Skip to content
← BlogCompliance

CCPA/CPRA and cold email: it's a privacy law, not an anti-spam law

California's CCPA/CPRA gives residents rights over their data, but it doesn't set cold-email consent rules like CASL or GDPR. Here's what it actually changes for a B2B sender.

By Gabriel Lara, Developer Relations, Norbelys

Founder-reviewed ·How we research and correct articles

Of everything in this series, California’s CCPA, as amended and expanded by the CPRA, is the one most often misfiled. People hear “California,” “privacy law,” and “email,” and assume it works like CASL or GDPR — some kind of consent gate you have to clear before you’re allowed to send. It doesn’t. Getting this distinction right is the entire value of this article, so it comes first, not last.

What CCPA/CPRA actually is: a data-rights law

CCPA/CPRA is consumer privacy legislation, not commercial-email legislation. Per the California Attorney General’s own guidance, it gives California residents a defined set of rights over the personal information businesses hold about them:

  • The right to know what personal information a business has collected, used, sold, or shared, and where it came from.
  • The right to delete personal information a business holds about them, subject to specific statutory exceptions.
  • The right to correct inaccurate personal information.
  • The right to opt out of the sale or sharing of their personal information, including for cross-context behavioral advertising.
  • The right to limit use of sensitive personal information.
  • The right to non-discrimination for exercising any of the above.

None of that is a rule about whether you’re allowed to send someone a cold email. That’s the core thing to internalize: CCPA/CPRA regulates what happens to data a business already holds — access, deletion, correction, sale, sharing — not the act of composing and sending an unsolicited message in the first place.

What actually governs sending the email: CAN-SPAM, not CCPA

The federal CAN-SPAM Act is the law that sets rules for the email itself in the U.S. — accurate headers, no deceptive subject lines, a working opt-out honored within the statutory window, a valid postal address, and clear ad disclosure where required. CAN-SPAM is opt-out by design: you generally don’t need consent before the first send, only a functioning, honored way to stop future ones. CCPA/CPRA doesn’t touch any of that. It doesn’t require opt-in consent before you email a California resident, and it doesn’t mandate the specific unsubscribe mechanics CAN-SPAM does — those requirements come from CAN-SPAM alone, covered in full in built on U.S. anti-spam law.

So a B2B sender operating in California is actually satisfying two separate, non-overlapping legal regimes at once: CAN-SPAM governs the email itself, and CCPA/CPRA governs what you do with the recipient’s data once you’re holding it. Neither substitutes for the other, and neither is a superset of the other.

What changed in 2023, and why it matters for B2B

CCPA originally included exemptions that took business contact information out of scope almost entirely: personal information collected in the course of an employment relationship, and personal information reflecting a business-to-business transaction or communication (think: a supplier’s sales contact information for a prospective business customer). Those exemptions were temporary by design, written to sunset automatically. They expired on December 31, 2022, with no legislative extension, and CCPA’s full scope — as expanded by the CPRA — has applied to employment and B2B personal information since January 1, 2023.

That’s the change that actually matters for a cold-email sender: a California resident’s work email address, name, and job title, once largely outside CCPA’s reach in a B2B context, is now personal information carrying the same access, deletion, correction, and opt-out rights as any consumer’s data. If your B2B contact database includes California residents — and for most SaaS and B2B outreach, it does — those contacts now have standing to make a CCPA/CPRA data-subject request against you, the same way an EU contact could invoke GDPR’s rights. The mechanics of handling a deletion request specifically are covered from the product side in GDPR right to erasure for cold email — the underlying operational discipline (find every copy of the record, actually remove it, don’t just suppress the account it lives under) transfers to a CCPA/CPRA deletion request even though the two laws are legally distinct.

Penalties are about mishandling data, not about sending unsolicited email

CCPA/CPRA’s administrative fines, enforced primarily by the California Privacy Protection Agency (CPPA), attach to violations of the data-rights framework — failing to honor a deletion or opt-out request, mishandling a data-subject request, or noncompliant sale or sharing practices — not to the fact of having sent a cold email. As of the CPPA’s most recent published inflation adjustment, effective January 1, 2025, the administrative fine ceiling is $2,663 per violation for unintentional violations and $7,988 per violation for intentional violations or those involving a minor’s data, recalibrated for inflation on a recurring statutory schedule — so treat these as the current figures, not permanent ones, and check the CPPA’s own announcements for the currently effective amount.

What this looks like in practice

For a B2B sender with California residents in the contact database, CCPA/ CPRA compliance runs on a separate track from cold-email consent rules:

  • Have a real process for access, deletion, and correction requests from contacts, including prospects who were never customers — the B2B exemption that used to make this optional is gone.
  • Don’t conflate “unsubscribed from email” with “deleted under CCPA/CPRA.” They’re different rights with different mechanics; an unsubscribe stops future sends, a deletion request removes the underlying record.
  • Keep CAN-SPAM’s mechanics — identification, working opt-out, honored promptly — running regardless, since CCPA/CPRA doesn’t relax or replace any of that federal requirement.
  • Don’t assume “we don’t sell data” means CCPA/CPRA doesn’t apply. The access, deletion, and correction rights apply to any covered business holding California residents’ personal information, independent of whether that business sells or shares data at all.

For the broader comparison of how consent-based regimes like GDPR and CASL differ from the U.S.’s opt-out model, see CAN-SPAM vs. GDPR vs. CASL compared — CCPA/CPRA doesn’t fit neatly into that comparison at all, which is really the point of this article: it’s answering a different question entirely. And since authentication hygiene matters under every legal regime discussed in this series, see DMARC monitoring for keeping your sending domain’s identity claims honest no matter which law is actually in play.

Frequently asked questions

Does CCPA require consent before sending cold email?

No. CCPA/CPRA does not set a consent requirement for sending commercial email; that is governed by the federal CAN-SPAM Act, which is opt-out rather than opt-in. CCPA/CPRA instead gives California residents rights over personal information a business already holds — access, deletion, correction, and opt-out of sale or sharing — independent of whether or how you send email.

Are B2B contacts exempt from CCPA?

Not anymore. CCPA originally exempted personal information collected in employment and business-to-business contexts, but those exemptions were temporary and expired on December 31, 2022, with no extension. Since January 1, 2023, a California resident's work contact information carries the same CCPA/CPRA rights as consumer data.

What is the difference between an email unsubscribe and a CCPA deletion request?

An unsubscribe, required under CAN-SPAM, stops future email sends but does not necessarily remove the underlying contact record. A CCPA/CPRA deletion request is a distinct data-subject right requiring the business to actually delete the personal information held about that person, subject to statutory exceptions. Honoring one does not automatically satisfy the other.

Who enforces CCPA and what are the penalties?

The California Privacy Protection Agency (CPPA) holds primary rulemaking and enforcement authority, alongside continued authority for the California Attorney General. As of the CPPA's most recent published inflation adjustment, the administrative fine ceiling is $2,663 per violation for unintentional violations and $7,988 per violation for intentional violations or those involving a minor's data, figures that are recalibrated periodically.