← Back to Blog 20 U.S. States, No Federal Floor. Your Cold Email Has to Pass California's Test—Even if You're in Texas.

20 U.S. States, No Federal Floor. Your Cold Email Has to Pass California's Test—Even if You're in Texas.

20 U.S. states now enforce comprehensive privacy laws with no federal preemption. Here's how B2B sellers can comply without slowing down outbound.

Twenty U.S. states now enforce comprehensive privacy laws. There is no federal baseline. That means your cold email program is legally bound by the strictest state rules that apply to your prospects, not your own office address. California remains the de facto national standard, so aligning with CCPA/CPRA covers most of the ground. Here's the map we use.

California is the floor, not the ceiling

We built MiraReach for founders and small sales teams who run their own pipeline. Compliance is not the sexy part of the job, but it is the part that gets you sued if you get it wrong. The good news: you do not need to track 20 separate rulebooks.

California's CCPA, amended by CPRA, is the most mature and the most enforced. It applies to any for-profit business that collects personal information from California residents and meets one of three thresholds: $25M+ annual revenue, buys or sells personal info of 100K+ consumers, or derives 50%+ of revenue from sharing personal info. Most B2B SaaS companies at scale trip at least one of those wires.

Here is what CCPA/CPRA actually requires for outbound sales:

If you are using a tool that auto-enriches prospect emails from third-party sources, you are "sharing" personal information under CPRA. That triggers the opt-out link requirement. No way around it.

The other 19 states are not identical, but they rhyme

Virginia, Colorado, Connecticut, Utah, and Texas were the early adopters. Then came Montana, Oregon, Tennessee, Florida, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Maryland, Minnesota, Nebraska, Rhode Island, and Vermont. Each has its own quirks. None of them are as strict as California on the B2B side.

The practical differences matter less than you think. Most state laws exempt business-to-business communications to a degree, but the exemptions are narrower than they look. Colorado and Connecticut, for example, do not have a blanket B2B exemption. They apply to personal information collected in a business context, which includes work email addresses.

What this means for your outreach: a work email address is personal information in most states. The "it's a business email, so it's fair game" argument died around 2021. If you are scraping LinkedIn or buying lists, you are collecting personal information. If you are sending to those addresses without a lawful basis, you are exposed.

What actually changes in your workflow

We run outbound for our own pipeline and we have tested what compliance does to reply rates. The short version: almost nothing, if you build it in from the start.

Three things we changed after the first wave of state laws went live:

1. We stopped buying lists entirely. Not because it is illegal, but because the legal basis is murky in states like Colorado. Instead, we use MiraReach to find prospects from public sources and company websites. That gives us a defensible position: the prospect's work email was published by their employer for business contact purposes.

2. We added a one-line opt-out to every email footer. Not the long legalese block. Just: "If this is not relevant, reply 'unsubscribe' and I will not contact you again." That satisfies the spirit of most state laws and it actually improves deliverability. People reply "unsubscribe" instead of marking you as spam.

3. We built a suppression list that syncs across every campaign. If someone opts out in one sequence, they are gone from all sequences. This is table stakes now. If you are running multiple tools and manually managing suppression, you are one mistake away from a complaint.

The enforcement reality is quieter than the headlines

State attorneys general are not raiding SDR teams. The first wave of enforcement has targeted data brokers and large platforms, not small B2B sellers. But the private right of action in California is the real risk. CPRA gives consumers a private right of action for data breaches involving certain categories of personal information. If you get breached and you did not have reasonable security measures, you are exposed to statutory damages of $100 to $750 per consumer per incident.

For a small team, that math gets ugly fast. A breach of 10,000 records at $500 per record is a $5M exposure. That is existential for a five-person company.

The practical takeaway: your email sending tool matters. If you are using a cheap tool that stores prospect data in plain text or lacks basic access controls, you are the weak link. We wrote about how the EU AI Act changes cold email setups earlier this year, and the same logic applies here. The tool you use is your security posture.

What we would do next

If you are starting from scratch, align with CCPA/CPRA first. It covers the strictest rules and most of the population. Then check whether your state has its own law and whether it adds anything material. Most do not for B2B outreach.

If you are already running outbound, audit your data sources. Where did each prospect email come from? If you cannot answer that in under 30 seconds, you have a compliance problem hiding in your pipeline.

We built MiraReach to keep this simple. It finds prospects from public sources, scores inboxes, and drafts personalized emails. It never sends anything without you pressing the button. That means you stay in control of consent, suppression, and the paper trail. See how MiraReach handles this if you want to stop worrying about the patchwork and start sending.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →