Privacy and preparation
State privacy laws taking effect in 2026: what changes for B2B and employee data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
State privacy laws taking effect in 2026, led by comprehensive laws in Indiana, Kentucky and Rhode Island on January 1, change little for business contact and employee records, because each generally excludes people acting in a commercial or employment role. The real change is for consumer records inside B2B systems and for licensing that may count as a sale.
Key takeaways
- Indiana, Kentucky and Rhode Island each have a comprehensive privacy law that took effect on January 1, 2026, bringing the total to 20 states by MultiState's count.
- Outside California, comprehensive state laws generally leave out people acting in a commercial or employment context, such as client buyers and your own staff.
- B2B archives still hold consumer data, such as homeowner warranty registrations, end-user tickets and ship-to addresses.
- Licensing records that contain personal data may count as a sale and bring opt-out, notice and assessment duties with it.
- Data that meets a law's de-identification test is generally outside these laws, which makes careful preparation the main lever.
What changed in state privacy law in 2026?#
State privacy law in 2026 changed mainly by addition: comprehensive laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, which MultiState counts as bringing the total to 20 states (19 if Florida's narrower law is left out). Several states that already had laws also amended them. None of the three new laws breaks sharply from the model most states have followed, so a company already working to Virginia- or Connecticut-style rules will recognize the structure.
The practical question for a general counsel is narrower than the headlines suggest. Which of your records concern residents of these states, in what capacity did those people appear in your systems, and do you plan any use of the records, such as licensing, that a privacy law treats as higher risk?
For a business-to-business company, the answer usually turns on capacity. A buyer at a client account and a technician on your payroll are treated very differently from a homeowner who called for service.
The 2026 watchlist at a glance#
The 2026 watchlist below groups the new laws with the comparison point most B2B companies need, California, and with the amendments that can quietly change an existing compliance position. Effective dates, applicability thresholds and amendment text should be confirmed against the enacted statutes before anyone relies on them.
Treat the last column as a work list. Each item is something counsel can confirm from the statute and your own records in a single review, before a licensing or retention decision depends on it.
| Law | Status in 2026 | Business contacts and employees | What to confirm |
|---|---|---|---|
| Indiana Consumer Data Protection Act | In effect since January 1, 2026 | Generally excluded when acting in a commercial or employment context | Applicability thresholds, sale definition, assessment duties |
| Kentucky Consumer Data Protection Act | In effect since January 1, 2026 | Same general exclusion for commercial and employment roles | Applicability thresholds, consumer definition, assessment duties |
| Rhode Island Data Transparency and Privacy Protection Act | In effect since January 1, 2026 | Generally excluded in commercial or employment roles; confirm the definitions | Applicability thresholds, notice content, sale definition |
| Amendments to earlier state laws | Several states revised existing laws | Usually unchanged, but read each amendment | Changed thresholds, new sensitive data categories, rules for minors |
| California CCPA | Employee and B2B exemptions expired January 1, 2023; employee-data rulemaking opened in 2026 | Covered as consumers when they are California residents | Notices, rights requests, sale and sharing rules for staff and contacts |
Do the new laws reach business contacts and employees?#
The new laws generally do not appear to reach business contacts or employees acting in those roles, because each is generally written to protect residents acting in a personal or household capacity and leaves out people acting for an employer or on behalf of a business. That pattern matches most comprehensive state laws outside California.
California remains the exception that shapes most B2B programs. Its temporary exemptions for employee and business contact data expired on January 1, 2023, so employees, job applicants and business contacts who live in California are treated as consumers. In April 2026 the California Privacy Protection Agency also opened preliminary rulemaking on how the CCPA applies to employee, applicant and contractor data, so expect more detail on that front. A company with California staff or client contacts already runs notice and rights processes that the 2026 laws do not add to.
The exclusion follows capacity, not the person. The same individual can be a business contact in your CRM and a consumer in your product's end-user records, and the record family decides which rules apply.
| Record in a B2B archive | Person's capacity | Likely treatment under the new laws |
|---|---|---|
| Client purchasing manager in Salesforce or HubSpot | Commercial | Generally outside the consumer definition |
| Technician name in ServiceTitan dispatch notes | Employment | Generally outside the consumer definition |
| Job applicant in an applicant tracking system | Employment | Generally outside, but confirm how each law treats applicants |
| Homeowner in a service ticket or estimate | Personal or household | In scope as a consumer |
| Recipient on an order fulfilled for an online retailer | Personal or household | In scope, plus any limits in the client's contract |
| End user inside a client's SaaS account | Varies | Often processed on the client's behalf, which limits your own use |
Where consumer data hides in B2B systems#
Consumer data hides in B2B systems wherever a business customer's own customers, or members of the public, leave a trace. These records are what the 2026 laws actually reach for most B2B companies, and they are easy to miss because nobody inside thinks of the company as consumer-facing.
