Skip to content

Home services and trades

Do state privacy laws apply to a local HVAC or plumbing company?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Most state privacy laws do not reach a local HVAC or plumbing company that stays under their thresholds, but some contractors cross them. California's CCPA turns on revenue, consumer volume or data-sale revenue, while most other states count residents. The deciding rule: count customers, leads and callers per state, then check whether you sell or share their data.

Key takeaways

  • California's CCPA covers a for-profit business that meets any one of three tests: annual revenue, consumer volume, or revenue from selling or sharing personal information.
  • Most other comprehensive state privacy laws turn on how many state residents' personal data you process in a year, not on revenue.
  • Leads, callers and website visitors can count toward resident totals, not only paying customers.
  • Licensing customer-linked records may count as a sale under some state laws unless the data meets that state's definition of de-identified.
  • Call recording consent laws and breach notification duties apply whatever your size.

The short answer for a local contractor#

State privacy laws apply to a local HVAC or plumbing company only when it meets a specific law's applicability test, and many single-market contractors do not. The comprehensive laws, such as California's CCPA and the newer laws in Oregon, New Jersey and Minnesota, were written with thresholds that leave many small businesses outside them.

The map has grown more crowded. By MultiState's count, comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20, including Florida's narrower law. A contractor near a state line, or one that bought a shop in a neighboring market, now has more tests to run than it did a few years ago.

Falling outside a comprehensive law does not mean no rules apply. Call recording consent laws, state breach notification laws and the promises in your own website privacy policy reach companies of every size.

What thresholds trigger the CCPA?#

The CCPA covers a for-profit business doing business in California that meets at least one of three tests. Privacy compliance guides summarize them as follows, and the revenue figure is adjusted over time, so confirm the current number before relying on it.

California is also the outlier on workforce and business contacts. The CCPA's employee and business-to-business exemptions expired on January 1, 2023, so a covered contractor treats technician records and commercial customer contacts as in scope too.

What thresholds trigger the CCPA?
TestWhat it measuresContractor reality check
Annual gross revenueSecondary guides report the threshold was adjusted from $25 million to $26,625,000 effective January 2025Multi-branch groups and private equity platforms can cross it even when no single shop would
Consumer volumeBuying, selling or sharing the personal information of 100,000 or more consumers or householdsTurns on buying, selling or sharing, not on how many customers you simply hold
Data revenueDeriving 50% or more of annual revenue from selling or sharing personal informationRarely met by a service contractor, but confirm it if you resell leads

How do other state laws decide who is covered?#

Most other comprehensive state privacy laws decide coverage by counting how many of the state's residents a business processes personal data about in a year, often with a lower count for businesses that earn revenue from selling personal data. The exact numbers differ by state, and a few states use different tests altogether, so read each law's own applicability section rather than assuming California's.

Many of these laws also leave out business and workforce data. The Virginia Consumer Data Protection Act generally does not apply to people acting in a commercial or employment context, with no sunset, and the Colorado Attorney General says the Colorado Privacy Act does not cover people acting in a commercial or employment context. For a contractor, homeowners count, while property managers and your own technicians may not, depending on the state.

How do other state laws decide who is covered?
Question for each stateWhy it matters for a contractor
How many residents' personal data did we process last year?Most non-California laws turn on this count
Did any of that involve selling personal data?A data-sale prong often lowers the count that triggers coverage
Are our customers mostly homeowners or businesses?Commercial contacts are excluded from many state definitions of consumer
Does an entity-level or data-level exemption fit us?Some laws exempt small businesses or certain regulated data outright

Which of your records count toward the thresholds?#

Resident counts include more than paying customers: any homeowner whose personal data your company processes can count. In a typical shop those records sit across the field service system, the phone system and the marketing stack.

Count per state, by person, and de-duplicate across systems. One homeowner can appear as a lead, a customer, a caller and a review contact; counting every row overstates exposure, while forgetting leads and callers understates it.

  • Customer and location records in ServiceTitan, Housecall Pro, Jobber or FieldEdge, including past customers you no longer serve.
  • Leads from web forms, online booking, lead marketplaces and call tracking numbers, even when no job was booked.
  • Call recordings and caller ID logs from the booking line and the after-hours answering service.
  • Maintenance agreement and membership rosters, renewal notices and review requests.
  • Financing applications passed to a lender partner and warranty registrations sent to manufacturers.
  • Website analytics and advertising pixels that identify devices or visitors.

A decision tree for HVAC and plumbing owners#

The decision tree below runs in order and stops at the first point where a law may apply. From there the next step is a review with counsel, not a self-diagnosis.

