Software companies
Is B2B contact data personal data under CCPA?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Yes. Since January 1, 2023, when the CCPA's temporary business-to-business exemption expired, B2B contact data about a California resident, such as a name, work email, direct phone number or call recording, is generally personal information. For licensing, treat every named contact in CRM and ticket records as personal information until it is removed.
Key takeaways
- Business contact details about California residents are generally personal information under the CCPA now that the temporary B2B exemption has ended.
- Company-level facts, such as an account's industry or plan, are usually not personal information unless they point to one person.
- Licensing records that still contain personal information may count as a sale under California law, even though the company keeps ownership.
- Removing names alone does not meet the law's standard for deidentified information, which has conditions of its own.
- Other state privacy laws define consumers differently, so each law that may apply is assessed with counsel.
What changed for B2B data under the CCPA?#
The CCPA's treatment of B2B data changed on January 1, 2023, when the temporary exemption for business-to-business communications expired. The exemption was added in October 2019 through AB 25 with an original end date of January 1, 2021, and the California Privacy Rights Act later moved that date to January 1, 2023. The legislature ended its 2022 session without extending it. While it applied, information about contacts at customers, vendors and prospects sat outside most of the law's requirements. With the exemption gone, those contacts are generally treated like any other California consumer.
The temporary exemption for employee and job applicant information expired on the same date. The California Privacy Protection Agency opened preliminary rulemaking in April 2026 on how the CCPA applies to employee, applicant and contractor information, so watch for new rules on that side. For a software company, two record families shift at once: the CRM and support histories that describe customer contacts, and the Slack, email and HR records that describe staff.
Whether the CCPA applies at all depends on the company. It reaches for-profit businesses that do business in California and meet at least one threshold tied to annual revenue, the volume of California consumers' personal information handled, or the share of revenue earned from selling or sharing personal information. Secondary guides report the revenue threshold was adjusted to $26,625,000 effective January 2025, alongside thresholds of 100,000 or more consumers or households and 50% or more of revenue from selling or sharing personal information. The figures are inflation-adjusted, so confirm the current ones with counsel.
Which CRM and ticket fields count as personal information?#
CRM and ticket fields count as personal information when they identify, describe or can reasonably be linked to a particular person. A contact's name, work email and title clearly do. An account's industry or subscription tier usually does not, unless the account is a sole proprietor trading under their own name.
The table below covers the fields a B2B software company most often holds in Salesforce, HubSpot, Zendesk and Intercom. Free-text fields cause most surprises, because names and phone numbers end up in notes, signatures and quoted email chains.
| Field or record | Usually personal information? | Typical treatment before licensing |
|---|---|---|
| Contact name, work email, direct or mobile phone | Yes | Remove or replace with consistent placeholders |
| Job title combined with company name | Often, when it points to one person | Generalize the title or remove the company |
| Call recordings and transcripts | Yes, including the voice itself | Exclude audio; review transcripts line by line |
| Email signatures, meeting notes, ticket comments naming people | Yes | Detect and redact names and contact details in free text |
| User IDs, IP addresses and device identifiers in tickets | Yes, when linkable to a person | Remove or replace with tokens |
| Account industry, plan, region and usage totals | Usually not | Keep, unless a small account makes a person identifiable |
| Opportunity stage, amount and close date | Not on its own, but linked to named contacts | Keep once contacts and customer names are removed |
Does licensing CRM records count as a sale under the CCPA?#
Licensing CRM records that still contain personal information may count as a sale under the CCPA, because the law defines selling broadly as making personal information available to another business for money or other valuable consideration. A license keeps ownership with the company, but the legal question turns on disclosure for value, not transfer of title.
If a license is a sale, the company generally faces notice, privacy policy and opt-out obligations, and an AI developer using records for its own models is usually a third party rather than a service provider. Opt-out requests the company has already received would also need to be honored. That is why most licensing programs remove personal information before delivery instead of managing opt-outs across years of contacts.
Why removing names is not the same as deidentification#
Removing names is not the same as deidentification under the CCPA, because the legal standard asks whether information can reasonably be linked back to a person, and it attaches conditions to how the company and its recipients handle the data. As commentators summarize Cal. Civ. Code 1798.140(m), the business must take reasonable measures so the information cannot be associated with a consumer or household, publicly commit to keep it deidentified and not attempt to reidentify it, and contractually bind recipients to the same terms. Counsel should check those conditions before any dataset is described as deidentified.
B2B records re-identify easily. A ticket saying the only controller at a family-owned freight broker could not close the month points to one person even with the name gone. Free-text fields, email threads and call transcripts carry most of this risk; structured fields are easier to clean.
- Remove direct identifiers: names, emails, phone numbers, user IDs and IP addresses.
- Generalize indirect identifiers: rare job titles, small company names and specific locations.
- Scan free text, signatures, attachments and quoted email chains, not only contact fields.
