California Consumer Privacy Act (CCPA): 2026 B2B Compliance Guide

What the California Consumer Privacy Act means for B2B sales and prospecting in 2026 — your rights, obligations, fines, and how to stay compliant.

Jun 23, 2026 8 min read 1,934 words
California Consumer Privacy Act (CCPA): 2026 B2B Compliance Guide

If your sales team buys lists, scrapes contacts, or enriches leads with data on Californians, the California Consumer Privacy Act now applies to you — even for pure B2B contacts. The old business-to-business carve-out expired in 2023, and the rules have teeth in 2026.

This guide explains what the law actually requires, who it covers, what it costs to get wrong, and how to keep prospecting without inviting a regulator's attention.

TL;DR#

  • The California Consumer Privacy Act (CCPA), as amended by the CPRA, gives Californians rights to know, delete, correct, and opt out of the sale or sharing of their personal information.
  • Since January 1, 2023, the B2B exemption is gone — work emails, titles, and company contacts are personal information under the law.
  • You're covered if you do business in California and hit one threshold: $25M+ revenue, data on 100,000+ consumers/households, or 50%+ of revenue from selling data.
  • Penalties run $2,500 per violation ($7,500 if intentional or involving minors), plus $100–$750 per consumer in breach damages.
  • You can still prospect legally with documented data sources, honored opt-outs, and a clear privacy notice — sourcing data responsibly is the whole game.

Diagram: TL;DR
Diagram: TL;DR

What is the California Consumer Privacy Act?#

The California Consumer Privacy Act is a state law that gives California residents control over the personal information businesses collect about them. Think of it as a receipt-and-return policy for your data: consumers can ask what you've collected, demand a copy, tell you to delete it, and forbid you from selling it.

Signed in 2018 and effective January 1, 2020, the original CCPA was substantially expanded by the California Privacy Rights Act (CPRA), which took full effect on January 1, 2023. The CPRA added new rights, created a dedicated regulator — the California Privacy Protection Agency (CPPA) — and, critically for sales teams, ended the temporary exemption for business contact data.

People often shorthand the whole framework as "CCPA," and that's how this guide uses it. For the authoritative text, the California Attorney General's office maintains the statute and regulations.

Marketer tempted to switch from grey-market lists to compliant Tomba data
Marketer tempted to switch from grey-market lists to compliant Tomba data

The core consumer rights you must honor#

Near the heart of the law are a handful of rights you have to support operationally. If you process Californians' data, build a process for each of these:

  1. Right to know — Consumers can request the categories and specific pieces of personal information you've collected, plus its sources and the purposes for use.
  2. Right to delete — They can ask you to erase the personal information you hold, subject to limited exceptions.
  3. Right to correct — Added by CPRA, consumers can demand you fix inaccurate personal information.
  4. Right to opt out of sale or sharing — They can stop you from selling their data or "sharing" it for cross-context behavioral advertising.
  5. Right to limit sensitive personal information — Use of data like precise geolocation, government IDs, or account credentials can be restricted to what's necessary.
  6. Right to non-discrimination — You can't deny service, charge more, or degrade quality because someone exercised a right.

Who does the CCPA apply to?#

The CCPA applies to for-profit businesses that collect California residents' personal information, determine the purposes and means of processing it, do business in California, and meet at least one of three thresholds. You don't have to be headquartered in California — selling into the state is enough.

Threshold Trigger Typical B2B example
Annual revenue $25 million+ gross revenue (prior year) Most funded SaaS and mid-market firms
Data volume Buys, sells, or shares data on 100,000+ consumers or households List buyers, data brokers, high-volume outbound teams
Data-driven revenue 50%+ of annual revenue from selling/sharing personal info Data brokers, lead resellers, ad networks
Service providers Process data on a covered business's behalf Enrichment vendors, CRMs, sequencers

A single trigger is enough — they are not cumulative. Many growth-stage outbound teams cross the 100,000-record line through bulk prospecting without realizing it, especially when buying lists or running large bulk lead generation campaigns. If your CRM holds six figures of contacts, assume you're in scope and document accordingly.

Diagram: Who does the CCPA apply to
Diagram: Who does the CCPA apply to

Why does the CCPA matter for B2B sales?#

The CCPA matters for B2B because the exemption that once shielded business contacts expired on January 1, 2023 — work emails and job-related data are now fully regulated personal information. Before that sunset, you could largely ignore CCPA when emailing someone in their professional capacity. That era is over.

In practice, this changes three things for revenue teams:

  • Sourced data carries obligations. When you find or buy a prospect's email, you've collected personal information and inherited duties to disclose, honor opt-outs, and delete on request.
  • "Sharing" is broadly defined. Passing contact data to an ad platform for retargeting can count as "sharing" even without money changing hands.
  • Your vendors are part of your risk. Data providers must operate as compliant service providers. If yours can't document where data comes from, that's your exposure.

This is exactly why data provenance has become a buying criterion. Knowing where your data comes from is no longer a nice-to-have — it's the difference between a defensible prospecting motion and a liability.

How is the CCPA different from the GDPR?#

The CCPA and GDPR both protect personal data, but they differ in scope, consent model, and enforcement. The GDPR (the EU's regulation) is consent-first and broader; the CCPA is opt-out-first and threshold-gated. If you sell internationally, you likely need to satisfy both — and meeting the stricter GDPR bar usually covers most CCPA requirements.

Attribute CCPA (California) GDPR (EU)
Default model Opt-out of sale/sharing Opt-in consent / lawful basis
Who's covered Businesses over set thresholds Any org processing EU data
Core unit "Consumer" (CA resident) "Data subject" (any individual)
B2B contacts Covered since Jan 1, 2023 Covered from the start
Max admin fines $7,500 per intentional violation Up to 4% of global revenue
Private lawsuits Yes, for data breaches Limited / member-state dependent
Regulator CPPA + CA Attorney General National data protection authorities

For a deeper side-by-side, the IAPP (International Association of Privacy Professionals) and Wikipedia's CCPA overview are reliable starting points. When in doubt, design your data practices to the higher standard and you simplify compliance across jurisdictions.

Diagram: How is the CCPA different from the GDPR
Diagram: How is the CCPA different from the GDPR

What are the penalties for CCPA violations?#

CCPA penalties come in two flavors: regulatory fines and private breach lawsuits. The regulator can levy $2,500 per violation for unintentional breaches and $7,500 per violation for intentional ones or any violation involving consumers under 16. "Per violation" can mean per affected consumer, so numbers scale fast across a large list.

Separately, consumers have a private right of action for data breaches caused by failure to maintain reasonable security. Statutory damages run $100 to $750 per consumer, per incident — without anyone needing to prove actual harm. A breach of 50,000 records could expose you to tens of millions in claims before any fine.

The CPRA also removed the automatic 30-day cure period that businesses once relied on, so you can no longer assume you'll get a free fix-it window. Enforcement is active, and the CPPA has signaled it's prioritizing data brokers and high-volume data practices.

Drake meme rejecting risky purchased lists and approving Tomba's compliant data
Drake meme rejecting risky purchased lists and approving Tomba's compliant data

Diagram: What are the penalties for CCPA violations
Diagram: What are the penalties for CCPA violations

How do you stay CCPA-compliant while prospecting?#

You stay compliant by sourcing data transparently, honoring rights requests quickly, and documenting everything. Compliance isn't a reason to stop prospecting — it's a reason to prospect cleanly. Here's a practical checklist:

  1. Publish a clear privacy notice. Disclose the categories of data you collect, why, and the rights Californians have. Include a "Do Not Sell or Share My Personal Information" link if applicable.
  2. Map your data sources. Know where every contact came from. Reputable tools document their sourcing — verify yours can too.
  3. Honor opt-outs and deletions fast. Build a workflow to process requests within the statutory windows (generally 45 days, extendable once). Suppress opted-out contacts across all systems.
  4. Vet your vendors as service providers. Your email finder, enrichment provider, and CRM should have CCPA-compliant terms and a documented data lineage.
  5. Verify before you send. Clean, accurate data reduces the chance you're contacting people whose records are stale or wrong — and the right-to-correct burden that follows. An email verifier keeps your lists tight.
  6. Minimize and retain sensibly. Collect only what you need for the stated purpose, and delete what you no longer use.

Tools matter here because compliance lives in your workflow, not a policy PDF. When you find email addresses through a provider that publishes its data practices and supports suppression, you're building compliance into the top of your funnel instead of bolting it on after a complaint.

A quick word on "reasonable security"#

Because the private right of action hinges on "reasonable security," the cheapest insurance is basic hygiene: encrypt data at rest and in transit, restrict CRM access by role, log who exports lists, and avoid hoarding data you don't use. Most breach claims trace back to over-collection plus weak access control — fix both and you remove the largest source of statutory-damages exposure.

Does the CCPA stop you from buying lead lists?#

The CCPA doesn't ban buying data, but it makes shady lists far riskier. If a list vendor can't tell you where the data originated, whether consumers were notified, or how to process opt-outs, you're inheriting undisclosed liability. The safer path is a provider whose data enrichment and lookup pipeline is transparent and built to honor consumer rights.

That's the real shift CCPA forces on outbound teams: from "how many contacts can I get?" to "can I defend every contact I have?" The first question got teams in trouble; the second keeps them out of it. Quality, documented data isn't just more compliant — it converts better, because accurate targeting beats spray-and-pray every time.

Frequently asked questions#

Is a work email address personal information under CCPA? Yes. Since the B2B exemption expired in 2023, work emails, titles, and employer-linked contact data are personal information when tied to an identifiable California resident.

Do I need consent to email a B2B prospect in California? The CCPA is opt-out-based, so it doesn't require prior opt-in to contact a business prospect. But you must provide notice, honor opt-out and deletion requests, and you still have to follow CAN-SPAM for the email itself.

Does CCPA apply if my company isn't in California? Yes, if you do business in California, process Californians' data, and meet a threshold. Physical location doesn't matter.

What's the difference between CCPA and CPRA? CPRA is the 2023 amendment that expanded CCPA — adding rights, creating the CPPA regulator, and removing the B2B exemption. People still call the combined framework "CCPA."

Build prospecting on data you can defend#

The California Consumer Privacy Act rewards teams that know exactly where their data comes from and can act on consumer rights quickly. That starts with your sourcing tool. The Tomba Email Finder finds professional email addresses by domain, name, or company through a documented data pipeline, pairs with a built-in verifier to keep lists clean, and supports the suppression and lineage practices CCPA expects. Start on the free tier (25 searches/month), or scale up on the Starter plan at $49/mo — see full Tomba pricing — and build an outbound motion you can defend, not just one you hope no regulator notices.

This article is general information, not legal advice. Consult qualified counsel for your specific situation.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.