How Data Broker Laws are Reaching Consumer-Facing Companies 

Law360 (August 12, 2026, 4:28 PM EDT) --

Sam Castic

New Jersey enacted a sweeping new data broker law on June 30, days after it was proposed.

While its potential for seven-figure registration fees and expansive scope have gotten a lot of attention, there's another trend that the New Jersey law advances: State data broker laws are now applying to companies that have never been thought to be data brokers — i.e., consumer-facing companies that deal with customer and first-party data.

Before this year, state data broker laws generally only applied to companies that sold or licensed data of people they had no relationship with. Now, data broker laws are regulating companies that disclose personal data that they collect directly from their customers or other people they interact with.

This new approach expands the reach of these laws to consumer-facing companies engaging in common business practices, like those disclosing customer data to certain vendors and partners.

Companies should take a fresh look at their practices to assess whether recently expanded and enacted data broker laws apply, and to validate that existing compliance practices are tailored to avoid applicability of the laws.

Laws now reach companies collecting customer and first-party data.

When states started enacting data broker laws, they applied to companies that sold or licensed personal data of people that they did not have a direct relationship with. This focused on the companies that people are most likely to view as data brokers — those that consumers may not know about, but that collect and share information about them for a fee.

Vermont — the first state in the U.S. to enact a data broker law on May 22, 2018 — took this approach in its legislation relating to data brokers and consumer protection.

Title 9 of the Vermont Statutes Annotated, Section 2430(4)(A), defines the term "data broker" to include businesses and business units that sell or license "brokered personal information of a consumer with whom the business does not have a direct relationship."[1] Past or present customers, subscribers or users of a business's goods or services were examples of direct relationships in the law.

Nevada, California and Oregon followed with similar approaches in their data broker laws — i.e., Nevada S.B. 260, Oregon H.B. 2052 and the California Delete Act — each of which excluded companies that dealt with data they directly collected from people or with data that was about people they had a customer or other direct relationship with.

The Texas Data Broker Act, enacted June 18, 2023, originally only applied to businesses with principal revenue sources from collecting, processing or transferring personal data that was not collected directly from the people the data pertained to. These approaches meant that companies that dealt only with data collected from or about their customers were generally out of scope for data broker laws.

The California Privacy Protection Agency changed this approach with Title 11 of the California Code of Regulations, Section 7601(d), where it amended data broker regulations to specify that even where there is a first party relationship or interaction with a consumer, businesses do not have a "direct relationship" with consumers for any personal information obtained outside of the consumer's intentional interaction with the business.[2] These amendments took effect Jan. 1 and expanded the scope of businesses that are data brokers in California.

Vermont followed California's lead by amending the data broker definition in H.B. 211 on June 16 to similarly define "direct relationship" and expand the reach of its law. These amendments take effect Jan. 1, 2027.[3]

Connecticut enacted a data broker law — S.B. 4 — concerning consumer privacy and protection on May 27, that entirely omits this "direct relationship" concept, though companies are not data brokers when they have a contractual or similar relationship with the people whose data they deal with.[4] The Connecticut law takes effect Oct. 1.

New Jersey has the most recently enacted data broker law — A.B. 5328, enacted on June 30 — and it expressly applies to both data brokers and data collectors, subjecting each to similar requirements.[5] According to the law, data collectors include businesses and business units that knowingly collect personal data of consumers with whom they have a direct relationship, when they sell or license that personal data to a data broker.

The New Jersey law took effect immediately on enactment, but registration and other requirements will not take effect until spring of 2027.[6]

Common marketing and business activities can be covered by data broker laws.

The approach New Jersey, Connecticut, Vermont and California have taken expands these laws to reach business practices that companies don't frequently view as data broker activities.

These laws could reach common practices, like passing data to adtech partners to target ads; clean rooms to facilitate marketing efforts with partners; data enrichment partners to better understand customer preferences; or potentially even to fraud and security vendors that combine data from various sources to provide their services.

It's possible that data disclosures to other vendors and partners that help companies offer their products and services, and operate their business, could also technically trigger applicability of some or all these data broker laws.

The reason these everyday business activities can bring companies in scope for the data broker laws is because they can involve sales or licenses of data. These four data broker laws generally apply to companies that sell personal data, and Connecticut, New Jersey and Vermont also apply to companies that license personal data.

The term "sell" under these laws tends to include disclosures to third parties for monetary or other valuable consideration, similar to the approach of state comprehensive privacy laws. While California, Connecticut and Vermont may not treat disclosures to vendors acting as data processors as sales, New Jersey's law could include such a disclosure to a vendor or data processor, as it doesn't expressly require the sale to be to a third party.

The term "license" is defined in Connecticut and Vermont's laws to include access to or distribution of personal data in exchange consideration, and to exclude such disclosures where they are only for the sole benefit of the company providing the data where that company retains control over the use of the data.

This definition means that even where a vendor is engaged as a data processor for purposes of comprehensive privacy laws, there could still be a license of personal data, particularly where the contract allows the vendor to develop or improve products or services, provide services to other customers, train AI models, or otherwise use it in a way that doesn't solely benefit the company engaging the vendor. These types of licenses are common in vendor agreements.

New Jersey's new law does not define "license," and would almost certainly be interpreted as broadly — if not more broadly — than the Connecticut and Vermont definitions.

The laws impose registration and compliance obligations.

Companies that are in-scope for the data broker laws as data brokers in any of these states, or as data collectors in New Jersey, can have significant compliance obligations. Each of these four states requires registration with the state, and some registrations require detailed information about the types of data collected, data rights offered, other data practices and other state and federal laws the company is subject to.

Registrations may need to be updated when practices change, and registration fees can vary from hundreds of dollars to up to $1.5 million under New Jersey's new law. Each of these states also publishes online lists of registered companies.

The laws have a variety of other obligations in addition to registration. For example, on Aug. 1 in California and in 2028 in Connecticut, data brokers will be required to honor consumer deletion requests that are shared via a state database.

The laws can also require internal controls and measures for compliance, information security controls, credentialing and due diligence of data purchasers and licensors, bonds and independent audits. The New Jersey law also prohibits sales and licenses of a number of types of sensitive data.

Companies should validate if they are in scope.

For companies that are not intending to be data brokers by obtaining revenue from selling and licensing personal data, like consumer businesses, it may be time to validate that existing data practices do not trigger these new and amended data broker laws. To assess that, here are three areas to pay attention to.

First, companies that say they sell personal data for state comprehensive privacy law purposes — such as to target ads to customers and prospects that visit the companies' websites or to enable partner or client business objectives — may be subject to data broker laws. Understand what data is disclosed for these purposes, and the types of entities it is disclosed to.

Second, companies with products or services that disclose personal data to customers or others may be at increased risk of being subject to data broker laws. Validate how these products and services work and what data is used and disclosed.

And finally, companies sharing personal data with vendors or partners, and allowing them to determine how the data will be used, should review these practices and contract terms, paying particular attention to vendors and partners that insist on being independent data controllers for privacy law purposes.

In each of these areas, the data disclosed, the nature of the relationship with the person whose data is disclosed, and other exceptions may help avoid applicability of the California, Connecticut and Vermont laws, but there may be fewer ways to avoid applicability of the New Jersey law in these contexts.

Companies should make sure they have reviewed these practices against the requirements of these new and amended laws.

Controls can help companies stay out of scope.

Companies that want to stay out of scope for these data broker laws should consider the following operational and programmatic steps.

First, update privacy impact assessment processes to catch business practices that implicate these data broker laws. When personal data is disclosed to another person or entity, review how and from where it was obtained, and whether the disclosure involves a license or sale, to help assess if data broker laws are affected. Consider updating processes and guidance for privacy team members conducting assessments so that data broker law impacts can be detected.

Second, revise vendor contracting processes in order to assess contract provisions regarding data licenses and to identify potential data sales. Review and update template vendor contract terms, playbooks and guidance for teams responsible for vendor contract reviews in order to minimize the risks that data shared with vendors will implicate data broker laws. Consider enhanced reviews and scrutiny of vendors that insist on being independent data controllers.

Third, tailor vendor due diligence processes to ask or determine whether the vendor is a registered data broker in any state. If so, consider whether additional assurances or approaches are needed to avoid applicability of the New Jersey data collector requirements.

And finally, enhance advertising and marketing governance to confirm that partner data sharing practices — including sharing via cookies, pixels, software development kits and tracking technologies on company website and mobile apps — do not implicate data broker laws.

Governance programs may need to consider how the specific data shared with partners was obtained and whether any was obtained from data enrichment services, even if there is a customer or first-party relationship with the people whose data is shared. Consider having governance programs also account for whether the partners are data brokers, or the disclosures involve a sale or license.

Sam Castic is a partner at Hintze Law LLC. He is chair of the firm's retail group, and co-chair of the firm's cybersecurity and breach response and fintech and financial services groups.

[1] 9 V.S.A. § 2430(4)(A) (2020).

[2] 11 CCR § 7601(d).

[3] VT H.B. No. 211 (Act 138) (2026).

[4] CT S.B. No. 4 (Public Act No. 26-64) (signed May 27, 2026), as amended by H.B. No. 5222 (Pub. Act No. 26-100) (signed Jun. 6, 2026).

[5] N.J. A.B. No. 5328 (2026).

[6] See New Jersey Office of Consumer Protection, Data Broker Legislation Alert (Jul. 10, 2026) available at https://www.njconsumeraffairs.gov/ocp/Pages/Alerts.aspx.