The short answer is yes — with three conditions. The processing has to stay at the company level, it has to be transparently disclosed in your privacy notice, and data subjects need a working way to object. Below is the long answer, written for people who actually have to defend the tool in a meeting with legal or the DPO.
Is a company IP even personal data?
For the GDPR, an IP address is treated as personal data whenever it can, in reasonable steps, be linked back to a natural person (Breyer, C-582/14). A company IP that only resolves to a legal entity is still personal data in a formal sense — some individual sits behind the connection — but the identification we perform never attaches to a person. We resolve the IP to an organisation, discard the raw IP after resolution, and store no user-level identifiers.
That is the crucial distinction: personal data is processed at the moment the IP hits the server, and immediately reduced to an organisation-level record. The GDPR still applies to that brief processing, so a legal basis is required — and legitimate interest is the natural fit.
Legitimate interest under Art. 6(1)(f)
Art. 6(1)(f) allows processing where a controller has a legitimate interest that is not overridden by the rights and interests of the data subject. For B2B visitor identification, the balancing test is well-trodden ground and looks like this.
| Element | Assessment |
|---|---|
| Legitimate interest | Sales / marketing analytics on your own site — recognised by recitals 47 and 48 as a legitimate business interest. |
| Necessity | Company resolution is the least intrusive means to answer which organisations are on the site — no personal profile is built. |
| Proportionality | IP is discarded post-resolution, no cross-site profile, no behavioural advertising, no data sales. |
| Reasonable expectation | A visitor from a company network expects that their employer's presence on a supplier site is visible; individual identification is neither promised nor delivered. |
| Safeguards | Transparent privacy notice, opt-out available, standard TOMs, EU processing, short retention windows. |
The balance tilts in your favour when — and only when — the processing stays at the company level. The moment you start attaching visits to named individuals without a separate legal basis, the analysis flips.
What about the ePrivacy directive (TDDDG / § 25)?
ePrivacy (in Germany implemented as the TDDDG, previously TTDSG § 25) governs access to information already stored on a terminal device — the classic reason cookie banners exist. Company-level identification via IP resolution does not store or read information on the visitor's device. No cookie, no localStorage, no fingerprint. Therefore § 25 does not trigger and no consent banner is required for this specific purpose.
Where teams still need a consent banner
Almost every real site runs additional analytics or ad pixels that do access the device (Google Analytics, LinkedIn Insight, Meta Pixel, chat widgets with session storage). Those still need a proper Consent Management Platform. Company-level identification simply is not one of the tools that puts you into banner territory.
What you as the customer have to do
The tool being GDPR-fit is one half; the other half sits with the site operator. Three actions cover it — none of them take longer than a coffee.
- Update your privacy notice. Add a paragraph on company-level visitor identification, the legitimate interest, the resolver step and the opt-out. A ready-to-copy snippet is on our GDPR page.
- Conclude the DPA. Under Art. 28 GDPR you conclude a data processing agreement with us — digitally, from the workspace settings. See our DPA page for the annex, TOMs summary and sub-processor list.
- Publish a working opt-out. Link the /opt-out page from your privacy notice so visitors can object. We honour the objection at the resolver level.
The opt-out
Objection is a right under Art. 21 GDPR, and a working opt-out is not just legally required — it is what makes the legitimate-interest argument credible in the first place. Two channels are always open: a self-service form at /opt-out that any visitor can use without an account, and an email to info@lead.box that we process manually within ten business days.
International transfers
All customer data, all resolver processing and all backups sit in the EU, in ISO 27001-certified data centres. There is no transfer to a third country as part of the standard product. If you enable a specific integration that ships data outside the EU (your choice, your CRM, your webhook target), that transfer is on your controller side; we document what leaves in the DPA.
This article provides general orientation, not legal advice. For a binding assessment of your specific setup, please consult qualified counsel or your DPO.
Published by
lead.box Team
More articles
See lead.box on your own traffic
Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.
