Markets

B2B website visitor identification under Montana's privacy law

Montana looks quiet on a traffic dashboard compared to California or Texas, but its privacy statute is anything but a footnote. The Montana Consumer Data Privacy Act sets the lowest applicability thresholds of any state law in the country, which means a mid-sized national business can find itself squarely in scope in Montana while staying comfortably outside the reach of larger states' laws entirely.

  • FrameworkMontana Consumer Data Privacy Act (MCDPA), Mont. Code Ann. §30-14-2801 et seq. (SB 384), effective 1 October 2024
  • SupervisionMontana Attorney General exclusively, under the Montana Unfair Trade Practices Act; 60-day cure period sunset 1 April 2026
  • Usual legal basisLegitimate business purpose; identification stays at company level, outside the MCDPA's definition of a covered 'consumer'
  • Processing locationISO-certified EU data centres

For a sales or marketing team watching anonymous research turn into a named account, that low bar matters: it is easier to trigger MCDPA obligations here than almost anywhere else, so understanding what the law actually covers — and what it deliberately leaves out — is worth doing properly rather than assuming Montana is a small-market afterthought.

At a glance

Framework
Montana Consumer Data Privacy Act (MCDPA), Mont. Code Ann. §30-14-2801 et seq. (SB 384), effective 1 October 2024
Supervision
Montana Attorney General exclusively, under the Montana Unfair Trade Practices Act; 60-day cure period sunset 1 April 2026
Usual legal basis
Legitimate business purpose; identification stays at company level, outside the MCDPA's definition of a covered 'consumer'
Processing location
ISO-certified EU data centres

The Montana Consumer Data Privacy Act

Regulation at a glance

  • FrameworkMontana Consumer Data Privacy Act (MCDPA), Mont. Code Ann. §30-14-2801 et seq. (SB 384), effective 1 October 2024
  • SupervisionMontana Attorney General exclusively, under the Montana Unfair Trade Practices Act; 60-day cure period sunset 1 April 2026
  • Usual legal basisLegitimate business purpose; identification stays at company level, outside the MCDPA's definition of a covered 'consumer'
  • Processing locationISO-certified EU data centres

The Montana Consumer Data Privacy Act, codified at Mont. Code Ann. §30-14-2801 et seq. and enacted as SB 384, took effect on 1 October 2024. It follows the general structure of the Virginia-style state privacy laws — consumer rights to access, delete and opt out, controller and processor obligations, data protection assessments for higher-risk processing — but its applicability thresholds set it apart from every other state that has passed comprehensive privacy legislation so far.

A business is covered if it controls or processes personal data of 50,000 or more Montana consumers, excluding data processed solely to complete a payment transaction, or if it controls or processes personal data of 25,000 or more consumers while deriving more than 25% of gross revenue from selling personal data. Both numbers are dramatically lower than the 100,000-consumer thresholds used in most comparable states, meaning far smaller companies — including many with no physical presence in Montana at all — need to check their exposure here.

Enforcement sits exclusively with the Montana Attorney General under the state's Unfair Trade Practices Act; there is no private right of action. A 60-day cure period allowing businesses to fix violations before enforcement proceeded was available initially, but that cure period sunset on 1 April 2026, after which the Attorney General can pursue enforcement without first offering a chance to remedy the issue.

Why the B2B carve-out matters here

The MCDPA defines a covered 'consumer' as a Montana resident acting only in an individual or household context, and it expressly excludes a person acting in a commercial or employment context. That single definitional choice removes purely business-to-business contact data — a work email, a job title, a company phone number collected in a sales or vendor relationship — from the statute's consumer rights provisions entirely, even though the same data would plainly be personal information in everyday usage.

This is a meaningfully different starting point from California, where the CCPA/CPRA's temporary B2B and employee exemptions expired on 1 January 2023, bringing business contact data fully into scope alongside consumer data. In Montana, a B2B sales team's CRM records of who they emailed at a prospect company generally sit outside the MCDPA's reach altogether, which changes what a privacy review needs to focus on.

That leaves a third and separate question: what lead.box itself resolves. lead.box identifies the organisation behind a website visit — company name, industry, size band — from network-level signals, not a named individual. Whether Montana's consumer definition applies to a given data flow, and whether that flow even involves personal data at all, is a question about the underlying activity; company-level identification is a different, narrower category again, and one that avoids most of this analysis by design.

Start free

Install the snippet and see the first named companies on your own traffic.

The federal picture

This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.

United States overview

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

What this means for Montana-facing sales and marketing teams

Montana's B2B economy is concentrated but genuine: Bozeman and Missoula have developed real tech clusters, alongside long-established energy, agriculture and natural-resource sectors with national and often out-of-state customers and suppliers. Procurement cycles in these sectors tend to run long, and vendor review is frequently handled by out-of-state HQ counsel serving a parent company or holding structure rather than a Montana-based legal team.

Because of that, buyers here often ask sharper, more document-driven questions than the low population might suggest — a signed processing agreement, a sub-processor list, and a plain description of what is collected and where it is stored are standard requests, not extras. Given the MCDPA's low thresholds, a Montana-facing vendor should also expect its own customers to ask whether the vendor itself might be a covered controller or processor under the Act, since the 25,000-to-50,000 consumer range catches companies that would never trigger a larger state's law.

From 1 January 2025, the MCDPA also requires controllers to honor universal opt-out mechanisms — browser or device-level signals indicating a consumer does not want their personal data processed for targeted advertising or sale — for consumers exercising an opt-out right. That obligation applies to personal data covered by the statute; it does not, on its own, change how company-level visitor identification is evaluated, since that activity sits outside the consumer-data category the opt-out mechanism is built to serve.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

Yes, and that is the defining feature of this statute. The MCDPA applies to a business that controls or processes personal data of 50,000 or more Montana consumers, excluding data processed solely to complete a payment transaction, or 25,000 or more consumers while deriving over 25% of gross revenue from selling personal data. Most comparable state laws set the bar at 100,000 consumers or higher, so Montana catches meaningfully smaller companies, including many with no office or employees in the state at all, simply because they have enough Montana website visitors, customers or app users to cross this lower line. A company that has confirmed it falls outside California's or Texas's thresholds should not assume the same holds for Montana; the calculation needs to be run separately for each state's numbers. This is a factual scoping exercise, not legal advice, and a company close to either threshold should have counsel review its actual data volumes before concluding it is out of scope.

Generally, no. The MCDPA defines a covered consumer as a Montana resident acting only in an individual or household context, and it explicitly excludes a person acting in a commercial or employment context. That means a work email address, job title or business phone number collected through a sales, vendor or partnership relationship typically falls outside the statute's consumer rights provisions, even though the same information would ordinarily be considered personal data. This differs from California, where the CCPA/CPRA's temporary B2B and employee exemptions expired on 1 January 2023, bringing business contact data into scope there. Because exclusions like this depend on the specific facts of how data was collected and used, a company relying on the B2B carve-out for a particular dataset should confirm that reliance with its own counsel rather than assuming the exclusion applies automatically to every business contact record it holds.

lead.box resolves the organisation behind a website visit — a company name, industry and approximate size — from network-level signals, without identifying a named individual, without cookies, and without building a profile that follows a person across unrelated sites. The MCDPA's rights and obligations are built around personal data tied to an identified or identifiable Montana resident acting in an individual or household context, which is a different fact pattern than resolving which organisation a visit came from. Whether a given data flow on your site involves personal data covered by the MCDPA at all, separate from any visitor identification tool, is a question about your own broader data practices. lead.box acts as a processor under a data processing agreement for the data it does handle and leaves the scoping question of whether the MCDPA applies to your business to the controller, supported by your own legal counsel rather than by lead.box's own assessment.

Enforcement authority sits exclusively with the Montana Attorney General, acting under the Montana Unfair Trade Practices Act; there is no private right of action, so individual Montana consumers cannot sue a business directly for an alleged MCDPA violation. A 60-day cure period initially gave businesses a chance to fix an identified violation before the Attorney General pursued formal enforcement, but that cure period sunset on 1 April 2026, meaning the Attorney General can now proceed to enforcement without first offering that remedy window. For a business evaluating its exposure, this shifts the practical incentive toward getting scoping, disclosures and vendor documentation right upfront rather than assuming a violation can simply be corrected after the fact once flagged. None of this constitutes legal advice, and a business with genuine uncertainty about its MCDPA obligations should raise it with its own counsel rather than relying on this summary.

From 1 January 2025, the MCDPA requires controllers to recognize universal opt-out mechanisms — browser extensions, device settings or other technical signals that communicate a consumer's choice to opt out of the processing of their personal data for targeted advertising or sale, without requiring the consumer to submit a separate request to each website. This applies to personal data within the MCDPA's scope, meaning data tied to an individual or household consumer as the statute defines that term. It does not, by itself, change the analysis for company-level visitor identification, since that activity resolves an organisation rather than processing an individual consumer's personal data for the advertising or sale purposes the opt-out mechanism addresses. Whether your broader advertising and analytics stack needs to honor these signals is a separate operational question your team should work through with counsel, given how many other tools a typical marketing site runs alongside any visitor identification service.

Yes, potentially, and this is one of the more counterintuitive aspects of Montana's law. The MCDPA applies based on how much personal data of Montana consumers a business controls or processes, not on where the business itself is headquartered or incorporated. Because the applicability thresholds are the lowest of any state — 50,000 consumers, or 25,000 with heavy reliance on selling personal data — an out-of-state company with a modest but real base of Montana customers, subscribers or website visitors can cross that line well before it would trigger a larger state's threshold. This catches some businesses by surprise, since they may have already concluded they are out of scope everywhere based on California's or Virginia's higher numbers. Running the Montana-specific calculation separately, with input from counsel, is the only reliable way to know where a given company actually stands.

Bozeman and Missoula's technology companies and Montana's established energy and agriculture sectors both tend to run longer procurement cycles than the state's overall size might suggest, particularly where legal review is handled by out-of-state headquarters counsel for a parent company or investor group rather than locally. Given the MCDPA's unusually low thresholds, these reviewers often specifically ask whether a vendor itself might be a covered controller or processor, not just whether the vendor complies with the MCDPA on the buyer's behalf. Standard requests include a signed data processing agreement, a current sub-processor list, and a clear, specific description of what data is collected, whether personal data of an identifiable individual is involved at all, and where it is stored and processed. Company-level visitor identification tends to answer these questions cleanly, since it does not involve the kind of individual-level personal data the MCDPA's consumer provisions are built around, but the documentation should still be provided rather than assumed.

The MCDPA's definition of 'sale' centers on the exchange of personal data for monetary or other valuable consideration, applied to data about an identified or identifiable Montana consumer acting in an individual or household context. lead.box does not transmit visitor-level personal information to advertising networks, does not exchange data for consideration in the sense this definition describes, and resolves a visiting organisation rather than a named person, which is a different fact pattern from the data flows the sale provisions were written to address. That said, whether any of your other Montana-facing data flows meet the MCDPA's definition of sale is a separate question about your broader business practices, unrelated to visitor identification specifically. This response is general information rather than a compliance determination, and a business with a genuine question about whether it is selling personal data under Montana law should have its own counsel review the specific arrangement.

See which companies are researching you from Montana

Install a first-party snippet, surface the organisations behind your Montana traffic, and hand counsel the documentation a low-threshold state law review actually needs.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links