← Back to list

The Legal Change That Quietly Put B2B Marketers at Risk (And Most of Them Still Don’t Know About…

A privacy law exemption expired in 2023. Thousands of US companies are still marketing as if it didn’t.

Theprospectsinfluentials · 2026-05-21 07:29 · 0 claps · 3.2 min read
#b2b-marketing #ccpa #privacy-law #compliance #data-privacy
Open on Medium ↗
Wiki topics: ECO · Economy · General MKT · Marketing · General 🔒 · Cybersecurity 🔧 · Data Engineering ⚖️ · Law & Justice

The Legal Change That Quietly Put B2B Marketers at Risk (And Most of Them Still Don’t Know About It)

A privacy law exemption expired in 2023. Thousands of US companies are still marketing as if it didn’t.

In January 2023, a quiet but significant change happened in US privacy law.

The CCPA’s B2B exemption expired.

Most B2B marketers have no idea. And the ones who do often assume it doesn’t apply to them. Both groups are accumulating legal exposure with every list they buy.

Here’s what changed, why it matters, and what you actually need to do about it.

The exemption that no longer exists.

The California Consumer Privacy Act took effect in 2020 with a temporary carve-out: business contact data work emails, direct phone lines, job titles was excluded from the same protections that covered consumer data.

The legislature extended that exemption twice. In August 2022, it adjourned without extending it a third time. On January 1, 2023, the exemption expired automatically.

Since then, a sales director in San Francisco whose work email appears on a B2B contact list is a protected person under California privacy law. Your right to collect, store, use, and sell that information is no longer automatically permitted just because your purpose is B2B marketing.

Who this actually affects.

You don’t have to be based in California. You need to:

  • Do business in California, AND
  • Meet at least one threshold: $25M+ annual revenue, data on 100k+ consumers or devices per year, or 50%+ of revenue from selling consumer personal information

A company headquartered in Texas, selling software to California businesses, with $30M in revenue: covered under CCPA.

This is the misconception that creates the most exposure. Marketers assume this is a California-company problem. It’s a California-contacts problem.

What B2B contacts can now demand from you.

When you purchase a B2B list containing California residents, those contacts now have:

  • The right to know what data you hold about them, where it came from, and who it’s been shared with
  • The right to delete their information from your records
  • The right to opt out of sale or sharing and this right existed even before the exemption expired
  • The right to correct inaccurate data
  • The right to restrict use of sensitive personal information

The most operationally significant for list buyers: opt-out requests must be honored within 15 business days. The fact that you received the data from a third-party provider doesn’t limit your obligation.

The penalty structure that makes this real.

Current fines: $2,663 per unintentional violation. $7,988 per intentional violation. Per contact affected.

A campaign sent to 10,000 California contacts whose opt-out rights weren’t properly managed isn’t one violation. Each contact is a separate potential violation.

The California Privacy Protection Agency approved a $1.35 million penalty against a single company in September 2025. The largest CCPA settlement to date is $2.75 million. Enforcement is active and it’s extending beyond large tech platforms.

Four things list buyers should do before their next purchase.

1. Ask for a Data Processing Agreement before you pay. A compliant provider produces this without hesitation. If the conversation stalls when you raise it, that tells you something about how they manage compliance overall.

2. Ask how California opt-outs are tracked and applied. Specifically: are suppression records updated before list delivery? If a contact previously opted out with the provider and that opt-out wasn’t honored before the data was transferred to you, you’ve inherited non-compliant data from the first use.

3. Build an internal process for data subject requests. When a California contact on a purchased list submits an access, deletion, or opt-out request to your company, you need a documented process to act within 15 business days. This should be in place before you run any campaign targeting California contacts.

4. Maintain and apply a suppression file. Every opt-out or deletion request goes on this list. Every new list you acquire gets filtered against it before deployment. This is an ongoing process, not a one-time setup.

The companies building these practices now aren’t just reducing current legal risk. They’re constructing the data infrastructure that additional state laws will require as US privacy legislation continues to expand. Twenty states now have comprehensive privacy laws in effect. Most still exclude B2B contact data but the trend is clear.

The full breakdown — including what changed for each rights category, how to evaluate list provider compliance practices, and the state-by-state landscape — is here:

👉 https://www.prospectsinfluential.com/the-ccpa-b2b-exemption-expired-what-every-us-marketer-buying-business-contact-lists-must-know-now/

This is not legal advice. For specific compliance questions, speak with a qualified privacy attorney.


메타데이터
post_id
afa1dbe42e45
slug
the-legal-change-that-quietly-put-b2b-marketers-at-risk-and-most-of-them-still-dont-know-about-afa1dbe42e45
url
https://medium.com/@theprospectsinfluentials/the-legal-change-that-quietly-put-b2b-marketers-at-risk-and-most-of-them-still-dont-know-about-afa1dbe42e45
canonical_url
https://medium.com/@theprospectsinfluentials/the-legal-change-that-quietly-put-b2b-marketers-at-risk-and-most-of-them-still-dont-know-about-afa1dbe42e45
author_url
https://medium.com/@theprospectsinfluentials
status
ok
fetched_at
2026-06-15 20:49:13