CCPA B2B Cold Outreach Compliance: 20 State Laws, One That Bites
CCPA B2B cold outreach compliance in 2026: 20 states have privacy laws, one covers business contacts. Here is what is legal and where the fines are landing.
You have probably seen the headline. Nineteen states regulate your cold outreach. Twenty, depending on who is counting and which month they published.
The count is right. The conclusion almost everyone draws from it is wrong, and it is sending sales teams into the wrong compliance work.
Here is the number that matters for CCPA B2B cold outreach compliance. Of the 20 states with comprehensive consumer privacy laws in effect in 2026, exactly one covers B2B contact data. Every other state follows the Virginia model and carves business-contact and employee records out of scope. So this is not a 20-state problem. It is a California problem, plus a federal law that has applied since 2003, plus a data broker registration regime in four states that most sales teams have never read.
That is four regimes, not twenty. More importantly, the enforcement in 2026 is not landing where the headlines suggest. Regulators are not fining companies for sending cold email. They are fining the companies that sold them the list.
This article maps what actually applies, names the enforcement actions by company, and gives you a checklist you can work through before your next security review.
Is Cold Email Still Legal? Yes. Start There.
Cold email to a US business contact is legal. No consent required, no opt-in, no prior relationship. That has not changed and nothing in the 2026 state laws changes it.
What governs it federally is CAN-SPAM, and CAN-SPAM is a conduct rule, not a permission rule. It tells you how to send, not whether you may. The requirements are short enough to hold in your head:
- Accurate "From," "Reply-To" and routing information
- A subject line that reflects the content of the message
- A valid physical postal address
- A clear opt-out mechanism, honoured within 10 business days
- No selling or transferring an address after someone opts out
The penalty is the part worth remembering. The FTC's maximum civil penalty is $53,088 per non-compliant email, set by the January 2025 inflation adjustment and still current through 2026 after the scheduled 2026 adjustment was cancelled. Per email. A 5,000-address send with a broken unsubscribe link is not a $53,088 problem, it is a theoretical $265 million one.
Nobody gets charged the maximum. That is not the point. The point is that the federal law almost nobody worries about carries the largest per-unit exposure of anything in this article, and it applies in all 50 states, which no state privacy law does.
If your outbound is CAN-SPAM clean, you have cleared the bar that covers the whole country. Everything after this is jurisdiction by jurisdiction.
Working through outbound compliance and deliverability at the same time? See how signal-based prospecting changes both →
Why California Is the Only State That Changes B2B Cold Outreach
The CCPA had a B2B exemption. Under AB 1355, business-to-business contact data sat outside the statute while the legislature decided what to do with it.
That exemption expired on January 1, 2023. It was not renewed. Since that date, a California resident's work email, direct dial and job title are personal information under the CCPA, in the same category as a home address. A record does not become exempt because the context is professional.
Two details catch teams out.
Sole proprietors count as consumers. The one-person consultancy in your list is not a business contact with a thin B2B shield. They are a consumer with full rights, and in most CRMs their record is indistinguishable from an enterprise VP's.
The rights are individual, not commercial. A California prospect can ask you what data you hold on them, ask you to delete it, ask you to correct it, and opt out of its sale or sharing. You have to be able to answer. For a purchased list, "I do not know" is the honest answer and it is also the problem.
Here is the map, because the state count on its own tells you nothing useful:
| Regime | Reaches B2B contact data? | Where it applies |
|---|---|---|
| CAN-SPAM | Yes | All 50 states |
| CCPA / CPRA (California) | Yes, since Jan 1 2023 | California residents |
| The other 19 state privacy laws | No, business-contact data exempt | n/a for outbound |
| Data broker registration (CA, TX, OR, VT) | Yes, if you share or sell data | Four states |
| GDPR | Yes | EU and UK contacts |
Maryland is the interesting near-miss. MODPA took effect with enforcement beginning April 1, 2026 after a six-month grace period, and it is the strictest state law on the books: mandatory data minimization regardless of consent, and a flat ban on selling sensitive data with no consent exception. It also exempts B2B data. A genuinely tough law that does not touch your prospect list. The MultiState privacy law tracker keeps the full state-by-state list current.
For the European side of the picture, the obligations are different in kind rather than degree, and the EU AI Act rules on AI-generated sales email are the ones to read next.
The Enforcement Is Hitting Your Vendors, Not You
This is the part missing from every compliance post written for sales teams, and it is the part that should change what you do this week.
Since November 2024, the California Privacy Protection Agency has been settling enforcement actions steadily. Read the names:
| Company | What they do | Fine |
|---|---|---|
| Growbots | Outbound sales platform | $35,400 |
| UpLead | B2B contact data provider | $34,400 |
| Accurate Append | Contact data append | ~$35,000 |
| Key Marketing Advantage | Marketing data | ~$35,000 |
| ROR Partners | Marketing data | ~$56,000 |
| LocateSmarter | People search data | $116,490 |
| Cybba | Marketing data | $52,400 |
CPPA enforcement announcements, November 2024 through August 2026.
Those are not obscure adtech firms. Growbots is an outbound sales platform of the kind that sits in thousands of sales stacks. UpLead is a contact database your team may have a seat on right now.
The violation in most cases was not misuse of data. It was failure to register as a data broker under California's Delete Act and pay the annual fee. Growbots was unregistered for 177 days between February and July 2024, at $200 per day. UpLead, 172 days. The arithmetic is that simple.
The two most recent actions escalated. On August 11, 2026 the agency fined LocateSmarter $116,490 for failing to register and for a separate CCPA violation: requiring consumers to hand over a Social Security number to exercise an opt-out right. Days later, Cybba was fined $52,400. The agency has also stood up a dedicated data broker strike force, which is what a regulator does when it intends to keep going.
So what does a vendor's fine have to do with you?
Your vendor's compliance does not transfer to you. This is the single most common misconception in B2B list buying. Teams purchase a list, assume the vendor cleared the legal path, and never check. When a California prospect files a deletion request against your CRM, the vendor's registration status is irrelevant. You are the business holding the record, and you are the one who has to answer.
The practical version: for every data source in your stack, you should be able to name where the records came from, what the contract says about your rights to use them, and whether the vendor is registered where registration applies. If you cannot answer that for a source, that source is your exposure.
Your Purchased List Now Has an Expiry Date
California's Delete Act built something new in 2026, and its consequences for outbound have gone almost entirely unnoticed by sales teams.
DROP, the Delete Request and Opt-Out Platform, opened to consumers on January 1, 2026. A California resident makes one request on one state-run platform, and every registered data broker has to honour it. From August 1, 2026, the 600-plus registered brokers must check DROP at least every 45 days and process the requests they find, or face $200 per request per day.
Follow that through to your funnel.
Every 45 days, the databases your team buys from are obligated to remove a slice of their California records. Not correct them. Remove them. Those deletions propagate into the exports you have already paid for, and into the enrichment that refreshes your CRM.
Your purchased list has always decayed for the ordinary reasons: people change jobs, companies fold, domains move. The average B2B database degrades somewhere around 25-30% a year on its own, which is the problem behind CRM data decay. DROP adds a second decay curve on top, one that is legal rather than natural, runs on a 45-day clock, and accelerates as consumer awareness of the platform grows.
Two consequences worth acting on.
Deletion has to propagate, not just register. If a prospect deletes upstream and their record still sits in your CRM, in your sequencing tool, in a CSV in someone's downloads folder, and in the enrichment cache, you have four copies of a record that is supposed to be gone. Map where contact data lands in your stack before you need the map.
A stale list is now a compliance artifact, not just a performance one. Sending to records that should have been deleted damages your deliverability and your legal position at the same time. The two failure modes have converged, which is the through-line connecting this to everything in cold email deliverability.
Are You a Data Broker? Check Before Your Next Security Review
Most sales teams read the data broker sections of these laws as someone else's problem. Sometimes it is not.
The statutory test is close to this: you are a data broker if you knowingly collect and sell personal information about consumers with whom you have no direct relationship. Four states require registration.
| State | Requirement | Fee |
|---|---|---|
| California | Register with the CPPA, honour DROP | Annual |
| Texas | Register before operating, disclose broker status on your website, maintain a security program | $300 |
| Oregon | Register before operating, renew by Dec 31, in-state registered agent, 45-day change notification | Annual |
| Vermont | Register annually by Jan 31 | $100 |
Vermont tightens further under H.211, effective January 1, 2027: a legitimate-purpose certification, a surety bond, and stricter breach notification.
