Yes. CCPA covers B2B data when a record is about a California resident, because the exemption for business contacts ended on January 1, 2023. This page covers who must comply, what it asks of you and where LeadOcean's filters fit. It is not legal advice. Ask a lawyer about your own case.
Key takeaways
- A name, job title and work email for a California resident is personal information. CCPA lists "professional or employment-related information" as a category.
- The B2B carve-outs in the statute became inoperative on January 1, 2023. Business contact data no longer sits outside the law.
- CCPA only binds a business that meets a threshold: revenue over $25M (as adjusted), 100,000 or more consumers or households a year, or 50% of revenue from selling or sharing data.
- LeadOcean has a
countryfilter and acityfilter. It has no filter for where a person lives, so California residency is a question you answer outside the data.
What it is
CCPA, the California Consumer Privacy Act, gives California residents rights over the personal information that businesses collect about them, and since 2023 that includes their business contact details.
The statute defines a "consumer" as a natural person who is a California resident (Cal. Civ. Code 1798.140(i), September 2026). Your job title does not take you out of that definition.
Personal information includes "professional or employment-related information" (Cal. Civ. Code 1798.140(v)(1)(I), September 2026). A name, an employer and a work email for a person in San Diego fit.
Two things stay outside. "Publicly available" information is excluded, which covers lawfully published government records and information the person made public. Aggregate and deidentified data is excluded too. Company facts such as revenue or headcount are not about a person at all.
The law has been amended since 2018. California's Attorney General says CPRA amended the CCPA rather than creating a separate law, so "CCPA, as amended" is the usual name (California Attorney General, September 2026).
How it works
Take a fictional case. Acme, a payroll vendor, wants to email Jane Doe, a finance director in San Diego. Here is what CCPA asks of Acme.
- Check that CCPA binds Acme. It applies to a business that meets a threshold in section 1798.140(d). If Acme is below all three, CCPA does not reach it, though other laws may.
- Treat Jane's record as personal information. Her name and work email identify her, and the professional category covers her job title and employer.
- Know where the record came from. Jane can ask what Acme holds, where it got it and who it shared it with. Keep a note of the source and date for each list.
- Be ready for her requests. The Attorney General lists the right to know, to delete, to correct, to opt out of sale or sharing, and to limit use of sensitive data.
- Act on a deletion or opt-out and keep her out. Add her to a suppression list. Screen every new list against it so she does not come back.
The Attorney General also says businesses may not discriminate against someone for using these rights. A person cannot waive them by contract either.
CCPA vs GDPR
People treat CCPA as California's copy of GDPR. It is not. The two laws start from different places, and the biggest gap is the legal basis.
| CCPA | GDPR | |
|---|---|---|
| Who it protects | California residents | People in the EU, under Article 3 reach rules |
| Who it binds | Businesses over a threshold | Any controller or processor in scope, no size floor |
| Legal basis needed | No. It is mostly notice and opt-out | Yes. Article 6 lists the bases, such as legitimate interests |
| Core control | Opt out of sale or sharing, delete, correct | Object under Article 21, erase, restrict |
| B2B contacts | Covered since January 1, 2023 | Covered whenever a person is identifiable |
| Regulator | California Privacy Protection Agency and Attorney General | National data protection authorities |
| Governs sending email | No. CAN-SPAM and state law do | No. ePrivacy rules and national law do |
Sources: Cal. Civ. Code 1798.140 and 1798.145, California Attorney General and GDPR text, all checked September 2026.
For the European side, read B2B data and GDPR. For the sending rules, read CAN-SPAM for cold email.
When it matters
Cold email to California contacts
CCPA does not write the rules for sending a message. It governs the data you hold behind the send. You still need to answer deletion and opt-out requests, and your sends must follow CAN-SPAM and any state law that applies.
Selling or sharing a list onward
The opt-out right is about sale or sharing. If you resell enriched lists, the sale trigger is in play. The Attorney General says "sharing" means cross-context behavioral advertising, which is a narrower thing than most outbound.
Enriching a CRM with California contacts
Once you pull a record into your CRM, you hold it. A deletion request reaches your copy, not only the provider's. Keep the source and fetch date next to each record so you can find and remove it.
Data brokers and the Delete Act
California has a separate rule for data brokers: businesses that sell personal information about people they have no direct relationship with. Since January 1, 2026, residents can use the DROP platform to send one deletion request to all registered brokers. Brokers must process those requests from August 1, 2026 (California Privacy Protection Agency, September 2026). Check whether your provider is on the public registry.
How LeadOcean handles it
LeadOcean does not tell you whether CCPA binds your company, and nothing on this page claims any dataset is compliant with anything. It gives you control over which countries and cities a list covers, plus the date each record was fetched.
The filters and fields that map to the points above:
country: an ISO 3166-1 code such asUS. Limit a list to the markets you have reviewed.city: city keywords for the person's listed location. It is a profile location, not a home address, so it does not prove residency.emailType: separateworkaddresses frompersonalones.fetched_at: every record carries the date it was last fetched. The dataset is refreshed monthly.
LeadOcean has no California or US-state filter for people. A person listed in New York can live in California. Treat any location filter as a sizing tool, not a residency test.
Size a segment for free before you pull rows. Send count=true as a query parameter with limit 1. meta.total is capped at 100,000.
curl -X POST "https://api.leadocean.io/v1/people/search?count=true" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"country": ["US"],
"city": ["San Diego"],
"jobFunction": ["Finance & Accounting"],
"jobLevel": ["Director"],
"emailType": ["work"],
"limit": 1
}'The response has an empty data array and meta.countOnly set to true. Remove count=true to pull rows. Each person returned counts one record.
Read LeadOcean's privacy policy before you build a suppression process.
Free gives 1,000 records, one-off, no card. Pro is $499 a month, flat, on /pricing. For a market-by-market view of providers, see B2B data providers in the UK, best B2B data providers and best B2B databases.
FAQ
Does CCPA apply to B2B data?
Yes, when a record is about a California resident. The B2B exemptions in the statute became inoperative on January 1, 2023, so work emails and job titles count as personal information. Company-level facts do not.
Does CCPA require consent to cold email?
No. CCPA is built on notice, access and opt-out, not opt-in consent for most uses. Sending is a separate matter, governed by CAN-SPAM and any state law. Check both.
Is a work email personal information under CCPA?
When it identifies a California resident, yes. The statute lists professional or employment-related information as a category. A role address such as info@acme.com that names no one is a weaker case.
What if the person is not in California?
CCPA protects California residents only. Other states have their own privacy laws, and the EU has GDPR. Check each market you send to rather than assuming one rule fits.
Does LeadOcean make my outreach CCPA compliant?
No. It gives you the country and city filters and a fetched_at date on each record. Whether CCPA binds you, and how you answer requests, is your call. This is not legal advice.
Build a country-filtered list and count it free
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →