Join the waitlist

Let us know how we should get in touch with you.

Thank you for your interest! We’re excited to show you what we’re building very soon.

Close
Oops! Something went wrong while submitting the form.

The Sales Leader's Guide to B2B Data Compliance (GDPR, CCPA, and Beyond)

Austin Hughes
·
Updated on: July 28, 2026
TL;DR: B2B data compliance now carries real financial risk beyond Europe. GDPR fines have hit €7.1 billion since 2018, and California has issued two record CCPA settlements since September 2025 ($1.35M and $2.75M). This guide is for sales, RevOps, and growth teams that prospect using purchased or enriched contact data. Six provider checks and a signal-based prospecting approach can cut your exposure without slowing outbound down.

Key Facts and Benchmarks at a Glance

Every quantitative claim in this guide, centralized with its source and date so you don't have to hunt through the article for numbers.

Fact Figure Source and date
Cumulative GDPR fines since May 2018 €7.1 billion DLA Piper, GDPR Fines and Data Breach Survey, January 2026
GDPR fines issued in 2025 alone €1.2 billion DLA Piper, GDPR Fines and Data Breach Survey, January 2026
Average daily data breach notifications (EU) 443/day, up 22% year over year DLA Piper, GDPR Fines and Data Breach Survey, January 2026
CCPA penalty, standard violation $2,663 per violation California Privacy Protection Agency, announcement dated December 17, 2024, effective January 1, 2025
CCPA penalty, intentional violation $7,988 per violation California Privacy Protection Agency, announcement dated December 17, 2024, effective January 1, 2025
Largest fine in CPPA history (at time issued) $1.35 million, Tractor Supply Company California Privacy Protection Agency, announcement dated September 30, 2025
Largest CCPA settlement in California history $2.75 million, Disney California Department of Justice press release, February 11, 2026
US states with comprehensive privacy laws in effect 19 (per IAPP; other trackers cite up to 24 depending on methodology) IAPP US State Privacy Legislation Tracker, updated June 29, 2026
CCPA opt-out request response window 15 business days California Privacy Protection Agency regulations
GDPR data subject request response window Up to 30 days (extendable) GDPR Article 12(3)
CPPA ADMT and risk assessment regulations, compliance deadline Effective January 1, 2026; ADMT-specific compliance required by January 1, 2027 California Privacy Protection Agency regulations page
Unify B2B database coverage 1.1B+ contacts, 65M+ companies, 40+ signal and data sources, 11+ vendor waterfall unifygtm.com/product/b2b-company-contact-data

Methodology and Limitations

Methodology: Regulatory figures in this guide were checked against primary government sources (California Privacy Protection Agency, California Department of Justice) and the DLA Piper GDPR Fines and Data Breach Survey (January 2026), current as of publication in July 2026. State privacy law counts vary by tracker depending on whether a signed-but-not-yet-effective law is counted; we cite IAPP's June 29, 2026 count (19) and note where other trackers differ.

What this guide does not cover: sector-specific rules (HIPAA, GLBA, FCRA), employee-data-specific carve-outs in a handful of states, and non-US/non-EU jurisdictions. This is not legal advice; consult counsel before finalizing your compliance program.

Unify customer figures: Every Unify-specific number in this guide is attributed to a named, published customer story (Campfire, CandorIQ) or to Unify's own product and legal pages. There is no aggregated "Unify benchmark" dataset, and individual customer results are not representative of average outcomes.

Why Is B2B Data Compliance No Longer Just a European Problem?

B2B data compliance now carries enforcement risk in California and a growing list of US states, not just under GDPR. GDPR fines have reached a cumulative €7.1 billion since enforcement began in May 2018, with €1.2 billion of that issued in 2025 alone, according to DLA Piper's GDPR Fines and Data Breach Survey, January 2026. The same survey found data breach notifications climbed to an average of 443 per day in the year ending January 2026, up 22% from 363 per day the prior year, the first time notifications have crossed 400 per day since GDPR took effect.

California has been just as active. In September 2025, the California Privacy Protection Agency (CPPA) fined Tractor Supply Company $1.35 million, the largest penalty in the agency's history, for failing to give consumers and job applicants proper privacy notices and a working opt-out mechanism. Five months later, the California Attorney General's office topped that with a $2.75 million settlement against Disney, the largest CCPA settlement in state history, over opt-out signals that did not carry across every connected device and streaming app.

Most sales teams still treat compliance as someone else's problem: legal's problem, or the data provider's problem. That assumption gets more expensive every quarter. This guide breaks down what actually applies to B2B prospecting and what to do about it.

What Regulations Actually Apply to B2B Prospecting?

Three regulatory frameworks matter for most B2B sales teams today: GDPR, CCPA/CPRA, and a fast-growing list of US state privacy laws. Here is how they compare on the fields that actually change what your team can do.

GDPR, CCPA/CPRA, and emerging state laws compared on the same fields: who it covers, the legal trigger, the key obligation, penalty range, and the most common red flag.

Field GDPR (EU/UK) CCPA/CPRA (California) Other US state laws
Who it covers Any business contact in the EU/UK, regardless of your company's location California residents, including B2B contacts, since the B2B exemption expired January 2023 Residents of each enacting state; most explicitly exclude B2B context
Legal trigger for cold outreach Legitimate interest under Article 6(1)(f), documented per campaign No consent required to contact, but sale/share must honor opt-out Varies; most follow a CCPA-like opt-out model
Key obligation Article 28 DPA with processors; honor erasure requests (Article 17) Honor Global Privacy Control and other opt-out-of-sale signals Consumer rights requests (access, deletion, correction)
Penalty range Up to €20M or 4% of global annual revenue $2,663 per violation; $7,988 if intentional Varies by state, generally civil penalties with AG enforcement
Most common red flag No documented Legitimate Interest Assessment on file Opt-out signal honored on one device but not others Treating "B2B" as a blanket exemption when it usually is not

The nuance sales teams miss most often: California is still the only state whose comprehensive privacy law explicitly reaches B2B contact data. Learn more about how coverage differs by region in our guide to which B2B data providers have the strongest European coverage. Most other states carve out business-to-business processing. But in practice, modern CRMs rarely separate personal from commercial data cleanly, and a sole proprietor's business email sits in the same table as an enterprise VP's. If you prospect nationally, building your compliance baseline around California's stricter standard is the safer default.

On the US state side, the count keeps moving. The IAPP's US State Privacy Legislation Tracker, last updated June 29, 2026, counts 19 states with comprehensive privacy laws currently in effect, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026, and Arkansas following on July 1. Other trackers cite as many as 24 because they include states that have signed a law that has not taken effect yet, such as Alabama, Louisiana, Oklahoma, and Vermont.

How Do You Evaluate a Data Provider's Compliance?

Evaluate any B2B data or enrichment provider against six criteria before you sign or renew. These are vendor-neutral: they apply the same way whether you're looking at a database vendor, an enrichment API, or a full outbound platform.

  • Data sourcing transparency. Where does the data actually come from: web scraping, cooperative publisher partnerships, public records, or user submissions? A provider who can't clearly explain provenance is a red flag on its own.
  • Consent and opt-out management. Does the provider track and honor opt-outs, and how fast? CCPA requires action within 15 business days; GDPR expects a response within 30 days.
  • Data Processing Agreement. Can the provider produce a DPA without weeks of legal back-and-forth? It should meet GDPR Article 28 requirements and clearly define processor versus controller roles.
  • Suppression list support. Can you upload and enforce do-not-contact lists across every campaign, not just the one where a prospect opted out?
  • Data retention and deletion. How long is data stored, and can you request deletion on demand? Common GDPR practice caps B2B contact retention around three years from the last real interaction.
  • Security certifications. Look for SOC 2 Type II, and ask whether the provider participates in the EU-US Data Privacy Framework, which survived a legal challenge at the EU General Court on September 3, 2025 and remains the valid mechanism for transatlantic transfers, though the ruling is still open to appeal.

No single vendor wins on every dimension, which is exactly why waterfall approaches that combine several sources tend to outperform single-vendor databases on both coverage and freshness; see our breakdown of waterfall enrichment architecture and our comparison of B2B data providers for sales prospecting for how that plays out on accuracy and match rate.

How Unify covers this: Unify's Data Processing Agreement incorporates the EU Standard Contractual Clauses (Module Two) and commits to at least 10 days' notice before adding a new subprocessor, with a full list published at trust.unifygtm.com. Unify backs its security commitments with a SOC 2 Type 2 report and annual penetration testing. On data sourcing, Unify's B2B Company and Contact Data product waterfalls more than 40 signal and data sources and 11-plus email and phone vendors rather than relying on one static database, and enrichment happens on demand per contact rather than as a bulk upfront purchase. On suppression, Campfire's Head of Marketing has credited Unify's exclusion rules with "minimizing contact fatigue and prioritizing only the warmest inboxes" (Campfire customer story).

Try Unify free to see how signal-triggered enrichment and built-in suppression rules work together before you commit to a new data provider.

How Does Signal-Based Prospecting Reduce Compliance Risk?

Signal-based prospecting reduces compliance risk by limiting how much personal data you store and process at any given time. Bulk data purchases carry the highest risk: buying a list of 50,000 contacts means storing personal data on people who have shown zero interest in your product, which weakens your legitimate interest argument and increases your exposure if something goes wrong.

Signal-based targeting flips that model. Instead of starting with a massive list and hoping some fraction is relevant, you start with a buying signal, such as a pricing page visit, a job posting, or new technology adoption, and only enrich and contact the people who show it. That directly serves GDPR's data minimization principle under Article 5(1)(c), and it gives you a much more specific, defensible legitimate interest rationale for each contact you reach: a VP who visited your pricing page three times this week is a different regulatory posture than 10,000 people from a purchased list.

Worked Example: Signal to Suppression, Timestamped

Here's an anonymized trace of what signal-based, compliance-aware prospecting looks like in practice, for a mid-market SaaS company selling into both the EU and US:

  • Day 0, 9:14 AM: A VP of Sales at a France-based target account visits the pricing page twice in one week. That's the buying signal, not a purchased list entry.
  • Day 0, 9:16 AM: The signal triggers enrichment for that one contact, not the other 400 people at the company. Within minutes the record includes a verified work email and a one-line rationale: pricing page revisit, EU-based, matches ICP.
  • Day 0, 9:20 AM: Because the contact is EU-based, the rep logs a short Legitimate Interest Assessment before the sequence goes out, covering relevance, source transparency, and the opt-out link.
  • Day 1: First email sends with a visible, working opt-out link.
  • Day 9: No reply. A second signal, a job posting for a similar role, triggers one more touch referencing the new context.
  • Day 14: The prospect replies asking to be removed. The suppression list updates across the CRM, sequencer, and enrichment vendor within the hour, before any other rep could re-add the contact.

Outcome: one targeted contact processed instead of an entire 400-person account list, a documented rationale on file, and a suppression record that travels with the account rather than living in a single rep's inbox.

Consolidating tools has a similar effect. CandorIQ's founding SDR replaced a stack of four separate tools, Apollo for list building, LinkedIn Sales Navigator, Factors.ai for web intent, and Claude for drafting, with a single platform, cutting bounce rates by 87% and manual data handling by 95% (CandorIQ customer story). Fewer tools touching the same personal data means fewer places a suppression request or deletion request can fall through the cracks.

Which Compliance Priorities Matter Most for Your Team?

Use this to figure out where to focus first, since not every team has the same exposure:

  • If you sell primarily into the EU or UK, prioritize documented Legitimate Interest Assessments and a signed Article 28 DPA with every processor before you scale outreach volume.
  • If you sell into California or nationally across the US, prioritize CCPA opt-out mechanics, especially honoring Global Privacy Control across every device, since that is exactly what triggered the Disney settlement.
  • If your team still runs on bulk purchased lists, prioritize migrating to signal-triggered enrichment to shrink the volume of personal data you would have to defend in an investigation.
  • If you sell into states outside California, prioritize a lightweight process for tracking new effective dates over deep per-state customization, since the state law count keeps expanding.
  • If you're a lean team without in-house privacy counsel, prioritize a data provider that can produce a DPA and SOC 2 report quickly over one that's marginally cheaper but slower on paperwork.
  • If you've never run a Legitimate Interest Assessment, prioritize documenting one per campaign before you scale EU outreach further, not after.

What Should Be on Your Practical Compliance Checklist?

Whether you use Unify or another platform, these are the baseline practices every outbound team should follow:

  • Maintain one suppression list, synced everywhere. Centralize do-not-contact records across your CRM, sequencer, and enrichment provider so an opt-out in one tool applies everywhere.
  • Honor opt-outs on time. CCPA requires action within 15 business days; GDPR allows up to 30. Build internal SLAs that beat both deadlines.
  • Include a working opt-out in every email. Not optional under CAN-SPAM, GDPR, or CCPA, and it needs to be easy to find and use.
  • Review your provider's DPA annually. Regulations change; confirm processor and controller responsibilities and transfer mechanisms are still current.
  • Document your legitimate interest rationale. A brief, campaign-level note explaining relevance and proportionality goes a long way if you're ever asked to show your work.
  • Train reps on the basics. Cover deletion requests, why contact lists shouldn't land on personal devices, and what to say if a prospect asks where their data came from.

Role and Region Variants: What Changes Based on Who You Are

  • Sales and BDR teams: Focus on the opt-out link, the suppression list, and not exporting contact data to personal spreadsheets or devices. These are the day-to-day actions reps actually control.
  • RevOps and Marketing Ops: Own the suppression list sync across CRM, sequencer, and enrichment vendor, and own the annual DPA review. This is where compliance breaks down operationally, not legally.
  • Teams selling only within the US, outside California: Track effective dates for newly enacted state laws as your main ongoing task; most exclude B2B context today, but that is trending toward change.
  • Teams selling into the EU or UK: Legitimate Interest Assessments and Article 28 DPAs are the two things worth getting right before anything else; they are the two most commonly missing artifacts in an investigation.

Edge Cases and Common Points of Confusion

  • Sole proprietors are not automatically "B2B." Under CCPA, an independent contractor or sole proprietor's business contact still counts as a consumer, so the B2B exemption doesn't shield you the way many teams assume.
  • Public data isn't consented data. Scraping a public LinkedIn profile or company website doesn't exempt you from GDPR or CCPA obligations; the data is still personal information once you store and use it.
  • Opt-out and suppression list are not the same thing. An opt-out is the legal right a person exercises. A suppression list is the operational mechanism that enforces it across every tool. Teams that build one without the other end up re-contacting people who already opted out.
  • State privacy law counts vary because trackers count differently. Some count only laws currently in effect (19, per IAPP); others include laws signed but not yet effective (up to 24). Neither number is "wrong," they're just measuring different things.
  • Legitimate interest is not a one-time company policy. It needs a fresh, documented assessment per campaign or purpose, not a single blanket sign-off from legal at the start of the year.

Stop Rules: When to Pause or Change an Outbound Sequence

Signals that should trigger an immediate change to an outbound sequence, the required action, how long to wait, and which channel to use afterward.

Signal Next action Wait time Channel after
Deletion or erasure request Purge across CRM, enrichment vendor, and sequencer Immediately; confirm within 30 days (GDPR) or 45 days (CCPA) None until removal is confirmed
Global Privacy Control signal received Treat as a valid opt-out of sale or share, across every device Immediate, no confirmation email required None for sale/share purposes
Provider can't produce a signed DPA Escalate to legal or pause onboarding Before the first data pull None until DPA is signed
Contact record older than 12 months, unverified Re-verify or drop from active sequencing Before the next campaign launch None until refreshed
Prospect replies "remove me" or unsubscribes Add to suppression list across every connected tool Permanent None

Top Mistakes to Avoid

  • Treating compliance as a one-time checkbox instead of a per-campaign practice, especially for legitimate interest documentation.
  • Buying bulk static lists instead of signal-triggered enrichment, which inflates the volume of personal data you would have to defend.
  • Letting the suppression list live in one tool only, instead of syncing it across CRM, sequencer, and enrichment vendor.
  • Ignoring Global Privacy Control signals because they arrive automatically instead of through a web form. They still count.
  • Assuming a SOC 2 badge covers privacy compliance. SOC 2 addresses security controls; it says nothing about your GDPR legal basis or CCPA opt-out mechanics.

Frequently Asked Questions

Is cold emailing legal under GDPR for B2B sales?

Yes. GDPR permits B2B cold email under the legitimate interest legal basis in Article 6(1)(f), provided the message is relevant to the recipient's professional role, you disclose where you obtained their data, and you include a clear opt-out. You should also document a short Legitimate Interest Assessment for each campaign, not just once at the company level.

Does CCPA apply to B2B contact data?

Yes. The CCPA's B2B exemption expired in January 2023. Business contact information for California residents, including work emails, direct phone numbers, and job titles, is now fully protected, and sole proprietors count as consumers too. Penalties start at $2,663 per violation and rise to $7,988 for intentional violations.

How many US states have comprehensive privacy laws in 2026?

The IAPP's tracker counted 19 states with comprehensive privacy laws in effect as of its June 29, 2026 update, with Indiana, Kentucky, and Rhode Island joining on January 1 and Arkansas following July 1. Other trackers cite numbers as high as 24 because they count laws that have been signed but are not yet in effect. California remains the only state that explicitly extends coverage to B2B contact data.

What certifications should I look for in a B2B data provider?

Look for SOC 2 Type II for operational security controls, and ask directly whether the provider participates in the EU-US Data Privacy Framework, which the EU General Court upheld against legal challenge in September 2025. A compliant provider should also produce a GDPR Article 28 Data Processing Agreement without weeks of back and forth.

How does signal-based prospecting reduce compliance risk?

Signal-based prospecting limits enrichment and outreach to contacts who have shown active buying intent, instead of storing personal data on an entire purchased list. That shrinks the volume of personal data you process at any given time, the core of GDPR's data minimization principle in Article 5(1)(c), and it gives you a stronger, more specific legitimate interest argument for each contact you reach.

Does Global Privacy Control count as a valid CCPA opt-out request?

Yes, and this is exactly what tripped up Disney in its $2.75 million settlement with the California Attorney General in February 2026. Businesses must treat a Global Privacy Control signal as a valid opt-out-of-sale-or-share request across every device and service tied to that consumer's account, not just the one browser session where the signal was sent.

What is the difference between a data controller and a data processor under GDPR?

A controller decides why and how personal data is processed and carries the primary legal responsibility. A processor handles data only on the controller's documented instructions, typically under a signed Article 28 agreement. Most B2B data and enrichment vendors act as processors, which means your company still owns the compliance obligation even when a vendor is doing the enrichment.

How long can you legally keep a prospect's contact data?

There is no single legal number, but common GDPR practice caps B2B contact retention around three years from the last genuine interaction, after which the legitimate interest justification weakens significantly. CCPA does not set a fixed retention period either, but requires that you disclose your retention practice and honor deletion requests within 45 days, extendable once by another 45.

Glossary

  • Legitimate Interest Assessment (LIA): A documented, campaign-level justification under GDPR Article 6(1)(f) explaining why an outreach is relevant, proportionate, and respects the recipient's rights.
  • Data Processing Agreement (DPA): A contract required under GDPR Article 28 that defines how a processor may handle personal data on a controller's behalf.
  • Data controller vs. data processor: A controller decides why and how data is processed and bears primary liability; a processor acts only on the controller's documented instructions.
  • Right to erasure: The GDPR Article 17 right allowing a data subject to request deletion of their personal data across every system that holds it.
  • Global Privacy Control (GPC): A browser-level signal that communicates a consumer's opt-out-of-sale-or-share preference automatically, which CCPA requires businesses to honor as a valid request.
  • Data minimization: The GDPR Article 5(1)(c) principle requiring that only the personal data necessary for a specific purpose be collected and processed.
  • Suppression list: The operational, cross-tool record of contacts who must not be contacted again, used to enforce opt-outs and deletion requests in practice.
  • Signal-based prospecting: An outbound approach that triggers enrichment and outreach only when a contact shows a specific buying signal, rather than processing an entire purchased list upfront.
  • ADMT (Automated Decision-Making Technology): The category of CCPA regulations, effective January 1, 2026, that governs businesses' use of automated tools to make decisions that significantly affect consumers.

Sources

About the Author
Austin Hughes is Co-Founder and CEO of Unify, outbound AI for sellers where AI agents and reps work side by side, from finding the buyers already in market to reaching them with the right message. Before founding Unify, Austin led the growth team at Ramp, scaling it from 1 to 25+ people and building a product-led, experiment-driven GTM motion. Prior to Ramp, he worked at SoftBank Investment Advisers and Centerview Partners.