Markets

B2B website visitor identification in Florida

A Florida-based B2B site sees the same pattern as anywhere else: a buying committee in Miami, Tampa or Orlando quietly reads pricing and integration pages for weeks before anyone fills out a form. Company-level identification turns that anonymous traffic into a named organisation your sales team can prioritise, instead of a session that expires the moment the browser tab closes.

  • FrameworkFlorida Digital Bill of Rights (FDBR), Fla. Stat. §501.701 et seq. (SB 262), effective 1 July 2024
  • SupervisionFlorida Attorney General / Department of Legal Affairs under FDUTPA, with a 45-day cure period
  • Usual legal basisLegitimate business purpose; identification stays at company level, outside the FDBR's narrow controller obligations and its 'consumer' definition
  • Processing locationISO-certified EU data centres

Florida's own privacy statute, the Florida Digital Bill of Rights, is unusual among its state peers: its core obligations apply only to a narrow band of very large, mostly ad- or platform-driven companies, not to most mid-market B2B sellers. This page walks through what the FDBR actually covers, who it leaves out, and why that gap does not mean a Florida sales team can skip the vendor review a buyer will still ask for.

At a glance

Framework
Florida Digital Bill of Rights (FDBR), Fla. Stat. §501.701 et seq. (SB 262), effective 1 July 2024
Supervision
Florida Attorney General / Department of Legal Affairs under FDUTPA, with a 45-day cure period
Usual legal basis
Legitimate business purpose; identification stays at company level, outside the FDBR's narrow controller obligations and its 'consumer' definition
Processing location
ISO-certified EU data centres

The Florida Digital Bill of Rights

Regulation at a glance

  • FrameworkFlorida Digital Bill of Rights (FDBR), Fla. Stat. §501.701 et seq. (SB 262), effective 1 July 2024
  • SupervisionFlorida Attorney General / Department of Legal Affairs under FDUTPA, with a 45-day cure period
  • Usual legal basisLegitimate business purpose; identification stays at company level, outside the FDBR's narrow controller obligations and its 'consumer' definition
  • Processing locationISO-certified EU data centres

The Florida Digital Bill of Rights, codified at Fla. Stat. §501.701 et seq. and enacted as SB 262, took effect on 1 July 2024. Unlike most other state privacy laws in this cluster, the FDBR does not impose its full set of controller obligations — access, deletion, opt-out of sale, and so on — on every business meeting a general revenue or volume threshold. Instead those core duties attach only to a for-profit entity that does business in Florida, earns in excess of $1 billion in global gross annual revenue, and additionally meets one of three narrow tests: at least half of that revenue comes from selling advertising online, the company operates a smart speaker or voice-assistant service, or it runs an app store or digital distribution platform listing at least 250,000 applications.

That structure means the FDBR was written with a handful of very large technology and advertising platforms in mind, not the typical Florida-based SaaS vendor, professional services firm or manufacturer with a website and a sales team. Separate FDBR provisions — on government-directed content moderation, the sale of sensitive data, and protections for known minors online — apply more broadly and are not limited to the billion-dollar-revenue tier, so a company can still have exposure on those narrower points even while sitting outside the main controller obligations.

Enforcement runs through the Florida Attorney General and the Department of Legal Affairs, using the state's existing Unfair and Deceptive Trade Practices Act (FDUTPA) as the enforcement vehicle rather than a standalone privacy penalty regime. Before the Attorney General pursues an action, a company generally gets a 45-day cure period to fix the identified violation. Penalties can run up to $50,000 per violation, and that figure can be trebled in specified circumstances, so the numbers involved are serious even though the population of companies directly bound by the core controller duties is small.

Who the FDBR actually covers — and the B2B carve-out

Two separate questions determine whether the FDBR's controller obligations even apply to a given company's website: first, does the company clear the revenue-plus-activity threshold described above, and second, even if it does, is the data in question about a 'consumer' as the statute defines that term. On the second point the FDBR is explicit — a consumer is a Florida resident acting only in an individual or household context, and the definition specifically excludes a person acting in a commercial or employment context. Purely business-to-business contact data, gathered because someone visited a website in their capacity as an employee evaluating a vendor, sits outside that definition entirely.

