CCPA B2B exemption expired: are CRM and email contacts personal information?

Yes, they can be. California's temporary exemptions for business-contact and employee data ended on January 1, 2023, so names, work emails and direct lines in CRM, support and email systems may be personal information for covered businesses. Owners may need to pseudonymize those fields before records are licensed.

Is B2B data personal information under the CCPA now?

Short answer: it can be. California's temporary partial exemptions for employee and business-to-business contact information ended on January 1, 2023, so names, work emails and direct lines of business contacts can be personal information for companies the CCPA covers. The test is the statute's definition of personal information, not whether the data came from a company. Confirm the current text on the California Legislative Information site.

California is the outlier among US states here. Most state privacy laws exclude people acting in a commercial or employment context, as the state privacy laws map explains. That makes California-heavy sales, support and email systems the place where owners most often need to pseudonymize contact fields before records are licensed.

What the law says and what it does not

The California Attorney General's CCPA overview describes the rights of California residents and notes that the law changed on January 1, 2023 after Proposition 24. The statute defines personal information as information that identifies, relates to, describes or could reasonably be linked with a particular consumer or household, and "consumer" means a California resident. Nothing in that wording distinguishes a person's home life from their job once the temporary exemptions lapsed.

Three limits keep this from applying to everyone:

  • The CCPA covers only businesses that meet one of its thresholds. The CPPA FAQ lists them, and the revenue figure is adjusted over time.
  • It protects California residents, wherever the company is based.
  • Regulations were updated in 2026; check the CPPA regulations index for the current text.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Which B2B fields in CRM, support and email get pseudonymized?

The table covers fields that routinely appear in sales and support records. Counsel decides the final treatment for each company.

SystemFieldTypical treatment before licensing
CRMContact name, work email, direct lineReplace with consistent tokens so account history stays linked
CRMJob title and employerKeep title; consider generalizing employer if the account is a single person
Support deskRequester name and email in ticket metadataTokenize; keep ticket timeline and resolution
Support deskNames and numbers in ticket textDetect and mask in free text
EmailSignatures, quoted reply chainsStrip signature blocks, mask names and numbers in the body
EmailCalendar invites with attendee listsTokenize attendees, keep meeting purpose and outcome
Sales notesPersonal remarks about a contactReview manually; drop if not business-relevant

Consistent tokens matter: if "Dana Whitfield" becomes "Contact 4471" in every record, a buyer can still see an account relationship evolve without learning who Dana is. The technique for email archives is in how to redact PII from email archives.

The owner's B2B screen in five questions

Use this decision rule before raising the topic with a counsel or compliance lead.

  1. Does the company meet a CCPA threshold, or does it expect to?
  2. Do California residents appear in the CRM, tickets or email, even as customer employees?
  3. Does the data include business contacts' names, direct lines and signatures, or only company-level data?
  4. Was a notice at collection provided to employees and contacts, covering reuse of the records?
  5. Can pseudonymization happen without breaking the account and ticket relationships buyers value?

If the answers are yes, yes, yes, no and yes, the company probably needs a privacy review and a pseudonymization plan before records move. If question 1 is no, the CCPA may not apply, but other laws and customer contracts still might.

How this interacts with licensing

Whether licensing counts as a "sale" or "sharing" under the CCPA is a separate question, answered in is licensing company records a sale under the CCPA. Employees have their own track; see the employee data exemption guide. The PII versus personal data comparison helps with vocabulary.

Nothing here makes a California-heavy company ineligible. It means the tokenization rules for contact fields are written down with the company early. A partner only raises the question and never handles the CRM or ticket data.

What an owner should do this quarter

StepOwnerOutput
Inventory systems holding contact fieldsRevOps or IT leadList of CRM, support and email systems and years of history
Check notices to employees and contactsGeneral counsel or outside counselShort memo on reuse language
Test tokenization on a samplePrivacy leadConfirmation that account links survive
Decide who is the authorized sponsorOwner, CEO or CFONamed person for the licensing decision

Illustrative scenario

Illustrative and fictional: a 120-person IT services firm headquartered outside California keeps ten years of tickets and a CRM. About a third of its clients are California businesses, so thousands of client contacts are California residents. The firm's counsel concludes the CCPA likely applies. The plan: tokenize requester names, emails and phone numbers, mask names inside ticket text, keep ticket timelines and resolutions, and document the method. The firm still decides whether to license, and on what terms.

Questions to ask your counsel

  • Do we meet a CCPA threshold today, and did we in prior years?
  • Do our privacy notices to employees, customers and contacts allow this reuse?
  • Is tokenized contact data deidentified under the statute, or still personal information?
  • Do customer contracts restrict use of their employees' contact details?
  • Which service providers hold copies of the CRM or help desk data?

What to say to an owner

Common mistakes with B2B contact data

MistakeWhy it hurtsFix
Treating the CRM as "business only"Contacts are people, and California residents may be coveredInclude the CRM in the privacy review
Masking only the name fieldEmails, phone numbers and signatures still identify the personTokenize every contact field consistently
Ignoring support attachmentsScreenshots and forms often show names and numbersScope attachments in the data inventory

When not to bother

Skip this path if the company is under the baseline of 50+ full-time employees at peak (contractors excluded), if most records are consumer data without a licensing basis, or if the owner will not consider an exclusive license for an agreed term.

Next step

Ask the owner to run the company fit checker and read how it works. If the company looks like a fit, register as a partner to introduce it, or have the owner apply directly at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does the CCPA apply to a company with no California office?

It can. The law protects California residents and applies to for-profit businesses that do business in California and meet a threshold, so an out-of-state company with California customers or employees may be covered. The company's counsel should test the thresholds against its facts, using the CPPA's published figures.

Are company-level records such as invoices and order totals covered?

Figures about a company, with no information linked to an individual, are generally not personal information. Fields that identify or are reasonably linkable to a named person, such as a billing contact's name or direct line, may be. Mixed records need to be split or pseudonymized, so check each system with counsel.

Does pseudonymizing a contact name solve the problem?

It reduces risk but does not end the analysis. The CCPA treats deidentified information differently from merely masked data, and records may still be linkable to a person through context. Counsel should decide what level of treatment fits the dataset and whether a tokenized version is acceptable.

Do other states treat B2B contacts the same way?

Most comprehensive state privacy laws exclude people acting in a commercial or employment context, which is why California is described as the outlier. State laws vary and change quickly, so owners should check each state where they hold contacts rather than assume California's approach applies everywhere.

Can a partner tell an owner that the CRM is safe to license?

No. Partners make introductions and give basic fit information only. Whether a CRM can be licensed depends on the company's rights, notices and counsel's review. SourceX agrees redaction requirements with the company before any work begins, and nothing is binding until the company signs.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment