Home » Blog » B2B Data Compliance in 2026: GDPR, CCPA and DNC Rules for Outbound Teams

B2B Data Compliance in 2026: GDPR, CCPA and DNC Rules for Outbound Teams

B2B data compliance map covering GDPR, CCPA and DNC obligations for outbound teams

B2B data compliance is no longer a legal footnote at the end of a procurement process. A single cold email can touch GDPR, CAN-SPAM and the CCPA at once, and the rules are not “pick the law where your head office sits”. They are the union of every jurisdiction your recipients sit in.

Two shifts make 2026 materially different from 2023. California’s business-to-business exemption expired, so a Californian’s work email and direct dial are now protected personal information. And California’s Delete Request and Opt-Out Platform went live to consumers on 1 January 2026, with data broker obligations biting from 1 August 2026.

This guide covers the three questions that define B2B data compliance, the GDPR legitimate-interest test in operational terms, what the CCPA now demands of a prospect database, the calling and emailing rules that still apply, a country quick-reference, ten vendor due-diligence questions and a remediation runbook for when you find a problem.

This article is practical orientation for revenue teams, not legal advice. Take qualified counsel for your jurisdictions before you change policy.

The three questions that define B2B data compliance

Almost every enforcement action reduces to one of three failures. Structure your programme around them and the detail becomes manageable.

  1. Lawful sourcing. Did whoever collected this record have the right to collect it, and can that be evidenced?
  2. Lawful processing. Do you have a documented legal basis for what you are doing with it now, including enrichment?
  3. Data subject rights. Can a person see, correct, or delete what you hold, within the statutory window, across every system?

Question three is where most teams quietly fail. Deleting a contact from the CRM while it lives on in a sequencing tool, a data warehouse and three exported spreadsheets is not deletion. Build the deletion path before you need it.

GDPR: legitimate interest, done properly

Cold B2B outreach in the EU and UK generally relies on legitimate interests under Article 6(1)(f) of the GDPR rather than consent. That basis is available, but it is conditional, and the condition is documentation.

The three-part test

  • Purpose. Is there a real, articulable business interest? Direct marketing qualifies in principle.
  • Necessity. Is processing this data necessary for that purpose, or would less data do?
  • Balancing. Would the person reasonably expect this contact, given their role and your relevance to it?

The balancing test is where role relevance earns its keep. Emailing a CFO about treasury software passes comfortably. Emailing that same CFO about office furniture, sourced from a scraped list, does not. The ICO’s guidance on legitimate interests sets out the test in full.

What a legitimate interest assessment should contain

An LIA is not legally mandated, but without one you have no evidence when a regulator asks. Keep it short and keep it current. A workable LIA records the purpose, the data categories, the source and its lawful basis, the necessity argument, the balancing analysis, the safeguards you apply, and a review date.

Two pages is usually enough. One LIA per campaign type beats one generic LIA for the whole company, because the balancing analysis changes with the persona and the offer.

The safeguards that make the argument stand up

  • Contact people at corporate domains, in their professional capacity, about their professional responsibilities.
  • Identify yourself and your company clearly in the first message.
  • Provide a genuine, one-click opt-out and honour it within days, not weeks.
  • State where you got the data if asked, which requires that you recorded it.
  • Cap frequency. Persistence that becomes harassment breaks the balancing test retroactively.

CCPA and CPRA: the B2B exemption is gone

This is the change most outbound teams have still not absorbed. Until the end of 2022, business contact information was largely carved out of the CCPA. That carve-out expired on 1 January 2023 and was not renewed.

Consequently, a California resident’s work email, direct dial and job title are personal information with full consumer rights attached. If you meet the CCPA thresholds, your prospect database is in scope, not just your customer database.

  • Notice at collection must be provided, which for purchased data usually means at first contact.
  • Right to know, delete and correct applies to prospect records.
  • Right to opt out of sale or sharing applies, and “sale” is defined broadly enough to catch data exchanges you may not think of as sales.
  • Service provider contracts are required with every vendor touching the data.

California’s DROP changes the operational picture

Under the Delete Act, California built a centralised deletion channel. A resident submits one request through the Delete Request and Opt-Out Platform, and it reaches every registered data broker at once. The platform opened to consumers on 1 January 2026.

From 1 August 2026, registered data brokers must retrieve requests at least every 45 days and finalise determinations within 90 days of retrieval, with penalties accruing per request per day for failures. The California Privacy Protection Agency publishes the operational detail on its data brokers and DROP page.

Two practical consequences follow for buyers. First, ask any data vendor whether it is a registered California data broker and how it processes DROP requests. Second, make sure deletions propagated by your vendor also propagate through your CRM and sequencing tools, which is a CRM data hygiene problem as much as a legal one.

Calling rules: TSR, DNC and TCPA

US calling law is more forgiving to B2B than most people assume, and more dangerous around mobiles than most people realise.

The FTC’s Telemarketing Sales Rule contains a business-to-business exemption at section 310.6(b)(7), and the National Do Not Call Registry does not cover business numbers called for a business purpose. The FTC sets out the detail in its guide to complying with the Telemarketing Sales Rule.

However, the exemption is narrower than the summary suggests:

  • Internal do-not-call lists still apply. If someone asks you to stop, you must stop and record it.
  • Caller ID must be accurate. This is a legal requirement, not a deliverability tactic.
  • Misrepresentation rules extend to B2B calls following the FTC’s recent TSR updates, alongside expanded record-keeping duties.
  • The TCPA governs autodialled calls and texts to mobile numbers, and B2B status does not switch that off. Since April 2025, consent revocation must also be honoured promptly and across channels.
  • State law diverges. Several states do not mirror the federal B2B exemption, so check each calling territory.

In short, calling is where B2B data compliance is most often assumed rather than checked: manually dialling a business desk line is low risk, and autodialling personal mobiles is where the class actions live. Our guide to direct dial phone numbers covers how to keep those two number types separated in your data model, which is the precondition for applying different rules to them.

Email rules: CAN-SPAM sets a floor, not a ceiling

CAN-SPAM is an opt-out regime, and it makes no exception for business-to-business email. Every commercial message needs accurate headers, a non-deceptive subject line, a physical postal address, a clear opt-out mechanism, and prompt honouring of opt-outs. Penalties run per email, and the current statutory maximum exceeds $53,000 per violation, as set out in the FTC’s CAN-SPAM compliance guide.

Mailbox providers now impose a second, stricter layer that has nothing to do with statute. Authentication, complaint-rate ceilings and one-click unsubscribe are enforced technically rather than legally, which means non-compliance costs you delivery immediately rather than a fine eventually. We covered that in Gmail bulk sender requirements.

B2B data compliance by country: a quick reference

RegionMain instrumentsUsual basis for cold B2BScreening obligationKey nuance
US federalCAN-SPAM, TSR, TCPAOpt-out for email; TSR B2B exemption for callsInternal do-not-call listAutodialled mobiles remain TCPA territory
CaliforniaCCPA / CPRA, Delete ActNotice plus opt-out rightsDROP for registered data brokersB2B exemption expired 1 January 2023
UKUK GDPR, PECRLegitimate interests with a documented LIATPS and CTPS before callingCorporate subscribers can register with CTPS
EU (general)GDPR, ePrivacyLegitimate interests, role-relevant, corporate domainsNational preference services varyMember state implementation genuinely differs
GermanyGDPR, UWGStricter: prior consent generally expected for email advertisingRobinson list conventionsTreat Germany as a consent market for email
FranceGDPR, CNIL guidanceLegitimate interests, corporate domains onlyBloctel for telephoneCNIL tightened prospecting rules in 2026; B2C now requires opt-in
CanadaCASL, PIPEDAExpress or implied consent, including conspicuous publicationCRTC National DNCLMaterially stricter than CAN-SPAM
AustraliaSpam Act, Privacy ActInferred consent from a conspicuously published business addressDo Not Call RegisterRelevance to the published role is required
A B2B data compliance quick reference. Confirm details with local counsel before scaling into a market.

The German row deserves emphasis because it is routinely missed. Sequencing a German prospect list on the same assumptions you use in Texas is one of the more common and more expensive mistakes in European expansion.

Ten due-diligence questions for any data vendor

  1. Where does each data category originate, and can you evidence the source per record?
  2. What lawful basis do you rely on, by jurisdiction?
  3. How do you provide notice to the people in your database?
  4. Are you a registered data broker in California, and how do you process DROP requests?
  5. How do deletion and objection requests propagate to me as a customer?
  6. Which do-not-call and preference registries do you screen, how often, and in which countries?
  7. Do you separate mobile numbers from desk lines in the data model?
  8. What does your data processing agreement cover, and will you sign standard contractual clauses?
  9. Will you indemnify us against claims arising from your sourcing?
  10. What certifications do you hold, and when were they last audited?

Questions four and nine are the ones that separate serious providers from resellers. Fold them into the same evaluation you run for coverage and accuracy, using our B2B data accuracy testing framework.

A B2B data compliance remediation runbook

Most compliance content assumes you are starting clean. Usually you are not. If an audit surfaces a problem, work in this order.

  1. Stop the bleeding. Pause campaigns running on the affected data source before anything else.
  2. Scope it. Identify which records came from that source, in which regions, and what was done with them.
  3. Quarantine, do not delete. You may need the records as evidence; suppress them from all outbound instead.
  4. Document the timeline. When the data arrived, when the issue was found, what you did next.
  5. Fix the intake. Close the route that allowed non-compliant data in, or the same audit repeats next year.
  6. Take counsel on notification. Whether a regulator or the individuals must be told depends on jurisdiction and severity.

Step three is counter-intuitive and important. Reflexive deletion destroys the evidence that would have shown you acted responsibly.

A practical B2B data compliance stack

  • Source field on every record, populated automatically at import. This single field answers most audit questions.
  • Consent and objection fields that sequencing tools respect natively, not via a nightly sync.
  • A global suppression list that every channel checks before send or dial.
  • Retention rules that archive and then delete records with no activity after a defined period.
  • An accessible privacy notice that explains prospect data specifically, like the ZenBee privacy policy.
  • A quarterly review covering vendor certifications, registry screening and open rights requests.

Notice how much of this overlaps with data quality work. Accurate, current, well-attributed records are easier to defend as well as more productive, which is why B2B data compliance and B2B data enrichment should be designed together rather than sequentially.

How ZenBee approaches B2B data compliance

ZenBee operates its 700M+ profile network on GDPR and CCPA-aligned practices, with source attribution retained per record and desk lines held separately from mobile numbers so different rules can be applied to each. Suppression and objection handling run inside the platform, which means an opt-out registered in the unified inbox stops sequences immediately rather than at the next sync.

Consolidation helps here in a way that is easy to underestimate. Every additional vendor in the chain is another data processing agreement, another deletion path and another audit surface. If you want the wider strategic context first, start with what sales intelligence is, then read our guide to B2B email verification for the deliverability half of the picture.

Frequently asked questions about B2B data compliance

Is cold email legal under GDPR?

It can be, where you rely on legitimate interests, contact people in their professional capacity about something relevant to their role, document a legitimate interest assessment and offer an easy opt-out. Some markets, notably Germany, expect consent for email advertising, so treat the EU as a set of markets rather than one.

Does the CCPA apply to B2B contact data?

Yes. The B2B exemption expired on 1 January 2023, so a California resident’s work email, direct dial and title are personal information with full consumer rights attached, provided your business meets the CCPA thresholds.

Do we need to screen B2B numbers against the Do Not Call Registry?

The federal registry does not cover business numbers called for a business purpose, and the TSR contains a B2B exemption. Even so, you must maintain an internal do-not-call list, transmit accurate caller ID, check state-level divergence, and treat autodialled calls to mobiles as TCPA-governed.

Is buying a contact list legal?

Buying is not automatically unlawful, but you inherit the seller’s sourcing. If they cannot evidence where records came from and on what basis, you cannot answer a regulator either. Sourcing diligence therefore matters more than list price.

Who should own B2B data compliance internally?

Legal or a data protection lead owns the policy, while RevOps owns the controls that implement it inside the CRM and sequencing tools. Splitting it that way keeps policy realistic and keeps enforcement close to where the data actually moves.