Feature Data Privacy
New Jersey's A5328 Is the Costliest Data Broker Law in the Country — and It's Already in Effect for Sensitive Data
New Jersey signed A5328 on June 30, 2026, banning the sale of sensitive financial and personal data immediately and creating registration fees up to $1.5 million. GLBA covers some fintechs — but 'financial services' doesn't automatically mean exempt. Here's the analysis every fintech and data aggregator needs to run now.
Table of Contents
TL;DR
- New Jersey signed A5328 on June 30, 2026 — creating the nation’s highest data broker registration fees (up to $1.5M annually) and immediately banning the sale of sensitive financial and personal data
- Unlike California’s DROP system deadline (which covered only registered data brokers without a direct consumer relationship), NJ’s law also covers “data collectors” — companies that sell data about their own direct customers
- The GLBA entity-level exemption exists but requires confirming your fintech is itself a GLBA-covered financial institution — being in financial services is not enough
- Penalties for selling sensitive data start at $50,000 per record; the ban is in effect now
The Law Nobody Saw Coming Was Already Effective Before Most Teams Noticed
California gets the headlines. Vermont gets the practitioners’ attention because it’s where data broker compliance started. New Jersey just wrote the most expensive version of either.
On June 30, 2026, New Jersey Governor Mikie Sherrill signed A5328 — a data broker and data collector registration and regulation law that does three things no prior state law has done at this scale:
- It bans the sale or licensing of “sensitive personal data” immediately on signing — no effective date, no grace period
- It creates registration fees that scale to $1.5 million annually for the largest data sellers
- It sweeps in “data collectors” — companies that sell consumer data even when they have a direct relationship with those consumers
That third element is what separates New Jersey from the existing framework. California’s Delete Act and Texas’s data broker law both focus on the classic broker model: companies collecting and selling data about people they’ve never interacted with directly. NJ creates a second category that reaches into direct-relationship businesses — and that changes the compliance calculus for a significant portion of the fintech ecosystem.
Two New Registration Requirements: Broker and Collector
A5328 creates two distinct registration obligations:
Data brokers: Businesses that sell or license personal data of New Jersey residents with whom they have no direct relationship. This tracks the standard data broker definition used in California, Vermont, and other states.
Data collectors: Businesses that sell or license personal data of New Jersey residents with whom they do have a direct relationship. This is new. If you’re a bank, lender, or insurance company that sells or licenses your customers’ data to third parties — even data about people who are your actual customers — you may now be a “data collector” under NJ law.
Both categories must register with the New Jersey Division of Consumer Affairs.
Registration opens April 1, 2027, and the initial period closes June 30, 2027. But registration and fees are the compliance deadline — the sensitive data prohibition is already in effect.
The Fee Schedule Is Not a Typo
New Jersey’s registration fees are set by the number of New Jersey consumer records you sell:
| Annual NJ Records Sold | Fee |
|---|---|
| 1 – 10,000 | $5,000 |
| 10,001 – 100,000 | $10,000 |
| 100,001 – 1,000,000 | $100,000 |
| 1,000,001 – 10,000,000 | $500,000 |
| 10,000,001+ | $1,500,000 |
New Jersey has approximately 9.3 million residents. A national data aggregator or people-search platform operating at scale could face a $1.5M annual registration bill before the first enforcement action. This is a significant departure from California ($6,000/year for data broker registration), Vermont ($100/year), and Texas ($300/year).
The fee isn’t a penalty — it’s the annual compliance cost. Penalties for violations stack on top of it.
The Sensitive Data Ban Is Already Live
The A5328 prohibition on selling or licensing sensitive personal data took effect the day the governor signed the bill. There is no delayed implementation, no compliance runway, no opportunity to cure before the prohibition applies.
“Sensitive personal data” under A5328 includes:
- Financial account numbers, log-ins, and credit or debit card numbers with security codes or access codes
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health condition, treatment, or diagnosis
- Sexual orientation or sex life
- Precise geolocation data
- Citizenship or immigration status
- Status as transgender or non-binary
- Genetic or biometric data for identifying individuals
- Personal data collected from children
- Social Security numbers
The financial data category is the one most directly relevant to fintechs. If your product involves sharing consumer banking credentials, account numbers, or payment card data with third parties — and you don’t have clear legal authority and a GLBA exemption — you’re selling sensitive data under A5328 and that prohibition is already in effect.
This covers more than the obvious cases. Financial data aggregators that pass credential-based login flows to third-party lenders or analytics providers, lead generators that package consumer financial profiles, and data brokers that compile credit-adjacent data products all need to evaluate whether the data they’re selling falls under the sensitive data definition.
The GLBA Exemption: What It Actually Covers
A5328 provides entity-level exemptions for:
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- State-chartered banks and insurance companies
- Secondary market institutions (e.g., Fannie Mae, Freddie Mac)
- State agencies
It also provides data-level exemptions for information already covered by GLBA, HIPAA, and FCRA.
The entity-level exemption is the one fintechs tend to lean on — but it requires scrutiny. GLBA covers “financial institutions” engaged in financial activities. That definition covers banks, broker-dealers, mortgage companies, and their subsidiaries engaged in financial activities. It does not automatically cover:
- Technology companies providing software or services to financial institutions
- Data analytics firms that work primarily in financial services
- Lead generators and affiliate marketers operating in the loan or insurance space
- Fintech platforms whose primary product is not a financial product but which handle financial data incidentally
The test is whether your company is itself a GLBA-covered financial institution — not whether you serve financial institutions or handle financial data. A data aggregation company that passes financial credentials between consumers and lenders is providing a service to the financial system, not necessarily operating within the GLBA framework.
If you’re uncertain, the analysis has three steps:
- Are we engaged in “financial activities” as defined by the Bank Holding Company Act Section 4(k)?
- Are we subject to a federal functional regulator’s oversight under GLBA?
- Is the consumer data we’re selling “nonpublic personal financial information” as GLBA defines it?
If you can’t confidently answer all three, you should not assume the GLBA exemption applies.
The Three Fintech Archetypes That Need to Act Now
Financial data aggregators: Companies using screen scraping or API-based access to pull consumer financial data and sell or license it to lenders, insurance companies, or analytics platforms. The data they handle — account numbers, transaction histories, credential-linked data — is sensitive personal data under A5328. The question is whether the aggregator itself is GLBA-covered or is simply a technology intermediary in the data supply chain.
Fintech lead generators: Companies that collect consumer financial profiles — credit score ranges, income data, employment data — and sell or license those leads to lenders, credit card issuers, or insurance companies. These companies typically don’t have a regulated financial products relationship with consumers, which means no GLBA exemption and likely no direct-relationship defense.
Marketing data platforms with financial overlays: Analytics and marketing technology companies that append financial data to consumer profiles for targeting purposes. If those overlays include account-level or payment card data, the sensitive data prohibition applies regardless of whether the platform considers itself a financial services company.
For all three categories, the immediate question isn’t registration (that opens April 2027) — it’s whether any current data products involve the sale or licensing of sensitive personal data under the prohibition that’s already in effect.
The Penalty Math
For selling or licensing sensitive personal data in violation of A5328: $50,000 per record.
Consider what that means at scale. A lead generator that packages and sells financial profiles to ten lenders, with each package containing 100,000 consumer records, faces potential exposure of $5 billion for a single product cycle — before any multiplier for ongoing violations.
The $50,000/record number is not a maximum. It’s listed in the statute as the applicable civil penalty. New Jersey’s Division of Consumer Affairs and Attorney General have independent enforcement authority.
For non-registration: $2,500 per day.
For context: the CPPA’s $200/deletion-request-per-day penalty for California DELETE Act violations — which compliance teams treated as serious — is a fraction of NJ’s enforcement authority for sensitive data violations.
What to Do Before Counsel Calls You
Whether or not you end up needing to register in New Jersey or are exempt, the compliance analysis you should be running right now:
-
Map what consumer data you’re selling or licensing: Identify every data product, data feed, or third-party data arrangement where NJ resident data is included. Don’t limit this to “data broker” activities — the data collector category means any sale of consumer data can be in scope.
-
Classify the data against the sensitive categories: Flag any product that includes financial account numbers, log-ins, payment card data, or any of the other enumerated sensitive categories. For those products, the prohibition is already in effect.
-
Run the GLBA analysis: Determine whether your organization is itself a GLBA-covered financial institution, and whether the GLBA data-level exemption covers the specific data in each product.
-
Assess registration obligation: If your data products survive the sensitive data analysis (or you’ve confirmed exemptions apply), evaluate whether you’ll need to register as a data broker, data collector, or both before the April 2027 registration window opens.
-
Document the analysis: Whether the conclusion is “exempt” or “must register,” the analysis should be documented. New Jersey AG enforcement investigations will start with requests for records about how companies determined their obligations.
So What?
New Jersey’s A5328 is not on most compliance teams’ calendars yet. The registration deadline isn’t until April 2027 and the law is less than a month old. But the sensitive data prohibition didn’t come with a clock — it went live June 30.
If you sell data products that include financial account numbers, login credentials, or payment card data about NJ residents, that prohibition applies to you today. The fee structure makes this the most expensive registration regime in the country. And the “data collector” category means this isn’t only a question for companies in the traditional data broker business.
California set the standard for consumer deletion rights. New Jersey may have just set the standard for how much non-compliance costs.
For a practical starting point on managing consumer data obligations, documenting GLBA applicability, and tracking data sharing arrangements across your program, the Data Privacy Compliance Kit includes templates for consumer data mapping, GLBA NPI assessment, and third-party data sharing agreement review.
Related reading: California’s DELETE Act and the August 1 DROP Deadline | State AG Data Privacy Enforcement in 2026 | FTC Safeguards Rule: The 9 Elements Non-Bank Financial Institutions Need
External sources: WilmerHale — NJ A5328 Analysis | Troutman Privacy — Nation’s Costliest Data Broker Law | McDermott — NJ Bans Sensitive Data Sales | Wiley — Immediate Effect Alert | Hunton Privacy — NJ Data Broker Regime
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is New Jersey's A5328 and when does it take effect?
How is New Jersey's law different from California's data broker laws?
Does the GLBA exemption protect fintech companies from A5328?
What counts as 'sensitive personal data' under New Jersey's law?
What are the penalties for non-compliance with A5328?
If we're already registered as a California data broker, do we still need to register in New Jersey?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
California's DELETE Act: The August 1, 2026 DROP Deadline and the GLBA Exemption Test Every Fintech Needs to Pass
California's DELETE Act requires data brokers to process consumer deletion requests through the DROP system starting August 1, 2026. The penalty is $200 per request per day. Most GLBA-covered financial institutions are exempt — but many fintechs aren't sure which category they're in. Here's how to run the analysis.
Jul 28, 2026
Data Privacy
Privacy Impact Assessment for Mixed GLBA and Non-GLBA Data: Scope the Data, Not the Entity
Use a data privacy impact assessment template to separate GLBA and non-GLBA processing by data flow, purpose, person, use, and state-law scope.
Jul 25, 2026
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026