Skip to content

Logistics and distribution

Do state privacy laws apply to a B2B distributor or 3PL?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

State privacy laws can apply to a B2B distributor or 3PL, usually through narrower doors than consumer brands face. Applicability turns on thresholds such as annual revenue and the volume of personal data handled, and on whether the law exempts employee and business-contact data. California's CCPA covers both; most other comprehensive state laws largely exclude them.

Key takeaways

  • Selling only to businesses does not by itself put a company outside state privacy laws; thresholds and data types decide.
  • California's law reaches employee and business-contact data, while most other comprehensive state laws generally exclude people acting in an employment or commercial context.
  • A 3PL shipping to consumers for clients usually handles that data as a service provider, which limits what it may do with it.
  • Biometric, employee monitoring and breach notification laws can apply where a comprehensive law does not.
  • Licensing data for AI training raises sale, sharing and de-identification questions that counsel assesses deal by deal.

The short answer for distributors and 3PLs#

State privacy laws apply to a B2B distributor or 3PL when the company crosses a law's applicability thresholds and handles personal data the law does not exempt. Many B2B firms assume they sit outside these laws because they sell to businesses, but personal data turns up in more places than the customer list.

Look for it in the CRM, where buyer and purchasing agent contacts live; in HR and payroll systems; in driver telematics and camera systems; in call recordings and support inboxes; and, for 3PLs with e-commerce clients, in consumer names and ship-to addresses on every parcel order. Each of these can be treated differently depending on the state and the role the company plays.

Which thresholds decide whether a state law applies?#

State privacy law thresholds measure company size, the volume of residents' personal data processed, and how much of the business depends on selling personal data. A company usually needs to meet a threshold and do business in the state, or with its residents, before the law applies.

Each state sets its own figures and definitions, and they change. By MultiState's count, 20 states had comprehensive consumer privacy laws in effect once Indiana, Kentucky and Rhode Island's laws took effect on January 1, 2026, or 19 if Florida's narrower law is left out. Counsel should check the current text of each statute rather than a summary, and remember that thresholds are usually measured company-wide.

Which thresholds decide whether a state law applies?
Threshold typeWhat it measuresWhy a distributor or 3PL may cross it
Annual gross revenueCompany-wide revenue; California's threshold was adjusted from $25 million to $26,625,000 in January 2025, according to secondary guidesMid-market distributors can cross it on revenue alone
Volume of consumers' personal dataCalifornia counts 100,000 or more consumers or households whose data is bought, sold or shared; other states typically count residents whose data is controlled or processedFulfillment 3PLs handle large numbers of consumer ship-to records
Revenue from selling personal dataCalifornia applies when 50% or more of annual revenue comes from selling or sharing personal information; other states use their own testsRarely crossed today, but a data license could bring it into view
Small business definitionsSome states rely on federal small business standards instead of fixed figuresSize standards vary by industry code, so check the one that applies
Entity and data exemptionsCarve-outs for certain regulated entities or data typesEntity exemptions rarely fit distributors; data-level ones matter more

Employee and B2B carve-outs differ by state#

The biggest difference between states is how they treat employee and business-contact data. California's temporary exemptions for that data expired on January 1, 2023, when the legislature did not extend them, so a distributor that meets the CCPA thresholds may owe California employees and customer contacts core privacy rights.

Most other comprehensive state laws generally define a consumer in a way that excludes people acting in an employment or commercial context. Virginia's law is an early example, and the Colorado Attorney General states that the Colorado Privacy Act does not cover people acting in a commercial or employment context. Newer statutes should still be read one by one.

California's rules for workforce data are still developing: the California Privacy Protection Agency opened preliminary rulemaking on April 20, 2026 on how the CCPA applies to employee, applicant and contractor information. Carve-outs also narrow only the comprehensive laws. Biometric statutes, electronic monitoring notice laws in some states, and state breach notification laws can still apply to employee and driver data.

Employee and B2B carve-outs differ by state
Data typeCaliforniaMost other comprehensive state lawsAlso check
Employee and applicant dataGenerally coveredGenerally excluded from the consumer definitionMonitoring notice and biometric laws
Contacts at customers and suppliersGenerally coveredGenerally excluded in a commercial contextMarketing and email rules
Consumer ship-to data held for a clientCovered; the 3PL is usually a service providerCovered; the 3PL is usually a processorClient contract and processing terms
Driver telematics and camera dataCovered as employee or contractor dataOften excluded for employees; contractors need reviewBiometric statutes and monitoring laws
Biometric data such as face geometryTreated as sensitive personal informationUsually sensitive data, often needing consentIllinois BIPA and other biometric statutes

Business or service provider: the role question#

A distributor or 3PL's role decides what it may do with personal data, and the same company can hold different roles for different records. For its own employees, drivers and customer contacts, it decides why and how data is used, so it acts as the business or controller.

For consumer ship-to data processed for an e-commerce client, a 3PL usually acts as a service provider or processor. These laws generally expect a contract limiting that data to the client's business purpose. Using it for the 3PL's own purposes, including licensing it to an AI developer, would likely fall outside that role, so most licensing reviews exclude it.

The same split appears at distributors that drop-ship to consumers for retail customers, and at brokers whose shipment records carry residential delivery addresses. Tagging each record family with the role the company held when it collected the data is the simplest way to keep later decisions consistent.

What licensing data for AI training adds#

Licensing records for AI training adds questions that ordinary operations do not raise. Several state laws define sale and sharing broadly enough that a license of personal data for value could qualify, which brings opt-out rights and disclosure duties into play.

De-identified data is generally outside these laws, but the definitions come with conditions. California's definition, for example, requires reasonable measures so the data cannot be associated with a consumer or household, a public commitment to keep it in de-identified form and not attempt re-identification, and contracts that bind every recipient to the same terms. Other states use similar but not identical tests, so counsel should confirm the exact wording in each state that applies.

  • Map which states' residents appear in each record family, including employees and contacts.
  • Confirm the company's role for each record family: controller or service provider.
  • Exclude client-owned consumer data processed as a service provider.
  • Decide whether records will be de-identified to the standard each applicable law sets.
  • Review the privacy policy and employee notices against the planned use.
  • Check biometric, monitoring and sector rules for driver and camera data.
  • Record the analysis so it can be shown to a buyer or acquirer later.

Illustrative: a distributor with a fulfillment arm narrows its scope#

Illustrative: a fictional industrial distributor runs Epicor for orders and inventory, Salesforce for its sales team, and a separate fulfillment division that ships to consumers for brand clients from its own WMS. Its inside sales and support staff work from several states, including California.

Before discussing a data license, the general counsel maps personal data by record family. Quote and order-exception histories on the distribution side contain buyer contact names and emails, which California's law covers. The fulfillment WMS holds consumer ship-to data processed for clients as a service provider.

The company scopes only distribution-side histories, removes contact names, emails and phone numbers during preparation, excludes all fulfillment consumer data and all HR records, and updates its privacy policy language with outside counsel. The analysis is filed with the deal records.

How SourceX approaches state privacy review#

SourceX treats state privacy law as a deal-by-deal assessment made with the supplier's counsel, not a box checked once. In the SourceX five-step transaction, the Rights and Preparation steps identify which record families contain personal data, which role the supplier holds for each, and which data must be excluded or de-identified.

The privacy record in the SourceX Evidence Packet documents what was removed, the standard applied and who approved release. No files are requested during the initial assessment, which runs on metadata only.

Frequently asked questions

If we only sell to businesses, are we exempt from state privacy laws?

Not necessarily. California's law has covered employee and business-contact data since its exemptions expired in 2023, and B2B companies often hold consumer data through fulfillment, warranty or direct shipments. Elsewhere, carve-outs for employment and commercial contexts narrow the laws but do not cover every record. Counsel should map the data before relying on an exemption.

Do these laws apply to a company headquartered in another state?

They can. Applicability generally depends on doing business in the state or with its residents and meeting the thresholds, not on where headquarters sits. A distributor with customers, employees or consumer shipments in several states may need to consider several laws at once.

Is de-identified data outside state privacy laws?

Generally, if it meets each law's definition. Those definitions usually require more than removing names, including reasonable measures against re-identification, a public commitment and contractual controls on recipients. Data that is only pseudonymized, such as tokenized in a reversible way, is often still personal data.

Do we need employee consent to license records that mention employees?

It depends on the state, the records and how they are prepared. In many cases names and identifiers are removed, and a clear employee notice about data use is the starting point. Counsel should decide whether any record family needs consent rather than notice.

What about contacts in Canada or the EU?

Laws outside the US, such as GDPR for individuals in the EU, may apply to those records and follow different rules. Many US distributors exclude non-US personal data from a first package and review it separately with counsel familiar with those regimes.

Sources

  • Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20 by MultiState's count, including Florida's narrower law (19 without Florida). Source
  • Secondary guides report the CCPA's annual gross revenue threshold was adjusted from $25 million to $26,625,000 effective January 2025, alongside thresholds of buying, selling or sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Source
  • The California legislature ended its 2022 session without extending the CCPA employee and business-to-business exemptions, so they expired on January 1, 2023. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial (B2B) or employment context. Source
  • The Colorado Attorney General states that the Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context. Source
  • The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source
  • Post-CPRA, Cal. Civ. Code 1798.140(m) treats information as deidentified only if the business takes reasonable measures against association with a consumer or household, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify