Recent State Privacy Laws Moving Beyond Traditional Privacy Frameworks Already Face Constitutional Challenge
This is Part 2 of Manatt’s series on developments in data broker law in 2026. Click for Part 1 in this series.
In the modern era of U.S. privacy regulation, state consumer privacy laws and other laws specifically targeting data brokers have largely followed a recognizable pattern. Comprehensive privacy statutes have typically granted consumers familiar rights to access, correct, delete and opt out of certain uses of personal data, while also excluding “publicly available information” from the definition of regulated personal data. Data broker laws, meanwhile, have often focused on registration, transparency, security or opt-out obligations and have incorporated the same “publicly available information” exclusion.
That model is beginning to change. Recent enactments in Vermont, Connecticut and New Jersey show states experimenting with new approaches that narrow traditional exclusions for publicly available data, impose more direct obligations on data brokers, rely on centralized deletion mechanisms, expand restrictions on sensitive data sales, and target the way public information is collated, profiled, inferred from, sold, or combined with other data. These laws present new operational challenges for businesses and are already teeing up a direct clash between privacy regulations and First Amendment principles that the courts will need to decide.
Vermont: Expanding Privacy Protections and Narrowing the Publicly Available Information Exclusion
Vermont’s S.71, signed on June 16, 2026, enacts a comprehensive consumer data privacy law that is scheduled to take effect in 2028. The law generally tracks the familiar structure of other state consumer privacy laws by granting consumers rights relating to personal data, imposing controller obligations governing data processing practices and mandating data protection assessments. Notable differences from other state consumer privacy statutes include Vermont's comparatively low applicability thresholds, which apply not only to entities that process the personal data of at least 35,000 consumers but also independently to entities that process sensitive data or offer for sale the personal data of at least 3,000 consumers. Vermont also incorporates concepts more commonly found in emerging AI legislation, such as a required disclosure in privacy notices of the processing of personal data to train large language models. Like Connecticut and Maryland, it also includes a consumer health data regime that restricts access to consumer health data, prohibits certain geofencing activities near health care facilities, and requires consumer consent before the sale of consumer health data.
The statute also departs from traditional models with respect to the publicly available information exclusion. In particular, the law excludes from that carveout certain information that is collated and combined to create a consumer profile made available through a publicly accessible website, inferences generated from such information, personal data created by combining personal data with publicly available information, and information provided by consumers on public websites or online services where there is a reasonable expectation of privacy in the information, such as by restricting the information to a specific audience.
The practical effect of narrowing the exclusion is that businesses may not be able to rely solely on a dataset’s public-source origination as a complete answer to consumer privacy obligations. For example, when publicly available information is aggregated into a profile, combined with nonpublic personal data, or offered for sale in covered circumstances, Vermont’s law may bring that activity within the reach of consumer rights and controller obligations. For data brokers and businesses using data broker products, this will require a reassessment of whether existing public-records-based products remain outside the scope of state privacy laws.
Connecticut: Going Beyond Data Broker Registration and Further Limiting the Public Data Exemption
Connecticut’s Public Act No. 26-64 significantly expands the Connecticut Data Privacy Act (CTDPA) and creates a new data broker framework. The amendments to the CTDPA take effect on October 1, 2026, while the data broker registration and deletion components phase in over time. The new data broker regime follows California’s centralized deletion mechanism and goes beyond a registration requirement. A registered data broker will be required to participate in Connecticut’s state-administered deletion mechanism; access the system at least once every 45 days beginning October 1, 2028; process verified deletion requests submitted through the system; repeatedly delete covered personal data; and generally refrain from maintaining, using, or disclosing personal data subsequently acquired about a consumer whose deletion request has been processed. Act 26-64 also requires registered data brokers to maintain records relating to compliance audits and, beginning in 2031, retain independent auditors to assess compliance with the deletion mechanism requirements. Civil penalties of up to $200 per day per consumer may be imposed for violations of the data broker provisions.
Like Vermont, Connecticut also narrows the traditional treatment of publicly available information by granting deletion rights for certain public-source information when it is collated and combined to create a consumer profile made available online, used to generate inferences about consumers, or made available for sale. This approach does not simply regulate hidden or nonpublic data; it regulates particular uses of information that may be publicly sourced, especially where that information is transformed into profiles, inferential products, or sold.
For businesses, Connecticut’s law may be especially consequential because it combines four features: a broad data broker concept, affirmative registration duties, a centralized deletion mechanism and rights to publicly available information. Data brokers will need to evaluate whether they fall within the new definition, how they will authenticate and process deletion requests received through the state mechanism, how they will address the new deletion rights to publicly available information, and how they will pass those requests to service providers or other downstream recipients where required.
