Is buying B2B contact data legal for staffing agencies?
Is buying B2B contact data legal in 2026? Yes, under CAN-SPAM and TCPA — but CCPA's B2B exemption expired in 2023. See what actually applies.

Yes, buying B2B contact data is legal for staffing agencies in the U.S. — the FTC and most state laws regulate how you contact someone, not whether a data vendor can sell you a hiring manager's name, title, and work email. The catch is California: the CCPA dropped its business-contact exemption on January 1, 2023, so hiring-manager records tied to California companies now carry the same opt-out and deletion rights as consumer data. Email outreach still has to follow the CAN-SPAM Act no matter where the list came from, and cold calls or texts fall under the TCPA instead.
TL;DR
- Buying B2B contact data is legal for staffing agencies when outreach follows CAN-SPAM and TCPA rules.
- California's CCPA dropped its B2B exemption on January 1, 2023 — business contacts now carry opt-out rights.
- The law cares about how you contact someone, not where the list came from.
- Scraped or purchased LinkedIn data raises separate contract and terms-of-service questions, not just privacy law.
- Rules vary by state and by channel — confirm current requirements with counsel before a large outreach push.
Why this matters
Staffing agencies live on cold outreach to hiring managers who never asked to be found. Buying contact data instead of manually researching every company saves the kind of hours a full-desk recruiter doesn't have, which is why so many agencies lean on staffing lead generation experts or a dedicated tool instead of a spreadsheet built by hand.
The legal exposure most agencies worry about — getting sued for "buying a list" — almost never happens that way. The real risk sits in the follow-up: sending commercial email without an opt-out link, texting a cell number without consent, or reusing a California contact's data after they've asked you to delete it. Read the specifics on running cold outreach within CAN-SPAM rules before your BD team sends the first sequence in 2026.
Is buying B2B contact data legal for staffing agencies?
It's legal, and the answer splits cleanly by channel and by where the contact lives. Here's the breakdown that actually matters for a staffing BD team:
| Data type | Governing law/agency | Key requirement | Applies to your outreach when |
|---|---|---|---|
| Business email addresses (US) | CAN-SPAM Act, enforced by the FTC | Accurate header info, valid physical address, working opt-out | Every cold email sequence you send |
| Cold calls and texts | TCPA, enforced by the FCC | Restrictions on automated dialing/texting to wireless numbers | Your BD team dials or texts a hiring manager's cell |
| California business contacts | CCPA/CPRA, enforced by the California AG | Opt-out and deletion rights now extend to B2B records | The contact's company is based in California |
| EU/UK contacts | GDPR / UK GDPR | Legitimate-interest basis or opt-in, depending on use | You're prospecting a hiring manager based in the EU or UK |
The bottom line: the purchase is legal, the outreach method is what creates liability. A verified work email you bought last week is treated the same under CAN-SPAM as one you found manually — the law doesn't ask how the address landed in your CRM.
Email outreach: what CAN-SPAM actually requires
CAN-SPAM applies to any commercial email, whether the address came from a purchased list, a scraped page, or your own research. It requires a truthful subject line, your agency's physical address in the footer, and a working way to opt out that you honor promptly. It does not require opt-in consent before the first email — that's the part people confuse with GDPR.
Cold calls and texts: where TCPA kicks in
The TCPA governs automated or prerecorded calls and texts to wireless numbers, and it's stricter than CAN-SPAM by design. If your team is manually dialing a landline at a hiring manager's office, TCPA exposure is low. If a tool is auto-texting a personal cell number pulled from a purchased dataset, the calculus changes — confirm with counsel how your specific dialing setup is classified before scaling it.
California contacts: CCPA/CPRA changed the exemption in 2023
Before January 1, 2023, California's privacy law carved out an exemption for data collected in a B2B or employment context. That exemption expired, and business contact information tied to California is now subject to the same core rights as consumer data: the right to know what's held, the right to opt out of sale/sharing, and the right to request deletion. If a chunk of your target list sits in California, build a process for handling those requests — it's now part of running outreach there, not an edge case.
Scraping vs. buying: a different legal question entirely
Buying data from a vendor and scraping it yourself sit under different bodies of law. Buying is a privacy and marketing-compliance question — CAN-SPAM, TCPA, state statutes. Scraping a site like LinkedIn against its terms of service is a contract and, in some readings, a computer-fraud question, separate from whether the resulting data can legally be emailed. A vendor's sourcing method matters more than most agencies realize, because it determines which of those two legal buckets your risk falls into.
Why the legal picture varies
A handful of variables decide how much compliance work a given outreach push actually requires:
- The channel — email, call, text, and LinkedIn message each sit under different rules
- The contact's state — California's CCPA/CPRA is the strictest so far, and other states are adding their own privacy statutes
- Whether the contact is US-based or EU/UK-based — GDPR territory changes the consent requirement entirely
- How the vendor sourced the record — public filings and opt-in forms carry less risk than scraped personal profiles
- Whether the message counts as "commercial" under CAN-SPAM — a straightforward sales pitch almost always does
- Your agency's own data retention practices — deletion requests have to actually be honored, not just accepted
"The purchase is legal, the outreach method is what creates liability."
Is scraping LinkedIn for hiring manager contacts legal?
Scraping public LinkedIn data is not automatically illegal under privacy law, but it can breach LinkedIn's own terms of service, which is a contract issue separate from CAN-SPAM or CCPA. Courts have treated scraping publicly visible profile data differently than logging in and scraping behind the login wall — the second is the riskier version. Either way, a scraped list still has to follow CAN-SPAM once you start emailing from it.
Do I need consent before emailing a hiring manager?
No, CAN-SPAM does not require opt-in consent before a first commercial email in the U.S. — you need accurate sender information and a working opt-out, not prior permission. That changes if the contact is based in the EU or UK, where GDPR generally requires a lawful basis such as legitimate interest or consent before you email them.
Is it legal to buy email lists for cold outreach in 2026?
Yes, buying email lists for cold outreach is legal in 2026 under the same framework described above: CAN-SPAM for the email itself, TCPA if you're also calling or texting, and CCPA/CPRA for any contacts tied to California. What's changed by 2026 isn't the legality of the purchase — it's the number of states layering on their own privacy statutes, which is why a list bought two years ago may need a fresh compliance check today.
StaffingLeads builds contact records from hiring, funding, and network signals rather than a static purchased file, and verifies the work email before it reaches a sequence — but the same CAN-SPAM and TCPA rules above still apply to whatever tool you use to send the outreach. If your team is weighing a dedicated lead gen tool against just using Sales Navigator for prospecting, the compliance obligations don't change either way — only the sourcing method does.
See how compliant sourcing works
Watch how verified hiring-manager contacts move into an outreach sequence.
FAQ
Is buying B2B contact data legal for staffing agencies?
Yes, buying B2B contact data is legal for staffing agencies in the U.S. as long as outreach follows CAN-SPAM for email and TCPA for calls and texts. The purchase itself isn't regulated the way the follow-up contact is.
What is the CAN-SPAM Act and does it apply to B2B email?
The CAN-SPAM Act is a federal law enforced by the FTC that governs commercial email, and it applies fully to B2B outreach. It requires a truthful subject line, a physical address, and a working opt-out link, but not prior opt-in consent.
Does GDPR apply to a U.S. staffing agency emailing EU contacts?
Yes, GDPR applies whenever you email a hiring manager physically based in the EU or UK, regardless of where your agency is located. It generally requires a lawful basis such as legitimate interest or opt-in consent before that first email.
Is cold calling hiring managers legal?
Cold calling hiring managers on business landlines is generally lower risk, while automated or prerecorded calls to wireless numbers fall under the TCPA and carry stricter requirements. Manual dialing from a real person is treated differently than an autodialer under most readings of the law.
What happened to CCPA's business-to-business exemption?
California's CCPA business-to-business exemption expired on January 1, 2023, so B2B contact records tied to California companies now carry the same opt-out and deletion rights as consumer data. Agencies with California-based targets need a process for handling those requests.
Is LinkedIn scraping against the law?
Scraping publicly visible LinkedIn data is not automatically illegal under privacy statutes, but it can breach LinkedIn's terms of service, which is a separate contract-law issue. Scraping behind the login wall carries more legal risk than scraping public profile pages.
Do state privacy laws besides California affect staffing outreach?
Yes, a growing list of states have passed their own privacy statutes since California's CCPA, and coverage of business contact data varies by state. Confirm current requirements with counsel for any state where a large share of your target list is based.
Can staffing agencies buy contact data from any vendor?
Legally, yes, but the vendor's sourcing method determines your downstream risk more than the purchase agreement does. A vendor that builds lists from public filings and verified signals carries less exposure than one built from scraped, login-gated data.
One last thing
The part of this question agencies skip is the vendor conversation. The purchase agreement doesn't create your legal exposure — the sourcing method behind the list does, and most agencies never ask a vendor how a hiring-manager email was actually collected. Before your next outreach push in 2026, ask any data vendor directly whether records come from public filings and signals or from scraped, login-gated profiles, and get that answer in writing.
Related guides
Let your agent start the conversations.
StaffingLeads watches hiring, funding, past-client and network signals, finds the decision-maker behind each one, and sends personalised email and LinkedIn outreach in your voice. You pick up the replies.
Start your 14-day free trial →Keep reading
Free, no signup