The B2B and employee exemptions are the most misread provisions in state privacy law. Read quickly, they say B2B companies and HR departments are off the hook. Read correctly, they say: except in California (fully covered), except when business data is used in consumer ways, except for the dozen other statutes that govern workforce data, and except for your consumer-facing website, which every law reaches. The exemption is real, but it is a scoping rule, not an exit.
Where the lines actually fall
| Data | California | Other comprehensive states | Also governed by |
|---|---|---|---|
| Employee/HR data | Fully covered (rights, notices) | Exempt (employment context) | BIPA, monitoring laws, SHIELD, breach statutes |
| Applicant data | Covered | Exempt | FCRA + state background-check rules |
| B2B contacts (CRM) | Covered | Exempt while commercial-context | Wiretap laws for recorded calls |
| B2B contacts in ad-targeting | Covered | Coverage arguable, purpose has left the exemption | Platform policies |
| Website visitors | Covered | Covered | All tracking rules |
Program implications
Build the California lane properly. HR access/deletion workflows with legal-hold and third-party-privacy exceptions, B2B contact rights handling in the unified DSAR intake, and notices at collection for employees and applicants, the CCPA compliance guide covers the machinery.
Police the context boundary. CRM enrichment, intent data, and audience-matching from B2B lists can constitute sale or sharing in California and erode the exemption elsewhere; tag B2B records so ad-flow entry is a deliberate, reviewed event.
Cover the exempt data’s other laws. BIPA’s employee docket, SHIELD’s safeguards, and breach readiness for HR systems, mapped in the same multi-state register as the consumer obligations.
Remember the website. Your marketing site’s visitors are consumers in all twenty states, GPC, opt-outs, and notice accuracy apply to B2B companies exactly as to retailers (comparison here). Check yours with a free scan.