CCPA Compliance for Cold Outreach: The B2B Exemption That Lapsed
CCPA's business-to-business exemption went inoperative on 1 January 2023, so a B2B prospect record for a California resident carries full consumer rights.
CCPA applies to a for-profit business doing business in California that meets one of three thresholds. Subdivisions (m) and (n) of Civil Code section 1798.145, which exempted employee and business-to-business contact data, became inoperative on 1 January 2023, so B2B prospect records for California residents now carry the full set of consumer rights.
Key takeaways
- Civil Code section 1798.145 subdivisions (m) and (n) each state that the subdivision becomes inoperative on 1 January 2023, and the CPPA's FAQ dates the expiry to 31 December 2022.
- Even while the exemption operated, section 1798.120, the right to opt out of sale or sharing, was absent from the list of obligations it suspended.
- California's two surfaces publish different revenue thresholds: the Attorney General's FAQ says over $25 million, the CPPA's says $26.625 million or more effective 1 January 2025.
- A business must answer a verifiable consumer request within 45 days, extendable once by a further 45 days if the person is told inside the first period.
Reviewed and updated August 12, 2026
A prospect in San Diego reads your first email, does not reply, and three weeks later sends back one line asking what personal information you hold about him and where you got it. That is a request California law gives him the right to make, and answering it is not optional for a company the Act covers.
Most outbound teams have filed the California Consumer Privacy Act under consumer retail: cookie banners, loyalty schemes, ad tech. That filing was close enough to right while the Act carried a temporary exemption covering business-to-business contact data. The exemption ended, and a B2B prospect record for a California resident has been ordinary personal information ever since.
This is not legal advice. It is an operator's reading of the California Civil Code and of what the state's two enforcers publish. Take your own advice before relying on any of it.
What California actually regulates
The Act says nothing about your subject line, your unsubscribe link or your postal address. Those rules come from CAN-SPAM, and the multi-regime picture is in is cold email legal. California regulates the record behind the message: what you collected, why, who else you handed it to, and what the person named in it can compel you to do.
Whether the Act applies to your company at all
The California Attorney General's CCPA page states that the Act "applies to for-profit businesses that do business in California and meet any of the following", and lists three thresholds: gross annual revenue over a set figure, buying, selling or sharing the personal information of 100,000 or more California residents or households, or deriving 50 percent or more of annual revenue from selling California residents' personal information (oag.ca.gov/privacy/ccpa). Doing business in California is the trigger, so being headquartered elsewhere settles nothing.
The revenue figure is where California's own surfaces disagree. Civil Code section 1798.140(d)(1)(A) sets it at "annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95". The Attorney General's consumer FAQ carries the unadjusted number, "a gross annual revenue of over $25 million". The California Privacy Protection Agency's FAQ carries the adjusted one: "Have a gross annual revenue of $26.625 million or more (effective January 1, 2025)" (cppa.ca.gov/faq.html). Treat the agency's figure as the live one and expect it to move again.
The second threshold is the one an outbound programme can meet without anyone deciding to, because buying is listed alongside selling and sharing. A company acquiring California contact data in bulk should check where it sits against that number.
What the exemption actually did, and when it ended
Civil Code section 1798.145 held two temporary carve-outs. Subdivision (m) covered employees, job applicants and contractors. Subdivision (n) is the one outbound teams inherited: it said the obligations imposed by sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.121, 1798.130 and 1798.135 "shall not apply to personal information reflecting a written or verbal communication or a transaction between the business and the consumer, where the consumer is a natural person who acted or is acting as an employee, owner, director, officer, or independent contractor of a company", where that contact happened solely in the context of due diligence or of supplying or receiving a product or service.
Two things repay a careful read, because the popular version of the carve-out was wider than the statute.
It was a list of named obligations rather than a blanket. Section 1798.120, the right to opt out of the sale or sharing of personal information, is absent from that list, so on the face of the statute the opt-out right applied to business contact data throughout the exemption period.
And it was anchored to a relationship: information reflecting a communication or transaction between the business and that person. A record about somebody you have never dealt with, bought or built for a first approach, does not obviously answer that description.
Then it ran out. Subdivisions (m) and (n) each closed with the same sentence: "This subdivision shall become inoperative on January 1, 2023." The history note printed under the section on California's legislative information site records it plainly, "Subdivisions (m) and (n) inoperative January 1, 2023, by their own provisions" (leginfo, section 1798.145). Asked whether the statutory exemptions for employee data and business-to-business transactions are still in effect, the Privacy Protection Agency's FAQ answers "No", dating the end to 31 December 2022: the same cutover from the other side of midnight. The agency said it again in September 2025: "Since 2023, job applicants, employees, and independent contractors have been afforded greater privacy protections."
- 2018The Act is added to the Civil Code
Title 1.81.5 is added by Stats. 2018, Ch. 55, Sec. 3.
- 1 January 2020The Act becomes operative
Civil Code section 1798.198 sets the operative date.
- November 2020Voters approve Proposition 24
The Attorney General's page records that the CPRA amended the CCPA and added protections that began on 1 January 2023.
- 1 January 2023The B2B and employee exemptions go inoperative
Subdivisions (m) and (n) of section 1798.145 end by their own terms. The CPPA's FAQ dates the expiry to 31 December 2022.
On the two acronyms, the Attorney General's page is blunt: "CPRA amends the CCPA; it does not create a separate, new law."
What a California prospect can ask you for
The Attorney General's page lists the rights a California resident holds: to know what personal information a business has collected and how it is used and shared, to delete it, to correct it, to opt out of the sale or sharing of it, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them.
The Privacy Protection Agency's FAQ makes the population explicit: California residents with these rights include "contacts for business customers, vendors, or independent contractors". That is the whole article in one line.
The clock is in section 1798.130. A business must respond "within 45 days of receiving a verifiable consumer request from the consumer", and that period "may be extended once by an additional 45 days when reasonably necessary", provided the person is told inside the first 45 days.
The deadline is the easy half. The request arrives as a reply to a cold email, in the same inbox as the out-of-office bounces, and reads like an annoyed prospect.
Notice at collection, when the first contact is a cold email
Section 1798.100(a) requires that a business controlling the collection of personal information "shall, at or before the point of collection, inform consumers of the following": the categories collected, the purposes, whether the information is sold or shared, and how long it is kept. The Attorney General's page describes the resulting artefact, a notice at collection, which "must list the categories of personal information businesses collect about consumers and the purposes for which they use the categories of information", carries a Do Not Sell or Share link where the business sells, and links to the privacy policy. The page also says when: "This notice must be provided at or before the point at which the business collects your personal information."
For a website that is straightforward. For outbound it is the least comfortable requirement in the Act: you collect the record before any contact exists, so there is no page the person is visiting at the point of collection. What operators do in practice is publish a reachable privacy notice covering prospect data and point at it from the message. Whether that satisfies the section for your business is a question for your counsel, and it is the one item here we would not claim as settled.
Sale, share, and why a bought list is the sharp edge
California's definitions are wider than the commercial meaning of the words. Section 1798.140 defines "sell" as "selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating" personal information "to a third party for monetary or other valuable consideration". No invoice is required. Trading lists with a partner, or handing enriched records to another company for its own use, can land inside it. "Share" is narrower: disclosing personal information to a third party "for cross-context behavioral advertising, whether or not for monetary or other valuable consideration".
The Privacy Protection Agency put the point bluntly in a decision announced on 3 December 2025, requiring a marketing firm to "pay $56,600 in fines and past-due fees for failing to register as a data broker". The announcement quotes the decision: "A sale is a sale. A business cannot bypass the CCPA's and the Delete Act's requirements by selling personal information as part of a larger suite of products and services it offers." The agency's head of enforcement added that consumer profiles are protected personal information under the Act and that a business can be a data broker by trafficking in them.
Read that beside how a lead list usually gets assembled. A bought database, a partner swap, an enrichment vendor that keeps what it learns from your queries: each is a transfer of personal information to or from a third party, and each needs an answer under these definitions rather than the ordinary meaning of selling.
Publicly available information, and where enrichment crosses the line
Section 1798.140 says personal information "does not include publicly available information or lawfully obtained, truthful information that is a matter of public concern", and defines publicly available to include government records and "Information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media."
A name and role published on a company website sits comfortably inside that. The line moves at the next step. The same section lists, as a category of personal information, "Inferences drawn from any of the information identified in this subdivision to create a profile about a consumer reflecting the consumer's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes."
So the scored, segmented, inferred output of an enrichment step is personal information even where every input was public. Sourcing from published pages remains a good habit, and it is the habit Canada rewards under conspicuous publication, covered in CASL compliance for cold email. What it does not do is take the resulting profile out of scope in California. We do not scrape LinkedIn for contact data, and the reasons are in LinkedIn web scraping.
CCPA and GDPR, for a sender
Satisfying one does not satisfy the other. They ask different questions, in a different order.
- Applies only to a for-profit business doing business in California that meets one of three thresholds: revenue, 100,000 residents or households bought, sold or shared, or 50 percent of revenue from selling personal information.
- No lawful basis is required before you process. The person can direct you to stop selling or sharing.
- Rights: know, delete, correct, opt out of sale or sharing, limit sensitive personal information, non-discrimination.
- Respond within 45 days, extendable once by a further 45 days with notice.
- Enforced by the California Privacy Protection Agency and the Attorney General.
- No revenue or volume threshold. The EDPB's guide says it can reach an organisation not established in the EEA whose products or services are offered to, or whose monitoring covers, individuals in the EEA.
- You need a legal basis before you process at all. The EDPB lists six, including your organisation's legitimate interests.
- Rights: information, access, rectification, erasure, restriction, portability, objection, and no solely automated decisions.
- Answer a data subject request within one month.
- Enforced by national data protection authorities.
Three consequences follow for an outbound team.
A legitimate interest assessment, the document most EU-ready senders already hold, answers a question California never asks. California asks instead whether you sell or share, and a clean answer to the European question tells you nothing about that one.
An objection under GDPR bites on the marketing itself: where a person objects, the EDPB's guide says, "the organisation must stop the direct marketing". A California opt-out under section 1798.120 bites on the selling and sharing. A team that treats one as an unsubscribe has done a useful thing and not the required one.
And the thresholds cut opposite ways. A small company outside the EEA emailing into Europe is squarely in scope of GDPR, and may sit entirely outside CCPA until it crosses a threshold, at which point a lot of obligations arrive at once.
The checklist
- Depends: Work out whether you meet one of the three thresholds, and re-check it each year against the agency's current revenue figure.
- Yes: Segment California records before a send, so jurisdiction is a field on the record and not a footnote.
- Yes: Store the source URL and the collection date on every record, and keep them for as long as you keep the record.
- Yes: Stop treating business contact data as exempt. The subdivision that made it exempt is inoperative.
- Yes: Publish a privacy notice that covers prospect data and can be reached from every message you send.
- Yes: Route rights requests off the reply inbox into a process that starts the 45-day clock the day they land.
- Yes: Write down whether you sell or share, using the statute's definitions rather than your accounting definition.
- Depends: Honour opt-out preference signals on any web property where you sell or share.
- Yes: Keep one suppression list across every campaign, every domain and every sending platform.
- Yes: Get the notice-at-collection question answered by counsel for your specific motion.
Source capture is the cheapest item there and the one that gets skipped: a request to know where you got somebody's details is answerable in seconds if the answer is a column, and close to unanswerable if it is not. The suppression list has to be global, because somebody who opts out of one campaign and then hears from another domain you own has been suppressed nowhere that matters. That is also plain list hygiene.
Opt-out preference signals are a web-property obligation rather than an email one. Section 1798.135(b) lets a business meet its opt-out duty by honouring a signal sent "through an opt-out preference signal sent with the consumer's consent by a platform, technology, or mechanism", and the Attorney General's page names the Global Privacy Control as a route consumers use.
Who enforces it, and what it has cost
Two bodies. Section 1798.155 makes a business "liable for an administrative fine of not more than two thousand five hundred dollars ($2,500) for each violation or seven thousand five hundred dollars ($7,500) for each intentional violation" in an action brought by the Privacy Protection Agency. Section 1798.199.90 gives the Attorney General a civil penalty in the same amounts, recovered in court. Both are stated in the statute as figures to be adjusted under section 1798.199.95.
Individuals mostly cannot sue. The Attorney General's page is explicit that for violations other than certain data breaches, "only the Attorney General or the California Privacy Protection Agency may take legal action against non-compliant entities". The private right of action is confined to breaches of unencrypted personal information, with statutory damages of up to $750 per incident.
The largest published agency fine so far went to a retailer. On 30 September 2025 the agency announced a decision requiring Tractor Supply Company to "pay a $1,350,000 fine to resolve claims that the company violated the California Consumer Privacy Act", noting that "The fine is the largest in the CPPA's history." Among the findings: "Failing to provide consumers with an effective mechanism to opt-out of the selling and sharing of their personal information, including through opt-out preference signals such as Global Privacy Control", and disclosing personal information to other companies without contracts containing privacy protections.
The decisions listed on the agency's announcements page are consumer-facing so far. The mechanics they turn on are the same ones an outbound programme runs on: notices, opt-out routes, and contracts with the companies you hand data to.
How we run it
Our posture is a set of standing rules. One message per campaign, so there are no thread replies and no bump sequences to unwind when somebody objects. Email and LinkedIn only. Suppression is global across every campaign and domain, and permanent. Every record carries its source and its date. We do not sell privacy software, templates or legal advice: we run outbound campaigns and are paid on attended qualified meetings, against criteria agreed in writing before anything launches. Verified addresses also mean fewer records about people who left the role, covered in email verification tools, and the fundamentals sit in the cold email deliverability guide.
Running outbound into California and want the record layer built in from the start? Get a free campaign plan and we will walk through how sourcing, source capture and suppression are wired.
Statutory and regulator text verified against the sources linked above as of August 2026. This is an operator's summary and not legal advice. Verify current requirements, and take your own advice, before relying on it.
Frequently asked questions.
Frequently asked questions- Does CCPA apply to B2B cold email?
- It applies to the prospect record rather than to the message. Civil Code section 1798.145 carried a temporary exemption for business-to-business contact data, and that subdivision became inoperative on 1 January 2023. A California resident contacted in a business capacity now holds the same rights as any other consumer, provided your company meets one of the three applicability thresholds.
- What is the difference between GDPR and CCPA for a sender?
- GDPR has no revenue or volume threshold and requires a legal basis before you process at all, with six listed by the EDPB including legitimate interests. CCPA applies only above a threshold and asks instead whether you sell or share personal information. Clearing one clears nothing in the other, and the response deadlines differ: one month against 45 days.
- Does buying a lead list count as a sale under CCPA?
- The statutory definition of sell covers releasing, disclosing, making available or transferring personal information to a third party for monetary or other valuable consideration, so no invoice is required for a transfer to qualify. Buying at volume also feeds the second applicability threshold, which counts personal information a business buys, sells or shares.
- Is a work email address from a public company page personal information?
- Section 1798.140 excludes publicly available information, including material a business reasonably believes was lawfully made available to the general public by the person or through widely distributed media. The same section lists inferences drawn to create a profile as a category of personal information, so enrichment output is in scope even when every input was public.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
GDPR for B2B Outbound: What Emailing Contacts in Europe Actually Requires
Territorial scope, the assessment behind a legitimate interest send, the national ePrivacy layer that decides whether you may send, and what the first message carries.
Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English
Cold email is legal in the US without consent, restricted in Canada, and conditional in the EU and UK. Here is what each regime requires and what it costs.
CAN-SPAM Act Compliance for B2B Cold Email: What the Law Requires
The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.
CASL Compliance for Cold Email: What Canadian Law Actually Requires
Express versus implied consent, the conspicuous publication route, the narrow B2B exemption, and the 60-day and 10-business-day rules CASL imposes on senders.
Suppression List: What It Means and Why the Textbook Definition Misleads
A suppression list is the memory of every instruction you have been given about who not to contact. Its value comes entirely from being enforced everywhere.
11 Cold Email Agencies: What Each One Publishes About Price
Eight of eleven cold email agencies publish a rate and three publish only terms. Four publish what they count as a qualified lead, and those definitions differ sharply.