Golden Gate Legal Review Independent Commentary on Law & Policy
January 18, 2022 · Technology & Intellectual Property

Narrowing CCPA Exemptions and the Reach of California Privacy Rights

As the CCPA's employee and B2B carve-outs sunset and only sectoral exemptions remain, the law's access and deletion rights reach a wider population of Californians.

When California voters approved Proposition 24, the California Privacy Rights Act of 2020 (CPRA), they did more than layer new rights onto the existing California Consumer Privacy Act (CCPA). They quietly set a clock running on two of the statute’s broadest carve-outs. The temporary exemptions that kept most employee and business-to-business (B2B) data outside the reach of the CCPA are scheduled to lapse on January 1, 2023, and the categorical exemptions that remain — for data already governed by federal sectoral laws — are themselves narrower than they first appear. The trajectory of California privacy law over the past several years suggests a deliberate pattern: as exemptions contract, the population of individuals who can actually invoke the statute’s access, deletion, and opt-out rights grows.

The employee and B2B exemptions were always temporary

The CCPA, codified at California Civil Code sections 1798.100 and following, took effect on January 1, 2020, and became enforceable on July 1, 2020. From the outset, the Legislature carved out two large categories of information that did not fit comfortably within a statute framed around the “consumer.” The first covers personal information collected about a natural person acting as a job applicant, employee, owner, director, officer, or contractor of a business — the so-called personnel or HR exemption. The second covers information reflecting a written or verbal communication or transaction between a business and a person acting as an employee or agent of another company, used in a purely B2B context.

Neither carve-out was meant to be permanent. The original sunset was January 1, 2021. The Legislature pushed it back, and AB 1281 (2020) provided a further one-year extension that would take effect only if Proposition 24 failed at the ballot. When the CPRA passed instead, its own text supplied the operative deadline, extending both exemptions to January 1, 2023. Through the 2022 legislative session, bills were introduced that would have prolonged or made these carve-outs permanent, but none was enacted before the session closed on August 31, 2022. Absent intervening legislation, the exemptions sunset on schedule.

What the sunset actually changed

The practical effect is significant in scope rather than in kind. After January 1, 2023, a business otherwise subject to the law must treat California employees, applicants, contractors, and B2B contacts as it treats any other consumer. That means furnishing the privacy notices the statute requires at or before the point of collection, honoring verifiable requests to know, correct, and delete, and respecting opt-outs of the sale or sharing of personal information. It also means extending the CPRA’s newer apparatus — including the right to limit the use of “sensitive personal information,” a defined category covering items such as precise geolocation, racial or ethnic origin, and certain health and biometric data — to the personnel context.

The change does not create new substantive rights so much as it deletes the wall that had kept a large class of Californians from exercising rights everyone else already held. An employer’s collection of payroll, benefits, and performance records, and a vendor’s collection of contact and transaction data about counterparties, now sit squarely inside the statute’s machinery. The compliance burden is real, but the doctrinal move is narrow: an exemption expired, and the default rule reasserted itself.

A sunset is not a transition rule

The lapse of an exemption operates prospectively on obligations, not retroactively to cure data already collected. Information gathered before January 1, 2023 does not become exempt because of when it was acquired; once the carve-out ends, the held data falls within scope and must be surfaced in response to a qualifying request.

The sectoral exemptions that remain — and their limits

The end of the personnel and B2B carve-outs should not be confused with a wholesale collapse of CCPA exemptions. Section 1798.145 still exempts whole bodies of information that are already regulated by federal or state sectoral statutes. Protected health information held by a HIPAA covered entity or business associate, and medical information governed by California’s Confidentiality of Medical Information Act, remain outside the CCPA’s reach. Personal information collected, processed, sold, or disclosed subject to the Gramm-Leach-Bliley Act, and information bearing on creditworthiness that is regulated by the Fair Credit Reporting Act, are similarly exempted to the extent the activity is governed by those regimes.

The recurring limitation is that these exemptions attach to data and to activity, not to entities. A hospital is not categorically beyond the statute; only its HIPAA-governed protected health information is. A financial institution does not escape the CCPA entirely; only the personal information actually handled under the GLBA falls away. The marketing database, the website analytics, the employee records that the CPRA newly reaches — none of that is shielded merely because the business operates in a regulated sector. Courts and regulators have generally read the sectoral carve-outs to track the underlying federal scheme rather than to grant a blanket pass.

Why the breach remedy survives the carve-outs

One feature of the statute resists even the surviving exemptions. The CCPA’s private right of action, available when a consumer’s nonencrypted and nonredacted personal information is exposed in a breach attributable to a business’s failure to maintain reasonable security, operates on a narrower and more durable footing than the access-and-deletion rights. Several of the categorical exemptions in section 1798.145 are written to preserve the breach remedy even where the rest of the statute does not apply. The drafting choice signals a legislative judgment that data-security accountability should be harder to contract or exempt around than the broader transparency regime.

