RatedWithAI

RatedWithAI

Accessibility scanner

CCPA ComplianceAugust 13, 2026

Your Enrichment Tool Knows Their Cell Number. They Never Gave You Their Email.

AI enrichment appends direct dials, job history and intent scores to contacts who have never visited your site, opened your email or heard of your company. Every one of those fields is personal information under the CCPA, and the B2B carve-out that used to cover it expired three years ago.

The Exemption Everyone Still Cites

The CCPA's original carve-out for business-to-business contact data sunset on January 1, 2023. Sales playbooks written before then still assume work emails are outside the statute. They are not. A prospect's work address, title and employer are personal information the moment they identify a California resident.

The Inference Problem

Enrichment does not just copy fields. It generates them: predicted seniority, estimated budget, likelihood to churn, an intent score derived from third-party browsing signals. Inferences drawn to create a profile are explicitly personal information under California law, which means they are subject to access and deletion requests like any other field.

Where Enrichment Breaks the Notice Requirement

Notice at collection is written for a consumer standing in front of you: a form, a checkout, a chat widget. Enrichment inverts that. The record arrives from a vendor, gets appended to a CRM object, and is scored by a model before the person has any interaction with your business at all. There is no interface on which to display a notice, which is exactly why California requires the chain of custody to carry the disclosure instead.

  • Indirect collection still needs a source: Before you sell or share personal information you did not collect directly, you must either provide notice yourself or confirm that the source provided it. "The vendor said it was compliant" is not the same as having the vendor's notice language and opt-out handling documented in your file.
  • Your privacy policy must name the categories: If you enrich, your disclosures need to describe the categories of personal information collected from sources other than the consumer, and the categories of sources. A policy that only describes your own web forms is incomplete the day you sign an enrichment contract.
  • Opt-out signals travel with the record: A consumer who opted out at the data broker did not opt out only there. Enrichment vendors are expected to pass those choices downstream, and you are expected to honor them rather than treating a fresh export as a clean slate.
  • Deletion has to reach the enriched copy: A deletion request that clears the CRM record but leaves the appended fields in a data warehouse, a reverse-ETL destination or a sequencing tool is not a completed deletion. Map every place enrichment output lands before you receive the first request, not after.

"Sale" and "Share" Do Not Require Money

The most common misreading in B2B is that a company does not sell data because no one pays it for a list. Under the CCPA, a sale includes making personal information available to a third party for other valuable consideration, and sharing covers disclosure for cross-context behavioral advertising. Uploading a prospect list to an ad platform to build a lookalike audience, or feeding contacts into a co-marketing exchange, can land in both definitions. If either applies, you owe a "Do Not Sell or Share My Personal Information" link and you must honor opt-out preference signals sent by the browser.

There is a second question worth answering before your next renewal: whether the enrichment relationship makes you a data broker in California's sense — a business that knowingly collects and sells personal information about consumers with whom it has no direct relationship. Businesses that meet the definition must register annually, and the state's deletion mechanism requires registered brokers to process consumer deletion directives on a recurring schedule. Most sellers never look at that question because they think of themselves as a software company, not a broker.

The Contract Terms That Do the Real Work

Whether your enrichment vendor is a service provider or a third party changes your obligations more than any setting in the product. A service provider is contractually restricted to processing on your behalf; a third party is a recipient, and disclosures to it can constitute a sale or share. Vendors that also sell the same enriched data to other customers frequently cannot honestly sign service provider terms, and the negotiation is where you find that out.

  • No secondary use: The contract should prohibit the vendor from retaining, using or disclosing the personal information for any purpose other than the services specified, including improving its own commercial data products or training generalized models.
  • Downstream flow-through: Require the vendor to bind its own subprocessors to the same restrictions, and to pass deletion and opt-out requests through to them.
  • Provenance representations: Ask the vendor to represent where the underlying data came from and that required notices were given at the source. If they will not put it in writing, you have your answer about the quality of the chain.
  • Audit and remediation: Reserve the right to take reasonable steps to stop and remediate unauthorized use. This is a specific statutory expectation, not boilerplate.

Compliance Debt Compounds Quietly

Privacy, accessibility and AI disclosure obligations all land on the same public surfaces — your forms, your policies, your widgets. RatedWithAI scans those surfaces so the gaps surface on your schedule instead of a regulator's.

Scan Your Site →

A Practical Sequence for Revenue Teams

You do not need to stop enriching. You need the paperwork and the plumbing to match what the tooling already does.

  1. Inventory every enrichment, intent and contact-data vendor touching the CRM, including the ones a single rep expensed.
  2. Classify each as service provider or third party, and fix the contract to match reality rather than the label you prefer.
  3. Update the privacy policy to disclose indirect collection categories and sources.
  4. Wire deletion and opt-out to every downstream destination enrichment output reaches, and test with a real request.
  5. Decide, in writing, whether any entity in your stack — including you — meets the data broker definition.

Frequently Asked Questions

We only sell to companies, not consumers. Does the CCPA really apply?

The statute protects California residents, and an employee acting in a business capacity is still a California resident. The temporary B2B exemption that made this argument work expired at the start of 2023. If you meet the CCPA's applicability thresholds, prospect data is in scope.

Our enrichment vendor says the data is publicly available. Does that exempt it?

Publicly available information is excluded, but the definition is narrower than most vendors imply: it generally covers lawfully obtained government records and information a consumer made available to the general public. Inferences built on top of public signals, and data scraped from sources with access restrictions, do not automatically inherit the exemption.

Do we have to honor a Global Privacy Control signal from a prospect's browser?

If you sell or share personal information, yes. The opt-out preference signal must be treated as a valid request for that browser, and California enforcement has already focused on businesses that displayed an opt-out link while ignoring the signal.

What about a prospect who asks us to delete their data mid-sequence?

Stop the sequence, delete across systems including enrichment-derived fields, and keep only what a recognized exception permits. If you need to remember not to re-import them, maintain a suppression record limited to the minimum data required to honor the request — that is an accepted use, not a workaround for keeping the profile.

Does an AI intent score count as sensitive personal information?

Usually not by itself. Sensitive categories are enumerated and include things like precise geolocation, government identifiers and certain health or biometric data. The risk with intent scoring is different: if a model infers a protected characteristic, or infers something like health status from browsing behavior, you may have created sensitive data you never intended to collect.

This article is general information, not legal advice. Privacy obligations depend on your specific data flows, contracts and applicability thresholds — consult qualified counsel before changing your program.