CCPA employee data exemption expired: what it means for licensing workplace records
The CCPA employee data exemption expired on January 1, 2023, so covered California businesses must treat staff and applicant information like consumer data. For a company licensing records, that means checking notices, excluding sensitive fields and agreeing de-identification rules before any work begins, with the company's own counsel deciding what applies.
What changed when the CCPA employee exemption expired?
California employee, job applicant and contractor personal information has been fully covered by the CCPA since January 1, 2023, so a covered company can no longer treat workplace records as outside the statute. For a company thinking about licensing internal records, that means email, chat, HR-adjacent files and call recordings need a privacy review before anything leaves the building.
The California Attorney General's CCPA overview describes the rights the law gives California residents, including rights to know, delete, correct, opt out of sale or sharing and limit use of sensitive personal information. Those rights now reach people in their roles as staff and applicants, not only as customers. The law applies only to for-profit businesses that meet one of its thresholds, so the first question is always whether the company is covered at all.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Does the CCPA apply to this company?
Treat coverage as a three-part check, answered by the company's counsel rather than by the partner.
| Question | Why it matters | Who answers it |
|---|---|---|
| Does the company do business in California and operate for profit? | The statute reaches only businesses, not nonprofits or government bodies | Company counsel |
| Does it meet a revenue, volume or revenue-source threshold in the CCPA? | A company below every threshold is outside the statute even if it has California staff | Company counsel, using the AG overview |
| Do the records contain information about California residents who are staff, applicants or contractors? | Workplace records are now in scope, so notices and handling rules apply | HR lead and counsel together |
A national company with one California office can be covered. A company with no California presence and no California residents in its records may not be, though other states' laws or its own contracts can still apply. The state privacy law map for employee and B2B data compares how other states treat the same records.
Which workplace records raise the most questions?
Not every record carries the same weight. Sort them before the conversation with the owner gets abstract.
- Email and chat archives: names, addresses, performance comments and personal asides mixed into business threads.
- HR-adjacent files: onboarding forms, compensation notes, leave requests and disciplinary records. These are the highest-sensitivity category and are rarely the reason a company is a good fit.
- Recruiting records: applicant resumes and interview notes, which fall under the same employee-and-applicant coverage.
- Call and meeting recordings: voices and statements of staff and customers, with consent rules that vary by state.
- Operational records with outcomes: tickets, approvals, project records and decision logs, usually the most valuable material and often manageable once names are removed.
The CCPA defines categories of sensitive personal information, such as government identifiers and certain account credentials, that carry extra limits. A scope that excludes those fields from the start is simpler to defend than one that tries to clean them up later.
How do notices and de-identification fit in?
The statute's notice requirement, in Civil Code section 1798.100, asks a business to tell people at or before collection what categories of personal information it collects, why, and whether it is sold or shared. A company that collected staff data under an older, narrow notice should have its counsel compare that notice against the planned license.
De-identification changes the analysis. Information that has been properly de-identified is generally treated differently from personal information, and the sale question depends on what is actually delivered. That is why SourceX agrees de-identification and redaction rules with the company before any work begins, and why data is delivered only after an executed agreement and the company's authorization. The sale definition itself is covered in is licensing company records a sale under the CCPA.
What the standard counts as "properly de-identified" is a legal question for the company's counsel. The explainer on what anonymized means in AI data licensing describes the practical side.
Questions to put to the company's counsel
Bring this list to the owner, CFO or general counsel and let them take it from there:
- Is the company a covered business under the CCPA, and does it hold records of California staff or applicants?
- What did the employee and applicant privacy notices promise about use and disclosure?
- Which record sets contain sensitive personal information, and can they be excluded from scope?
- Will the buyer receive identifiable personal information, or only de-identified records?
- Do employment agreements, handbooks or union terms restrict disclosure of workplace communications?
- Is employee notice or consent advisable even where the law may not strictly require it? See do you need employee consent to license workplace data.
How does this change what a referral partner does?
Nothing about the partner's job becomes legal work. You make an introduction and give basic fit information; you never export, upload or describe confidential records.
- Ask whether the company has California staff and keep the answer as a flag, not a conclusion.
- Tell the sponsor that privacy review happens inside the process, with the company's counsel.
- Introduce through the referral form or your referral link, and let SourceX run qualification, the data inventory and rights review.
- Leave scoping and redaction rules to the company and SourceX, agreed before any work starts.
The company still needs 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to license the data and an authorized sponsor. A privacy question is a scoping issue, not usually a disqualifier. The company fit checker is a preliminary, non-binding screen.
Illustrative: a California-headquartered IT services firm
Illustrative and fictional. A managed services firm with several hundred staff and ten years of ticketing history wants to explore a license. Its counsel sorts the records into three tiers.
| Record set | Likely handling to discuss | Reason |
|---|---|---|
| Resolved support tickets with outcomes | Candidate for scope after names and contact details are removed | High workflow value, limited sensitive content |
| Engineering reviews and runbooks | Candidate for scope after credentials and personal references are removed | Structured, mostly company-authored |
| HR files and recruiting notes | Excluded from scope | Sensitive, low fit for the purpose |
The sponsor takes that sorting to SourceX at qualification, and the inventory step documents what exists. Nothing is binding until the company agrees price and terms and signs.
When to slow down
Pause the introduction, or ask the company to involve counsel first, when:
- The most valuable records are HR files or applicant data.
- Staff were told in writing that their communications would never be shared.
- The company cannot say who is responsible for privacy compliance.
- The owner expects identifiable employee data to be delivered as is.
Next step
If the company has years of operational records across several systems and a sponsor willing to review scope with counsel, register as a partner and make the introduction. The how it works page shows each stage that follows. Rewards are not guaranteed and are paid only after the buyer pays and SourceX receives its fee.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is California employee data now subject to the CCPA?
Yes, for covered businesses. Since January 1, 2023, personal information about California employees, job applicants and contractors is generally treated like any other California resident's data under the CCPA. Whether a particular company is a covered business depends on the statute's thresholds, which the company's counsel should confirm.
Does the CCPA stop a company from licensing workplace records?
No, it does not prohibit licensing as such. It adds notice, purpose and handling duties where records contain personal information. Many companies reduce the burden by agreeing de-identification and redaction rules before any work begins and by excluding sensitive fields entirely. Counsel decides what the company's situation requires.
Do small companies have to worry about this?
Possibly not. The CCPA applies only to for-profit businesses that meet one of its thresholds, so a smaller company with limited California data may be outside it. Companies introduced through SourceX still have 50+ full-time employees at peak, so coverage is a real question, and counsel should answer it.
Should a partner ask about employee privacy during the introduction?
Only lightly. Ask whether the company has California staff and whether anyone owns privacy compliance, then pass the topic to the sponsor and SourceX. Partners never review, describe or handle the records themselves, and legal conclusions belong to the company's counsel.
Are customer records handled differently from employee records?
The CCPA covers both, but notices, expectations and contracts differ. Customer and business-contact data brings its own questions, covered in the guide to the CCPA B2B exemption. In practice the company reviews each record set separately and scopes out what it cannot clear.
Related pages
- Which state privacy laws cover employee and B2B data? A framework for 2026
- How SourceX US company data referrals work
- What does anonymized mean in AI data licensing?
- Do you need employee consent to license workplace data?
- Is licensing company records a 'sale' under the CCPA?
- Check Company Fit for Data Licensing
Free resources
- Time value of money calculator — Future and present value with optional regular payments.
- Business DSCR calculator — Debt service coverage from cash flow and loan terms.
- MCP ROI calculator — Estimate hours saved, implied savings and first-year ROI from MCP.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment