The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), is the strictest and most detailed comprehensive privacy law currently in force in the United States, and it is the only one enforced jointly by a dedicated regulator and the state Attorney General. This page sets out how that statute reaches B2B data, what 'sale' and 'sharing' mean for a visitor identification tool, and why lead.box treats company-level resolution as a distinct question from the personal-data rules the CCPA/CPRA is built around.
At a glance
- Framework
- California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Cal. Civ. Code §1798.100 et seq.
- Supervision
- California Privacy Protection Agency (CPPA) and the California Attorney General, sharing enforcement authority
- Usual legal basis
- Legitimate business purpose; identification stays at company level and is not a 'sale' or 'sharing' of personal information for cross-context behavioural advertising
- Processing location
- ISO-certified EU data centres
The CCPA/CPRA and why California is different
Regulation at a glance
- FrameworkCalifornia Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Cal. Civ. Code §1798.100 et seq.
- SupervisionCalifornia Privacy Protection Agency (CPPA) and the California Attorney General, sharing enforcement authority
- Usual legal basisLegitimate business purpose; identification stays at company level and is not a 'sale' or 'sharing' of personal information for cross-context behavioural advertising
- Processing locationISO-certified EU data centres
The CCPA/CPRA, codified at Cal. Civ. Code §1798.100 and following, applies to a for-profit business that does business in California and meets at least one of three thresholds: annual gross revenue over $25 million, buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50% or more of annual revenue from selling or sharing personal information. Any website operator meeting one of these thresholds and receiving California traffic needs to work out where a visitor identification tool sits inside the statute, rather than assuming B2B activity is automatically out of scope.
That assumption used to hold: the original CCPA included temporary exemptions for personal information collected in a business-to-business context and for employee and job-applicant data. Both exemptions were always meant to be temporary, and both expired on 1 January 2023 when the legislature did not renew them again. Since that date, a business contact's name, work email or job title collected in a B2B transaction is personal information under California law in the same way a consumer's is, subject to the same rights of access, deletion, correction and opt-out.
Enforcement is shared between two bodies with different tools: the California Privacy Protection Agency (CPPA), created by the CPRA specifically to write regulations and bring enforcement actions, and the California Attorney General, who retains independent authority to enforce the statute. There is no general cure period built into the current law for most violations, which raises the practical stakes of getting the underlying data flow right rather than assuming a grace period exists to fix a documented mismatch after the fact.
The B2B dimension: California covers it, most other states do not
This is the point that sets California apart from Virginia, Colorado, Connecticut, Texas and the other comprehensive state privacy laws in this cluster: those statutes define a covered 'consumer' as a natural person acting in an individual or household context and expressly exclude data processed about a person acting in a commercial or employment capacity. California removed that exclusion. A work email address, a job title, or a business phone number tied to an identified employee visiting your site from California is personal information under the CCPA/CPRA, full stop, regardless of whether the relationship is B2B.
For a visitor identification product, the practical question becomes whether the data collected is 'personal information' at all, and separately, whether any disclosure of it counts as a 'sale' or 'sharing' under the statute's specific definitions. 'Sharing' in particular covers disclosure for cross-context behavioural advertising, and California consumers have a standing right to opt out of it, which is why Global Privacy Control (GPC) exists as a browser-level signal a site is expected to honour as a valid opt-out request without further steps from the visitor. Sensitive personal information, a category the CPRA introduced with its own stricter rules, adds a further layer businesses need to track separately.
lead.box resolves the organisation behind a visit from network-level signals — IP ranges associated with a company, not a named individual — and does not transmit that signal to advertising networks or build cross-site advertising profiles, so it does not fall into the 'sharing' category the GPC opt-out is designed to catch. That distinction matters more in California than anywhere else in this cluster precisely because the B2B exemption that would otherwise settle the question elsewhere does not exist here.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
What this means for a California sales or marketing team
Procurement teams reviewing a vendor in California increasingly ask CCPA/CPRA-specific questions that would not come up in a Colorado or Connecticut review: whether a tool sells or shares personal information, whether it recognises Global Privacy Control, and whether any of the resolved data qualifies as sensitive personal information. A clear, written answer describing company-level resolution, the absence of advertising disclosure, and GPC handling tends to move a review forward faster than a general privacy statement.
Because enforcement runs through two separate bodies, legal teams in California also tend to ask for documentation they can hold on file rather than take on trust: a data processing agreement, a sub-processor list, and a plain description of what triggers a company-level match. lead.box provides the same documentation set requested by European customers, adjusted to reference the CCPA/CPRA specifically, so a California legal or privacy team can complete its own review without starting from a blank page.
None of this is a substitute for legal advice. The CCPA/CPRA's thresholds, its 'sale' and 'sharing' definitions, and its treatment of sensitive personal information are detailed and continue to be shaped by CPPA rulemaking, so a business relying on the exemptions or scope questions discussed here should have its own counsel confirm how the statute applies to its specific data flows before relying on any general description, including this one.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Yes, and this is the fact that separates California from most other US states with comprehensive privacy laws. The original CCPA included a temporary exemption for personal information collected in a business-to-business context, alongside a separate temporary exemption for employee and job-applicant data. Both were extended year over year by the legislature, but neither was renewed again after 1 January 2023, so both exemptions expired on that date. Since then, a business contact's name, work email address, job title or business phone number collected through a B2B interaction is personal information under the CCPA/CPRA on the same footing as a consumer's data, subject to the same access, deletion, correction and opt-out rights. Businesses operating in California, or receiving traffic from California, that assumed B2B data was automatically outside scope should revisit that assumption, ideally with counsel, since it has not been accurate for several years.
The CCPA/CPRA defines 'sale' around disclosure for money or other valuable consideration, and 'sharing' around disclosure for cross-context behavioural advertising specifically, and both definitions describe a different data flow than company-level identification. lead.box resolves the organisation behind a website visit from network-level signals such as IP address ranges, without identifying a named individual, and does not transmit that information to advertising networks or use it to build cross-site advertising profiles. That means the activity does not match the fact pattern either definition is built to reach, but confirming this against your own specific implementation and your own privacy notice remains the business's responsibility under California law, since the statute's definitions and CPPA guidance continue to develop and a general description like this one cannot substitute for that review.
Global Privacy Control (GPC) is a browser or extension-level signal that a California consumer can enable once, which the CCPA/CPRA treats as a valid, standing request to opt out of the sale or sharing of personal information, without the consumer needing to submit a separate opt-out form on every site they visit. Sites subject to the CCPA/CPRA are expected to detect and honour that signal. Because lead.box does not sell or share personal information for cross-context behavioural advertising in the first place, its company-level identification activity is not the kind of processing GPC is designed to stop, but a business layering other tools with genuine sale or sharing activity onto the same site still needs its own GPC handling for those other tools, independent of how lead.box operates.
Enforcement is shared between two bodies, which is unusual among US privacy statutes. The California Privacy Protection Agency (CPPA), created specifically by the CPRA, writes implementing regulations and can bring its own enforcement actions, including administrative proceedings. The California Attorney General retains separate, independent authority to enforce the statute as well, so a business can in principle face scrutiny from either body. There is no general statutory cure period for most current violations, unlike some other state privacy laws in this cluster that give a business a defined window to fix a documented issue before penalties apply. That makes accurate, specific documentation of what a visitor identification tool does — and does not do — a more immediate priority for a California-facing business than for one operating only in states with a standing cure period.
The CCPA/CPRA gives California consumers rights including access, deletion, correction and opt-out of sale or sharing, and since the B2B exemption expired those rights extend to business contacts too. Because lead.box does not sell or share personal information as those terms are defined by the statute, and does not link resolved company data to a named individual's profile, the specific opt-out-of-sale-or-sharing mechanism is not the operative right for this activity. A business running lead.box on a California-facing site should still maintain a general privacy notice describing this processing and a route for a visitor to raise a request, since the broader set of CCPA/CPRA rights and the business's own disclosure obligations exist independently of whether any single vendor's activity meets the definition of a sale or sharing.
The CCPA/CPRA's rights and obligations attach to personal information reasonably linkable to an identified or identifiable natural person or household. lead.box resolves which organisation is visiting a site — a company name, industry and size band, inferred from network-level signals such as IP address ranges — without identifying which specific employee is browsing, and without producing a list of named contacts, job titles or personal email addresses. That is a materially different output than a tool that identifies an individual visitor, and it is the reason company-level identification raises a different set of questions under California law than, say, a form-fill or an email-append service would. The distinction is worth stating explicitly in your own privacy documentation rather than assumed, since 'B2B' and 'company-level, not individual-level' are two separate scope questions under the statute, not one.
Expect a California-facing review to ask, at minimum, whether the tool sells or shares personal information as those terms are statutorily defined, how it handles the Global Privacy Control signal, whether any sensitive personal information is collected, and what documentation exists to support those answers, such as a data processing agreement and a sub-processor list. lead.box provides that documentation set on request, describing the mechanism plainly enough for a privacy team to check it against the CCPA/CPRA's current text and any applicable CPPA regulations. Because the statute and its implementing regulations continue to evolve, and because this description is written for general orientation rather than as a compliance opinion, a business should have its own counsel confirm the current requirements before finalising an approval, rather than relying solely on a vendor's own summary.
No. This page explains, at a general level, how the CCPA/CPRA's scope, its 'sale' and 'sharing' definitions, and its enforcement structure relate to company-level visitor identification, and it is not a substitute for legal advice about your specific business, your specific data flows, or your specific California traffic. lead.box acts as a processor under a data processing agreement and can provide documentation describing what the product does and does not collect, but it does not and cannot issue a compliance opinion binding on a customer's own use of the tool alongside its other systems, disclosures and vendors. Given the joint CPPA and Attorney General enforcement structure and the absence of a general cure period, a business should have qualified counsel review its complete data practices, including but not limited to its use of lead.box, before relying on any vendor's description as sufficient on its own.
See which California companies are already researching you
Install a first-party snippet, review the same CCPA/CPRA-specific documentation your legal team will ask for, and turn quiet research into a company name your sales team can act on.