other states.

Data collectors: Businesses that sell or license personal data of New Jersey residents with whom they do have a direct relationship. This is new. If you’re a bank, lender, or insurance company that sells or licenses your customers’ data to third parties — even data about people who are your actual customers — you may now be a “data collector” under NJ law.

Both categories must register with the New Jersey Division of Consumer Affairs.

Registration opens April 1, 2027, and the initial period closes June 30, 2027. But registration and fees are the compliance deadline — the sensitive data prohibition is already in effect.

The Fee Schedule Is Not a Typo

New Jersey’s registration fees are set by the number of New Jersey consumer records you sell:

Annual NJ Records SoldFee
1 – 10,000$5,000
10,001 – 100,000$10,000
100,001 – 1,000,000$100,000
1,000,001 – 10,000,000$500,000
10,000,001+$1,500,000

New Jersey has approximately 9.3 million residents. A national data aggregator or people-search platform operating at scale could face a $1.5M annual registration bill before the first enforcement action. This is a significant departure from California ($6,000/year for data broker registration), Vermont ($100/year), and Texas ($300/year).

The fee isn’t a penalty — it’s the annual compliance cost. Penalties for violations stack on top of it.

The Sensitive Data Ban Is Already Live

The A5328 prohibition on selling or licensing sensitive personal data took effect the day the governor signed the bill. There is no delayed implementation, no compliance runway, no opportunity to cure before the prohibition applies.

“Sensitive personal data” under A5328 includes:

  • Financial account numbers, log-ins, and credit or debit card numbers with security codes or access codes
  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health condition, treatment, or diagnosis
  • Sexual orientation or sex life
  • Precise geolocation data
  • Citizenship or immigration status
  • Status as transgender or non-binary
  • Genetic or biometric data for identifying individuals
  • Personal data collected from children
  • Social Security numbers

The financial data category is the one most directly relevant to fintechs. If your product involves sharing consumer banking credentials, account numbers, or payment card data with third parties — and you don’t have clear legal authority and a GLBA exemption — you’re selling sensitive data under A5328 and that prohibition is already in effect.

This covers more than the obvious cases. Financial data aggregators that pass credential-based login flows to third-party lenders or analytics providers, lead generators that package consumer financial profiles, and data brokers that compile credit-adjacent data products all need to evaluate whether the data they’re selling falls under the sensitive data definition.

The GLBA Exemption: What It Actually Covers

A5328 provides entity-level exemptions for:

  • Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
  • State-chartered banks and insurance companies
  • Secondary market institutions (e.g., Fannie Mae, Freddie Mac)
  • State agencies

It also provides data-level exemptions for information already covered by GLBA, HIPAA, and FCRA.

The entity-level exemption is the one fintechs tend to lean on — but it requires scrutiny. GLBA covers “financial institutions” engaged in financial activities. That definition covers banks, broker-dealers, mortgage companies, and their subsidiaries engaged in financial activities. It does not automatically cover:

  • Technology companies providing software or services to financial institutions
  • Data analytics firms that work primarily in financial services
  • Lead generators and affiliate marketers operating in the loan or insurance space
  • Fintech platforms whose primary product is not a financial product but which handle financial data incidentally

The test is whether your company is itself a GLBA-covered financial institution — not whether you serve financial institutions or handle financial data. A data aggregation company that passes financial credentials between consumers and lenders is providing a service to the financial system, not necessarily operating within the GLBA framework.

If you’re uncertain, the analysis has three steps:

  1. Are we engaged in “financial activities” as defined by the Bank Holding Company Act Section 4(k)?
  2. Are we subject to a federal functional regulator’s oversight under GLBA?
  3. Is the consumer data we’re selling “nonpublic personal financial information” as GLBA defines it?

If you can’t confidently answer all three, you should not assume the GLBA exemption applies.

The Three Fintech Archetypes That Need to Act Now

Financial data aggregators: Companies using screen scraping or API-based access to pull consumer financial data and sell or license it to lenders, insurance companies, or analytics platforms. The data they handle — account numbers, transaction histories, credential-linked data — is sensitive personal data under A5328. The question is whether the aggregator itself is GLBA-covered or is simply a technology intermediary in the data supply chain.

Fintech lead generators: Companies that collect consumer financial profiles — credit score ranges, income data, employment data — and sell or license those leads to lenders, credit card issuers, or insurance companies. These companies typically don’t have a regulated financial products relationship with consumers, which means no GLBA exemption and likely no direct-relationship defense.

Marketing data platforms with financial overlays: Analytics and marketing technology companies that append financial data to consumer profiles for targeting purposes. If those overlays include account-level or payment card data, the sensitive data prohibition applies regardless of whether the platform considers itself a financial services company.

For all three categories, the immediate question isn’t registration (that opens April 2027) — it’s whether any current data products involve the sale or licensing of sensitive personal data under the prohibition that’s already in effect.

The Penalty Math

For selling or licensing sensitive personal data in violation of A5328: $50,000 per record.

Consider what that means at scale. A lead generator that packages and sells financial profiles to ten lenders, with each package containing 100,000 consumer records, faces potential exposure of $5 billion for a single product cycle — before any multiplier for ongoing violations.

The $50,000/record number is not a maximum. It’s listed in the statute as the applicable civil penalty. New Jersey’s Division of Consumer Affairs and Attorney General have independent enforcement authority.

For non-registration: $2,500 per day.

For context: the CPPA’s $200/deletion-request-per-day penalty for California DELETE Act violations — which compliance teams treated as serious — is a fraction of NJ’s enforcement authority for sensitive data violations.

What to Do Before Counsel Calls You

Whether or not you end up needing to register in New Jersey or are exempt, the compliance analysis you should be running right now:

  1. Map what consumer data you’re selling or licensing: Identify every data product, data feed, or third-party data arrangement where NJ resident data is included. Don’t limit this to “data broker” activities — the data collector category means any sale of consumer data can be in scope.

  2. Classify the data against the sensitive categories: Flag any product that includes financial account numbers, log-ins, payment card data, or any of the other enumerated sensitive categories. For those products, the prohibition is already in effect.

  3. Run the GLBA analysis: Determine whether your organization is itself a GLBA-covered financial institution, and whether the GLBA data-level exemption covers the specific data in each product.

  4. Assess registration obligation: If your data products survive the sensitive data analysis (or you’ve confirmed exemptions apply), evaluate whether you’ll need to register as a data broker, data collector, or both before the April 2027 registration window opens.

  5. Document the analysis: Whether the conclusion is “exempt” or “must register,” the analysis should be documented. New Jersey AG enforcement investigations will start with requests for records about how companies determined their obligations.

So What?

New Jersey’s A5328 is not on most compliance teams’ calendars yet. The registration deadline isn’t until April 2027 and the law is less than a month old. But the sensitive data prohibition didn’t come with a clock — it went live June 30.

If you sell data products that include financial account numbers, login credentials, or payment card data about NJ residents, that prohibition applies to you today. The fee structure makes this the most expensive registration regime in the country. And the “data collector” category means this isn’t only a question for companies in the traditional data broker business.

California set the standard for consumer deletion rights. New Jersey may have just set the standard for how much non-compliance costs.

For a practical starting point on managing consumer data obligations, documenting GLBA applicability, and tracking data sharing arrangements across your program, the Data Privacy Compliance Kit includes templates for consumer data mapping, GLBA NPI assessment, and third-party data sharing agreement review.


Related reading: California’s DELETE Act and the August 1 DROP Deadline | State AG Data Privacy Enforcement in 2026 | FTC Safeguards Rule: The 9 Elements Non-Bank Financial Institutions Need

External sources: WilmerHale — NJ A5328 Analysis | Troutman Privacy — Nation’s Costliest Data Broker Law | McDermott — NJ Bans Sensitive Data Sales | Wiley — Immediate Effect Alert | Hunton Privacy — NJ Data Broker Regime

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is New Jersey's A5328 and when does it take effect?
A5328 is New Jersey's data broker and data collector registration law, signed by Governor Mikie Sherrill on June 30, 2026. The prohibition on selling or licensing 'sensitive personal data' took effect immediately on signing. Registration requirements for both data brokers and data collectors open April 1, 2027, with the initial registration period closing June 30, 2027. Penalties for selling sensitive data — $50,000 per record — apply from the date of signing.
How is New Jersey's law different from California's data broker laws?
Three key differences. First, New Jersey covers 'data collectors' — companies that sell consumer data even if they have a direct relationship with those consumers — not just data brokers with no direct customer relationship. Second, NJ's registration fees are the highest in the country: up to $1.5 million annually based on volume. Third, NJ banned the sale of sensitive personal data immediately on signing, with no grace period or compliance timeline.
Does the GLBA exemption protect fintech companies from A5328?
It depends. A5328 provides entity-level exemptions for financial institutions subject to GLBA, insurance companies, and secondary market institutions. If your fintech is itself a GLBA-covered financial institution — meaning you engage in activities 'incidental to financial services' and are subject to GLBA's privacy requirements — you may be exempt. Non-bank technology companies, data aggregators that aren't themselves financial institutions, and fintech-adjacent marketing platforms are NOT automatically covered by the GLBA exemption just because they operate in financial services.
What counts as 'sensitive personal data' under New Jersey's law?
A5328 defines sensitive personal data to include financial account numbers, log-ins, and credit/debit card numbers with security codes; racial or ethnic origin; religious beliefs; mental or physical health condition or diagnosis; precise geolocation; sexual orientation; sex life; immigration or citizenship status; transgender or non-binary status; genetic or biometric data; and personal data collected from children. For fintechs, the financial data category — account numbers, log-in credentials — is particularly significant since it covers data many financial data aggregators and credential-sharing services routinely handle.
What are the penalties for non-compliance with A5328?
Two penalty tracks. For selling or licensing sensitive personal data in violation of the prohibition: $50,000 per record. For failing to register as a data broker or data collector, or failing to pay required fees: $2,500 per day until in compliance. Given that many data operations involve thousands or millions of consumer records, a single enforcement action for sensitive data violations could produce penalties in the hundreds of millions.
If we're already registered as a California data broker, do we still need to register in New Jersey?
Yes. State data broker registrations are separate. California's DELETE Act registration and New Jersey's A5328 registration are independent requirements, administered by different agencies with different fee structures, disclosure requirements, and registration timelines. Being compliant in California does not satisfy New Jersey's requirements. A company that sells data about California and New Jersey consumers must assess both regimes separately.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.