US State Law United States

B2B and Employee Data Under State Privacy Laws

How US state privacy laws treat B2B contact and employee data: California's full coverage, the consumer-context exemptions elsewhere, and what B2B companies still owe.

Regulation

Scope and exemption provisions of comprehensive state privacy laws (2023-2026)

Max Penalty

$2,500-$20,000 per violation; California employee/B2B claims are fully enforceable since January 1, 2023

Enforcing Authority

State attorneys general; California CPPA

Official Source

cppa.ca.gov

Executive Summary

  • California is the split: since January 1, 2023, the CCPA fully covers employee, applicant, contractor, and B2B contact data, rights requests, notices, and all, while every other comprehensive state law defines 'consumer' to exclude people acting in employment or commercial contexts.
  • The non-California exemption is contextual, not categorical: the same person's data is exempt when processed as a business contact and covered when processed as an individual, remarketing a webinar registrant's email to their personal social feeds moves the context.
  • Exemption from the comprehensive laws is not exemption from law: BIPA (employee biometrics is its largest docket), state wiretap and employee-monitoring statutes, breach-notification laws, and the security statutes (SHIELD) all reach workforce and B2B data.
  • GDPR never had a B2B or employee exemption, so multinationals already run rights-capable HR and CRM systems; extending them to California is configuration, not construction.
  • The strategic question for B2B companies is applicability itself: thresholds count consumers, and a pure-B2B processor may fall under the counts everywhere except Texas (no threshold) and California ($25M revenue alone qualifies).

The B2B and employee exemptions are the most misread provisions in state privacy law. Read quickly, they say B2B companies and HR departments are off the hook. Read correctly, they say: except in California (fully covered), except when business data is used in consumer ways, except for the dozen other statutes that govern workforce data, and except for your consumer-facing website, which every law reaches. The exemption is real, but it is a scoping rule, not an exit.

Where the lines actually fall

DataCaliforniaOther comprehensive statesAlso governed by
Employee/HR dataFully covered (rights, notices)Exempt (employment context)BIPA, monitoring laws, SHIELD, breach statutes
Applicant dataCoveredExemptFCRA + state background-check rules
B2B contacts (CRM)CoveredExempt while commercial-contextWiretap laws for recorded calls
B2B contacts in ad-targetingCoveredCoverage arguable, purpose has left the exemptionPlatform policies
Website visitorsCoveredCoveredAll tracking rules

Program implications

Build the California lane properly. HR access/deletion workflows with legal-hold and third-party-privacy exceptions, B2B contact rights handling in the unified DSAR intake, and notices at collection for employees and applicants, the CCPA compliance guide covers the machinery.

Police the context boundary. CRM enrichment, intent data, and audience-matching from B2B lists can constitute sale or sharing in California and erode the exemption elsewhere; tag B2B records so ad-flow entry is a deliberate, reviewed event.

Cover the exempt data’s other laws. BIPA’s employee docket, SHIELD’s safeguards, and breach readiness for HR systems, mapped in the same multi-state register as the consumer obligations.

Remember the website. Your marketing site’s visitors are consumers in all twenty states, GPC, opt-outs, and notice accuracy apply to B2B companies exactly as to retailers (comparison here). Check yours with a free scan.

Frequently Asked Questions

What exactly did California's expiration of the exemptions change?

The CCPA's temporary carve-outs for HR and B2B data expired January 1, 2023, making California the only state where employees, applicants, contractors, and business contacts hold the full rights set against covered businesses: access (including personnel-file-adjacent data), deletion (subject to exceptions like legal holds), correction, opt-outs, and non-retaliation. Operationally the hard parts are HR access requests (performance data, investigation records, with third-party privacy balancing) and sales-stack sharing (CRM enrichment and intent-data vendors can constitute selling B2B contacts).

How does the consumer-context exemption work in the other states?

Their 'consumer' definitions cover individuals acting in a personal or household context and exclude those acting in a commercial or employment context. A procurement manager's work email in your CRM: exempt. The same manager retargeted on their personal Instagram from a list built on that email: the processing has left the commercial context, and several AGs read the exemption functionally. The safe line is purpose-based: B2B relationship management stays exempt; consumer-style profiling and ad-targeting of the same records does not.

Does a pure-B2B company escape the state laws entirely?

Rarely. Texas has no consumer-count threshold, so a non-small-business B2B company processing any Texans' personal data in consumer contexts (a newsletter, an event, website analytics on individuals) is covered. California's $25M revenue prong plus its B2B coverage reaches most mid-size B2B firms. And website visitors are consumers everywhere: the analytics, advertising, and consent obligations attach to your marketing site regardless of what you sell. The exemption shrinks the data in scope, not the company.

What laws govern the exempt employee data?

A thick layer: BIPA for biometrics (timeclocks are its largest class-action category), state employee-monitoring notice laws (Connecticut, Delaware, New York), wiretap and call-recording statutes for monitored communications, the SHIELD Act and its analogues for safeguards, all states' breach-notification laws (employee SSNs are classic breach data), background-check rules (FCRA and state analogues), and sector rules (HIPAA for health plans). 'Exempt from the CCPA-style law' describes one statute's scope, not a compliance holiday.

What should a B2B/employer program actually implement?

Five moves: (1) a California-grade rights process for HR and B2B data, mandatory in California, cheap insurance elsewhere, and GDPR-required for EU workforces anyway; (2) purpose discipline in the CRM, flag when B2B records enter consumer-style ad flows; (3) the biometric program from the BIPA playbook for any workforce biometrics; (4) monitoring notices where required; (5) security and breach readiness treating HR data as the high-value target it is. The applicability analysis gets documented per state and refreshed when the business model shifts.

Regulatory Crosswalk

GDPR (no B2B exemption)CCPA/CPRABIPA (employee claims)

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.