Legal · June 19, 2026 · 8 min read

Privacy in plain terms: what your website may know about visitors

You are not a lawyer. You do not want to become one. Here is what your website is actually allowed to know about the people (and companies) who visit — in the same everyday words you would use to explain it at a dinner table.

An open book with a small shield-and-checkmark overlay and soft rays of light.

Data-protection law can sound like a foreign language. It doesn’t need to. Below is the same law explained the way you would explain it to a friend over dinner — with examples, without paragraphs of Latin, and with an honest note where things get uncertain. This is not legal advice; use your DPO for anything binding.

The basic idea, in one paragraph

GDPR asks you to (a) be clear about what you collect and why, (b) collect only what you need, (c) keep it as long as you need it and not longer, (d) let people see or delete it if they ask, and (e) protect it. That’s it. Everything else is detail.

‘Legitimate interest’ — the phrase everyone stumbles over

There are six lawful reasons you may process personal data. The most common one in B2B marketing is called ‘legitimate interest’. It’s a fancy way of saying: you have a real business reason, the person isn’t reasonably harmed, and if you had to explain yourself in plain terms it would sound reasonable.

Think of it like this. If you write down that you visited a shop yesterday, and next week the shop calls you and says ‘Hi, saw you were interested in bread — want to try our sourdough?’ — most people would say ‘okay’. That’s roughly the level of surprise B2B account intelligence causes. Not zero. But defensible.

Non-legal-advice

This piece uses everyday analogies to explain concepts. It is not a legal opinion and cannot replace advice from a qualified DPO or lawyer. Wording for policies should be reviewed with your own counsel.

Company data vs personal data

Knowing that ‘Nordwerk GmbH visited your website’ is different from knowing that ‘Anna Schmidt visited your website’. The first is company-level information — largely not personal data in the sense the law worries about. The second is a person, and rules tighten immediately.

A company-level visitor-identification tool sits deliberately on the company side of that line. It sees the delivery van’s logo, not the driver.

DetailSensitivity
Company name and domainLow
Industry and rough sizeLow
Anonymous browsing on your own siteLow
A person's name and emailHigher
Health, religion, political viewsSpecial category — very high
Cross-site advertising profileHigher, and often requires consent
What GDPR treats as high-sensitivity versus low.

You need a cookie/consent banner when you place things on the visitor’s device that are not strictly necessary for the service they asked for — chiefly advertising and analytics that persist across sites. First-party identifiers strictly necessary for the requested service fall under a narrower ‘strictly necessary’ exemption. If you also run advertising cookies, you still need a banner for those — company-level identification does not remove that need.

Practical answer: keep your consent banner for whatever advertising and cross-site analytics you already run. Add a paragraph to your privacy policy about company-level identification (we have a template linked below).

What visitors can ask you

Any visitor may ask what you know about them, ask to correct it, or ask to delete it. For company-level data, the ‘about them’ question rarely returns anything person-specific. The right answer is always: respond promptly, honestly, and in plain language. See /opt-out for our self-serve mechanism.

One-page summary

  1. Collect what you need for a real reason. Not more.
  2. Prefer company-level data over person-level whenever it does the job.
  3. Keep a cookie banner for advertising and cross-site analytics.
  4. Publish a plain privacy paragraph explaining what you do.
  5. Answer requests promptly. Delete when asked.
  • Related: [Is website visitor identification GDPR-compliant?](/blog/is-website-visitor-identification-gdpr-compliant)
  • Related: [What your privacy policy must say when you identify companies](/blog/privacy-policy-paragraph-when-you-identify-companies)
  • Related: [Data minimalism: why collecting less makes marketing stronger](/blog/data-minimalism-why-collecting-less-makes-b2b-marketing-stronger)
lead.box Team

Published by

lead.box Team

More articles

See lead.box on your own traffic

Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.

Start free trial

Notes on GDPR B2B lead intelligence

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links