Which state privacy laws cover employee and B2B data? A framework for 2026
Most comprehensive state privacy laws are built around consumers and many exclude employment and business-to-business data, while California's carve-outs expired on January 1, 2023. Because each statute words its exclusion differently, a company licensing workplace or CRM records should check every relevant state with counsel.
Which state privacy laws cover employee and B2B data?
Most comprehensive state privacy laws are written around people acting as consumers, and many carve out data collected in an employment or business-to-business context. California is the notable outlier: it let those carve-outs expire on January 1, 2023. The wording of each state's exclusion differs, so a company licensing workplace or CRM records should read the statute for every state where it has staff or contacts, with counsel.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting. This page does not list individual state statutes or their effective dates, because they change and differ; use it as a framework and pull each state's current text.
Why California is different
California's law reaches a covered business's employees, applicants and business contacts in the same way as consumers. The California Attorney General's CCPA overview lists the covered rights and the law's application tests. The CPPA FAQ states one of those tests as a gross annual revenue threshold of $26,625,000 for the preceding calendar year, as adjusted effective January 1, 2025, and notes it may be adjusted again. The full treatment of workplace data is in the employee data exemption guide, and contact records are covered in the CCPA B2B exemption guide.
A framework for reading any state law
For each state, ask the same five questions of the statute's text.
| Question | What to look for | Effect on a licensing scope |
|---|---|---|
| Who is protected? | Definition of consumer or resident, and whether it excludes people acting in an employment or commercial context | If excluded, workplace and B2B records may fall outside the statute |
| Who is covered? | Applicability thresholds, such as volume or revenue tests | Smaller companies may be outside it |
| What is exempt? | Entity-level and data-level exemptions, for example for certain regulated data | Some record sets fall under other regimes instead |
| What counts as sale or other disclosure? | Definitions of sale, sharing and processing for targeted advertising | Determines whether a paid license triggers notices or opt-outs |
| What happens to de-identified data? | Conditions for de-identified or aggregate status | Often the practical route to a cleaner scope |
A company that answers these for California, plus the other states where it has many employees or customers, has most of what counsel needs.
What do situations look like in practice?
| Situation | What to check | Typical outcome to confirm |
|---|---|---|
| Staff in several states, CRM with US business contacts | Whether each state excludes employment and commercial-context data | Often fewer duties outside California, but confirm statute by statute |
| California office, national customer base | Whether the CCPA thresholds are met and which records relate to California residents | California-resident records may need notice, de-identification or exclusion |
| CRM mixing business contacts and individual consumers | Whether individuals appear as consumers rather than in a business capacity | Consumer records may be covered, so split the sets |
| Records of sole proprietors and individual customers | Whether a person acting for a business counts as a consumer | Varies by statute, so do not assume |
| Company with EU contacts | GDPR applicability, see the EU question | Separate regime layered on top |
Which record sets sit where?
Map each record family to the likely question before reading any statute.
| Record family | Employment context? | Business context? | First question |
|---|---|---|---|
| Payroll, benefits and HR files | Yes | No | Is the state's employment exclusion broad enough? |
| Internal email and chat | Mostly | Sometimes | Do messages include personal matters or non-employee individuals? |
| CRM contacts at other companies | No | Yes | Does the statute exclude business-contact data or require notice? |
| Customer support tickets from consumers | No | Sometimes | Are the requesters individuals acting for themselves? |
| Engineering and operations logs | Mostly | Mostly | Do they name individuals, and can names be removed? |
Where a record family has no personal information once names and contact fields are removed, state privacy statutes tend to matter less. That is why de-identification rules are agreed with the company before any work begins.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Assuming one state's rule applies everywhere | A company with staff and customers in several states faces several statutes | Map locations first, then read each text |
| Treating an exclusion as a clearance | Contracts, notices and recording laws still apply | Run the wider rights review |
| Using outdated summaries | Laws are amended and new ones take effect | Check current official text and effective dates |
| Mixing business contacts and consumers in one export | Consumer records may be covered even where B2B data is not | Split the record sets |
Beyond privacy statutes
A state exclusion for employment data does not clear a record set by itself. Other limits can still apply:
- The privacy promises in notices and terms. The FTC's staff view in its post on privacy and confidentiality commitments is that promises about not using customer data for undisclosed purposes, such as training models, are enforceable. That is staff guidance, not a rule. Read do privacy promises follow data in an acquisition for the transfer angle.
- Client contracts that restrict use.
- Call recording and wiretap rules.
- Employee relations: see do you need employee consent to license workplace data.
What a partner does with this
Nothing legal. When the sponsor asks, point to the framework and send them to counsel. Ask three simple things: where do your staff work, where are your customers, and do you hold contact or employee records in your systems. Candidates must still have 50+ full-time employees at peak (contractors excluded), documented history, rights to license and an authorized sponsor. The company fit checker gives a preliminary, non-binding screen.
How often should the review be repeated?
State privacy law keeps moving: statutes are amended, new ones take effect on staggered dates, and regulators publish rules. Repeat the five-question read whenever the company opens a new office, starts selling to a new state, or begins a new licensing discussion. Write down the date each statute text was read, so counsel can see at a glance which conclusions may be stale.
Checklist for the company's counsel
- List the states where the company has employees, applicants and customers.
- For each, record whether the privacy statute applies to the company and to employment and commercial-context data.
- Mark record sets that mix business contacts with individual consumers.
- Confirm current effective dates, because several laws have been amended or phased in.
- Decide which record sets to de-identify or exclude, with the company and SourceX, before any work begins.
Next step
If you know a company whose counsel is ready to work through this list, register as a partner and introduce it. The how it works page explains the stages after the introduction. No reward is guaranteed; it is paid only after the buyer pays and SourceX receives its fee.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Do state privacy laws apply to employee data?
It varies. Many comprehensive state laws are written around consumers and exclude data collected in an employment or commercial context, while California's law covers staff and applicants. Read each statute's definitions and exclusions, and have the company's counsel confirm which apply to its record sets.
Does California's B2B exemption still exist?
No. Like the employee exemption, the temporary business-to-business carve-out expired on January 1, 2023, so business contacts who are California residents are generally treated like other individuals when a covered business holds their information. Counsel can confirm how that affects a CRM.
Which states should a company check first?
Start where it has the most employees and customers, plus California because of its broad coverage. Then add any state where a statute applies to the company's size and data volume. The list changes as new laws take effect, so verify current text rather than relying on a fixed count.
Does an employment exclusion mean workplace data is free to license?
No. Even where a privacy statute does not apply, other limits remain, including privacy promises made in notices, client confidentiality terms, recording laws and employee relations. A rights and privacy review looks at all of them before a record set enters the licensed scope.
Can a partner say which states are safe?
No. Partners make introductions and give basic fit information. Telling a company that a state is safe would be legal advice. Suggest the owner ask counsel to apply the state-by-state questions to the company's records and bring the answers to the qualification conversation.
Related pages
- CCPA B2B exemption expired: are CRM and email contacts personal information?
- CCPA employee data exemption expired: what it means for licensing workplace records
- How SourceX US company data referrals work
- Does the EU AI Act apply to a US company that licenses data?
- Do you need employee consent to license workplace data?
- Do privacy promises follow data in an acquisition? What M&A advisors should know
Free resources
- Operational data inventory builder — List systems, record types, years held and owners.
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment