There's something ironic with data brokers who power any number of companies using people's data (often against their knowledge and certainly proliferating it against their knowledge) via targeted advertising and other purposes, to suddenly find themselves targeted. States are increasingly targeting data brokers with new legislation, requirements, and (COMING SOON!) enforcement actions. While all eyes have been on California, however, it's New Jersey that has upped the ante by dropping a new privacy law targeted at data brokers and those who sell to them with some real teeth behind it.
First, over the weekend, NJ Governor Mikie Sherill has put a stay on enforcing the new law, which was effective immediately. As much as I dislike data brokers in general and think they need to be more tightly regulated, this is the right move because the burdens are substantial, onerous, and will ripple across not just the data brokers but their customers (more on this below). Businesses will now have until June 2027 to get into compliance with the new law.
So, what does this new law require and why does it change the stakes? Assembly Bill 5328 (A5328) creates a data broker registry with substantial registration fees, prohibits the sales of sensitive data, adds a new class of companies subject to data broker laws, and levies substantial penalties.
Who is subject to the law? Data Brokers and Data Collectors
Data Brokers is a fairly settled concept that we already understand and are already in the ambit of a number of state data broker registration laws and opt out laws, such as the California Delete Act.
Here's the definition from AB 5328 with the key part underlined:
“Data broker” means a person or legal entity, including, but not limited to, a controller, that knowingly collects or purchases the personal data of a consumer with whom the person or legal entity does not have a direct relationship and sells or licenses that data to a third party. A third party shall not include a processor if licensure or disclosure of personal data to the processor is solely to process the personal data on the data broker’s or data controller’s behalf.
Now here's the new Data Collector definition:
“Data collector” means a business, or units of a business, separately or together, that knowingly: (1) collect the personal data of a consumer with whom the data collector has a direct relationship; and (2) sell or license such personal data to a data broker.
This is your controllers, friends. This is every business that collects data from a customer and decides to sell it to a data broker. (And just to be clear, this statute is leveraging the modern definition of "Sale," so it's not just monetary data transactions swept up in this law.) Not to point fingers, but that's you, Weather Channel and you Ebay and you Google. Grabbing a short term revenue stream (personal data) until you can make money off your product directly is suddenly not going to be feasible anymore, startups and VCs.
Ban on Sale of Sensitive Personal Data finally arrives.
If you've worked in this space as long as I have, you'll have an opinion or three, and the big one I've developed over the years is that the sale of Precise Geolocation Data ought to be banned. Precise Geolocation Data is Digital Plutonium, I've been known to say: highly useful and invaluable for a variety of issues from mapping to Pokemon Go to weather apps, but it's also extremely dangerous in the hands of stalkers and other bad actors who use it for no good reasons, including in some cases compromising national security. The NYT did an excellent breakdown of Precise Geolocation risks six (6!) years ago and we're just now finally starting to see legislative movement on this.
A5328 flat out PROHIBITS the sale of Sensitive Data by Controllers and Data Brokers. That's monumental. Per the bill, Controllers shall "not sell sensitive data, which shall apply to all individuals or legal entities regardless of the number of consumers whose data the individual or entity controls or processes." No thresholds. No minimums here. I expect this will be challenged and someone will try to get a small business carveout here, but as the text reads right now, that's a blanket ban on businesses selling Sensitive Data.
Sensitive Data here is pretty unremarkable as these definitions go. We've seen privacy laws coalesce around this definition across the board.
“Sensitive data” means personal data revealing racial or ethnic origin; religious beliefs; mental or physical health condition, treatment, or diagnosis; financial information, which shall include a consumer’s account number, account log-in, financial account, or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a consumer’s financial account; sex life or sexual orientation; citizenship or immigration status; status as transgender or non-binary; genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data.
The outstanding question here is whether "personal data revealing" would also cover inferred data. For instance, if I know you watch certain TV shows, I can infer your race (advertisers have been doing this for decades, by the way) and put you in a racial segment while also claiming to respect your privacy and that we don't process Sensitive Data. We reveal more of ourselves than we ever intend to based on our online history and companies have been using that to their advantage for decades at this point.
There are a handful of interesting exceptions to the prohibition on sale (emphasis added):
- developing or maintaining a third-party e-commerce or application platform;
- providing 411 directory assistance or directory information services, including name, address, and telephone number, on behalf of or as a function of a telecommunications carrier;
- providing publicly available information related to an individual’s business or profession or related to providing financial or real estate services;
- providing publicly available information via real-time or near real-time alert services for health or safety purposes; or
- providing title and settlement services that are regulated and examined by the New Jersey Department of Banking and Insurance; or
- the person or entity is a nonprofit organization established to provide enrollment data reporting services on behalf of postsecondary educational institutions.
My read on these is that most of them are already regulated under other laws or had excellent lobbyists to carve them out.
Registration is not cheap.
All Data Brokers and Data Collectors that Sell or license personal data to a Data Broker are required to register with the NJ Division of Consumer Affairs in the Department of Law and Public Safety. The website isn't active and won't be until March 2027. Fees are scaled based on the amount of data you are selling or sharing:
- <100k consumers or fewer in the State: $5,000;
- 100k- 500k: $10,000;
- 500k - 1M: $100,000;
- 1M-1.5M: $500,000;
- 1.5M-2.5M: $750,000;
- 2.5M-4.5M: $1,000,000; and
- >4.5M: 1,500,000.
That's not insignificant money that can fund an entire enforcement office at the NJ Division of Consumer Affairs.
Non-Compliance is also not cheap.
There are two types of penalties under A5328. Once the registration website goes live, failure to register is $2,500 a day. But the big teeth are in the penalties for Selling Sensitive Data: $50,000 per record. This will rapidly scale to tens of millions of dollars if you don't have your databases on lockdown.
Takeaways
If you are a business that sells personal data, it's time to take stock of your business relationships and how that data is shared. You're at the very least going to have to register as a data broker or data collector and you may be in line for some significant penalties if those datasets contain anything that might be considered Sensitive Data.
If you need any help navigating A5328 or any other state data broker or privacy laws, reach out to us at Brandi@BennettTechLaw.com for help.