California’s temporary exemption for business-to-business and employee personal information expired on 1 January 2023, so a bought or scraped list of California business contacts is now “personal information” under the CPRA — full stop, with opt-out and notice obligations attached. Most vendor pitches for outbound data still assume the old B2B carve-out is live. It is not.
The short answer: a handful of comprehensive US state privacy laws — California’s CCPA/CPRA, Virginia’s VCDPA, Colorado’s CPA, Connecticut’s CTDPA, Oregon’s OCPA and Texas’s TDPSA among them — now govern notice, opt-out-of-sale and (in California) business-contact data for outbound prospecting, on top of separate data-broker registries in California, Texas, Oregon and Vermont, and on top of the TCPA.
This page is general information for a RevOps or legal team scoping a vendor, not legal advice. Confirm anything you rely on with your own counsel before you sign off on a list.
The structural point most list vendors get wrong
It is a reasonable assumption: consumer privacy laws protect consumers, and a business email address you got from LinkedIn or a data broker is not consumer data — it is B2B data, and B2B data is exempt. That was true in California from 2018 through the end of 2022. It has not been true since.
The original CCPA carved out personal information collected in the course of a business-to-business transaction or an employment relationship, but that carve-out was always a temporary sunset provision, not a permanent exemption. The California Privacy Rights Act (CPRA) set that sunset to 1 January 2023. Several bills that would have extended the carve-out further — including SB 1454 — did not pass before the legislature adjourned in August 2022, so the exemption in Civil Code §1798.145 became inoperative on schedule. Since then, a Californian’s work email, job title and phone number carry the same notice-at-collection and opt-out-of-sale rights as their personal Gmail address, and the California Attorney General confirms the exemptions for employment and B2B personal information expired at the end of 2022 (California Attorney General, CCPA overview).
Most of the other comprehensive state laws still exempt B2B and employment data outright — which is exactly why treating “privacy law” as one uniform rule is the mistake. California is the outlier that bites a national list, not the norm.
How it works
How an AI sales agent books your appointments
Six channels feed in
Outbound email, SMS, voice and social — plus inbound search and AI referrals from our own AI SEO and chat agents.
Your list or CRM
Outbound starts from data you already own — past enquiries, dormant customers, or a targeted prospect list.
Qualified against your rules
Budget, timing and fit are checked before anything reaches your team, using criteria you set.
Booked into your calendar
Only qualified prospects reach the booking step, so your closers spend their time selling.
MAKE MORE SALES.
Pay-Per-Result pricing — We scale sales HARD aligned to your interests, better than anyone else.
Which states actually have a comprehensive privacy law right now
State privacy trackers do not agree on a single number, and that is worth saying plainly rather than repeating whatever count is fastest to find — a chunk of the disagreement is just whether to count Florida’s narrower-scope privacy law alongside the broader comprehensive ones. One widely-cited tracker puts the current count at twenty states, including Florida (MultiState’s 2026 rundown). Rather than lead with a headline figure that will be stale within a quarter, here is what we individually verified against the state attorney general’s office or the legislature’s own published text, which is the set that matters for a US outbound sales list:
- California — CCPA as amended by the CPRA, in force since 1 January 2020, B2B/employee exemption expired 1 January 2023 (oag.ca.gov)
- Virginia — Consumer Data Protection Act (VCDPA), in force since 1 January 2023, excludes anyone “acting in a commercial or employment context” (Code of Virginia, Chapter 53)
- Colorado — Colorado Privacy Act (CPA), in force since 1 July 2023, same commercial/employment exclusion (Colorado Attorney General)
- Connecticut — Data Privacy Act (CTDPA), in force since 1 July 2023, excludes data processed solely within an employment or B2B relationship (Connecticut Attorney General)
- Oregon — Consumer Privacy Act (OCPA), in force since 1 July 2024, excludes commercial/employment context
- Texas — Data Privacy and Security Act (TDPSA), in force since 1 July 2024, excludes B2B and employment data (Texas Attorney General)
If a fact about a seventh state matters to your specific list, verify it the same way — at the AG’s page or the statute — before you rely on it. That is the whole point of this section: the count moves, the individual answer for a state you actually use does not, provided you check it at source.
Want this done for you? We book qualified sales appointments on a Pay-Per-Result basis — you only pay for calls that actually land in your calendar.
The obligations that actually bite an outbound list
Strip away the marketing language and every comprehensive state law asks the same handful of questions about a prospecting list:
Notice at or before collection. If you are the one collecting the data directly (a form fill, a chat widget, an inbound call), you need a notice describing what you collect and why before or at the point of collection. If you are buying or renting a list from someone else, that obligation sat with them — but you inherit the downstream opt-out and deletion obligations regardless of who did the original collecting.
Opt-out of sale or sharing, and “sale” is defined wider than you’d assume. California’s statute defines “sell” as “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating… a consumer’s personal information by the business to a third party for monetary or other valuable consideration” (Civil Code §1798.140(ad)(1), via FindLaw’s codified text). Renting a database from a data broker to seed your CRM is a sale under that definition, even though no cash changes hands between you and the consumer. “Sharing” is a separate, even broader category covering disclosure for cross-context behavioral advertising, with or without payment.
Global Privacy Control. California and Colorado both require businesses to treat a Global Privacy Control browser signal as a valid opt-out-of-sale request, and in September 2025 the California, Colorado and Connecticut attorneys general ran a joint investigative sweep specifically targeting businesses that were not honouring it (California DOJ press release). If your outbound stack includes a web form or landing page that captures leads, that page needs to detect and respect GPC, not just a manual cookie-banner toggle.
Sensitive-data rules. Health, immigration status, precise geolocation and similar categories trigger stricter consent requirements across most of these laws — relevant if your ICP filtering or enrichment data touches any of it, which is more common in healthcare and government-adjacent B2B selling than people expect.
Data-broker registration. Separately from the consumer-rights laws above, four states now require the broker you are buying from — not you, the buyer, but the seller — to be on a public register:
- California’s Delete Act created DROP, a platform where consumers submit one deletion request that reaches every registered broker; brokers must access it at least every 45 days starting 1 August 2026 and pay a $6,000 annual registration fee, with $200-per-day penalties for non-compliance (California Privacy Protection Agency)
- Texas requires data brokers to register with the Secretary of State for a $300 fee under Business & Commerce Code Chapter 510 (redesignated from Chapter 509 effective 1 September 2025) (Texas Secretary of State); the Texas AG has already put over 100 companies on notice for apparent non-compliance
- Oregon requires registration with the Division of Financial Regulation for a $600 fee, effective since 1 January 2024 (Oregon DFR)
- Vermont was first, in 2018: annual registration with the Secretary of State, a $100 fee, and a $50-per-day penalty for failing to register (Vermont Attorney General guidance)
If your list vendor cannot tell you which of these registers they are on, that is itself an answer. A legitimate data broker selling into California, Texas, Oregon or Vermont residents should be a matter of public record. For the wider set of questions an enterprise buyer’s legal or security team will run a vendor through before approving a list source, see our breakdown of what enterprise privacy and security reviewers actually ask.
State-by-state comparison
| State | Law | In effect since | Applies to B2B contact data? | Opt-out of sale required? | Notable extra |
|---|---|---|---|---|---|
| California | CCPA / CPRA | 1 Jan 2020 (B2B exemption expired 1 Jan 2023) | Yes | Yes, incl. GPC | Delete Act / DROP data-broker deletion platform |
| Virginia | VCDPA | 1 Jan 2023 | No | Yes (consumer data only) | AG-only enforcement, no private right of action |
| Colorado | CPA | 1 Jul 2023 | No | Yes, incl. GPC since 1 Jul 2024 | Joint GPC enforcement sweep with CA/CT |
| Connecticut | CTDPA | 1 Jul 2023 | No | Yes (consumer data only) | Statutory cure period expired end of 2024 |
| Oregon | OCPA | 1 Jul 2024 | No | Yes (consumer data only) | Separate data-broker registry, $600/yr |
| Texas | TDPSA | 1 Jul 2024 | No | Yes (consumer data only) | Separate data-broker registry, $300/yr, active AG enforcement |
| Vermont | Data broker law only (Act 171) | 2018 | N/A — broker registration, not a consumer-rights law | N/A | First US data-broker registry; $50/day penalty |
If we can’t make you money, we don’t deserve yours.
Pay-Per-Result pricing — performance-based alignment.
Where the TCPA and state mini-TCPAs fit in
Everything above governs the data itself — whose consent you need to collect and hold it, and whether the person can opt out of it being sold. It says nothing about whether you are allowed to call, text or robodial the numbers on that list, which is a separate and, for outbound teams, usually a bigger source of exposure. The federal TCPA sets the baseline, and Florida, Oklahoma, Washington and Texas have each layered a state-level “mini-TCPA” or telemarketing statute on top with their own consent, calling-window and penalty rules, independent of whether the underlying data was collected in a privacy-law-compliant way. Treat privacy-law compliance and TCPA/mini-TCPA compliance as two separate checklists for the same list — passing one says nothing about the other. We cover the calling and texting side in detail in our TCPA compliance guide for AI voice and SMS agents, including how it interacts with A2P 10DLC registration if your outbound motion includes SMS — see our A2P 10DLC registration guide for that piece specifically.
What a defensible US outbound list actually looks like
None of this means outbound prospecting into the US is off the table for scale-ups and mid-market teams — it means the list needs a paper trail before your first call. In practice that is five things:
- Provenance you can evidence. Know, in writing, where every record came from — first-party form fill, licensed data broker, public directory — and keep that record per-source, not per-campaign, so you can answer a legal or security review question in minutes rather than days.
- A notice at collection you actually served. If you collected it yourself, the notice needs to have existed at the point of collection, not been retrofitted after a review flagged it.
- Suppression against opt-outs and broker deletions. A record that a California, Colorado, Connecticut, Oregon or Texas resident opted out — or that a data broker processed a DROP deletion request — needs to suppress that contact everywhere downstream, not just in the system where the opt-out landed.
- Contractual flow-down to every vendor touching the list. Your data-processing terms with any enrichment, dialer or CRM vendor should require them to honour the same suppression and deletion obligations you do, in writing.
- A documented retention rule. A stated, followed policy for how long a non-converting record sits in the system before it is purged beats an undocumented “we keep everything” default in every review we have seen.
This is the same discipline enterprise buyers expect from any AI-run outbound motion, not just the list sourcing — see our AI outbound compliance checklist for enterprise teams for the fuller operating picture.
FAQ
Does the CCPA really apply to business contact data now?
Yes. The original exemption for personal information collected in a B2B or employment context expired on 1 January 2023 when the legislature adjourned in 2022 without passing any of the bills that would have extended it, per the California Attorney General’s CCPA overview. A California business contact’s work email and phone number now carry the same notice and opt-out rights as any other California resident’s personal information.
How many US states have a comprehensive privacy law as of September 2026?
Trackers disagree on the exact figure, partly over whether to count Florida’s narrower-scope law alongside the broader comprehensive ones. One widely-cited tracker, MultiState, puts the current count at twenty states, including Florida. We verified six directly against the relevant AG’s office or statute for this page — California, Virginia, Colorado, Connecticut, Oregon and Texas — and recommend checking any other state the same way rather than trusting a single headline number.
Is buying a list from a data broker a “sale” that triggers opt-out rights?
In California, yes. The statutory definition of “sell” covers renting, disclosing or otherwise transferring personal information for monetary or other valuable consideration (Civil Code §1798.140(ad)(1)), which covers a paid list rental even where no direct payment flows from the consumer’s side of the transaction.
Do we have to honour Global Privacy Control signals on a B2B landing page?
If the visitor is a California or Colorado resident, yes — both states require GPC to be treated as a valid opt-out-of-sale request, and both states have participated in a joint enforcement sweep specifically targeting businesses that ignore it.
If our list already complies with state privacy law, are we clear on the calling side?
No. State privacy laws govern the data; the TCPA and state mini-TCPAs in Florida, Oklahoma, Washington and Texas govern the act of calling or texting. They are enforced independently and a list can be fully privacy-law compliant while the calling campaign built on it is not.
What is California’s Delete Act / DROP and does it affect an outbound sales team?
It is a single portal where a California consumer can request deletion from every registered data broker at once. If your list vendor is a registered broker, a DROP deletion request they receive should flow through to suppress that contact in whatever data they have sold you — ask your vendor how they push DROP deletions downstream to customers.
Do employee or job-title based B2B lists need special handling outside California?
In Virginia, Colorado, Connecticut, Oregon and Texas, no — each of those laws excludes data processed solely in a commercial or employment context, so a straightforward B2B contact list sits outside their consumer-rights provisions. California is the exception, not the rule, which is exactly why a one-size answer is the wrong answer.
Pay-Per-Result appointments
See if we’re a fit
We book qualified sales appointments for you and you pay on results, not retainers. Our booking page asks a few quick questions so you find out in two minutes whether that model suits your business.
- 50,769+ appointments booked without cold calling.
- Pay-Per-Result pricing — you pay for booked, qualified calls.
- Pick your own time on our live calendar, no phone tag.
