Sales organizations operating in the United States have long relied on external data providers to supply email addresses, phone numbers, and job titles. For years, the commercial market operated under the assumption that business-to-business (B2B) contact details sat in a protected category, separate from general consumer privacy obligations. Recent regulatory actions in California have altered that equation.
Regulatory enforcement by the California Privacy Protection Agency (CalPrivacy) under both the California Consumer Privacy Act (CCPA) and the California Delete Act demonstrates that commercial prospecting lists fall squarely within data broker scrutiny. For revenue leaders and growth teams, this shift transforms vendor selection from a simple cost-per-lead calculation into an operational compliance audit.
Why B2B Contact Databases Fall Under Data Broker Regulations
The widespread belief that business data is categorically exempt from state privacy rules dissolved when California's statutory business exemption expired. Under California Civil Code Section 1798.145, the former exemption covering communications between businesses became inoperative on January 1, 2023.
Without this carve-out, the standard statutory definitions govern commercial records. California Civil Code Section 1798.140 defines a consumer as any natural person who is a California resident, without excluding people operating in their professional or corporate capacities.
Furthermore, California Civil Code Section 1798.99.80 defines a data broker as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. When an external contact database scrapes, verifies, and packages business profiles containing individual mobile numbers, corporate emails, and employment histories, it meets the standard definition of a data broker unless a specific statutory exemption applies.
When outbound teams build campaign workflows or define market segments, as outlined in our guide on how to use the NAICS classification to structure your ideal customer profile in the US, knowing how your list vendor sources and maintains those profiles is essential to avoid contaminated records.
Recent Enforcement Precedents: Unlawful Verification and Registration Deficits
Enforcement orders from CalPrivacy demonstrate that state regulators are actively penalizing data brokers servicing commercial workflows. Two primary enforcement themes have emerged: failure to register on the state's public registry, and imposing unlawful hurdles when individuals attempt to opt out.
On August 11, 2026, CalPrivacy announced its first joint enforcement action under both the CCPA and the Delete Act, fining Iowa data broker LocateSmarter LLC $116,490 for registration failures and improper opt-out procedures. According to the enforcement notice, the company unlawfully required California residents to submit the last four digits of their Social Security numbers before honoring their requests to opt out of data sales. Regulators ruled that conditioning an opt-out on collecting sensitive identifying details violated data minimization principles and acted as a barrier to consumer rights.
Shortly after, on September 1, 2026, CalPrivacy announced a $36,400 fine against Virginia-based data broker SalesIntel Research, Inc. for failing to register timely with the Agency Data Broker Registry by the 2025 deadline. The agency's announcement highlighted that SalesIntel Research sells personal information and offers more than 200 million professional contacts, 54 million mobile phone numbers, and inferences regarding career shifts.
According to the official final stipulated order, the proceeding addressed the company's conduct in 2024 and its missed registration in 2025, while noting that the firm registered on time in 2026 for its 2025 activity. The enforcement action did not penalize the commercial distribution of B2B data itself, but rather enforced the mandatory administrative transparency requirements and compliance with state registries.
The DROP Mandate and Ongoing Deletion Obligations
The regulatory framework took another significant operational turn in mid-2026 with the activation of the California Delete Request and Opt-out Platform (DROP).
Under California Civil Code Section 1798.99.86, beginning August 1, 2026, registered data brokers must access this centralized deletion mechanism at least once every 45 days. The statute requires brokers to process all deletion requests received through the system within 45 days and delete all personal information tied to the requesting individuals. If a data broker cannot verify a request, the law mandates that it treat the submission as an opt-out of selling or sharing that person's personal information. Once deleted, the broker is prohibited from selling or sharing newly collected personal information about that individual unless specific legal statutory exceptions apply.
For commercial teams buying data, this creates a rolling retention issue. A static list purchased six months ago may include individuals who have since submitted deletion requests through the central state platform. If your provider synchronizes with DROP on a 45-day cycle, the vendor's central repository will remove those contacts, but static exports stored locally inside your customer relationship management (CRM) platform will remain unscrubbed.
Maintaining strict system hygiene becomes necessary. For operational approaches to maintaining clean pipeline databases, see our analysis on keeping your CRM clean when prospecting at scale.
Downstream Risk: The 2027 Third-Party Deletion Mandate
The boundary between a vendor's compliance obligations and your internal CRM responsibilities is shifting further under newly signed California legislation.
On September 27, 2026, California enacted Senate Bill 923, which takes effect on January 1, 2027, to expand consumer deletion rights to third-party data. Under the CCPA's original statutory text, covered businesses were generally required to delete personal information collected directly from the consumer, but maintained an exception for data sourced from external third parties.
Starting January 1, 2027, covered businesses subject to the CCPA must process verifiable consumer deletion requests covering personal information regardless of whether the business gathered it directly or purchased it from an external data broker. The legislation explicitly allows businesses to maintain an internal suppression list so that deleted consumer profiles are not inadvertently reacquired or re-added during subsequent third-party database imports.
Signals to Check When Auditing B2B Data Providers
To mitigate operational, deliverability, and legal friction, procurement teams should evaluate external database vendors against explicit regulatory baselines:
- Active Registration on the California Data Broker Registry. Ask prospective contact vendors to supply their registry documentation. Regulators have demonstrated that failing to meet mandatory registration deadlines leads directly to state enforcement orders.
- Documented DROP Synchronization Procedures. Inquire how often the vendor accesses California's central platform. A vendor operating within California statutory requirements must access the platform at least once every 45 days and reflect those deletions across its platform.
- Opt-Out Request Verification Workflows. Review the provider's publicly available privacy policy and request forms. Demanding excessive sensitive data, such as government identification or partial Social Security numbers to honor an opt-out, has already been cited by CalPrivacy as a direct violation of data minimization standards.
- Suppression List Management for Downstream Buyers. When purchasing lists or running automated CRM enrichment, verify whether the vendor provides updated suppression files. Because downstream companies will need to delete third-party enrichment data upon request under SB 923, your enrichment tooling must support permanent suppression matching.
Aligning Outbound Targeting with Compliance Architecture
High-velocity sales teams are reevaluating the practice of buying bulk, unverified contact spreadsheets. Purchasing broad lead databases not only risks data contamination under the Delete Act, but it also harms outbound deliverability when commercial domains are spammed with stale or unconsented records. Additional strategies for architecting outbound sales workflows can be explored across the Knowledge guides for sales.
Modern outbound execution focuses on targeting verified buyers who exhibit real business timing rather than mass harvesting static records. Modern enrichment workflows, such as Ember Lead Intelligence, emphasize account research, intent discovery, and verified direct contact lookup on demand without bulk indiscriminate scraping or automated messaging.
By grounding your sales pipeline in real-time context and strict data vetting, you protect brand reputation while ensuring that prospecting strategies remain effective in an evolving regulatory climate.
Sources
- Californie : CalPrivacy sanctionne SalesIntel, fournisseur de plus de 200 millions de contacts professionnels, à 36 400 dollars (1er septembre 2026) : source S1
- SalesIntel : source S2
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S1
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S2
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S3
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S4
- Californie : SB 923 signée le 27 septembre 2026, le droit de suppression couvre aussi les données obtenues auprès de tiers dès le 1er janvier 2027 : source S1
- Californie, SB 923 : source S2
- Californie : LocateSmarter à 116 490 dollars, première décision CalPrivacy à la fois sous la CCPA et le Delete Act (11 août 2026) : source S1
- LocateSmarter : source S2
FAQ
Free diagnostic
Test your sales file
Drop an Excel or CSV and check its readiness without sending its rows to Ember.