- Sample the output by hand and record what was found and fixed.
- Bind the recipient by contract not to attempt re-identification or onward disclosure.
How do other state privacy laws treat B2B contacts?#
Other state privacy laws treat B2B contacts differently from California. Several comprehensive state laws define a consumer in a way that excludes people acting in a commercial or employment context, so the same business contact may fall outside one law and inside another. Virginia's Consumer Data Protection Act, for example, generally does not apply to a person acting in a commercial or employment context, and that exclusion has no sunset. Newer state laws vary, so check each statute's definition of consumer.
CRM systems rarely record where a contact lives, and a work address says little about residence. The practical approach is to prepare records to the strictest standard that may apply and to review state differences with counsel for each deal, rather than filtering contacts by company address.
| Question for counsel | Why it matters |
|---|---|
| Is our company subject to the CCPA, and which other state laws may apply? | Thresholds and definitions decide which obligations exist. |
| Did we collect these contacts for ourselves or as a service provider for customers? | Data processed on customers' behalf usually cannot be repurposed. |
| What do our privacy policy and notices say about disclosure? | Undisclosed uses create notice problems even after cleanup. |
| Will any personal information remain after preparation? | Remaining personal information can turn a license into a sale. |
| What contract terms will bind the recipient? | Limits on re-identification and onward transfer support a deidentification position. |
Illustrative: a CRM history review at a vertical SaaS company#
Illustrative: a fictional company selling scheduling software to commercial cleaning contractors wants to license its Salesforce opportunity history and Zendesk tickets. Its general counsel had assumed business contacts were exempt, based on advice the company received years earlier.
The review finds named contacts on every opportunity, call notes summarizing conversations with operations managers, and ticket threads full of email signatures. Counsel concludes that licensing the raw records would raise sale and notice questions. The company keeps deal stages, product issues and resolution steps, removes contacts, signatures and customer names, and has its privacy policy reviewed before any delivery.
How SourceX handles business contact data#
SourceX treats business contact details as personal information during the Preparation step of the SourceX five-step transaction and removes them from CRM, email and ticket records before anything reaches a buyer. The supplier approves the preparation rules and reviews samples of the output.
The SourceX Evidence Packet for each package includes the privacy record: which fields were removed or generalized, how free text was reviewed and which laws counsel considered. Nothing is shared during the initial fit check, which collects metadata only.
Frequently asked questions
Does the CCPA apply if our contacts work for large enterprises?
Potentially, yes. The law protects individuals, not companies, so a contact at a large enterprise is still a person whose information may be covered if they are a California resident. The size of their employer does not change that, although company-level facts about the enterprise itself usually are not personal information.
Are shared mailboxes such as a support or billing address personal information?
Usually not on their own, because a role address does not identify a particular person. The messages sent from them often do, through signatures, names in the body and replies from individuals. Treat the address as low risk and the message content as needing the same review as any other email.
Do we need to update our privacy policy before licensing?
If any personal information will be disclosed, the privacy policy and notices likely need to describe it, and counsel should review them first. If records are fully prepared so that no personal information remains, the analysis may differ. Many companies review the policy either way so contacts are not surprised.
What about contacts who are not California residents?
The CCPA covers California residents, but other state laws, and laws outside the US, may cover everyone else. Since CRM records rarely show residence, most companies cannot reliably filter by state. Preparing every contact record to the same standard is usually simpler and safer than sorting contacts by assumed location.
Are B2B records in retired systems treated differently?
No. Personal information in a retired CRM or helpdesk archive is still personal information, and the age of a record does not remove obligations. Archives can carry more risk, because contacts may have changed employers and earlier notices may not have mentioned any licensing use.
Sources
- The California legislature ended its 2022 session without extending the CCPA employee and B2B exemptions, so they expired on January 1, 2023. Source
- The employee and B2B exemptions were adopted in October 2019 via AB 25 with an original January 1, 2021 expiration, and the CPRA set the sunset at January 1, 2023. Source
- The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to employee, applicant and contractor personal information. Source
- Secondary guides report the CCPA revenue threshold was adjusted to $26,625,000 effective January 2025, alongside the 100,000 consumers or households and 50% of revenue thresholds. Source
- Cal. Civ. Code 1798.140(m) treats information as deidentified only with reasonable measures against association, a public commitment not to reidentify, and contractual obligations on recipients. Source
- The Virginia Consumer Data Protection Act generally does not apply to a person acting in a commercial or employment context, with no sunset on this exemption. Source
Related resources
- IndustryBPO & contact centers data
- DataCall recordings
- QuestionCan CRM data be licensed?
- InsightHow do I de-identify sales call recordings for AI training?
- InsightPurpose limitation: can records collected for one purpose be licensed for AI?
- InsightShared inboxes like support@ and sales@: often your most licensable email
See if your company qualifies
A short company assessment. No data uploads are needed.