Legal · May 9, 2026 · 9 min read

Is website visitor identification GDPR-compliant?

Yes — done at the company level, under Art. 6(1)(f) legitimate interest, with a proper privacy notice and an opt-out. Here is what that actually looks like in practice.

EU-styled shield with a golden padlock next to a compliance document.

The short answer is yes — with three conditions. The processing has to stay at the company level, it has to be transparently disclosed in your privacy notice, and data subjects need a working way to object. Below is the long answer, written for people who actually have to defend the tool in a meeting with legal or the DPO.

Is a company IP even personal data?

For the GDPR, an IP address is treated as personal data whenever it can, in reasonable steps, be linked back to a natural person (Breyer, C-582/14). A company IP that only resolves to a legal entity is still personal data in a formal sense — some individual sits behind the connection — but the identification we perform never attaches to a person. We resolve the IP to an organisation, discard the raw IP after resolution, and store no user-level identifiers.

That is the crucial distinction: personal data is processed at the moment the IP hits the server, and immediately reduced to an organisation-level record. The GDPR still applies to that brief processing, so a legal basis is required — and legitimate interest is the natural fit.

Legitimate interest under Art. 6(1)(f)

Art. 6(1)(f) allows processing where a controller has a legitimate interest that is not overridden by the rights and interests of the data subject. For B2B visitor identification, the balancing test is well-trodden ground and looks like this.

ElementAssessment
Legitimate interestSales / marketing analytics on your own site — recognised by recitals 47 and 48 as a legitimate business interest.
NecessityCompany resolution is the least intrusive means to answer which organisations are on the site — no personal profile is built.
ProportionalityIP is discarded post-resolution, no cross-site profile, no behavioural advertising, no data sales.
Reasonable expectationA visitor from a company network expects that their employer's presence on a supplier site is visible; individual identification is neither promised nor delivered.
SafeguardsTransparent privacy notice, opt-out available, standard TOMs, EU processing, short retention windows.
Legitimate-interest balancing test — company-level B2B visitor identification.

The balance tilts in your favour when — and only when — the processing stays at the company level. The moment you start attaching visits to named individuals without a separate legal basis, the analysis flips.

What about the ePrivacy directive (TDDDG / § 25)?

ePrivacy (in Germany implemented as the TDDDG, previously TTDSG § 25) governs access to information already stored on a terminal device — the classic reason cookie banners exist. Company-level identification via IP resolution does not store or read information on the visitor's device. No cookie, no localStorage, no fingerprint. Therefore § 25 does not trigger and no consent banner is required for this specific purpose.

Where teams still need a consent banner

Almost every real site runs additional analytics or ad pixels that do access the device (Google Analytics, LinkedIn Insight, Meta Pixel, chat widgets with session storage). Those still need a proper Consent Management Platform. Company-level identification simply is not one of the tools that puts you into banner territory.

What you as the customer have to do

The tool being GDPR-fit is one half; the other half sits with the site operator. Three actions cover it — none of them take longer than a coffee.

  1. Update your privacy notice. Add a paragraph on company-level visitor identification, the legitimate interest, the resolver step and the opt-out. A ready-to-copy snippet is on our GDPR page.
  2. Conclude the DPA. Under Art. 28 GDPR you conclude a data processing agreement with us — digitally, from the workspace settings. See our DPA page for the annex, TOMs summary and sub-processor list.
  3. Publish a working opt-out. Link the /opt-out page from your privacy notice so visitors can object. We honour the objection at the resolver level.

The opt-out

Objection is a right under Art. 21 GDPR, and a working opt-out is not just legally required — it is what makes the legitimate-interest argument credible in the first place. Two channels are always open: a self-service form at /opt-out that any visitor can use without an account, and an email to info@lead.box that we process manually within ten business days.

International transfers

All customer data, all resolver processing and all backups sit in the EU, in ISO 27001-certified data centres. There is no transfer to a third country as part of the standard product. If you enable a specific integration that ships data outside the EU (your choice, your CRM, your webhook target), that transfer is on your controller side; we document what leaves in the DPA.

This article provides general orientation, not legal advice. For a binding assessment of your specific setup, please consult qualified counsel or your DPO.

lead.box Team

Published by

lead.box Team

More articles

See lead.box on your own traffic

Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.

Start free trial

Notes on GDPR B2B lead intelligence

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links