That is a meaningful contrast with California, where the equivalent temporary B2B and employee exemptions under the CCPA/CPRA expired on 1 January 2023, bringing business contact data back inside scope for California residents. Florida never had that expiration to begin with, because the FDBR's consumer definition excludes the commercial and employment context from the outset rather than phasing an exemption out. For most B2B sellers, this means the FDBR is doubly distant: the revenue-and-activity threshold likely excludes the company as a controller in the first place, and even where it would not, the underlying data about business visitors likely falls outside the statute's consumer definition anyway.

Layer on top of both of those points the distinction that matters for a tool like lead.box: company-level identification resolves the visiting organisation — a name, an industry, a size band — rather than a named individual. That is a different question again from whether personal data about a Florida resident is in scope under the FDBR, and it stays a different question regardless of how the revenue threshold or the consumer definition eventually gets applied to a given business. None of this is a substitute for legal advice; whether a specific company clears the $1 billion-plus-activity threshold, and how the commercial-context exclusion interacts with any sensitive-data or minors provisions that apply more broadly, is exactly the kind of scoping question that needs a lawyer familiar with the statute's text, not a blog post.

Start free

Install the snippet and see the first named companies on your own traffic.

The federal picture

This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.

United States overview

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

What this means for sales teams in Miami, Tampa and Orlando

Florida's tech and services economy is concentrated around a few hubs — fintech and logistics in Miami, healthcare and insurance services in Tampa, hospitality tech and aerospace suppliers around Orlando — and sales teams in all three tend to sell into procurement processes that ask the same vendor-review questions as everywhere else in the country, largely independent of what the FDBR itself requires. A narrow statute does not narrow a buyer's security questionnaire: legal and IT reviewers still want to know what data is collected, whether it is sold or shared, where it is processed, and whether a written data processing agreement is available, regardless of whether the vendor or the buyer happens to clear the FDBR's own thresholds.

In practice that means a Florida-based or Florida-selling company should be ready to explain, in plain language, that company-level visitor identification does not fall under the FDBR's narrow controller obligations for the vast majority of businesses, that the underlying data is organisational rather than about an identified Florida resident acting in an individual context, and that the vendor still maintains the same processing documentation a buyer in a stricter state would expect. Being able to answer clearly, rather than assuming a narrow statute means no questions get asked, is what actually shortens a Florida procurement cycle.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

For most B2B companies, no — and this is the single most important fact about the FDBR. Its core controller obligations, such as consumer access and deletion rights and opt-out of sale, attach only to a for-profit entity that does business in Florida, earns more than $1 billion in global gross annual revenue, and additionally either earns at least half that revenue from online advertising, operates a smart speaker or voice-assistant service, or runs an app store with at least 250,000 apps. A mid-market SaaS vendor, professional services firm or manufacturer almost never meets that combined threshold, so it is not a controller under the FDBR's main provisions in the first place. Separate FDBR rules on government-directed moderation, sale of sensitive data and protections for minors apply more broadly and are worth checking independently. Whether a specific company clears the revenue-and-activity threshold is a factual and legal question that deserves review by counsel familiar with the statute, not a general assumption either way.

The two states reached a similar practical result through very different routes, and the difference matters for anyone comparing states. California's CCPA originally exempted business-to-business contact and employee data on a temporary basis, but that exemption expired on 1 January 2023, meaning business contact data about California residents is now fully within CCPA/CPRA's scope. Florida never had that kind of temporary carve-out to expire: the FDBR defines a 'consumer' as a Florida resident acting only in an individual or household context, and explicitly excludes a person acting in a commercial or employment context, from the statute's outset. So in Florida, purely B2B data has arguably always sat outside the consumer definition, while in California it has been back inside scope for years. Confirming exactly how each definition applies to a specific data flow is a job for counsel, not a general comparison like this one.

The revenue-and-activity threshold means the FDBR's core controller obligations almost certainly do not apply to a company that size, which is the case for the large majority of B2B sellers active in Florida. That said, the FDBR contains a few provisions — around government-directed content moderation, sale of sensitive personal data, and protections for known minors online — that are not limited to the billion-dollar tier and could theoretically reach a smaller company depending on what it does. It is also worth remembering that Florida buyers still operate under other laws, general consumer-protection rules, and their own contractual expectations regardless of whether the FDBR itself applies. Treating 'below the threshold' as the end of the analysis, rather than confirming it with counsel and checking the narrower provisions separately, is the kind of shortcut that tends to cause problems later.

Generally no, for two independent reasons that are worth keeping separate. First, lead.box resolves the visiting organisation — a company name, industry and size band derived from network-level signals — rather than identifying a named person, so there is no individual being profiled in the sense the FDBR's rights provisions are built around. Second, even where an individual's activity is involved, the FDBR's consumer definition excludes a Florida resident acting in a commercial or employment context, which describes most B2B website research. Both of these are separate from the question of whether your company even qualifies as an FDBR controller in the first place, given the statute's revenue-and-activity threshold. Documenting all three points distinctly, rather than treating them as one argument, tends to hold up better under a buyer's or counsel's scrutiny.

For the narrow set of companies that do qualify as controllers under the FDBR, the Florida Attorney General generally must provide notice of an alleged violation and allow 45 days for the company to cure it before pursuing enforcement action under FDUTPA. That grace period gives a qualifying company a real opportunity to fix a compliance gap — updating a disclosure, honoring a deletion request, adjusting an opt-out mechanism — before facing the statute's penalties, which can run up to $50,000 per violation and can be trebled in specified circumstances. Because the cure period only matters if a company is a controller under the FDBR to begin with, most B2B sellers will never need to rely on it, but it is a meaningful protection for the platforms the statute was actually written to reach. None of this changes what non-covered businesses should still document for their own buyers.

Enforcement authority sits with the Florida Attorney General and the Department of Legal Affairs, who bring actions under the state's existing Unfair and Deceptive Trade Practices Act rather than a separate standalone privacy enforcement mechanism. There is no general private right of action built into the FDBR allowing an individual Florida resident to sue a company directly over a statutory violation; enforcement is channelled through the Attorney General's office, following the 45-day cure period described above for qualifying controllers. This centralised, single-regulator structure is simpler than states that split authority between an attorney general and a dedicated privacy agency, but it does not change who is covered — the narrow revenue-and-activity threshold still determines whether the FDBR's main obligations apply to a given company at all.

A Florida vendor review typically asks the same questions a review anywhere else in the country asks, largely regardless of whether the FDBR itself applies to either party: what data is collected, whether any of it is sold or shared with third parties, where it is processed and stored, and whether a written data processing agreement is available for signature. lead.box can answer all four plainly — it identifies the visiting organisation rather than a named individual, does not sell or share personal information for advertising, processes data in ISO-certified EU data centres, and provides a data processing agreement along with a published sub-processor list. Having those answers ready, rather than pointing to the FDBR's narrow scope as if it closes the conversation, is what actually moves a Florida procurement process along.

No, and that distinction matters more here than in most states, precisely because the FDBR's applicability turns on a specific combination of revenue and business-activity facts that only your own legal team can confirm for your company. This page describes the statute's structure, its narrow controller threshold, its consumer definition and its enforcement mechanism as general background, and explains where company-level identification sits relative to those provisions, but it is not a substitute for a lawyer reviewing your specific revenue figures, business activities and data flows. Florida's threshold-based approach makes the scoping question genuinely more complex than a simple 'does this law apply to my industry' check, so getting counsel involved before relying on any conclusion here is the right next step, not an optional extra.

See which Florida companies are already researching you

Install a first-party snippet, watch the first Miami, Tampa and Orlando companies appear, and hand your legal team the same documentation any buyer would ask for.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links