Employee and B2B Data

Most U.S. privacy laws exempt employee and B2B data, but that is no longer the case with the CCPA. Under the California law, this data is treated the same as personal information from any other source, such as customers and website visitors.

Because of this, businesses must make a fundamental shift in how they think of employee and B2B data, treating it with the same diligence as they do the data of other consumers. They should take a fresh look at their data privacy practices, paying particular attention to the following areas.


Privacy Disclosures

The CCPA requires businesses to disclose information about their data practices as well as inform consumers of their privacy rights. These disclosures must be made at or before the point of collection.

For employees, businesses already have to disclose what personal information they are collecting and why. This is typically done as part of the job application and onboarding of new employees. Now these disclosures must be expanded, and include a description of the CCPA's privacy rights.

As for B2B data, businesses did not have any disclosure responsibilities before; now they must consider their collection points and how to direct B2B contacts to the required information. At the least, this will likely mean including privacy policy links in business emails.


Access Requests

Honoring requests to know/access personal information has the potential to be problematic for these two groups, especially for employees. Businesses tend to collect large volumes of personal information on employees, from biographical data to internal messages to timesheets. Performance reviews can be of particular sensitivity, as they may contain frank assessments of an employee’s abilities and personality. Access requests may also be precursors to litigation, especially from former employees. When deciding how to respond to these requests (for example, whether some data should be redacted), it is a good idea to consult with an attorney.


Deletion Requests

Consumers have the right to request the deletion of their personal information, and this right is now being extended to employees and B2B contacts. With particular regard to employees, the ability to have their personnel records deleted could create chaos. Fortunately, the CCPA recognizes a number of important exceptions where a business may deny a request to delete, including:

  • To comply with a legal obligation
  • To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer’s relationship with the business and compatible with the context in which the consumer provided the information.

These two exceptions will likely apply to most employee and B2B data, provided they are not exploiting that data for wider purposes or disclosing it to third parties.