The United States has no single federal privacy statute; instead a patchwork of state laws and FTC enforcement shapes what a website may quietly collect. This page sets out that framework, how lead.box LLC — itself a Wyoming company — is positioned inside it, and why the product is built to the stricter European standard rather than the minimum a US site could get away with.
At a glance
- Framework
- No general federal privacy law; state laws (e.g. CCPA/CPRA in California, plus Virginia, Colorado, Connecticut, Texas) and FTC Act Section 5
- Supervision
- FTC (unfair or deceptive practices) plus state attorneys general and state privacy agencies
- Usual legal basis
- Legitimate business purpose; identification stays at company level, outside the definition of a 'sale' or 'sharing' of personal information
- Processing location
- ISO-certified EU data centres
The legal framework in the United States
Regulation at a glance
- FrameworkNo general federal privacy law; state laws (e.g. CCPA/CPRA in California, plus Virginia, Colorado, Connecticut, Texas) and FTC Act Section 5
- SupervisionFTC (unfair or deceptive practices) plus state attorneys general and state privacy agencies
- Usual legal basisLegitimate business purpose; identification stays at company level, outside the definition of a 'sale' or 'sharing' of personal information
- Processing locationISO-certified EU data centres
There is no general federal data protection law comparable to the GDPR. Instead, a growing number of states have passed their own comprehensive privacy statutes — California's CCPA, as amended and expanded by the CPRA, was first, and Virginia, Colorado, Connecticut, Texas and others have since added their own versions with overlapping but not identical definitions of personal information, consumer rights and business obligations. A website operating nationally has to track which state laws apply to its visitors rather than reading a single rulebook.
At the federal level, the Federal Trade Commission enforces Section 5 of the FTC Act against unfair or deceptive practices, which in privacy terms mostly means: say what you do, and do what you say. There is no FTC registration or pre-approval process for a tool like lead.box; the practical constraint is that public statements about data handling need to match the actual mechanism, because a mismatch is exactly what the FTC pursues.
lead.box LLC is itself organised in Sheridan, Wyoming, which means the company sits inside the same US legal environment as its customers rather than observing it from outside. Because the product was originally built to satisfy GDPR-level obligations, it applies that stricter standard as the common baseline everywhere it operates, including for US customers and US website visitors, rather than maintaining a separate, looser US configuration.
What US buyers and legal teams expect
A procurement or legal review in the US rarely starts with 'is this CCPA-compliant' as a checkbox; it starts with what data is collected, whether it is sold or shared for advertising, and whether an individual is being tracked or profiled. lead.box identifies the visiting company from firmographic and network signals, not the individual person, and it does not sell or share personal information for cross-context behavioural advertising — those are useful facts for a review, not a certificate to wave.
The second expectation is a plain description of scope: no advertising identifiers, no device fingerprinting for ad targeting, no building of a profile that follows a person across unrelated sites. Company-level identification sits outside that category of activity by design, but confirming that against your own state's definitions, and against your own privacy notice, remains the customer's responsibility as the business (in CCPA/CPRA terms) or controller.
Third, buyers expect a written processing agreement and a clear answer on where data lives. lead.box processes data in ISO-certified EU data centres and publishes its sub-processor list, so a US legal team can review the same documentation a European one would ask for, adjusted for the state laws that actually apply to their business.
Start free
Install the snippet and see the first named companies on your own traffic.
State privacy laws in the United States
There is no single federal privacy statute, so the rules that matter depend on the state your buyer sits in. Each page below sets out one state law, who enforces it, and how it treats business-to-business data.
- CaliforniaLaw: CCPA/CPRA
The one state law in this cluster that also covers B2B contact data — the temporary business-to-business exemption expired at the start of 2023.
- TexasLaw: TDPSA
No revenue or volume threshold, a broad small-business test, and a clean carve-out for data processed in a commercial context.
- VirginiaLaw: VCDPA
The template most later state laws copied: consumer-only scope, assessment duties, and enforcement by the Attorney General alone.
- ColoradoLaw: CPA
The only state in this cluster with detailed implementing rules and an official list of recognised universal opt-out mechanisms.
- ConnecticutLaw: CTDPA
A consumer-scoped statute whose cure period has already sunset, in a state whose insurers run long vendor questionnaires.
- UtahLaw: UCPA
The lightest-touch comprehensive statute in the country, with a conjunctive revenue test and a two-step enforcement path.
- OregonLaw: OCPA
A wide definition of personal data and a right to a list of named third-party recipients that no peer statute matches.
- MontanaLaw: MCDPA
The lowest applicability threshold in the United States, which pulls in mid-sized companies that stay out of scope elsewhere.
- FloridaLaw: FDBR
Not a general privacy law: its controller duties target a very narrow class of very large online platforms.
- New JerseyLaw: NJDPA
A wider second applicability prong, financial data treated as sensitive, and rulemaking still to come.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off in the US market
The pattern repeats across US SaaS, professional services and industrial suppliers with a national sales motion: a multi-person buying committee researches quietly for weeks across several sessions and IP addresses before anyone books a call. Seeing the company name early lets a sales rep reach out during the evaluation window instead of after a competitor already closed the deal.
