Markets

B2B website visitor identification under Colorado's privacy law

Denver and Boulder software teams are used to a research-heavy buying cycle: a technical evaluator reads documentation and pricing pages for weeks, loops in a manager, and only then books a call. Company-level identification turns those quiet visits into a company name your sales team can act on, well before a form gets filled in.

  • FrameworkColorado Privacy Act (CPA), Colo. Rev. Stat. §6-1-1301 et seq., plus the Colorado Privacy Act Rules
  • SupervisionColorado Attorney General and district attorneys, enforced as a deceptive trade practice
  • Usual legal basisLegitimate business purpose; identification stays at company level, outside the CPA's definition of 'consumer' data
  • Processing locationISO-certified EU data centres

Colorado was the third state to pass a comprehensive consumer privacy law, and it went a step further than most by backing the statute with detailed rules from the Attorney General's office. This page walks through the Colorado Privacy Act, what its rulebook actually covers, and why purely business-to-business visitor data sits outside its reach in a way that differs sharply from California's approach.

At a glance

Framework
Colorado Privacy Act (CPA), Colo. Rev. Stat. §6-1-1301 et seq., plus the Colorado Privacy Act Rules
Supervision
Colorado Attorney General and district attorneys, enforced as a deceptive trade practice
Usual legal basis
Legitimate business purpose; identification stays at company level, outside the CPA's definition of 'consumer' data
Processing location
ISO-certified EU data centres

The Colorado Privacy Act and its Rules

Regulation at a glance

  • FrameworkColorado Privacy Act (CPA), Colo. Rev. Stat. §6-1-1301 et seq., plus the Colorado Privacy Act Rules
  • SupervisionColorado Attorney General and district attorneys, enforced as a deceptive trade practice
  • Usual legal basisLegitimate business purpose; identification stays at company level, outside the CPA's definition of 'consumer' data
  • Processing locationISO-certified EU data centres

The Colorado Privacy Act (CPA), codified at Colo. Rev. Stat. §6-1-1301 et seq., took effect on 1 July 2023 and applies to a controller that conducts business in Colorado or targets Colorado residents and either controls or processes the personal data of 100,000 or more Colorado consumers in a calendar year, or of 25,000 or more consumers while deriving revenue or a discount on goods or services from selling personal data. There is no revenue-only threshold as such — a business with substantial national revenue but a small Colorado footprint can fall entirely outside the CPA if it does not clear either consumer-count test.

What sets Colorado apart from most of its peer states is that the statute is not left to stand alone: the Attorney General has issued a detailed set of Colorado Privacy Act Rules covering topics such as the mechanics of consumer rights requests, requirements for data protection assessments, universal opt-out signal recognition and profiling disclosures. That level of implementing detail is unusual for a state privacy law and gives Colorado a more prescriptive, almost regulation-like character compared with statutes that leave more to later interpretation.

Enforcement sits with the Colorado Attorney General and, notably, with local district attorneys, who can also bring actions under the statute; violations are treated as deceptive trade practices under Colorado's existing consumer protection law. The CPA originally included a cure period allowing 60 days to fix a violation before an enforcement action proceeded, but that cure right was written to sunset on 1 January 2025, after which the Attorney General retains discretion whether to offer an opportunity to cure at all.

Why B2B contact data sits outside Colorado's consumer scope

The CPA defines 'consumer' narrowly: a Colorado resident acting only in an individual or household context. The statute explicitly excludes an individual acting in a commercial or employment context — someone acting as a job applicant, an employee, or a representative of a business dealing with another business. That means data generated when a company's own employee visits a supplier's website in the course of their job, such as a name, work email or job title captured on a form, falls outside the CPA's consumer rights and obligations entirely, because it was never within scope in the first place.

This is the opposite of what happened in California. The CCPA originally carried temporary exemptions for business-to-business and employment-context personal information, but those exemptions expired on 1 January 2023, and the CPRA now folds B2B contact data squarely into the same consumer rights regime as any other personal information. Colorado never had a B2B exemption to expire — it built the individual-or-household-context limitation into the statute's core definition from the outset, so the exclusion is permanent by design rather than a lapsed transitional carve-out.

That leaves a third, separate distinction worth stating plainly: lead.box does not resolve either category of person. It identifies the organisation behind a website visit — a company name, industry and size band derived from network-level signals — without producing a named individual's contact details at all. Whether Colorado's B2B exclusion would apply to a given data point is a question the CPA answers only for personal data tied to an identifiable person; company-level identification is a different question again, and one that a Colorado business should still confirm against its own privacy notice and, ideally, its own counsel.

Start free

Install the snippet and see the first named companies on your own traffic.

The federal picture

This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.

United States overview

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

What Denver and Boulder buying committees ask for

Colorado's Front Range tech corridor has a reputation for a careful, documentation-driven procurement culture, partly a byproduct of the CPA Rules themselves: legal and security reviewers there are used to controllers running formal data protection assessments for higher-risk processing such as targeted advertising, profiling or the sale of personal data, and they often ask a vendor for the paperwork trail behind a similar internal process. A vendor that can point to a written record of what it processes and why tends to move through review faster than one that answers case by case.

Reviewers also increasingly ask whether a site responds to the Universal Opt-Out Mechanism list the Colorado Attorney General maintains, since the CPA requires controllers to honor a recognized opt-out signal for the sale of personal data or targeted advertising by mid-2024 onward. Company-level visitor identification does not sell personal data or serve targeted advertising, so it sits outside that particular obligation, but explaining why — rather than staying silent on the question — is what a Boulder security reviewer typically expects to see documented.

For a Colorado sales or marketing team, the practical payoff mirrors the rest of the region's technical buyer culture: a multi-week evaluation by a distributed buying committee becomes visible early, as company names rather than anonymous sessions, letting a rep reach out during the window when the deal is still being shaped rather than after a decision has already been made elsewhere.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

The CPA regulates personal data tied to a Colorado consumer, defined as a resident acting in an individual or household context, and it applies once a controller crosses the statute's processing thresholds. Company-level identification, as lead.box performs it, resolves a visiting organisation's name, industry and size band from network-level signals rather than producing a named individual's record, so it does not generate the kind of consumer personal data the CPA's rights provisions are built around. Whether any other data your site separately collects — a form submission with a name and email, for instance — falls inside the CPA's scope is a distinct question that depends on your own data flows and consumer counts. lead.box acts as a processor for the data it handles and leaves the controller-level assessment of applicability to your organisation, ideally with input from counsel familiar with the CPA and its implementing rules.

California's CCPA originally exempted business-to-business and employment-context personal information from most consumer rights, but that exemption was always temporary and expired on 1 January 2023, so the CPRA now covers a B2B contact's data much like any other consumer's. Colorado took the opposite path from the start: the CPA defines 'consumer' to exclude anyone acting in a commercial or employment context, so a business card exchanged at a conference or a work email submitted on a supplier's contact form was never inside the CPA's consumer rights regime, and there is no sunset date because there was never a temporary carve-out to expire. A Colorado business selling into California, or vice versa, needs to track both rules separately rather than assuming one state's treatment of B2B data applies in the other.

The Colorado Attorney General adopted a detailed set of implementing rules alongside the statute, covering matters such as the technical specifications for recognizing Universal Opt-Out signals, the required content of data protection assessments, and disclosures around profiling that produces legal or similarly significant effects. These rules are unusually prescriptive compared with other state privacy laws in this cluster and are worth reading directly if your organisation is a controller under the CPA. Company-level identification does not involve selling personal data, serving targeted advertising, or profiling an individual consumer for significant decisions, so it does not trigger the assessment or opt-out-signal obligations the rules describe in most configurations, but confirming that against your specific setup remains a task for your own privacy or legal team.

Enforcement authority rests with the Colorado Attorney General and, distinctively among the states in this cluster, with local district attorneys, who may also bring actions treating a CPA violation as a deceptive trade practice under existing Colorado consumer protection law. The statute originally gave a business 60 days to cure a violation after notice before an enforcement action could proceed, but that mandatory cure right was written to sunset on 1 January 2025. After that date, the Attorney General has discretion over whether to offer a cure opportunity at all, considering factors such as the number of violations and whether the business acted in good faith, which raises the practical stakes of getting a compliance posture right before a complaint is ever filed.

The Colorado Attorney General maintains a list of recognized Universal Opt-Out Mechanisms, and the CPA requires controllers to honor an opt-out signal sent through one of these mechanisms for the sale of personal data or for targeted advertising. lead.box does not sell personal data to third parties and does not serve targeted advertising based on visitor data, so the opt-out-signal requirement is not something a site typically needs to route through the identification tool itself. Whether other parts of your site — advertising pixels, retargeting tags or data brokers you work with separately — need to respond to these signals is a broader compliance question about your full technology stack, not one that company-level identification changes on its own.

It comes up regularly in this region, partly because the CPA Rules formalise what a data protection assessment should contain for higher-risk processing such as profiling, targeted advertising or selling personal data, and local security and privacy reviewers are accustomed to that documentation style. Since company-level identification does not fall into those higher-risk categories under the CPA in most deployments, a formal assessment is usually not legally required for the identification activity itself, but many Colorado buyers still ask for a written summary of what data is processed and why, which lead.box can support with its own documentation. Whether your organisation needs to run a formal assessment as controller for its broader data practices is a separate question tied to your full processing activities, not just this one tool.

The service maps network-level signals from a visit — chiefly IP address ranges associated with organisations — to a company name, industry and size band, without identifying which specific employee was browsing, without setting cookies or advertising identifiers, and without assembling a profile that follows a person across unrelated sites. No login, form fill or email address is required for a company to be identified, and nothing in the resulting record names an individual person or their job title. What is stored is simply a record that a given organisation visited certain pages during a certain window, which is the input a sales team typically uses to decide who to contact next, not a substitute for verifying who that contact should be.

No, and no vendor can honestly offer that guarantee. The CPA's applicability depends on your organisation's total consumer counts, your broader data practices, whether you sell personal data or run targeted advertising, and how you handle rights requests, all of which sit outside anything a website visitor identification tool touches. lead.box can describe accurately what it collects, how it processes data, and where that data is stored, and it can point to company-level identification's structural distance from the CPA's consumer-data provisions, but confirming your organisation's overall compliance posture under the Colorado Privacy Act and its implementing rules is a legal determination. This page is informational only, not legal advice, and a Colorado business should have its own qualified counsel review its specific facts before relying on any characterization here.

See which Colorado companies are already on your site

Install a first-party snippet, watch the first companies appear, and hand your legal team documentation built to a stricter standard than the CPA requires.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links