Most of the coverage of New Jersey’s new data broker law has been aimed at the large data companies, and most store owners have reasonably assumed it has nothing to do with them. For the majority of AARA members, that is correct. But the law created a second category called “data collector” that is defined by what you do with customer data rather than by how big you are, and there is no small-business exemption anywhere in it.
Governor Sherrill signed A5328 on June 30, 2026, and most of it took effect that same day. The registration fees are on hold until 2027. The ban on selling sensitive customer data is live right now.
The One Sentence That Decides Whether This Touches You
A data collector is a business that collects personal data from customers it has a direct relationship with, and then sells or licenses that data to a data broker.
Read that second half carefully, because it is the whole test. Running a loyalty program does not put you in scope. Keeping a customer email list does not put you in scope. Knowing what your regulars buy does not put you in scope. Selling or licensing that information onward is what puts you in scope.
So Where Is the Risk for a Store Owner?
The risk is usually not in what you do. It is in what your vendor does. Some third-party loyalty apps, receipt-marketing platforms, and analytics add-ons reserve the right in their contract to monetize the shopper data they gather in your store. If your signage and your terms present that program as yours, you may be closer to the definition of a data collector than you would expect. That is a contract question, and it has a definite answer.
What Is Already Illegal Today
The provision that took effect on June 30 is a flat prohibition on selling or licensing sensitive data. Sensitive data covers categories such as health information, precise location, and other protected characteristics. The penalty is $50,000 per record, not per incident. That per-record structure is what makes this law an outlier among state privacy statutes.
The law carves out data already governed by other regimes, including HIPAA-covered health information, financial data under GLBA, consumer reporting under the FCRA, certain research activity, and insurance and government records.
What Is Coming, and When
If you are a covered data broker or data collector, you will eventually have to register annually and pay a fee that starts at $5,000 for 100,000 consumers or fewer and scales up to $1.5 million. Once registration is live, missing it runs $2,500 per day, with no cap.
None of that is owed yet. The Division of Consumer Affairs said on July 10 that registration and fees wait until the registry is operational, and that the first registration window is expected to run from April 1 through June 30, 2027. Further guidance, including on the sensitive data restrictions, has been promised before then.
Timeline
| Date | What Applies |
|---|---|
| June 30, 2026 | Signed into law. The sensitive data sale and license ban is in force at $50,000 per record. |
| July 10, 2026 | Division of Consumer Affairs confirms no registration or fees are owed until the registry opens. |
| March 27, 2027 | The public registry requirement takes effect. |
| April 1 to June 30, 2027 | Expected first registration period. |
What It Means for AARA Members
- Pull the contract for any loyalty, rewards, or marketing platform you use and look for the clause covering data sharing, data licensing, or “partners.” If it lets the vendor sell or license shopper data, ask them in writing whether they consider you a data collector under A5328 and what they are doing about it. Keep their answer on file.
- If you do not sell customer data, you almost certainly have no filing to make. This brief is not a reason to shut down your loyalty program. It is a reason to know what your vendor agreement actually permits.
- You have time on the paperwork, but not on the ban. Registration is roughly nine months out. The sensitive data prohibition applies today.
What Is Still Unsettled
The Division has said it will publish more detail on the sensitive data restrictions and on exactly who counts as a covered business. Several edge cases, including how far the term “data collector” reaches into ordinary retail, are not yet settled. AARA is tracking this and will send members an update when that guidance lands.
Verify This Yourself
The New Jersey Division of Consumer Affairs posts its guidance on the Office of Consumer Protection alerts page, including the July 10, 2026 notice on data broker registration.
For the definitions, thresholds, and penalties, see the Future of Privacy Forum analysis, Navigating New Jersey’s Data Broker and Data Collector Registration Law, and the Zwillgen summary of effective dates and the delayed registry.
This is a compliance brief for AARA members, current as of July 20, 2026. A5328 (P.L.2026, c.25) is enacted New Jersey law. Whether a particular store qualifies as a data collector depends on its vendor contracts and its own data practices. This is not legal advice, so confirm your position with your attorney or the New Jersey Division of Consumer Affairs.
