State Bans on Sales of Sensitive Data: How New Jersey’s Recent Ban Pushes the Envelope
by: Dave Radmore
On June 30 this year, New Jersey’s governor Mikie Sherrill signed A.5328 into law, making New Jersey the latest in a growing list of states to impose restrictions on businesses involved in the sale of consumer data. The headlines about the law have focused on new requirements and restrictions on data brokers but equally as news-worthy is the amendment to New Jersey’s comprehensive privacy law implementing a blanket prohibition on the sale of New Jersey’s residents’ sensitive data. Most importantly, the law expands the reach of the ban to anyone seeking to sell a New Jersey resident’s sensitive data, even those who are not otherwise subject to the New Jersey privacy law. And the law took effect immediately, requiring anyone that may do business in New Jersey and that may engage in activity that is considered a sale of sensitive data to stop such sales immediately. In this post, we discuss the trend in state regulations from permissive to restrictive rules on sales of sensitive data and how the New Jersey law pushes the envelope on restrictions on such sales.
State Laws Are Becoming More Restrictive on Sales of Sensitive Data
Over the past decade of state privacy lawmaking there has been a distinct trend to greater restrictions on what companies can do with consumers’ sensitive data. The first state privacy law, California’s CCPA, now appears to be one of the more permissive state privacy laws with no specific restrictions on whether a business can sell consumers’ sensitive data, instead requiring that consumers are provided the right to limit the use and disclosure of their sensitive data, subject to a number of regulatory exceptions, and to opt out of the sale of their sensitive data under the umbrella of the right to opt out of sales of any personal data (which extends to sensitive data as a subset of personal data). A handful of states have also taken an opt-out approach to sales of sensitive data, such as Utah and Iowa.
Virginia’s privacy law, the second state privacy law to be passed, took a stricter approach, requiring that a consumer provide consent before their sensitive data is sold. However, Virginia defined “sale” more narrowly than California, explicitly tying sales to the receipt of monetary compensation, whereas California’s definition used a much broader concept of monetary “or other valuable consideration” in exchange for personal data. More recently, Virginia has amended its law to implement a prohibition on the sale of precise geolocation data specifically, but other types of sensitive data may continue to be sold with the consumer’s consent (note that Oregon similarly banned sales of precise geolocation data).
Most states have followed the Virginia consumer consent model, allowing for sensitive data to be sold but subject to a consumer’s opt-in consent, though many states use the broader definition of “sale” that California adopted. However, typically the state privacy laws have coverage qualifications that mean they are not universally applicable, meaning that non-profits or smaller businesses that do not have the consumer base, or revenues in the case of some states such as California, are not subject to the restrictions.
Texas’s privacy law, passed in 2023, took the next step to a more restrictive framework. Similar to the Virginia model, the Texas law requires a consumer’s opt-in consent before the consumer’s sensitive data can be sold. But what Texas does differently is that it extends the reach of the consent requirement for sales of sensitive data to all businesses, even those who are not otherwise subject to the law. Nebraska and Minnesota’s privacy laws include similar provisions that obligate all businesses to obtain opt-in consent even if the business is not otherwise subject to the state’s privacy law.
Maryland’s privacy law, passed in 2024 nearly a year after Texas’s law, took a further step towards a more restrictive framework, dispensing with the opt-in consent model and instead outright prohibiting sales of sensitive data. As such, Maryland’s law prohibits data controllers under any circumstance from selling Maryland residents’ sensitive personal data, irrespective of consumer consent. However, unlike Texas’s law, Maryland’s prohibition remains subject to the law’s threshold requirements for coverage so that not all entities are necessarily subject to the law’s obligations nor the restriction on sale of sensitive data.
New Jersey’s recent amendment to its privacy law fuses Texas’s blanket applicability with Maryland’s blanket prohibition on sales of sensitive data, to create the most restrictive ban on sales of sensitive data in the United States to date.
New Jersey’s Blanket Ban on Sales of Sensitive Data
Simply put, New Jersey’s amended privacy law prohibits data controllers from selling the sensitive data of any New Jersey residents. New Jersey defines “sensitive data” similarly to other states’ privacy laws, including data relating to race, ethnicity, religion, citizenship or immigration status, or a person’s mental or physical health condition, treatment or diagnosis, and a person’s status as transgender or non-binary. Any data collected from a known child (using COPPA’s definition of a child, meaning a person under the age of 13) is also defined as sensitive data. Genetic or biometric data constitutes sensitive data only if it is processed to uniquely identify an individual. Finally, precise geolocation is considered sensitive data, defined as information that directly identifies the location of a person within a radius of 1,750 feet.
There are two elements that make the law stricter than any other state’s regulation of sales of sensitive data:
No consent exception: New Jersey does not include an exception from the prohibition if a person consents to the sale of their sensitive data, meaning that the consumer cannot choose, even if fully informed, to any sale. Note though that there are some standard exceptions from the definition of “sale” in the New Jersey privacy law, including disclosures of data to processors, disclosures to third parties to provide a service or product requested by the consumer, and disclosures to affiliates or in connection with a merger or acquisition of the business.
No threshold floor: The prohibition on sales of sensitive data is extended to any controller selling the sensitive data of a New Jersey resident regardless of whether the controller is otherwise covered by the privacy law’s processing thresholds for applicability. This means that a company that has a single New Jersey resident customer and not otherwise subject to the New Jersey privacy law could still violate the law if it sells that customer’s sensitive data.
Penalties for violating the ban could be significant. Controllers that sell, offer for sale or license sensitive data can be subject to civil penalties of $50,000 per record under the law. In addition, the act of the sale itself would likely pull the business into coverage under the partner New Jersey data broker registration obligations with knock-on sanctions for failing to register as a data collector or data broker. It is also unclear how the $50,000 penalty interacts with the existing penalty scheme under the state’s privacy law, which establishes violations as unlawful practices under the state’s Consumer Fraud Act under which there are penalties of up to $10,000 for a first violation and up to $20,000 for subsequent violations. It is possible that the $50,000-per-record penalty is not an exclusive sanction.
Finally, unlike many privacy laws and amendments, there is no delay in implementation. The law took effect immediately upon its enactment on June 30, having been introduced and signed over the course of a mere few days to meet the state’s end-of-fiscal year budget deadline.
Business Takeaways
There are a few compliance actions businesses should take to ensure they remain compliant with New Jersey’s law:
Reassess whether you are subject to the New Jersey law: Companies previously out of scope of New Jersey’s law due to the size of their customer base in the state may now be captured by the ban. Check the following: (1) if you have any customers, leads, or other data subjects that may be located in New Jersey; (2) if you collect or otherwise maintain any sensitive data on your consumers; and (3) if you transfer sensitive data outside the company. If the answer to any of these is not a clear, evidence-supported “no”, reassess whether any existing data practices could now be subject to the ban on sales of sensitive data.
Know your data: It remains the case, and is increasingly important, that companies have a clear understanding of their data collection, sharing, and monetization practices. Conducting thorough data mapping and regularly updating the resultant data map is highly recommended.
Don’t rely on consent in New Jersey: Because there is no consent exception, opt-in mechanics that may satisfy other states’ laws will not cure a sale of New Jersey sensitive data. If you have been engaging in sales of sensitive data, and have relied on consent as the basis, make sure to exclude New Jersey consumers from such sales immediately.
Multi-state privacy compliance is becoming increasingly more complicated as states like New Jersey implement different approaches to privacy. Beyond the immediate need to ensure that you are compliant with the New Jersey ban on sensitive data sales, it is important to have procedures in place to regularly re-evaluate and update your company’s privacy compliance program to ensure that your company continues to account for and respond to new requirements.
Originally published by InfoLawGroup LLP. If you would like to receive regular emails from us, in which we share updates and our take on current legal news, please subscribe to InfoLawGroup’s Insights HERE. This summary does not constitute legal advice.