  • Step 1: List every state where you serve homes or take calls, including service areas that cross a state line.
  • Step 2: For each state, check whether a comprehensive privacy law is in effect, using a current tracker or a privacy rules checker.
  • Step 3: If you serve California residents, test total company revenue against the CCPA revenue threshold first.
  • Step 4: For every other state, count unique residents across customers, leads, callers and website visitors for the last full year.
  • Step 5: Ask whether you sell or share personal data through lead resale, partner referrals, advertising pixels or, later, a data license.
  • Step 6: Check whether your company or the data falls under an exemption, such as commercial-context or employment-context data.
  • Step 7: Record the answer, the counts and the date, and repeat the check each year and after every acquisition.

Illustrative: an HVAC company with one shop across a state line#

Illustrative: a fictional HVAC and electrical company runs one shop in a metro area that straddles two states. Its ServiceTitan account holds customer and location records for both states, its call tracking platform logs every inbound number, and a marketing agency runs paid search with website pixels.

The office manager counts unique residents per state from ServiceTitan, the call tracking export and form leads, de-duplicating by phone number and service address. One state has no comprehensive law. In the other, the combined count of customers, leads and callers sits closer to the threshold than the owner expected, and counsel flags the agency's pixels for review under the sale and sharing definitions.

The owner decides to operate as if the law may apply: the privacy policy is rewritten, a deletion request process is set up in the CRM, and pixel settings are reviewed with the agency. When the company later weighs licensing its job histories, that groundwork shortens the rights review.

Why licensing data can change the answer#

Licensing customer-linked records to an AI developer may count as selling personal information under some state laws, which can bring a company into scope or add duties it did not have before. De-identification is the usual route, but the term has a legal meaning, not just a technical one.

Under California's definition, information is deidentified only if the business takes reasonable measures to ensure it cannot be associated with a consumer or household, publicly commits to keep and use it only in deidentified form and not to reidentify it, and contractually obligates recipients to follow the same rules. Other states use similar but not identical definitions, so the standard is checked state by state.

SourceX handles this inside the Rights and Preparation steps of the SourceX five-step transaction. Which state laws may apply is assessed deal by deal with the supplier's counsel, personal and confidential details are removed before anything is shared, and the SourceX Evidence Packet records the privacy steps taken and who authorized release. The initial fit check collects metadata only.

Frequently asked questions

Do commercial customers count toward state privacy thresholds?

Often not outside California. Several state laws exclude people acting in a commercial or employment context, so a facilities manager who books service for a building may not count as a consumer. California's employee and business-to-business exemptions expired on January 1, 2023, so a business covered by the CCPA treats those contacts as in scope. Confirm each state's definition with counsel.

Are franchise locations assessed separately from the franchisor?

Usually each legal entity is assessed on its own, but definitions of who counts as the business can reach related entities under some laws. Franchise agreements also tend to split data ownership and privacy duties between franchisor and franchisee. A franchisee should read the agreement's data clauses and ask counsel how each state's definitions treat its records.

Do we need a privacy policy if no state privacy law applies?

Many contractors publish one anyway, and whatever it says becomes a promise. Regulators can treat a business that breaks its own privacy statement as acting deceptively, whatever its size. Keep the policy short, accurate and matched to what your systems actually do, including call recording, texting and any sharing with marketing or financing partners.

Do call recording laws depend on company size?

No. Call recording consent rules come from state wiretap and eavesdropping laws, which apply to businesses of every size. Certain states need every participant to agree to a recording while others accept one participant's agreement, so a booking line that serves callers in several states should plan around the stricter rule.

Does de-identified data still count toward resident totals?

Data that meets a state's legal definition of de-identified generally falls outside that law's personal data rules, but the definitions carry process duties such as public commitments and contract terms with recipients. Removing names alone rarely meets the standard, because service addresses, phone numbers and job notes can still point to a household.

Sources

  • Secondary guides report the CCPA's annual gross revenue threshold was adjusted from $25 million to $26,625,000 effective January 2025, alongside the alternative thresholds of buying, selling or sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Source
  • Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20 by MultiState's count, which includes Florida's narrower law. Source
  • The CCPA employee and business-to-business personal information exemptions expired on January 1, 2023. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial or employment context, and it has no sunset on this exemption. Source
  • The Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context and does not apply to data maintained for employment records purposes. Source
  • Cal. Civ. Code 1798.140(m) treats information as deidentified only if the business takes reasonable measures to ensure it cannot be associated with a consumer or household, publicly commits to maintain and use it in deidentified form and not attempt to reidentify it, and contractually obligates any recipients to comply. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify