S 2316 New Jersey Senate · 2026-2027 Regular Session

Regulates data brokers, data collectors, and collection and dissemination of certain sensitive information.**

This bill requires data brokers operating in New Jersey to register with the Division of Consumer Affairs annually ($100 fee) and submit detailed information about their data collection, privacy policies, opt-out options, and data breach history. It directly affects businesses that collect and sell personal identifying information without a direct relationship to the individual, such as those selling health data. The key provision bans data brokers from selling, sharing, or transmitting physical health records (covering treatments for physical conditions) or behavioral health records (covering mental health, substance use, or emotional disorder care). The law establishes a public registry of registered brokers to increase transparency about how sensitive health data is handled.
Bill status in committee 1 of 4 stages cleared
Introduction
Jan 2026
Committee Review
Floor Vote
Governor
Introduced Jan 13, 2026 Last action Jun 30, 2026
Maddy AI version diff · 2 comparisons

What changed between versions

Senate Committee Substitute Reprint Of Substitute · 12 edits
MAJOR
The bill significantly expands its scope by adding 'data collectors' (businesses that collect consumer data and sell it to data brokers) alongside the existing 'data broker' category, replaces a flat $5,500 registration fee with a tiered schedule reaching up to $1.5 million based on consumer volume, adds a new standalone prohibition on selling sensitive data with broad federal preemption-style exemptions (HIPAA, GLBA, FCRA, insurance, research), and extends the inoperative period for registration requirements from 180 to 270 days.
SCOPE

A new category of regulated entity, 'data collector,' is added. A data collector is a business that collects personal data from consumers with whom it has a direct relationship and sells or licenses that data to a data broker. Data collectors are subject to the same registration, reporting, and penalty requirements as data brokers.

A new section (section 3) creates a standalone prohibition: no data broker or data collector may sell or license sensitive data to any other individual or entity. This carries a $50,000 per-record civil penalty and includes ten specific exemptions covering HIPAA-covered entities, GLBA financial institutions, FCRA consumer reporting agencies, insurance institutions, research data, securities associations, state agencies, and others.

A new general exemption section (subsection g of section 2) exempts from the entire registration regime: HIPAA-protected health information, GLBA-covered financial institutions, secondary market institutions, insurance institutions, NJ Motor Vehicle Commission sales under federal law, FCRA consumer reporting agencies, state agencies and political subdivisions, federally compliant research data, insurance-support organizations, and national securities associations.

A new section 6 clarifies that the act's provisions apply in addition to, and not in lieu of, the existing New Jersey consumer privacy law (P.L.2023, c.266).

Exemptions from data broker status were expanded: title and settlement services regulated by the NJ Department of Banking and Insurance are now exempt, as are nonprofit organizations providing enrollment data reporting for postsecondary institutions. The financial institution exemption was moved from a narrow paragraph to the broader general exemptions section.

DEFINITION

The definition of 'data broker' was narrowed: the activity changed from 'sells, licenses or otherwise provides' to 'sells or licenses.' A processor exclusion was added (disclosure solely for processing on behalf of the broker does not make one a data broker). Government entities are explicitly excluded.

New definitions added for 'data collector,' 'processor' (an entity that solely processes personal data on behalf of a data broker or data collector), and 'sale/sell' (sharing, disclosing, or transferring personal data for monetary or other valuable consideration).

References to 'controller' throughout the bill were replaced with 'data broker or data collector' in the definitions of de-identified data, processing, and publicly available information. The de-identified data definition now also requires the entity to 'enforce or otherwise ensure compliance' with contractual obligations imposed on data recipients.

FISCAL

The flat $5,500 registration fee was replaced with a tiered schedule: $5,000 for 100,000 consumers or fewer; $10,000 for up to 500,000; $100,000 for up to 1 million; $500,000 for up to 1.5 million; $750,000 for up to 2.5 million; $1,000,000 for up to 4.5 million; and $1,500,000 for more than 4.5 million consumers.

REQUIREMENT

Registration requirements now apply to data collectors as well as data brokers. A new registration item requires disclosure of the processors who process personal data on behalf of the registrant. The division is prohibited from publishing data breach history information submitted by registrants.

ENFORCEMENT

Penalties for failure to register now apply to data collectors in addition to data brokers, and the penalty is assessed 'in addition to such registration fees' owed for each year of non-registration. The sensitive data violation penalty (section 5) was narrowed from 'sells, offers for sale, licenses, or otherwise furnishes, provides, or transmits' to 'sells, offers for sale, or licenses.'

TIMELINE

The inoperative period changed from 180 days to 270 days following enactment. It now applies specifically to subsection b. of section 2 (the registration and fee requirements) rather than to the entire former penalties section.

Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
5
Key actions
0
Committee
1
May 18, 2026
Committee
Referred to Senate Budget and Appropriations Committee
upper
Jan 13, 2026
Introduced
Introduced in the Senate, Referred to Senate Commerce Committee
upper
2 primary · 1 co-sponsor

Sponsors