Flag each of these record families by state of residence where the system allows it. A distributor with no direct consumer sales can still hold a sizable file of homeowner warranty records, and that file, not the CRM, is what decides its exposure.
- Warranty registrations submitted by homeowners for equipment sold through dealers or contractors.
- Support tickets opened by individual end users of a product sold to businesses.
- Ship-to names and addresses on orders fulfilled for e-commerce clients.
- Call recordings and web chat transcripts from a public-facing service line.
- Marketing lists that mix business contacts with personal email addresses.
- Reviews, testimonials and survey responses collected from individuals.
Why licensing can change your position#
Data licensing can change a company's position under these laws because a license fee is monetary consideration, and disclosing personal data to a third party for money is generally a sale under comprehensive state laws. Some states define a sale more broadly to include other valuable consideration, but a paid license meets even the narrower definitions.
A sale brings duties with it. Comprehensive state laws commonly give consumers a right to opt out of sales, require the privacy notice to disclose them and call for a documented data protection assessment before personal data is processed for sale. Several also count revenue from selling personal data toward lower applicability thresholds, so licensing identifiable records can pull a company into a law it never met before.
De-identified data is the other branch. If a package cannot reasonably be tied back to anyone, and the public commitment and recipient contract terms most state laws expect are in place, it generally falls outside these laws. Whether a specific package meets that test, and whether a specific license is a sale, is assessed deal by deal with counsel.
A 2026 checklist for general counsel#
A 2026 review for a B2B company is mostly a mapping exercise followed by a few decisions. The checklist below keeps it short enough to finish before the next licensing, retention or system migration decision depends on it.
- List the states where your consumers, employees and business contacts live, using system data rather than office locations.
- Sort record families by capacity: consumer, business contact, employee or applicant.
- Read the consumer definition, sale definition and thresholds in each new law that may apply.
- Check amendments to laws you already follow, especially changes to thresholds or sensitive data categories.
- Confirm whether your privacy notice describes any planned licensing or other disclosure for value.
- Decide whether planned licenses will carry personal data or only de-identified records, and write down the reasoning.
- Put the next review on the calendar, since states continue to enact and amend these laws.
Illustrative: an equipment distributor rechecks its archive#
Illustrative: a fictional HVAC equipment distributor based in Indiana sells to contractors across Indiana, Kentucky and neighboring states. It runs orders in Epicor and accounts in Salesforce, and it is weighing a license of order exception and returns records.
Counsel's first view is that the new laws barely touch the plan, because the records center on contractor buyers acting for their businesses and on the distributor's own staff. The mapping step finds one exception: a warranty registration portal where homeowners entered names, addresses and equipment serial numbers, linked to returns in Epicor.
The company keeps warranty registrations out of the licensed package, removes contractor contact details as well because the package does not need them, and records the analysis in its license file. A privacy notice review is scheduled before signing.
How SourceX approaches changing state laws#
In the SourceX five-step transaction, state privacy law is reviewed at Rights, before Preparation touches any record. Before any record moves, the fit check asks only descriptive questions, including which states the people in the records live in, so the initial assessment shares no files.
Preparation then removes personal and confidential details, and the SourceX Evidence Packet's privacy record notes which laws counsel considered and why. SourceX does not give legal advice; the supplier's counsel confirms the legal position for each deal.
Frequently asked questions
Should a B2B company apply the strictest state law to everyone?
Many companies choose one baseline, often drawn from California, because a single process is easier to run than state-by-state rules. The trade-off is extending rights and notices to people no law requires you to cover. Decide with counsel which record families get the baseline and which follow each state's own scope.
Do the new laws apply to records collected before they took effect?
They generally govern processing that happens after the effective date, and processing includes using, disclosing or licensing older records. A license signed this year is a disclosure made this year, even when the tickets or orders behind it are years old. Counsel can confirm how a specific law treats legacy data.
Does a de-identified license still need a data protection assessment?
Assessment duties generally attach to processing personal data, so a package that meets a law's de-identification test usually sits outside them. Many companies still write a short memo explaining why the package qualifies as de-identified, because that reasoning is what a regulator, auditor or acquirer would ask to see.
Do these laws change how we use business contacts for sales outreach?
In most states, no: business contacts acting in a commercial context generally fall outside the consumer definition. Other rules still govern outreach, such as email marketing and telemarketing laws, and California treats business contacts who live there as consumers with notice and rights.
How often should we revisit our state law map?
Revisit it on a regular schedule and before any major data decision, such as a license, a system retirement or an acquisition. New laws, amendments and regulations keep arriving, and a map that was accurate when a license was scoped can be out of date by the time it is signed.
Sources
- Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws to 20 by MultiState's count (19 without Florida). Source
- The CCPA employee and business-to-business exemptions were not extended and expired on January 1, 2023. Source
- The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to employee, applicant and independent contractor data. Source
- The Virginia Consumer Data Protection Act generally does not apply to information about a person acting in a commercial or employment context. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.