This is the corner of CCPA B2B cold outreach compliance most teams skip. Run the test honestly against your own business. You are probably fine if you collect contact data for your own outbound only. You should get legal input if you enrich contact data and pass it to partners, resell or syndicate leads you did not source directly, or offer any product feature that hands your customers contact records you collected. Plenty of GTM companies crossed that line without noticing, which is exactly how Growbots ended up on the list above.
The CCPA B2B Cold Outreach Compliance Checklist
Work through this in order. Most teams can clear the first five in an afternoon.
- Audit CAN-SPAM basics on every sending domain. Physical address, honest headers, working unsubscribe, opt-outs processed within 10 business days. Highest exposure, cheapest fix.
- Document provenance for every data source. For each vendor, database and scraper: where the records came from, what the contract permits, registration status where it applies. A source you cannot document is a source you cannot defend.
- Read the data processing terms in your vendor contracts. Specifically the indemnity and the deletion-propagation clauses. Most standard terms put the obligation on you.
- Build one suppression list that every tool respects. Opt-outs and deletion requests belong in one place that your sequencer, CRM and enrichment layer all read. Fragmented suppression is how a deleted contact gets emailed again.
- Write down where contact data lives. CRM, sequencer, enrichment cache, exports, spreadsheets, warehouse. You cannot honour a deletion request across a map you do not have.
- Set a deletion-propagation SLA. A California deletion request has to reach every system on that map. Pick a number, 30 days is defensible, and instrument it.
- Publish a notice at collection. If you collect contact data from public sources, say so, at the point of collection, with the categories and purposes. Brief, public, linkable.
- Set a retention policy on prospect records. Records held indefinitely with no purpose are the hardest thing to justify under data minimization principles now spreading through state law.
- Re-audit list sources quarterly. Registration status changes, vendors get fined, DROP deletions accumulate. An annual review is already behind the 45-day cycle.
Keep this separate from the mailbox-provider rules, which are policy rather than law and move faster. Those live in the Microsoft bulk sender requirements.
The Structural Fix: Less List, More Signal
Every obligation in CCPA B2B cold outreach compliance scales with one variable: how many records you hold that you cannot account for.
Provenance documentation is trivial for 400 contacts you sourced deliberately and brutal for 400,000 you bought. Deletion propagation is manageable when you know why each record is in your system. Retention policy writes itself when every contact has a reason to be there. The compliance burden is not really a function of what you send. It is a function of how much undefendable data you are sitting on.
Which lands on the same conclusion the performance data has been pointing at for two years.
The Ehrenberg-Bass Institute's research puts roughly 5% of any target market in-market in a given quarter. The other 95% are not going to buy from you this quarter no matter how well you write. Hold that next to response data: campaigns of 50 recipients or fewer average 5.8% response against 2.1% for large lists, and signal-based personalised outreach reports 15-25% reply rates against a 3.43% cold average.
The 400,000-record database is worse on both axes at once. It performs worse, and it is the thing that makes compliance hard.
There is also a meaningful difference in posture between record types. A contact record purchased from a database you cannot audit is a liability you inherited. A contact you identified because they posted publicly about a problem you solve, and who you then contacted as a human with a relevant message, is a defensible position: observed public professional activity, a clear purpose, a documented reason for contact, and no purchased list in the chain at all. That is the basis of signal-based selling, and compliance is a side effect of it rather than a feature.
If you are rebuilding list sourcing anyway, rebuild it around the 5% rather than around volume. The approach to building a prospecting list matters more now than the size of the list it produces.
What to Do With This
CCPA B2B cold outreach compliance is narrower than the headlines and sharper than most teams assume. Four things are true at once:
- Cold email is legal. CAN-SPAM governs how you send, not whether you may, and $53,088 per email is the largest per-unit exposure in this article.
- California is the only state that reaches B2B contact data. The other 19 laws exempt it. Count regimes, not states.
- Enforcement is landing on data vendors, not senders. Growbots, UpLead, LocateSmarter and five others have paid. Their compliance does not transfer to you.
- Purchased lists now expire legally. DROP's 45-day cycle, live since August 1 2026, means deletions you did not make are already working through your data.
Five things to do this quarter: audit CAN-SPAM on every sending domain, document provenance for every data source, consolidate suppression into one list, map where contact data lives so deletion can propagate, and re-audit sources quarterly instead of annually.
Then do the structural one. The smaller and better-sourced your list, the smaller every obligation on this page becomes, and the better it performs. Start finding the 5% instead of emailing the 95% →