Legal · June 29, 2026 · 7 min read

GDPR fear in sales: what you can actually do after identifying a company

"Aren't we allowed to?" is the most expensive sentence in B2B sales. In plain language, here is what you may do with an identified company, and where the line actually sits.

Abstract navy grid with a green check and red X, cleanly separated.

A lot of B2B sales caution is second-hand fear, not law. Below is a practical map of what you can typically do after your tool identifies a company that visited — and where the line is.

The framing that helps

Identifying a company from an IP address is not the same as identifying a person. B2B account intelligence has been standard for years. The GDPR care mostly kicks in when you start attaching person-level data: name, email, phone.

What you can typically do (in the EU/EEA)

  • Log the company name, industry, size, country, and which pages of your website they visited.
  • Keep that information for a reasonable, documented time (12 months is a common default).
  • Use it to decide who to reach out to on LinkedIn or via publicly listed business email.
  • Add the company to a sales-CRM company record — as a company, not as a person profile.

Where you get careful

ActionUsually OKGet careful / seek advice
Company + pages loggedYes
Public business email (info@)Yes
Named person on LinkedInYes (public source)Don't scrape at scale
Cold email to a specific employeeDepends on country and existing relationshipVerify local rules
Combine person + behaviour publiclyNoNo
Do's and don'ts on the person-level line.

Not legal advice

Rules vary by country and situation, and B2B email rules differ across Germany, France, Italy, and beyond. Check locally when in doubt — this article is a starting map, not counsel.

Practical do's

  • Do use company visits to prioritise. Fewer, better outbound emails beat larger, colder ones.
  • Do reference behaviour by inference, not surveillance: "companies in your space often ask us about X", not "I saw your team on our pricing page".
  • Do publish an opt-out on your privacy page so any business can ask to be excluded.

Practical don'ts

  • Don't blast personal emails scraped from a data broker.
  • Don't reveal to a prospect that you're tracking specific individuals — you're not, and saying you are looks bad.
  • Don't store visitor data "forever". Set a retention window and delete on schedule.

The bottom line

B2B sales in the EU is very much alive. The rules aren't there to stop you from doing your job; they're there to stop the shady versions of it. Company-level identification with a documented retention policy fits comfortably inside the lines.

  • Related: [Is visitor identification GDPR-compliant?](/blog/is-website-visitor-identification-gdpr-compliant)
  • Related: [Legitimate interest, plainly explained](/blog/legitimate-interest-plainly-explained)
  • Related: [Compliance questions your CFO will ask](/blog/compliance-questions-your-cfo-will-ask-and-the-answers)
lead.box Team

Published by

lead.box Team

More articles

See lead.box on your own traffic

Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.

Start free trial

Notes on GDPR B2B lead intelligence

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links