FAQ in detail

Legitimate interest and visitor identification

Art. 6(1)(f) GDPR is not a blank cheque. It is a three-step test — and company-level identification is designed to pass it.

What Art. 6(1)(f) actually requires

Legitimate interest allows processing that a controller needs for a genuine interest of its own, provided the interests and rights of the data subject do not override it. Regulators read that as a three-step test: is there a legitimate purpose, is the processing necessary for it, and does the balancing come out in the controller's favour?

The test is a documentation exercise, not a formality. You are expected to have written down your reasoning before the processing starts, and to be able to show it if someone asks. This page is a plain-language walkthrough, not legal advice — your own data protection counsel makes the final call.

Step 1 — purpose

The purpose here is ordinary B2B sales and marketing: recognising which companies show interest in your offering so you can follow up with the ones that matter and stop guessing about the rest. That is a recognised commercial interest, and it is the same reason trade fairs, account-based marketing and outbound calling exist.

What matters for the file is specificity. "Improving marketing" is too vague to test; "identifying companies that visit our pricing and product pages so sales can prioritise follow-up" is a purpose you can actually assess.

Step 2 — necessity

Necessity asks whether the processing is a reasonable way to reach that purpose, and whether a less intrusive route exists. Aggregate web analytics cannot tell you which company was interested; forms only capture the small share of visitors willing to fill them in. Company-level identification is the least intrusive option that still answers the question, because it stops at the organisation.

Necessity also constrains scope. Processing more than you need — for example resolving individuals, or keeping data far longer than your sales cycle — weakens the necessity argument even when the purpose is fine.

Step 3 — balancing

Balancing weighs the visitor's rights and reasonable expectations against your interest. Three properties of company-level identification move that balance in your favour: the output is a legal entity rather than a person, the data is not combined into cross-site profiles, and the processing happens in the EU on infrastructure you can review before you commit.

Transparency and control complete the picture. lead.box gives you a ready-made privacy-policy paragraph to disclose the processing, and there is a public opt-out page where a visitor can object; companies can additionally request a company-level opt-out. We keep a documented balancing test on file and share it on request, so your own assessment does not have to start from a blank page.

Related questions

Review it before you buy

The DPA, the sub-processor list and the privacy-policy paragraph are all public, so legal review can happen during the free 14-day trial — no credit card required.

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links