New Jersey: Outright Bans on Sensitive Data Sales, New “Data Collector” Designation and Steep Fees and Penalties
New Jersey’s Assembly Bill 5328, approved on June 30, 2026, establishes a sweeping data broker law and amends the state’s privacy framework. The law requires data brokers and newly defined “data collectors” to register with the Division of Consumer Affairs in the Department of Law and Public Safety and pay annual fees that can reach up to $1.5million depending on the number of New Jersey residents whose data is sold or licensed. The designation of “data collector”—a first among the comprehensive state consumer privacy laws—applies to any business that collects personal data from a consumer with whom the data collector has a direct relationship and sells or licenses that data to a data broker.
The bill also significantly expands New Jersey’s privacy protections by outright prohibiting the sale of sensitive data and authorizing substantial civil penalties of $50,000 per record for violations, reflecting a more restrictive approach to sensitive data monetization than many comprehensive state privacy statutes.
New Jersey’s approach differs from Vermont’s and Connecticut’s in emphasis. Rather than primarily narrowing the publicly available information carveout, New Jersey directly targets the sale of sensitive data and imposes significant registration costs that could be material for entities operating at scale. The law may therefore alter the economics of data broker activity in the state, particularly for companies that license large volumes of resident data or offer products that include sensitive data categories.
At the heels of the law’s quick passage through the state legislature and immediate effective date, the New Jersey Division of Consumer Affairs stating that the registration deadline would be postponed until a spring 2027 registration period from April 1 to June 30. The office also advised that it would provide “additional guidance” in coming months “to provide the public with further clarity about the new law's requirements.”
Why These Laws Matter
Taken together, the Vermont, Connecticut and New Jersey statutes reflect a broader trend toward increased regulation of the commercial data broker ecosystem, and Vermont and Connecticut’s laws especially suggest that state legislatures are increasingly pushing existing privacy regimes for greater restrictions on public-source or inferred data. The new laws target not only the source of data, but also the way data is assembled, enriched, marketed, licensed and acted upon.
This shift presents several compliance challenges. Businesses will need to revisit their existing mapping of public-source data, distinguish raw public information from profiles and inferences, evaluate whether data broker laws apply to discrete business units or product lines, and build processes to respond to deletion or opt-out requests that may apply to information previously treated as outside the scope of state privacy laws. Companies that buy data broker products may also need additional contractual protections, diligence procedures and downstream deletion workflows.
Testing the Constitutional Limits of Privacy Regulations: Litigation Risks Illustrated by Connecticut
These statutes are already inviting litigation. Restrictions on the collection, sale, licensing or deletion of information derived from public sources can raise constitutional questions, including whether the laws burden protected speech or restrict the dissemination of lawfully obtained, truthful information. The risk may be more pronounced where laws require deletion of information drawn from public records, prohibit sale of defined categories of information, target specific speakers, or regulate the creation and publication of profiles based on public data.
For Connecticut, those questions are no longer theoretical. On September 17, 2026, a group of popular consumer-facing people search companies filed a lawsuit in the U.S. District Court, District of Connecticut seeking to invalidate the provisions of Public Act No. 26-64 that give consumers deletion rights to publicly available information. They allege in the complaint that, “Connecticut has enacted a first-of-its-kind law singling out companies that publish consumer profiles comprised of publicly available information and subjecting them to draconian penalties for their speech.” The lawsuit specifically seeks a declaratory judgment that these provisions are unconstitutional facially and as applied to the plaintiffs’ businesses. The plaintiffs also filed for a preliminary injunction that may fast-track a decision on these critical issues.
The court’s resolution of this case is likely to inform and shape the ongoing debate pitting privacy interests against free-speech interests, not only in Connecticut but throughout the country. The courts will now have the opportunity to weigh in on how far states can go in regulating data broker products built from public or semipublic information, and whether distinctions between raw public records, aggregated profiles, inferences, and saleable datasets are constitutionally meaningful, among other issues.
The lawsuit is Spokeo, Inc., et al. v. William M. Tong, Case No. 3:26-cv-01510 (D. Conn.). The State has yet to file a response.
Key Takeaways for Businesses
- Publicly available information may not remain outside the scope of certain state consumer privacy laws when it is aggregated into profiles, combined with other data, made available for sale or used to generate inferences.
- Data brokers should reassess registration obligations, deletion workflows, data inventories, downstream contractual commitments, and product lines involving sensitive data or public-source data.
- Businesses that purchase data broker products should diligence the provenance of data, the availability of public-source exclusions, and the seller’s ability to comply with relevant obligations.
- Businesses should monitor the ongoing debate over the appropriate boundary between privacy regulation and First Amendment protections for lawfully obtained publicly available information that will now be resolved by the courts, while ensuring they remain compliant until there are answers.