Does CCPA apply to B2B sales?
Yes. The original CCPA included a temporary carve-out for business contact information collected in a B2B context, but that carve-out expired on January 1, 2023 under CPRA. Work emails, work phones, and job titles of California residents are now covered the same as consumer data. A prospect list for California-based buyers is subject to the full set of CCPA rights.
Do I have to publish a "Do Not Sell" link if I only sell B2B?
If your business meets the CCPA thresholds and you either sell or share personal information under the law's broad definition, yes. "Sharing" was added by CPRA and covers sending personal information to third parties for cross-context behavioral advertising. Using an ad network pixel to retarget California visitors on LinkedIn is generally sharing, even if the underlying motion is B2B. When in doubt, publish the link and route requests through a consent management tool.
What is the difference between CCPA and CPRA?
CCPA is the original California Consumer Privacy Act, which took effect in January 2020. CPRA (California Privacy Rights Act) is a 2020 ballot initiative that amended CCPA with new rights (correction, limit use of sensitive data), a new regulator (California Privacy Protection Agency), the expiration of the B2B and HR carve-outs, and a new "sharing" category. Most CPRA provisions took effect January 1, 2023. People use "CCPA" to refer to the combined law in casual usage, which is how this answer treats it.
How long do I have to respond to a CCPA request?
Opt-out requests must be honored within 15 business days. Access, deletion, and correction requests have 45 calendar days, extendable by an additional 45 days with written notice to the consumer if the request is complex. The clock starts when you receive the request, not when you verify the requester's identity. Build the intake form so verification happens quickly to protect the response window.
What does CCPA mean for cold outbound email and calling?
CCPA does not ban cold outbound. It requires that you honor opt-out requests ("stop emailing me," "remove me from your list") as a rights request, maintain a retention schedule so you are not calling a lead from four years ago, and respect the Global Privacy Control signal on your website. TCPA and CAN-SPAM continue to govern the mechanics of calling and emailing. CCPA governs the underlying personal information those channels rely on.
Which other states have CCPA-style privacy laws?
As of 2026, Virginia (VCDPA), Colorado (CPA), Utah (UCPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), and Delaware (DPDPA) have active consumer privacy laws, with more states passing legislation each year. The laws differ on thresholds, opt-in versus opt-out defaults, cure periods, and sensitive-data rules, but the operational shape (notice, access, deletion, opt-out of sale) is similar. A CCPA-ready data map and opt-out workflow cover most of what the other states require.
Does the CRM vendor or my company own CCPA compliance?
Your company owns compliance as the "business" under CCPA. The CRM vendor is typically a "service provider" or "contractor" and has to support your rights-request workflow (honor forwarded deletion requests, restrict use to the business purpose, provide a DPA). Picking a CRM that supports deletion, a Do-Not-Sell field, retention policies, and audit trails makes compliance tractable. Picking one that does not forces the work into spreadsheets and manual follow-up.
Is this legal advice?
No. This page is a general explanation of CCPA written for sales operations and revenue leaders who need enough context to pick tools and build workflows. It is not legal advice. For a specific compliance program, enforcement question, or incident response, work with a qualified privacy attorney licensed in your jurisdiction. The rules change, the agency guidance evolves, and the facts of a given situation almost always matter.