B2B prospecting in the United States has long operated on the assumption that commercial contact information is exempt from strict consumer privacy rules. In California, that assumption no longer holds. Through the Delete Act and its centralized platform, known as the Accessible Deletion Mechanism or Delete Request and Opt-out Platform (DROP), California has established enforcement rules that reach directly into data brokers selling business contact databases.
For founders, revenue leaders, and commercial operators buying or enriching prospecting lists, regulatory risk does not stop at pure consumer marketing databases. Understanding how DROP functions, who qualifies as a data broker, and how regulatory scrutiny is shifting will determine how safely your acquisition pipeline operates in the United States.
The End of the B2B Exemption Under California Law
For several years, the California Consumer Privacy Act (CCPA) contained a temporary exemption covering business-to-business communications. Under California Civil Code Section 1798.145, obligations surrounding personal data did not apply to communications or transactions where a natural person acted solely as an employee, owner, director, officer, or contractor of a company or government agency. However, as explicitly enacted in Civil Code Section 1798.145, this subdivision became inoperative on January 1, 2023.
Since that expiration, professional identities receive baseline protections under California privacy law. The statutory framework does not carve out professional contacts from the core definition of an individual:
- Under Civil Code Section 1798.140, a consumer is defined as a natural person who is a California resident. The definition carries no automatic carve-out for a person acting in a professional or workplace capacity.
- Under Civil Code Section 1798.99.80, a data broker is defined as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.
When an external vendor gathers business emails, corporate mobile numbers, or career records of California residents and resells them without having an existing commercial relationship with those professionals, that vendor fits the statutory definition of a data broker.
How DROP Operates: The 45-Day Deletion Cycle
The Delete Act amended the California data broker registry system to centralize consumer rights under DROP, managed by the California Privacy Protection Agency (CalPrivacy).
Instead of requiring an individual to track down dozens or hundreds of independent data aggregators, DROP allows a California resident to submit a single deletion request. That single submission applies across registered data brokers statewide.
The operational cadence for data brokers is codified under Civil Code Section 1798.99.86:
- Mandatory Access: Beginning August 1, 2026, a registered data broker must access the accessible deletion mechanism at least once every 45 days.
- Mandatory Execution: Within 45 days after receiving a deletion request through DROP, the data broker must process the deletion and remove all personal information related to the requesting individual.
- Opt-Out Handling: If a data broker cannot verify a request made through the platform, it is required to treat that request as an opt-out of the sale or sharing of the individual's personal information.
- Ongoing Restriction: Once personal information is deleted, the data broker cannot sell or share new personal information belonging to that individual, unless the individual requests otherwise or the processing is permitted under statutory exemptions.
This creates a rolling 45-day wipe cycle. Registered vendors who feed outbound prospecting tools must repeatedly strip California residents from their commercial catalogs.
Enforcement Trends: Recent CalPrivacy Actions Against Data Vendors
Enforcement by CalPrivacy demonstrates that regulatory oversight is not theoretical, nor is it confined to consumer retail lists. Two enforcement decisions highlight how the agency enforces data broker compliance and rights requests.
On August 11, 2026, CalPrivacy announced its first joint enforcement action under both the CCPA and the Delete Act, fining an Iowa data broker named LocateSmarter LLC $116,490, as reported in the official CalPrivacy enforcement announcement. According to the stipulated order against LocateSmarter, the company failed to register timely as a data broker and unlawfully required Californians to provide partial Social Security numbers before honoring their opt-out requests. The agency affirmed that businesses cannot condition an opt-out on collecting sensitive, unneeded personal information or requiring burdensome identity verification.
Shortly after, on September 1, 2026, CalPrivacy issued a decision requiring Virginia-based vendor SalesIntel Research, Inc. to pay a $36,400 fine, as published in the CalPrivacy SalesIntel announcement. The SalesIntel final stipulated order clarified that the case specifically concerned the company's conduct in 2024 and its failure to register by the 2025 deadline. The agency described SalesIntel Research as an entity that sells consumers' personal information and offers more than 200 million professional contacts, 54 million mobile phone numbers, and career change signals to facilitate targeted advertising.
The penalty against SalesIntel did not stem from selling B2B data itself, but from failing to register timely as a data broker under California law. Along with the $36,400 fine, the decision ordered the vendor to post privacy metrics on its website, access the DROP registry, and process deletion requests through the platform.
For commercial teams buying B2B databases, this distinction is critical: regulators view large-scale professional profile repositories as data brokers subject to registration, mandatory DROP access, and deletion rules.
What DROP Means for Sales and Revenue Teams
When external data brokers purge profiles under DROP, the ripple effect reaches downstream outbound pipelines.
While static data suppliers may work well enough for high-volume territory mapping in states without aggressive data broker regulations, relying on static, unverified lists creates distinct risks when targeting California prospects:
Fast Data Decay and Downstream Inconsistencies
When a prospect triggers a deletion request in DROP, their profile disappears from the registered vendor's catalog. However, if your team previously imported that record into a customer relationship management (CRM) tool or an outbound dialer, that record remains in your local system. While California law does not automatically turn every downstream customer of a data broker into a registered data broker, maintaining unverified contact points increases bounce rates, invalid dials, and the risk of contacting individuals who have formally opted out of business outreach.
Increased Scrutiny on List Vendors
Before licensing a database that covers United States accounts, evaluate your data provider's compliance status. If a vendor resells professional contacts of California residents without direct consumer relationships, ask whether they are registered on the California Data Broker Registry and actively connected to DROP. Working with unregistered brokers exposes your outbound operations to vendors facing enforcement actions, operational disruption, or abrupt list removals.
Shift from Mass Aggregation to Signal-Led Timing
The continuous clearing of contact lists via DROP makes bulk scraping and indiscriminate volume prospecting less reliable over time. When contacts cycle out of databases every 45 days, outbound success depends less on hoarding static contact pools and more on reaching qualified prospects at the right moment with relevant context.
Managing Outbound Compliance and Contact Governance
Adapting to tighter privacy frameworks requires teams to tighten how they handle objections, preferences, and data sources. Whether you are reviewing domestic US regulations or evaluating international standards across the Knowledge guides for sales, commercial data governance rests on three operational controls:
- Strict Respect for Objections and Do-Not-Contact Registries: When a prospect indicates they do not want to be contacted or requests deletion, that status must immediately stop all active actions, follow-ups, and data refreshes across your sales tools.
- Source Transparency: Know where your data originates. Relying on verified professional signals, authorized first-degree connections, public domain records, and contractually governed enrichment provides clearer operational boundaries than buying unverified third-party scrapings.
- Controlled Workflows Over Indiscriminate Automation: Automated pipelines that send mass messages without contextual verification increase complaint rates. Retaining human oversight before an outreach action is launched ensures that data hygiene and individual objections are caught before communication occurs.
Commercial intelligence platforms must align with this reality. Within Ember, lead discovery and contextual qualification are designed to identify who to contact and why the timing is appropriate, rather than accumulating unmaintained bulk databases. According to the Ember prospect data rights policy, when an objection, opt-out, or do-not-contact entry applies to a prospect, active actions, follow-ups, monitoring, digests, and paid enrichments are blocked for that contact. Furthermore, client users configure and manage their own prospecting missions as data controllers, retaining prospect data for the mission's duration up to three years after the last contact, while objection records are preserved to guarantee that an individual's refusal remains respected.
As California continues enforcing the Delete Act through DROP, the sales teams that succeed will be those that transition from rented, decaying contact databases to qualified, verified, and signal-driven outbound workflows. Explore how Ember Lead Intelligence structures outbound acquisition around actionable business timing and controlled execution.
Sources
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S1
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S2
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S3
- Californie : depuis le 1er août 2026, les courtiers en données doivent traiter les demandes DROP tous les 45 jours : source S4
- Californie : CalPrivacy sanctionne SalesIntel, fournisseur de plus de 200 millions de contacts professionnels, à 36 400 dollars (1er septembre 2026) : source S1
- SalesIntel : source S2
- Californie : LocateSmarter à 116 490 dollars, première décision CalPrivacy à la fois sous la CCPA et le Delete Act (11 août 2026) : source S1
- LocateSmarter : source S2
- Connecticut : depuis le 1er juillet 2026 la loi s'applique dès 35 000 consommateurs, et son texte exclut le contact agissant dans son rôle professionnel : source S1
- Connecticut : depuis le 1er juillet 2026 la loi s'applique dès 35 000 consommateurs, et son texte exclut le contact agissant dans son rôle professionnel : source S2
FAQ
Free diagnostic
Test your sales file
Drop an Excel or CSV and check its readiness without sending its rows to Ember.