It also fits companies selling into regulated or enterprise accounts, where a single identified visit from a target account is worth a personalised follow-up regardless of overall traffic volume. A modest US site with a few hundred weekly visits can still surface a workable list of companies worth a call, without needing individual-level tracking to do it.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
There is no single federal privacy statute in the US, so the answer runs through whichever state laws apply to your visitors: California's CCPA/CPRA, Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, and the newer statutes that followed them in Texas and elsewhere. Most of these laws build their obligations around personal information tied to an identified or identifiable individual, and several explicitly carve business-to-business contact and transaction data out of consumer rights provisions or narrow their scope in ways that are relevant here. lead.box resolves a visiting company from network-level signals rather than singling out a named person, which is the fact pattern that matters when a state statute is applied to this specific activity. Whether that keeps a given deployment fully outside a particular state's definitions is a question for the organisation running the site, since the statutory text and interpretive guidance differ state by state. lead.box acts as processor under a data processing agreement and leaves that legal assessment to the controller or business, as the relevant state law defines that role.
CCPA/CPRA and the comparable state statutes define 'sale' and 'sharing' around the disclosure of personal information for money or other valuable consideration, or for cross-context behavioural advertising, and they are built to address a different data flow than company-level identification. lead.box does not transmit visitor-level personal information to advertising networks, does not build cross-site advertising profiles, and does not exchange data for consideration in the sense these statutes describe; it resolves a visiting organisation from network signals and returns a company name to the site operator that installed it. That distinction is worth documenting precisely rather than assumed, because state definitions vary and some enforcement actions have turned on exactly this kind of disclosure question. Reviewing the specific data flow against your own privacy notice and against the state laws that apply to your visitor base is the organisation's own responsibility as the business or controller; lead.box supports that review with documentation but does not issue a compliance opinion on your behalf.
There is no dedicated federal privacy regulator for a tool like this. The Federal Trade Commission enforces Section 5 of the FTC Act against unfair or deceptive practices, which in privacy terms means public statements about data handling have to match what actually happens; a mismatch, not the underlying activity itself, is what typically draws FTC attention. Alongside the FTC, state attorneys general enforce their own comprehensive privacy statutes, and California additionally has a dedicated agency, the California Privacy Protection Agency, with its own rulemaking and enforcement authority. Because enforcement is distributed across multiple bodies rather than centralised, the practical discipline for any site operator is accurate, specific disclosure of what a visitor identification tool does and does not collect, rather than relying on any single approval or registration, since none exists for this category of software in the United States.
Company-level identification through lead.box does not read from or write to the visitor's browser storage, does not set advertising identifiers, and does not rely on a persistent device identifier the way analytics or ad-tech tags typically do, so it does not depend on the consent mechanisms that a US cookie or tracking-preference banner is built to capture. That means the snippet's own operation does not require sitting behind a consent gate for its own purpose. Whether the rest of the site needs a cookie banner is a separate matter entirely, governed by whatever combination of state law, industry practice and the site's own other tools applies, and it remains the operator's decision as controller of the site as a whole. Documenting this distinction clearly for whoever manages the site's consent tooling avoids the tool being lumped in with advertising trackers it does not resemble.
Yes, and this comes up often: a growing number of US buyers on this page are subsidiaries, portfolio companies or licensees of a European parent, and that parent's group-wide privacy policy frequently requires every vendor, including ones only serving US traffic, to sign the same data processing agreement used for EU entities rather than a lighter US-specific version. lead.box was built to GDPR obligations as its baseline rather than to the minimum required by any single US state, so the same Art. 28-style processing agreement, the same published sub-processor list, and the same EU processing location apply regardless of whether the signing entity is based in Wyoming, California or Frankfurt. That consistency tends to shorten procurement for US subsidiaries of European groups, since legal does not need to negotiate a separate, weaker contract just because the buying entity happens to sit in the US.
The service resolves network-level signals from a website visit — primarily IP address ranges associated with organisations — into a company name, industry and size band, without identifying a named individual, without setting cookies or device fingerprints, and without building a profile that follows a person across unrelated websites. No form submissions, email addresses or account logins are required for identification to occur, and nothing about the visit is linked back to a specific employee. What is stored is a record that a given organisation visited certain pages during a certain window, which is the input a sales team uses to prioritise outreach. What is explicitly not produced is a list of named people, their job titles or their contact details, since that would be a materially different and more sensitive category of data than company-level identification is designed to handle.
US B2B sales organisations vary widely in tooling, from tightly instrumented Salesforce or HubSpot pipelines with automated lead scoring to smaller teams running mostly off spreadsheets and a shared inbox, and lead.box is built to slot into either pattern rather than force a new workflow. Identified companies can be exported as CSV or Excel files for a rep to work manually, or pushed automatically by webhook into an existing CRM so a named account gets flagged the moment research activity appears. For companies running account-based marketing against a defined target list, the more useful signal is often which named accounts are visiting and which pages they are reading, rather than a raw volume count; for higher-volume inbound motions, a daily or weekly digest of newly identified companies tends to be the practical starting point before deeper CRM automation is built out.
Identification relies on mapping IP address ranges to organisations, which works reliably for visits from an office network, a corporate VPN or a fixed business connection, but is inherently less precise for visitors on residential ISPs, mobile carrier networks, shared coworking spaces or consumer VPN services, where the underlying network range is not clearly tied to one company. In practice this means some US visits, particularly from remote or hybrid employees on home internet, will not resolve to a company at all rather than resolving incorrectly, and match rates vary by industry and by how a given company's network infrastructure is set up. Sales teams should treat the identified company list as a prioritisation signal for further outreach and verification, not as a confirmed record of who specifically viewed which page, and the controller remains responsible for how that signal is used downstream.
See which US companies are already on your site
Install a first-party snippet, watch the first companies appear, and hand your legal team the same documentation a European customer would ask for.