Skip to content

Power

New Jersey Gives You Data Rights. Brokers Still Control the Door.

New Jersey residents can request access to and deletion of brokered data. The forms reveal the catch: companies still decide how easily your identity can be matched, verified and rejected.

Simone AchebePower — Surveillance

August 11, 2026 · 8 min read

A laptop displaying a data privacy request form beside a notebook logging submissions and verification emails.
A laptop displaying a data privacy request form beside a notebook logging submissions and verification emails.

The concrete object in this audit was an old Gmail address.

It has survived several apartments, two phone numbers and enough mailing lists to make deletion feel theoretical. I entered that same address into the public privacy-request portals operated by Acxiom, LiveRamp and Experian, pairing it with a current New Jersey address and, where a form allowed it, a former address. The requests were ordinary: show me the data, delete what the law covers and stop selling or using it for targeted advertising.

The audit did not test whether every database behind those companies had been purged. An outsider cannot prove that from a confirmation screen. It followed the route a New Jersey resident can see: locating the correct portal, choosing a right, supplying matching details, completing identity checks and preserving enough evidence to challenge a denial later.

That route explains the law’s practical weakness. New Jersey created rights. It did not create one door through which residents can exercise them.

What New Jersey changed

The New Jersey Data Privacy Act took effect in January 2025. It gives residents rights to confirm whether a covered controller is processing their personal data, access that data, correct inaccuracies, request deletion and obtain a portable copy. A controller is the company that decides why and how personal data gets processed.

Residents can also opt out of targeted advertising, certain profiling and the sale of personal data. Under the statute, a sale can involve money or another valuable consideration, although the definition contains exclusions. The law also requires covered businesses to recognize qualifying universal opt-out mechanisms, browser or device signals that communicate a privacy choice without making the user visit every company separately.

Coverage depends on business activity and the volume of personal data processed. The law also contains entity-level and data-level exemptions, including for some information governed by federal financial, health and credit-reporting rules. A company with a familiar name may hold data in several legal compartments, which means a general privacy request, a credit-file dispute and a marketing opt-out can travel through different systems.

That distinction matters at Experian. Its consumer credit operations are not interchangeable with its broader advertising and identity businesses, and the company’s public privacy materials route users according to the data or service involved. A New Jersey deletion request is not a credit freeze. Deleting covered marketing data does not erase a credit history governed by federal law.

The statute generally gives a controller 45 days to respond, with a possible extension when reasonably necessary. A resident can appeal a refusal through the company’s stated process. Enforcement belongs to the New Jersey attorney general; the law does not give residents a general private right of action.

This is not legal advice. It is a map of the doors that were visible during reporting.

The old Gmail address enters the portals

Acxiom’s privacy portal offered consumer request categories covering access, deletion and opt-out choices. To find a record, the form asked for identifying and contact information. Email verification then tied the request to an inbox, which is sensible as far as it goes: deleting the wrong person’s file would create a second privacy failure.

The problem appears when the broker’s record is old. My anchor address could be verified because I still controlled the Gmail account, but an email click proves control of an inbox, not that the company has correctly linked every address, phone number, device identifier or household record associated with the person making the request. The form accepts a clean identity. Broker databases are valuable precisely because their identities are assembled from untidy fragments.

LiveRamp’s public consumer flow similarly asked for information that could be used to locate and authenticate a record, while presenting privacy choices around access, deletion and limits on sale or advertising uses. The resident again has to supply the bridge between the company’s identifiers and a recognizable person.

Experian added another layer: choosing the right institutional lane. A person looking for marketing-data deletion can easily arrive at pages dealing with credit reports, freezes, fraud or disputes, each of which solves a different problem. The separation may follow real legal boundaries, but the navigation cost lands on the individual, who must diagnose which Experian product has acted on them before they can ask it to stop.

None of these companies invented identity verification to defeat New Jersey’s statute. The friction comes from a deeper asymmetry. A broker can sell or use a probabilistic match, meaning a link inferred from signals rather than proven with certainty, but may demand a cleaner, more deterministic match before honoring access or deletion. Loose identification creates the commercial record.

Strict identification controls the exit.

Build a request that can survive the appeal

Start with a log. Record the company, portal address, rights selected, information supplied and the month of submission. Save the privacy notice that governed the form, because portal language changes and a later screen may not explain what you originally requested.

Use a separate row for every company. The old Gmail address remained constant in my audit, but the forms did not share a common case number or state inbox. New Jersey’s rights operate company by company, so the resident becomes the case-management system.

Ask for access before or alongside deletion if you want to understand what the company associates with you. A deletion-only request may produce a confirmation without revealing the shape of the underlying record. Access can show categories of data, purposes, recipients or other information the law requires, subject to exemptions and the company’s ability to verify the request.

Select the opt-outs explicitly. Deletion and opting out solve different problems. Deletion addresses covered data already held; an opt-out tells the company not to use future data for specified activities such as targeted advertising or sale. A portal that displays separate boxes is signaling that one click may not do both.

Provide enough information for a match, but do not treat every blank field as mandatory. Start with the identifiers the company says it needs, such as name, email and address. If it requests an identity document, read the stated reason, retention terms and alternatives before sending it. Redact information the company says it does not need.

A privacy request should not become a fresh package of high-value data by default.

Complete email verification promptly and save the confirmation. Take screenshots of the submitted choices, not only the final success page. The old Gmail address was useful here because it created a continuous paper trail, but that convenience exposes another bias in the system: people who have lost access to an old inbox, changed names or moved frequently face a harder authentication problem than people whose records remain stable.

If the company says it cannot verify you, ask what additional information would resolve the mismatch and whether another method is available. Do not send a passport or driver’s license merely because the first automated match failed. The useful question is narrower: what field is missing, and how will any added document be used and deleted?

Track the response window from submission. If the company extends its deadline, preserve that notice. If it denies the request, use the appeal method described in the response and state the original request, the denial reason and the evidence you already supplied. Keep the language plain.

You are building a record for a company reviewer and, if necessary, a regulator.

Turn on a recognized universal opt-out signal in a compatible browser after handling the individual requests. Global Privacy Control is one such signal, although recognition and implementation can vary by company and context. It reduces repeat labor for future browsing; it does not prove that old broker records have been deleted.

What a deletion confirmation cannot show

A confirmation is evidence that the company processed a request. It is not a window into every production database, backup, vendor copy or exempt record.

Companies may retain information needed for security, legal obligations, fraud prevention or other permitted purposes. Data governed by another statute may remain even when covered advertising data is deleted. Deidentified data may also remain if it meets the applicable standard, meaning it cannot reasonably be linked back to an individual under the company’s controls.

The old Gmail address therefore ends the audit in an awkward position. It is strong enough to receive verification links and marketing messages, yet it cannot reveal which invisible identifiers were matched to it or whether a disconnected household record survived. New Jersey gives the resident a claim against a controller. The controller still owns the map of the system against which that claim must be checked.

The better alternative would be a state-run request interface with standardized fields, status receipts and a common appeal record, while companies retained responsibility for secure authentication behind it. New Jersey did not build that layer. The cost is paid in tabs, screenshots, repeated disclosures and the attention required to remember which version of you each broker recognizes.

Questions people ask

Can

I ask a data broker to delete everything it has about me?

You can request deletion of personal data covered by New Jersey’s law, but exemptions and permitted retention can limit the result. Credit-reporting, financial or other federally regulated data may follow separate rules, and a company may keep information needed for security, legal compliance or another allowed purpose.

Do

I have to upload identification to make a privacy request?

A company can authenticate a request so it does not disclose or delete the wrong person’s data. That does not make every document request proportionate. Check what information is required, whether email or account verification is available, how an uploaded document will be retained and whether unnecessary fields can be redacted.

What should

I do if the company says it cannot verify me?

Preserve the denial and ask which identifier failed or what alternative verification method is available. If the company refuses the request, follow its appeal instructions and keep the original submission, confirmation screens and correspondence together. New Jersey’s attorney general handles enforcement complaints; the statute does not create a general private lawsuit right.

Does

Global Privacy Control delete data a broker already holds?

No. A qualifying universal opt-out signal communicates choices about covered sale or targeted-advertising activity, but it is not a retroactive deletion request. Use it to reduce future collection and reuse, then send a separate access or deletion request when you want the company to address an existing record.

Was this worth your time?
ShareFacebook
surveillanceinternet policydata brokersprivacy rightsidentity verificationconsumer data

One update a day

Today's story, in your inbox

One story each morning — no hype, no filler, no algorithm deciding for you.

Read next

A laptop showing an AI meeting transcript beside a calendar invite labeled Weekly Check-In.

Power

Your AI Meeting Notes Can Become Workplace Evidence

A convenience bot can turn one meeting into audio, transcript, summary and action items spread across several systems. Deleting the bot from the call does not delete that second room.

Lena Vasquez · 7 min read

A square pop-up canopy on a campus lawn with one fabric sidewall attached and folded blankets visible underneath.

Power

Campus Protest Rules Now Police the Tent’s Sidewalls

Public universities are recoding protest as a problem of structures, sound and sleeping. The rules look neutral because they describe equipment, while discretion decides whose equipment becomes an offense.

Lena Vasquez · 8 min read