This is part of why narrowing the front-end exemptions matters less for litigation exposure than compliance commentary sometimes suggests. The breach remedy was already reaching data across many of the supposedly exempt categories; the sunset of the personnel and B2B carve-outs principally expands the population of individuals who can make access, correction, and opt-out demands, and who must receive statutory notices.

A pattern of contraction, and what comes next

Read together, these developments describe a single direction of travel. California began with a consumer-privacy statute riddled with temporary accommodations, then let the largest of them lapse on a fixed schedule while retaining only the sectoral exemptions tethered to preexisting federal law. Enforcement authority has likewise consolidated: the CPRA created the California Privacy Protection Agency and vested it with rulemaking and enforcement power, with administrative enforcement of the new provisions commencing July 1, 2023. The institutional message is that the exemptions were scaffolding for a transition, not permanent boundaries.

What remains genuinely unsettled is whether the Legislature will revisit any of the surviving carve-outs, and how the sectoral exemptions will be construed at their edges as agency rulemaking matures. Businesses that read the personnel and B2B sunset as a one-time event, rather than as one move in a longer contraction, are likely to be surprised by the next. For the privacy-rights project that the CCPA and CPRA together advance, the steady narrowing of exemptions is not incidental — it is the mechanism by which the promised protections reach the people the statute names.

Questions readers ask

What were the CCPA’s employee and B2B exemptions?

They were temporary carve-outs that kept most personal information about a business’s own personnel — employees, applicants, contractors, owners, officers — and most data exchanged in a business-to-business context outside the CCPA’s access, deletion, and opt-out rights.

When did those exemptions expire?

They were scheduled to sunset on January 1, 2023. The California Privacy Rights Act set that deadline, and the 2022 legislative session closed without enacting any extension.

What changed for employers after the sunset?

A covered business must treat California employees, applicants, contractors, and B2B contacts like any other consumer: provide the required privacy notices and honor verifiable requests to know, correct, delete, and opt out of sale or sharing.

Does the sunset apply to data collected before January 1, 2023?

The lapse operates prospectively on obligations. Data does not become exempt because of when it was acquired; once the carve-out ends, previously collected personnel and B2B information falls within scope.

Are there still CCPA exemptions after the personnel and B2B carve-outs ended?

Yes. Section 1798.145 still exempts data governed by certain federal and state sectoral laws, including HIPAA-protected health information, medical information under California’s CMIA, and information handled under the Gramm-Leach-Bliley Act and the Fair Credit Reporting Act.

Do the HIPAA and GLBA exemptions cover an entire company?

Generally no. The exemptions attach to specific data and activities governed by those laws, not to the entity. Other personal information a regulated business collects may still fall under the CCPA.

Does the FCRA exemption mean background-check data is fully outside the law?

Activity governed by the Fair Credit Reporting Act is broadly exempted from the CCPA’s main obligations, but the exemption tracks the FCRA-regulated activity rather than every record a business holds about a person.

What is “sensitive personal information” under the CPRA?

It is a defined category that includes items such as precise geolocation, racial or ethnic origin, religious beliefs, genetic and biometric data, contents of private communications, and certain health and sexual-orientation information, with a right to limit its use.

Did narrowing the exemptions create new privacy rights?

Largely it removed a barrier rather than inventing rights. Affected individuals gained access to rights other consumers already held, which is why the practical effect is a larger covered population rather than a new substantive entitlement.

Does a breach claim survive the surviving exemptions?

The CCPA’s private right of action for breaches caused by a failure to maintain reasonable security is written to persist even where several categorical exemptions otherwise apply, reflecting a stronger footing for data-security accountability.

Who enforces these provisions?

The California Privacy Protection Agency, created by the CPRA, holds rulemaking and enforcement authority alongside the Attorney General, with administrative enforcement of the new provisions beginning July 1, 2023.

The Golden Gate Legal Review publishes commentary and analysis for general information; it does not provide legal advice, and readers facing specific compliance questions should consult qualified counsel. Related coverage appears in the journal’s ongoing commentary and case-tracker, including earlier work on employee privacy rights while working from home and on geofence warrants and the Fourth Amendment.

Diane M. Calloway

Diane M. Calloway

Contributing Editor ยท Constitutional Law

Diane M. Calloway writes on the Fourth Amendment, digital privacy, and appellate procedure. A former appellate clerk, she follows how courts apply older search-and-seizure doctrine to new surveillance technology.