Data brokers that continue publishing the home addresses and unpublished phone numbers of New Jersey judges, police officers, prosecutors, and certain other public officials after receiving deletion requests can be sued — even if the plaintiffs do not prove negligence, recklessness, or intent. That is the core holding of a New Jersey Supreme Court decision issued this week, and it meaningfully strengthens the state’s Daniel’s Law.
Why Daniel’s Law Exists
Daniel’s Law is named for Daniel Anderl, the 20-year-old son of U.S. District Judge Esther Salas. In July 2020, a disgruntled lawyer who had located the family’s home address online shot and killed Daniel at their New Jersey residence while intending to assassinate the judge. The tragedy prompted the state to enact protections for the residential addresses and unpublished telephone numbers of judges, law enforcement officers, and other public officials whose roles expose them to heightened risk of retaliation or targeted violence.
The statute requires covered entities to stop disclosing that protected information once they receive a proper request. In practice, many public officials and the privacy services that assist them have spent years sending takedown notices to data brokers and related companies, only to see the same details reappear or remain available.
What the Court Decided
Plaintiffs, including privacy firm Atlas Data Privacy and individual officials, alleged that defendants continued to display protected information after receiving tens of thousands of removal requests. The data brokers argued they could not face financial liability unless plaintiffs proved a culpable mental state — negligence, recklessness, or intentional misconduct.
The New Jersey Supreme Court rejected that position. Justice Fabiana Pierre-Louis, writing for the Court, made clear that the statute does not condition basic liability on proof of a particular mental state. Brokers and other covered entities must comply with valid deletion requests. Failure to do so can support a claim even without a showing of negligence.
The Court did draw a line on damages. Punitive damages still require proof that the defendant acted with willful or wanton disregard of the law. Ordinary liability for non-compliance, however, does not.
Importantly, the justices did not decide whether Daniel’s Law is constitutional. That question remains pending before the U.S. Court of Appeals for the Third Circuit. The New Jersey Supreme Court answered only the certified question before it concerning the mental-state requirement.
Practical Consequences for Data Brokers
The decision changes the risk calculation for any company that maintains databases containing New Jersey public officials’ residential or contact information. Ignoring or slow-walking deletion requests is no longer a low-stakes operational choice protected by the need to prove fault. Plaintiffs can pursue claims based on non-compliance itself.
That reality has several immediate implications:
- Deletion request handling needs to be reliable, documented, and relatively prompt. Volume is not an excuse if the statute does not require proof of negligence.
- Companies that resell or republish data obtained from other brokers remain exposed if they continue displaying protected information after notice.
- Automated or bulk data products that refresh from public records or other brokers create recurring risk unless suppression lists and suppression logic are effective.
- Because the constitutional challenge is still live in the Third Circuit, the legal landscape could shift again. Until then, the New Jersey Supreme Court’s interpretation governs liability questions under state law.
Atlas Data Privacy and similar services have positioned themselves as intermediaries that industrialize the sending of takedown notices. The ruling increases the leverage of those notices. Brokers that previously treated them as low-priority correspondence now face clearer financial exposure for non-response.
A Broader Pattern in State-Level Protections
Daniel’s Law is part of a wider trend of state statutes that create heightened protections for specific high-risk populations — judges, law enforcement, victims of certain crimes, and in some states additional categories of public servants. These laws often operate alongside more general consumer privacy statutes that grant broader deletion or opt-out rights.
The New Jersey decision underscores a practical difference. General privacy laws frequently require consumers to navigate verification processes and may limit remedies. Daniel’s Law, as interpreted by the state’s highest court, creates a more direct path to liability when covered information is not removed after notice. That stricter posture reflects the specific safety rationale behind the statute.
For national data brokers, the patchwork is the compliance challenge. Information that is lawful to publish in one state may trigger statutory duties and private rights of action in another. Systems that do not support granular suppression by jurisdiction and by protected category will continue to generate avoidable risk.
New Jersey is the Next Hot Spot For Privacy Lawsuits
The Third Circuit’s eventual ruling on the constitutionality of Daniel’s Law will be the next major inflection point. Challenges to similar laws often focus on First Amendment questions involving public records and commercial speech. Until that court speaks, the New Jersey Supreme Court’s clarification on liability standards remains the operative rule for claims brought under the statute.
In the meantime, data brokers and companies that incorporate broker-sourced data into marketing, real-estate, or people-search products have a clear operational message: valid removal requests under Daniel’s Law must be honored. The cost of non-compliance is no longer insulated by the need to prove a culpable mental state for basic liability.
Public officials in New Jersey gained a stronger tool this week. Data brokers that treat deletion as optional lost one of their primary legal arguments. The practical result is straightforward — when a covered individual asks for their protected information to be taken down, the safer course is to take it down.