Blog
New Jersey Passes Age Appropriate Design Code and Amends Data Privacy Act with New Data Broker Rules
July 7, 2026
Want to receive these privacy recaps in your inbox each week? Subscribe here.
New Jersey’s Assembly passed a narrower version of the Age Appropriate Design Code, while separately enacting amendments to the New Jersey Data Privacy Act over a three-day period. The amendments ban the sale of sensitive data without a consent exception, tighten consent revocation requirements, and add a data broker framework that applies to upstream sellers as well as downstream brokers, expanding compliance obligations for businesses that share consumer data with third parties.
Keep reading to learn more and discover my takeaways.
United states
New Jersey Legislature Passes Age Appropriate Design Code.
New Jersey Assembly Bill 4015, which adopts the New Jersey Age Appropriate Design Code, passed both houses. If signed by the Governor, New Jersey will be the sixth state with an Age Appropriate Design Code, following California, Maryland, Nebraska, Vermont, and South Carolina.
TAKEAWAY
Compared to the broad coverage of most other AADC laws, (applying to any online service, product or feature reasonably likely to be accessed by minors), New Jersey’s law is the narrowest of the six regarding the types of services it restricts. It applies only to services that are reasonably likely to be accessed by children, are internet-accessible, display account-holder-generated content, have an actual New Jersey account holder, and allow account holders to interact with other individual account holders’ content as a central feature. Therefore, a large publisher of purely editorial content with no interactive features would likely fall outside this law’s scope but may still be covered by the other AADC laws. For those companies within scope, however, New Jersey’s law may pose the greatest risk, since it is the only AADC law that affirmatively creates a private right of action.
New Jersey is also the only AADC that gives minors and parents a right to access, review, and change the underlying personal data the system uses to drive content recommendations. Beyond those distinctions, the New Jersey law largely borrows existing elements from the other five laws. These include requirements to provide real-time geolocation signals (present in all six) and parental-monitoring signals (present in all but Maryland), requirements to suppress notifications during certain quiet hours (Nebraska and South Carolina), and several previously Vermont-specific elements, such as restrictions on adult-to-minor messaging and content visibility, prohibitions on a master toggle to make multiple defaults less protective at once, and a closed list of permissible bases for algorithmic personalization.
Broad New Jersey Privacy / Data Broker Bill Takes Effect Immediately
New Jersey Assembly Bill 5328 was introduced, passed, signed, and became effective, in the primary part, over a 3-day period. The bill amends the New Jersey Data Privacy Act (NJDPA) to ban the sale of sensitive data (without a consent exception), require that consent revocation mechanisms be at least as easy as consent mechanisms, and require that processing cease as soon as practicable after consent revocation, but no later than 15 days after the request is received. The bill also adds a new chapter regulating data brokers (no direct consumer relationship; buys/sells third-party data) and data collectors (has a direct relationship, sells to a broker). All elements of the bill took effect immediately upon signature except for the Division of Consumer Affiar’s obligation to establish and maintain a public registry of data brokers and data collectors, which takes effect in March 2027 (and arguably is a prerequisite to the obligation for covered entities to actually register, although that’s not specified).
TAKEAWAY
New Jersey is now only the second state (after Maryland) to include an outright ban (without a consent exception) on the sale of all sensitive data. Some other states include such a ban for particular types of sensitive data, like Connecticut, Virginia and Oregon for geolocation data and New Hampshire and Oregon for children’s data, but not the full category of sensitive data. New Jersey takes the outright ban even further than Maryland, expressly applying it “regardless of the number of consumers whose data the individual or entity controls or processes,” despite thresholds that apply to the rest of the New Jersey law. No other state has that volume-indifferent extension.
The consent revocation requirements are not novel. They bring New Jersey in line with several other states that include both the same 15-day requirement and the “as-easy” standard.
Separate from the comprehensive privacy law amendments, the bill includes some truly novel data broker requirements, differentiating it from other state data broker laws. In particular, New Jersey includes a two-tiered data broker / data collector split, applying the requirements of the law to both the upstream direct-relationship seller and the downstream reseller. The only difference between the categories is how registration fees are calculated: data brokers pay based on the volume of data they sell generally and data collectors pay based on the volume of data they sell specifically to data brokers.
Every other data broker law regulates only the downstream broker, not the upstream seller, in a seller-to-broker transaction. The original first-party company that sold the data to the broker previously only had obligations under comprehensive privacy laws, not data broker laws. New Jersey changes that by applying the same data broker obligations (including registration and disclosures) to the ordinary retailer, publisher, app, telecom or service provider selling their genuine first-party data to data brokers.
Notably, the New Jersey data broker law reiterates the ban on the sale of sensitive data that was also included in the amendment to the comprehensive privacy law. That sounds redundant, but the impact is the difference in potential penalties. If an ordinary controller under the comprehensive privacy law sells sensitive data outside the data collector / data broker relationship, fines under the comprehensive privacy law apply: up to $10,000 for the first violation and $20,000 for each subsequent violation. If that sale of sensitive data (including geolocation data) is to a data broker, penalties jump to up to $50,000 per record, posing a compoundingly higher risk.
A LITTLE MORE PRIVACY, IF YOU PLEASE
- Connecticut, Maryland, Utah and Virginia Privacy Amendments Took Effect July 1
- Opt for better: Our renewed vision for quality, consented first-party data
- Dead-end data: The silent roadblock to your revenue operations
- How can premium publishers turn privacy into a competitive advantage? By Nial Ferguson
A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.
Latest Blog Posts
SCOTUS Lets Texas App Store Accountability Act Stand as CNIL Clarifies Geolocation Consent Rules for Mobile Apps
July 15, 2026SCOTUS allows enforcement of the Texas App Store Accountability...
New Jersey Passes Age Appropriate Design Code and Amends Data Privacy Act with New Data Broker Rules
July 7, 2026New Jersey's latest privacy laws include a narrow AADC,...
New York’s S9269 Advances as ICO Finalizes Consumer IoT Guidance
June 16, 2026NY's S9269 health privacy bill heads to the Governor...
Latest White Papers
Connecting Legal & Marketing Teams on Consent and Preferences
February 4, 2025Break down data silos and unlock better collaboration. Marketing...
Navigating Sensitive Data in the U.S.
February 4, 2025Download our comprehensive guide to learn how different states...
Enterprise Guide To Cookie management & Tracker List Curation
July 1, 2024How to review the tracking tech on your websites...