US B2B Lead Generation and the State Privacy Patchwork
The Shape of the Problem
European marketers are used to one regulation with local variation on top. The United States works the other way round. There is no comprehensive federal consumer privacy statute, so obligations come from state law, and each state arrived on its own timetable with its own definitions.
By 2026 around twenty states have comprehensive consumer privacy laws in force, with more enacted and waiting to commence. The IAPP US State Privacy Legislation Tracker maintains the current list and is the practical thing to check before a launch, because the count changes.
An important qualifier that gets lost in summaries: these laws do not apply to every business that has a customer in the state. Most set thresholds. California's CCPA, for example, applies to for-profit businesses that meet at least one of three tests: annual gross revenue above a stated figure, processing personal information of a stated number of consumers or households, or deriving half or more of annual revenue from selling or sharing personal information. The California Attorney General's CCPA pages set out the current figures. Other states set their own, and several exempt categories of organisation entirely.
So the first question is not what the laws require. It is which of them reach you at all. That is a question for counsel with your actual volumes in front of them, and answering it can materially reduce the surface you are working with.
The Two Provisions That Touch a Media Funnel
Where a law does apply, two features matter to advertising operations.
Opt-out preference signals
Most state privacy laws give people a right to opt out of targeted advertising. Several require businesses to accept an automated browser signal expressing that choice, rather than requiring the person to use a preference centre on each site.
Colorado maintains a public list of approved universal opt-out mechanisms under the Colorado Privacy Act, and the Global Privacy Control is on it. California treats an opt-out preference signal as a valid request under the CCPA regulations published by the California Privacy Protection Agency.
The mechanism is simple: the browser sends a header, or exposes a JavaScript property, indicating the visitor has opted out. What catches teams out is that the signal is invisible during normal use. Nobody on the team has it enabled, so nobody notices whether the site responds. There is no error and no console warning. The specification is public at globalprivacycontrol.org, and testing it takes a browser extension and the network tab.
Business contact data is not exempt everywhere
Several state laws define a consumer as someone acting in an individual or household context, which excludes a person acting for their employer. Virginia's statute and those modelled on it take this approach.
California does not. When the California Privacy Rights Act amended the CCPA, the temporary exemptions for business-to-business contact data and employee data were allowed to lapse. For a company selling to Californian buyers, the job title on the lead form does not change the analysis.
The practical consequence is that segmenting your compliance approach by whether a record looks like a work contact tends to create more work than it saves.
Want to know what your site does when an opt-out signal arrives? It is a short check and it is worth knowing the answer either way.
Book a 30 minute callWorked Example: Why Cost Per Lead Sends You the Wrong Way
Here is the part that pays for itself regardless of which privacy laws apply to you.
When some share of your audience stops being trackable, platform-reported conversions become a less reliable guide. The usual reaction is to lean harder on the metric the platform still reports confidently, which is cost per lead. That is the wrong direction, and the arithmetic shows why.
The figures below are illustrative. Run the same table on your own CRM data, because the ratios are what matter and they differ by business.
Two campaigns, each given $10,000 a month.
| Stage | A: content download | B: demo request |
|---|---|---|
| Spend | $10,000 | $10,000 |
| Form fills | 200 | 40 |
| Cost per lead | $50 | $250 |
| Assumed lead to qualified rate | 4% | 35% |
| Qualified leads | 8 | 14 |
| Cost per qualified lead | $1,250 | $714 |
| Assumed qualified to closed won | 15% | 22% |
| Deals | 1.2 | 3.08 |
| Cost per deal | $8,333 | $3,247 |
On cost per lead, campaign A looks five times better. On cost per deal, campaign B is roughly two and a half times better. A team optimising to the metric the ad platform reports most confidently would move budget from B to A and reduce pipeline while improving every number on the dashboard.
This gap exists in any B2B account. Reduced trackability makes it worse, because it pushes teams further towards the platform-native metric at exactly the moment that metric is least representative.
The fix is to send the later stages back:
- Capture a click identifier on the form and store it against the CRM record
- Upload qualified lead, opportunity and closed-won events back to the platforms as offline conversions
- Bid on the latest stage that has enough volume to train on, which for many accounts is qualified lead rather than closed won
- Report cost per qualified lead and cost per deal to the board, and keep cost per lead as a diagnostic rather than a target
If your monthly deal count is small, bidding on closed won will not give the platform enough signal. Qualified lead is usually the workable compromise, and the table above is the argument for making that change rather than staying on form fills.
Measuring at the Account Level
B2B buying is done by groups over months. Five people from one company may each arrive through a different channel across a long evaluation, and last-click attribution will credit whichever one happened to be last.
Rolling touches up to the account, then judging channels on pipeline created rather than on leads generated, produces a more stable picture. It also survives tracking loss better, because it depends on CRM records rather than on browser state.
What the FTC Regulates, Which Is Separate
Privacy statutes are one thing. The Federal Trade Commission polices deceptive advertising nationally, and B2B marketing sits inside that remit.
Two areas cause most of the trouble. Claims about results need substantiation, and need to reflect what a typical customer can expect rather than the best case. Testimonials and endorsements are covered by the Guides at 16 CFR Part 255, with the FTC's plain-language explanation in The FTC's Endorsement Guides: What People Are Asking. These reach case study pages and paid social creative in the same way they reach a television spot.
Email is governed separately by the CAN-SPAM Act, which covers commercial email to US recipients including B2B. It is an opt-out regime rather than an opt-in one, which surprises European teams, but it carries hard requirements on headers, subject lines, a physical postal address and a working unsubscribe.
What to Do, In Order
- Establish with counsel which state laws actually reach your business at your current volumes
- Test what your site does when an opt-out preference signal arrives, and document the result
- Move tag firing behind a single server-side consent decision rather than trusting each tag
- Capture click identifiers into the CRM at form submission
- Run the cost per deal table above on your own numbers and take it to whoever sets budget
- Upload qualified stages back to the platforms and move bidding to the latest stage with enough volume
- Review results claims and testimonials against the FTC guides
- Write down which rules apply, what the site does about each, and who decided
The teams that handle this well are usually the ones that stopped treating measurement as a tagging exercise and started treating it as a data model that has to work when part of the audience is not observable.
None of this is legal advice. It is the operational shape of the problem, and the point at which to ask counsel a specific question rather than a general one.
Sources
- IAPP, US State Privacy Legislation Tracker
- Colorado Attorney General, Universal Opt-Out and the Colorado Privacy Act
- California Privacy Protection Agency, Regulations
- California Attorney General, California Consumer Privacy Act
- Global Privacy Control specification
- eCFR, 16 CFR Part 255, Guides Concerning Use of Endorsements and Testimonials in Advertising
- FTC, The FTC's Endorsement Guides: What People Are Asking
- FTC, CAN-SPAM Act: A Compliance Guide for Business