Explainer

B2B Data and CCPA: Does It Apply?

Business contact data about California residents is personal information under CCPA. Here is who has to comply, what people can ask for, and the filters that help.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

Yes. CCPA covers B2B data when a record is about a California resident, because the exemption for business contacts ended on January 1, 2023. This page covers who must comply, what it asks of you and where LeadOcean's filters fit. It is not legal advice. Ask a lawyer about your own case.

Key takeaways

  • A name, job title and work email for a California resident is personal information. CCPA lists "professional or employment-related information" as a category.
  • The B2B carve-outs in the statute became inoperative on January 1, 2023. Business contact data no longer sits outside the law.
  • CCPA only binds a business that meets a threshold: revenue over $25M (as adjusted), 100,000 or more consumers or households a year, or 50% of revenue from selling or sharing data.
  • LeadOcean has a country filter and a city filter. It has no filter for where a person lives, so California residency is a question you answer outside the data.

What it is

CCPA, the California Consumer Privacy Act, gives California residents rights over the personal information that businesses collect about them, and since 2023 that includes their business contact details.

The statute defines a "consumer" as a natural person who is a California resident (Cal. Civ. Code 1798.140(i), September 2026). Your job title does not take you out of that definition.

Personal information includes "professional or employment-related information" (Cal. Civ. Code 1798.140(v)(1)(I), September 2026). A name, an employer and a work email for a person in San Diego fit.

Two things stay outside. "Publicly available" information is excluded, which covers lawfully published government records and information the person made public. Aggregate and deidentified data is excluded too. Company facts such as revenue or headcount are not about a person at all.

The law has been amended since 2018. California's Attorney General says CPRA amended the CCPA rather than creating a separate law, so "CCPA, as amended" is the usual name (California Attorney General, September 2026).

How it works

Take a fictional case. Acme, a payroll vendor, wants to email Jane Doe, a finance director in San Diego. Here is what CCPA asks of Acme.

  1. Check that CCPA binds Acme. It applies to a business that meets a threshold in section 1798.140(d). If Acme is below all three, CCPA does not reach it, though other laws may.
  2. Treat Jane's record as personal information. Her name and work email identify her, and the professional category covers her job title and employer.
  3. Know where the record came from. Jane can ask what Acme holds, where it got it and who it shared it with. Keep a note of the source and date for each list.
  4. Be ready for her requests. The Attorney General lists the right to know, to delete, to correct, to opt out of sale or sharing, and to limit use of sensitive data.
  5. Act on a deletion or opt-out and keep her out. Add her to a suppression list. Screen every new list against it so she does not come back.

The Attorney General also says businesses may not discriminate against someone for using these rights. A person cannot waive them by contract either.

CCPA vs GDPR

People treat CCPA as California's copy of GDPR. It is not. The two laws start from different places, and the biggest gap is the legal basis.

CCPAGDPR
Who it protectsCalifornia residentsPeople in the EU, under Article 3 reach rules
Who it bindsBusinesses over a thresholdAny controller or processor in scope, no size floor
Legal basis neededNo. It is mostly notice and opt-outYes. Article 6 lists the bases, such as legitimate interests
Core controlOpt out of sale or sharing, delete, correctObject under Article 21, erase, restrict
B2B contactsCovered since January 1, 2023Covered whenever a person is identifiable
RegulatorCalifornia Privacy Protection Agency and Attorney GeneralNational data protection authorities
Governs sending emailNo. CAN-SPAM and state law doNo. ePrivacy rules and national law do

Sources: Cal. Civ. Code 1798.140 and 1798.145, California Attorney General and GDPR text, all checked September 2026.

For the European side, read B2B data and GDPR. For the sending rules, read CAN-SPAM for cold email.

When it matters

Cold email to California contacts

CCPA does not write the rules for sending a message. It governs the data you hold behind the send. You still need to answer deletion and opt-out requests, and your sends must follow CAN-SPAM and any state law that applies.

Selling or sharing a list onward

The opt-out right is about sale or sharing. If you resell enriched lists, the sale trigger is in play. The Attorney General says "sharing" means cross-context behavioral advertising, which is a narrower thing than most outbound.

Enriching a CRM with California contacts

Once you pull a record into your CRM, you hold it. A deletion request reaches your copy, not only the provider's. Keep the source and fetch date next to each record so you can find and remove it.

Data brokers and the Delete Act

California has a separate rule for data brokers: businesses that sell personal information about people they have no direct relationship with. Since January 1, 2026, residents can use the DROP platform to send one deletion request to all registered brokers. Brokers must process those requests from August 1, 2026 (California Privacy Protection Agency, September 2026). Check whether your provider is on the public registry.

How LeadOcean handles it

LeadOcean does not tell you whether CCPA binds your company, and nothing on this page claims any dataset is compliant with anything. It gives you control over which countries and cities a list covers, plus the date each record was fetched.

The filters and fields that map to the points above:

  • country: an ISO 3166-1 code such as US. Limit a list to the markets you have reviewed.
  • city: city keywords for the person's listed location. It is a profile location, not a home address, so it does not prove residency.
  • emailType: separate work addresses from personal ones.
  • fetched_at: every record carries the date it was last fetched. The dataset is refreshed monthly.

LeadOcean has no California or US-state filter for people. A person listed in New York can live in California. Treat any location filter as a sizing tool, not a residency test.

Size a segment for free before you pull rows. Send count=true as a query parameter with limit 1. meta.total is capped at 100,000.

bash
curl -X POST "https://api.leadocean.io/v1/people/search?count=true" \
  -H "x-api-key: $LEADOCEAN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "country": ["US"],
    "city": ["San Diego"],
    "jobFunction": ["Finance & Accounting"],
    "jobLevel": ["Director"],
    "emailType": ["work"],
    "limit": 1
  }'

The response has an empty data array and meta.countOnly set to true. Remove count=true to pull rows. Each person returned counts one record.

Read LeadOcean's privacy policy before you build a suppression process.

Free gives 1,000 records, one-off, no card. Pro is $499 a month, flat, on /pricing. For a market-by-market view of providers, see B2B data providers in the UK, best B2B data providers and best B2B databases.

FAQ

Does CCPA apply to B2B data?

Yes, when a record is about a California resident. The B2B exemptions in the statute became inoperative on January 1, 2023, so work emails and job titles count as personal information. Company-level facts do not.

Does CCPA require consent to cold email?

No. CCPA is built on notice, access and opt-out, not opt-in consent for most uses. Sending is a separate matter, governed by CAN-SPAM and any state law. Check both.

Is a work email personal information under CCPA?

When it identifies a California resident, yes. The statute lists professional or employment-related information as a category. A role address such as info@acme.com that names no one is a weaker case.

What if the person is not in California?

CCPA protects California residents only. Other states have their own privacy laws, and the EU has GDPR. Check each market you send to rather than assuming one rule fits.

Does LeadOcean make my outreach CCPA compliant?

No. It gives you the country and city filters and a fetched_at date on each record. Whether CCPA binds you, and how you answer requests, is your call. This is not legal advice.

Build a country-filtered list and count it free

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →