Answer · CCPA

What is CCPA for sales?

Sales teams run on contact lists, enriched prospect data, and third-party intent signals, which is exactly the kind of personal information CCPA governs. The rules do not block outbound selling, but they do shape where the data lives, how long it stays, and what the consumer can ask you to do with it.

Short answer

CCPA is the California Consumer Privacy Act, a 2020 state privacy law amended by the 2023 CPRA. It gives California residents the right to see, delete, and opt out of the sale or sharing of their personal information. For sales teams, CCPA means mapping where contact data lives, publishing a "Do Not Sell or Share My Personal Information" link, honoring opt-out requests inside the CRM, and retiring data on a schedule. This is a general explanation, not legal advice.

Key points

What matters most.

Six things sales leaders should know about CCPA before building the opt-out workflow, picking a CRM, or buying another prospect list.

The law

California residents, enforced statewide.

CCPA (California Consumer Privacy Act) took effect January 1, 2020. CPRA (California Privacy Rights Act) amended it in 2023 and created the California Privacy Protection Agency as a dedicated regulator. The rules protect California residents regardless of where your company is based. If you sell into California at any scale, the law reaches you.

Who it covers

For-profit businesses over a threshold.

CCPA applies to for-profit companies doing business in California that meet one of three thresholds: annual gross revenue over 25 million dollars, buying or sharing the personal information of 100,000 or more California consumers or households, or earning more than half of annual revenue from selling or sharing personal information. Smaller companies are generally outside scope, but their vendors are not.

Consumer rights

Access, deletion, opt-out, correction.

A California resident can request a copy of the personal information you hold on them, ask you to delete it, opt out of the sale or sharing of it, correct inaccurate records, and limit the use of sensitive personal information. CPRA added the correction right and the "limit use" right on top of the original CCPA rights.

The link

"Do Not Sell or Share My Personal Information."

If your business sells or shares personal information under the CCPA definition, you must publish a clear link on your website homepage titled "Do Not Sell or Share My Personal Information" or "Your Privacy Choices." The link has to work without an account, honor a Global Privacy Control (GPC) browser signal, and route the request into your opt-out workflow in a reasonable time.

B2B carve-out expired

Business contacts are now covered.

The original CCPA included a temporary carve-out for personal information collected in a business-to-business context (names, work emails, work phones of someone acting on behalf of their employer). CPRA let that carve-out expire on January 1, 2023. B2B contact data is now treated the same as consumer data for CCPA purposes.

Copycat states

The California rules are spreading.

Virginia, Colorado, Utah, Connecticut, Texas, Oregon, Montana, and Delaware have all passed CCPA-adjacent laws. They differ in detail (thresholds, opt-in vs opt-out defaults, cure periods, enforcement bodies) but the shape is similar: notice, access, deletion, opt-out of sale or targeted advertising. Building for CCPA gives sales teams most of what the other states require.

The rights in practice

What a California consumer can ask you to do.

CCPA is a rights-based law. The business obligation is mostly about honoring consumer requests inside 45 days (extendable by another 45 with notice) and keeping records that the requests were handled. Below are the six rights your intake form, your DPA with vendors, and your CRM all have to support. Sales teams rarely build the intake form themselves, but every rights request eventually lands on records a sales team touches.

Right to know

What you collect and why.

A consumer can ask what categories of personal information you have collected about them, the sources, the business purposes, and the third parties you have shared it with. Your privacy policy covers the general disclosure. A verified individual request pulls their specific record. Sales CRMs are usually the biggest hit on these requests because of enriched data and activity history.

Right to delete

Remove the record, with exceptions.

A consumer can ask you to delete the personal information you hold on them. Narrow exceptions exist for completing a transaction, security, legal compliance, and internal uses the consumer would reasonably expect. "I want to be removed from your sales database" generally qualifies, so the CRM has to support a true delete, not just a status flag.

Right to opt out of sale

Stop selling or sharing their data.

A consumer can tell you to stop selling or sharing their personal information. "Sharing" was added by CPRA and specifically covers cross-context behavioral advertising (sending the record to an ad network to retarget them). The CRM has to tag the record and the downstream integrations have to honor the tag before every outbound sync.

Right to correct

Fix inaccurate records.

Added by CPRA. A consumer can ask you to correct information you hold on them if it is inaccurate. For sales teams this usually hits enriched data from a prospect database that was wrong, or an outdated job title that was imported five years ago and never refreshed. The CRM needs an audit trail of what was changed and when.

Right to limit use

Sensitive personal information only.

CPRA created a separate category of "sensitive personal information" (SSN, driver's license, precise geolocation, health, financial account credentials, racial or ethnic origin, union membership, communications contents, and others). Consumers can limit your use of this category to what is strictly necessary. Most B2B sales data does not touch this category, but any enrichment that does needs its own workflow.

Right to non-discrimination

No pricing penalty for exercising rights.

You cannot charge a consumer more, give them worse service, or deny them your product because they exercised a CCPA right. Loyalty programs that reward the consumer for sharing more data are allowed if the value exchange is proportionate and documented. This mostly affects the ecommerce and consumer-app side, less the B2B sales team.

What it means in the CRM

Six operational jobs CCPA creates for sales.

The law is written in rights language. The work your sales operations team actually does is more concrete. These are the six jobs that have to exist somewhere, usually some combination of CRM, consent management platform, and a legal process document. If any of the six is missing, the opt-out workflow fails the first time a verified request lands.

Data map

Know where every contact lives.

List every system that stores personal information: CRM, marketing automation, sales engagement tool, prospect database, data warehouse, backup files, support ticketing. When a deletion request lands, you need to be able to find every copy. Teams that skip the data map discover shadow copies when the first audit happens.

Opt-out mechanism

A real workflow, not a note.

The "Do Not Sell or Share" link has to route to an intake, verify the request, propagate the opt-out to every downstream system, and finish inside 15 business days for opt-out (45 days for access and deletion). Honoring the Global Privacy Control browser signal is required. The CRM needs a field for the opt-out state and a trigger that stops outbound sync.

Retention schedule

Delete on a documented clock.

CPRA requires you to disclose how long you retain each category of personal information and to delete it when the purpose is complete. Sales teams often keep records forever because "we might sell to them again." That is no longer compliant. Set a retention clock per record type (closed-lost after 24 months, cold prospect after 12 months, and so on) and let the CRM enforce it.

Vendor contracts

Flow the obligations downstream.

Your data processors (CRM vendor, sales tool, enrichment provider, email provider) are "service providers" or "contractors" under CCPA. The contracts with them have to restrict their use of the data to the business purpose, forbid combining with other data, and support consumer rights requests you forward to them. A missing DPA is a straight finding in any audit.

Privacy policy

Specific disclosures, updated yearly.

Your privacy policy has to list the categories of personal information you collect, the sources, the business purposes, the categories of third parties you share with, retention periods, and consumer rights with instructions on how to exercise them. CPRA requires an annual review and update. A privacy policy that has not changed since 2019 is a visible red flag.

Training

The people handling requests know the rules.

CPRA requires that staff who handle personal information or consumer rights requests be trained. For sales teams this usually means a short annual module on what consent and opt-out mean, how to recognize a rights request that comes in through a sales channel ("please stop emailing me" counts), and who to escalate to. Treat it as part of onboarding.

CCPA vs GDPR

Different shapes, overlapping jobs.

Teams that already comply with GDPR often ask whether CCPA just comes for free. The answer is mostly, but not entirely. The two laws share the same core rights (access, deletion, correction) and the same discipline (data map, retention, vendor contracts), but they differ on defaults and on who is in scope. Below are the differences that matter for a sales workflow.

Default

Opt-out (CCPA) vs opt-in (GDPR).

CCPA assumes you can process personal information unless the consumer opts out. GDPR requires a lawful basis (usually opt-in consent, legitimate interest, or contract) before you process at all. For cold outbound, GDPR is the stricter bar. For warm pipeline, both laws reach similar outcomes.

Scope

Thresholds (CCPA) vs any processing (GDPR).

CCPA only applies to businesses that cross a size or volume threshold. GDPR applies to anyone processing personal data of EU residents, regardless of size. A ten-person startup selling into Germany has GDPR obligations on day one. The same startup selling only into California may not hit CCPA until it scales.

Fines

Per-violation (CCPA) vs percent-of-revenue (GDPR).

CCPA penalties run up to 2,500 dollars per violation or 7,500 per intentional violation, plus statutory damages for consumers in a data breach. GDPR tops out at 4 percent of annual global revenue or 20 million euros, whichever is higher. GDPR fines make headlines; CCPA fines accumulate per record.

B2B data

Both now cover work contacts.

GDPR has always treated work email addresses as personal data. CCPA used to carve them out but no longer does after January 1, 2023. A LinkedIn-scraped prospect list is personal information under both laws, which means both an access right and a deletion right apply.

Regulator

One agency (CCPA) vs 27 DPAs (GDPR).

CPRA created a single enforcement body, the California Privacy Protection Agency, alongside the Attorney General. GDPR is enforced by each member state's data protection authority, with a lead supervisory authority rule for cross-border cases. Expect more predictable guidance under CCPA, more variation under GDPR.

Shared discipline

The CRM work is the same.

Data map, opt-out field, retention clock, vendor contracts, training, privacy policy. If the CRM supports these for GDPR it supports them for CCPA. The hard part is making sure the opt-out signal propagates to every downstream integration before the outbound email fires. That is a sales-ops problem, not a legal problem.

A CRM with the opt-out workflow built in.

Strkr ships with consent fields, retention rules, deletion workflows, and audit trails on every record. The data map is the CRM. Start free, see the platform, and build the compliance story on top of a tool that was designed for it.

People also ask

Related questions.

Does CCPA apply to B2B sales?

Yes. The original CCPA included a temporary carve-out for business contact information collected in a B2B context, but that carve-out expired on January 1, 2023 under CPRA. Work emails, work phones, and job titles of California residents are now covered the same as consumer data. A prospect list for California-based buyers is subject to the full set of CCPA rights.

Do I have to publish a "Do Not Sell" link if I only sell B2B?

If your business meets the CCPA thresholds and you either sell or share personal information under the law's broad definition, yes. "Sharing" was added by CPRA and covers sending personal information to third parties for cross-context behavioral advertising. Using an ad network pixel to retarget California visitors on LinkedIn is generally sharing, even if the underlying motion is B2B. When in doubt, publish the link and route requests through a consent management tool.

What is the difference between CCPA and CPRA?

CCPA is the original California Consumer Privacy Act, which took effect in January 2020. CPRA (California Privacy Rights Act) is a 2020 ballot initiative that amended CCPA with new rights (correction, limit use of sensitive data), a new regulator (California Privacy Protection Agency), the expiration of the B2B and HR carve-outs, and a new "sharing" category. Most CPRA provisions took effect January 1, 2023. People use "CCPA" to refer to the combined law in casual usage, which is how this answer treats it.

How long do I have to respond to a CCPA request?

Opt-out requests must be honored within 15 business days. Access, deletion, and correction requests have 45 calendar days, extendable by an additional 45 days with written notice to the consumer if the request is complex. The clock starts when you receive the request, not when you verify the requester's identity. Build the intake form so verification happens quickly to protect the response window.

What does CCPA mean for cold outbound email and calling?

CCPA does not ban cold outbound. It requires that you honor opt-out requests ("stop emailing me," "remove me from your list") as a rights request, maintain a retention schedule so you are not calling a lead from four years ago, and respect the Global Privacy Control signal on your website. TCPA and CAN-SPAM continue to govern the mechanics of calling and emailing. CCPA governs the underlying personal information those channels rely on.

Which other states have CCPA-style privacy laws?

As of 2026, Virginia (VCDPA), Colorado (CPA), Utah (UCPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), and Delaware (DPDPA) have active consumer privacy laws, with more states passing legislation each year. The laws differ on thresholds, opt-in versus opt-out defaults, cure periods, and sensitive-data rules, but the operational shape (notice, access, deletion, opt-out of sale) is similar. A CCPA-ready data map and opt-out workflow cover most of what the other states require.

Does the CRM vendor or my company own CCPA compliance?

Your company owns compliance as the "business" under CCPA. The CRM vendor is typically a "service provider" or "contractor" and has to support your rights-request workflow (honor forwarded deletion requests, restrict use to the business purpose, provide a DPA). Picking a CRM that supports deletion, a Do-Not-Sell field, retention policies, and audit trails makes compliance tractable. Picking one that does not forces the work into spreadsheets and manual follow-up.

Is this legal advice?

No. This page is a general explanation of CCPA written for sales operations and revenue leaders who need enough context to pick tools and build workflows. It is not legal advice. For a specific compliance program, enforcement question, or incident response, work with a qualified privacy attorney licensed in your jurisdiction. The rules change, the agency guidance evolves, and the facts of a given situation almost always matter.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.