1 min read
New 2025 Data Privacy Laws: Delaware, New Jersey, and New Hampshire
We kicked off 2025 with five state-level data privacy laws going into effect. Last month, we covered new data privacy policies inNebraska and Iowa....
Technology and workflow tools
Making screening easy for candidates
With Verified Credentials' mobile-first candidate experience, you meet candidates where it's most convenient. Learn how easy we make it.
|
|
Now offering DOT services! Get your drivers on the road quickly and meet DOT regulations. |
Featured resource

Our new Ban the Box Guide makes it easier than ever to decipher the patchwork of fair chance laws across the country. Check the map to quickly identify what laws apply to you.

Verified Credentials is proud to be accredited by PBSA and an original founding member. Our accreditation confirms that our policies, processes, and team member training meet rigorous industry compliance standards.
4 min read
Verified Credentials Sep 10, 2026, 2:33:00 PM
Several states have recently updated their consumer privacy laws to modify regulations on how businesses collect, process, and use consumer data. Employers in Connecticut, Maryland, New Hampshire, and New Jersey can review the high-level summaries below to familiarize themselves with the new data-handling expectations in their respective states.
On May 27, 2026, Connecticut Governor Ned Lamont signed an amendment to the Connecticut Data Privacy Act (CTDPA), thereby enacting Senate Bill 4 as Connecticut Public Act 26-64 (The Act). The changes proposed in this new legislation apply to “controllers” and “data brokers” covered in the CTDPA framework. Changes will phase in, with the first taking effect on October 1, 2026.
Registry and Deletion System: Brokers may be required to register with the Department of Consumer Protection (DCP) and renew annually, with a $2,500 fee, allowing the DCP to operate the registry and a statewide, publicly accessible deletion mechanism modeled after California’s Delete Act (SB 362).
Facial Recognition Technology: Tighter restrictions for this technology requires controllers that use facial recognition tech for security, fraud, harassment, or other protective purposes to: (1) limit matching sourced from internally run databases; (2) provide clear notification that the technology is in use; (3) provide a way for consumers to view the company’s facial recognition technology policy; and (4) ensure Attorney General contact information is included in the policy.
“Surveillance Pricing” Framework: PrivacyLawMap defines “surveillance pricing,” or algorithmic pricing, as “the practice of using personal data, browsing history, location, biometric signals, device tracking, sensors, or other consumer signals to set individualized prices.” The Act enforces two main conditions for surveillance pricing:
Businesses that use a consumer’s personal data to increase an online price must display a disclosure notifying the consumer of this action.
Retail sellers and third-party delivery services are restricted from engaging in surveillance pricing, with a few exceptions for loyalty/membership rewards, justifiable supply and demand costs, out-of-range delivery expenses, and other similar reasons for pricing changes.
The specific provisions above take effect on July 1, 2027.
Geolocation Limitations: Under the Act’s provisions, controllers and third parties are prohibited from selling any consumer’s precise geolocation data, making Connecticut the fourth state to enact heavy restrictions on location data sharing. The legislation defines “precise geolocation data” as a location within a 1,750-foot radius.
October 1, 2026: Most provisions take effect, including the ban on geolocation sales and limitations on facial recognition technology use.
January 1, 2027: Cut-off date requiring data brokers to register with the DCP to be permitted to sell or license brokered personal data.
July 1, 2027: Surveillance pricing provisions take effect.
July 1, 2028: DCP must have the accessible deletion mechanism established by this date.
October 1, 2028: Registered brokers are required to begin 45-day checks and deletion processing starting on this date.
You can review the full legislative text of Connecticut’s Public Act 26-64 here.
Maryland House Bill 711 became law on May 31, 2026, without the governor's signature. Governor Wes Moore’s failure to sign or veto it within the required timeframe triggered Article II, Section 17(c) of the Maryland Constitution, causing the bill to automatically become law. This law has been in effect since July 1, 2026.
These updates apply to the same businesses covered under MODPA: entities that “control or process” personal data of 35,000+ Maryland residents, or 10,000+ residents if selling personal data makes up 20% of their gross revenue, known as “controllers.”
HB 711 builds on the core framework of Maryland’s Online Data Privacy Act (MODPA), adding immigration-related consumer privacy protections to the list:
Further restriction on certain personal data sales and disclosures: Controllers are prohibited from selling personal consumer data to federal, state, or local governmental units that have engaged in or supported civil immigration enforcement in the last six months by providing personnel or material resources. The only exception to this new ruling is the receipt of a valid warrant from a federal or state court that specifically describes the requested personal data. For requests from governmental units that have no record of supporting civil immigration enforcement, businesses may comply with their standard procedures.
Added operational duties: Custodians of public records must take “reasonable steps” to determine whether a public record is accessed for enforcing immigration law. Additionally, entities that operate message switching systems, the databases that allow agencies to view each other’s records, are required to take certain actions related to system access.
View the full text of Maryland’s HB 711 here.
New Hampshire Governor Kelly Ayotte signed House Bill 1460 into law on June 19, 2026. HB 1460 takes effect on January 1, 2027.
This new law is an amendment to the New Hampshire Data Privacy Act:
Data sale prohibition: HB 1460 prohibits a controller from selling a child's personal data, defined as an individual under the age of 13.
Enforcement: The amendment is solely enforced by the New Hampshire Department of Justice through its Consumer Protection and Antitrust Bureau.
Read the entirety of New Hampshire’s HB 1460 brief text here.
On June 30, 2026, New Jersey Governor Mikie Sherrill signed A5328 into law, amending the New Jersey Data Privacy Act. Most provisions of this law took effect on June 30, 2026, immediately upon the bill’s passing, and the remainder will come into effect on March 27, 2027.
Expanding the law’s reach: Unlike the others we’ve covered, this ruling broadens the state’s data privacy act to include new categories of entities previously not governed by similar state laws. While other states use consumer data quantity minimums to categorize a business as a data controller, this legislation bypasses the New Jersey Data Privacy Act’s applicability thresholds and instead governs all individuals or legal entities that sell, offer to sell, or license sensitive data to other individuals or entities.
Banning sensitive data sales and establishing a registry: A5328 bans the sale of sensitive data by all individuals and legal entities, regardless of whether they are subject to the New Jersey Data Privacy Act. It also creates new registration requirements for data brokers and data collectors:
Registration with the New Jersey Division of Consumer Affairs must be completed annually, with a fee range of $5,000 to $1.5 million, determined by the volume of consumer data possessed by the organization.
Detailed registrant information regarding the organization’s data processing procedures must be provided.
Enforcement and fines: Failure to register, pay the required annual fees, and submit or update required registration information may result in the data broker or data collector being held liable for unpaid registration fees, in addition to a $ 2,500-per-day civil penalty. Each sensitive data record sold, offered for sale, or licensed in violation of the law may subject the violator to a $50,000 civil penalty. The New Jersey Division of Consumer Affairs is authorized to adopt rules and regulations as necessary to implement and clarify the law.
Check out the full text of New Jersey’s A5328 here.
This content is for informational purposes only and shall not constitute legal opinion or advice. Consult your legal counsel to ensure compliance.
1 min read
We kicked off 2025 with five state-level data privacy laws going into effect. Last month, we covered new data privacy policies inNebraska and Iowa....
1 min read
In 2024, we covered both Minnesota’s and Rhode Island’s Data Privacy Acts. While Rhode Island’s law will not go into effect until 2026, Minnesota’s...
1 min read
2024 was a big year for consumer data privacy laws, with states like Minnesota, Rhode Island,and Montanapassing laws to protect consumer rights and...