Regulates data brokers, data collectors, and collection and dissemination of certain sensitive information.**
What changed between versions
A new category of regulated entity, 'data collector,' is added. A data collector is a business that collects personal data from consumers with whom it has a direct relationship and sells or licenses that data to a data broker. Data collectors are subject to the same registration, reporting, and penalty requirements as data brokers.
A new section (section 3) creates a standalone prohibition: no data broker or data collector may sell or license sensitive data to any other individual or entity. This carries a $50,000 per-record civil penalty and includes ten specific exemptions covering HIPAA-covered entities, GLBA financial institutions, FCRA consumer reporting agencies, insurance institutions, research data, securities associations, state agencies, and others.
A new general exemption section (subsection g of section 2) exempts from the entire registration regime: HIPAA-protected health information, GLBA-covered financial institutions, secondary market institutions, insurance institutions, NJ Motor Vehicle Commission sales under federal law, FCRA consumer reporting agencies, state agencies and political subdivisions, federally compliant research data, insurance-support organizations, and national securities associations.
A new section 6 clarifies that the act's provisions apply in addition to, and not in lieu of, the existing New Jersey consumer privacy law (P.L.2023, c.266).
Exemptions from data broker status were expanded: title and settlement services regulated by the NJ Department of Banking and Insurance are now exempt, as are nonprofit organizations providing enrollment data reporting for postsecondary institutions. The financial institution exemption was moved from a narrow paragraph to the broader general exemptions section.
The definition of 'data broker' was narrowed: the activity changed from 'sells, licenses or otherwise provides' to 'sells or licenses.' A processor exclusion was added (disclosure solely for processing on behalf of the broker does not make one a data broker). Government entities are explicitly excluded.
New definitions added for 'data collector,' 'processor' (an entity that solely processes personal data on behalf of a data broker or data collector), and 'sale/sell' (sharing, disclosing, or transferring personal data for monetary or other valuable consideration).
References to 'controller' throughout the bill were replaced with 'data broker or data collector' in the definitions of de-identified data, processing, and publicly available information. The de-identified data definition now also requires the entity to 'enforce or otherwise ensure compliance' with contractual obligations imposed on data recipients.
The flat $5,500 registration fee was replaced with a tiered schedule: $5,000 for 100,000 consumers or fewer; $10,000 for up to 500,000; $100,000 for up to 1 million; $500,000 for up to 1.5 million; $750,000 for up to 2.5 million; $1,000,000 for up to 4.5 million; and $1,500,000 for more than 4.5 million consumers.
Registration requirements now apply to data collectors as well as data brokers. A new registration item requires disclosure of the processors who process personal data on behalf of the registrant. The division is prohibited from publishing data breach history information submitted by registrants.
Penalties for failure to register now apply to data collectors in addition to data brokers, and the penalty is assessed 'in addition to such registration fees' owed for each year of non-registration. The sensitive data violation penalty (section 5) was narrowed from 'sells, offers for sale, licenses, or otherwise furnishes, provides, or transmits' to 'sells, offers for sale, or licenses.'
The inoperative period changed from 180 days to 270 days following enactment. It now applies specifically to subsection b. of section 2 (the registration and fee requirements) rather than to the entire former penalties section.