Does the CCPA apply to B2B contacts?
No. The CCPA's business-to-business exemption at Cal. Civ. Code 1798.145(n) became inoperative on 1 January 2023 by its own terms, and the employee exemption at 1798.145(m) lapsed the same day. Personal information about business contacts and employees is now ordinary personal information carrying full CCPA rights.
Applies to: B2B SaaS companies, agencies, distributors and any CCPA-covered business holding CRM records, prospect lists, or procurement contacts for people at other companies in California.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanA surprising number of B2B companies still operate on a rule that stopped being law over three years ago. The belief is that because your customers are companies rather than consumers, the CCPA does not really reach your CRM. It did not survive 1 January 2023, and the statute says so in its own text.
What the B2B exemption used to do
Cal. Civ. Code Section 1798.145(n)(1) suspended the obligations imposed by Sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.121, 1798.130 and 1798.135 for:
"personal information reflecting a written or verbal communication or a transaction between the business and the consumer, where the consumer is a natural person who acted or is acting as an employee, owner, director, officer, or independent contractor of a company, partnership, sole proprietorship, nonprofit, or government agency and whose communications or transaction with the business occur solely within the context of the business conducting due diligence regarding, or providing or receiving a product or service to or from such company, partnership, sole proprietorship, nonprofit, or government agency."
That is a wide carve-out, and while it was live it covered most of what sits in a B2B sales stack. Note what it never did: it suspended named obligations, it did not put the data outside the CCPA altogether, and it never reached Section 1798.150, the breach cause of action.
The sentence that ended it
Subdivision (n)(3) reads in full:
"This subdivision shall become inoperative on January 1, 2023."
There is no renewal, no successor provision, and no replacement carve-out elsewhere in the title. The exemption was written with an expiry date and reached it.
The same thing happened to the HR-data exemption one subdivision earlier. Section 1798.145(m)(4) says: "This subdivision shall become inoperative on January 1, 2023." Both lapsed on the same day, which is why the CCPA's reach over employee data and over business contact data changed simultaneously.
The statute's own credit line confirms it
This is the part worth checking yourself rather than taking on trust. At the end of Section 1798.145, the official California legislative text prints the provenance of the current version:
"(Amended by Stats. 2023, Ch. 567, Sec. 2. (AB 1194) Effective January 1, 2024. Subdivisions (m) and (n) inoperative January 1, 2023, by their own provisions.)"
The legislature's own credit line records the lapse. When two official sources, the operative section text and the version line, say the same thing, the question is closed.
What changed in practice on that date
Business contact data became ordinary personal information. Under Section 1798.140(v), personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household. A work email address at a California-based prospect meets that easily, and so do the notes attached to it.
The obligations that were suspended came back in one step. That means the notice at collection and privacy policy disclosures under Section 1798.130, the right to know and to delete, the right to correct, the right to limit use of sensitive personal information, and the opt-out mechanics under Section 1798.135 all now apply to that data on the same terms as anything else you hold.
The three places this usually breaks
The first is the DSAR search scope. If your access and deletion runbook searches the product database and the support inbox but not the CRM, it is now incomplete. Contact records, enrichment data, call recordings and intent signals are all in scope.
The second is the privacy policy. Policies written in 2021 and 2022 often describe categories of personal information collected from "consumers" while quietly omitting prospect and customer-contact data on the theory that it was exempt. The disclosure duty now covers it.
The third is data enrichment and sale-or-share analysis. B2B contact data bought from a data broker, or shared with advertising partners for account-based targeting, runs straight into the do not sell or share analysis. Being B2B does not change whether a disclosure is a sale or a share; it only changes who the data is about.
What did not change
Section 1798.145 still contains real, permanent exemptions, and they are worth distinguishing from the ones that lapsed. Subdivision (e) covers personal information subject to the Gramm-Leach-Bliley Act, subdivision (d) covers FCRA-regulated activity, and subdivision (c) covers HIPAA-governed protected health information and medical information under the Confidentiality of Medical Information Act. Those are data-level exemptions with no sunset attached.
The B2B and HR provisions were different in kind. They were temporary relief written with a date on them, and the date passed.
Next step
Compliance checklist
- Treat your CRM as consumer data. Names, business email addresses, job titles and call notes about California-based contacts are personal information under Cal. Civ. Code Section 1798.140(v).
- Extend request handling to B2B records. Requests to know, delete, correct and opt out now reach business contact data, so your DSAR search must cover the CRM, marketing automation and support tooling.
- Add B2B categories to your notice at collection and privacy policy, since the disclosure duties in Section 1798.130 no longer carve this data out.
- Check the same lapse for HR data. Subdivision (m), covering job applicants, employees, owners, directors, officers, medical staff members and independent contractors, became inoperative on the same date under Section 1798.145(m)(4).
- Re-examine any vendor contract or internal policy drafted before 2023 that assumes a B2B carve-out still exists.
Sources
- Cal. Civ. Code Section 1798.145 (exemptions; subdivision (n) business-to-business, subdivision (n)(3) inoperative 1 January 2023; subdivision (m) employee data, subdivision (m)(4) inoperative 1 January 2023), version line 'Amended by Stats. 2023, Ch. 567, Sec. 2. (AB 1194) Effective January 1, 2024. Subdivisions (m) and (n) inoperative January 1, 2023, by their own provisions.'
- California Privacy Protection Agency, California Consumer Privacy Act of 2018, consolidated statute text
- Cal. Civ. Code Section 1798.140 (definitions, including 'personal information' at subdivision (v))
Last verified: 2026-09-16
Informational, not legal advice.