What Art. 6(1)(f) actually requires
Legitimate interest allows processing that a controller needs for a genuine interest of its own, provided the interests and rights of the data subject do not override it. Regulators read that as a three-step test: is there a legitimate purpose, is the processing necessary for it, and does the balancing come out in the controller's favour?
The test is a documentation exercise, not a formality. You are expected to have written down your reasoning before the processing starts, and to be able to show it if someone asks. This page is a plain-language walkthrough, not legal advice — your own data protection counsel makes the final call.
Step 1 — purpose
The purpose here is ordinary B2B sales and marketing: recognising which companies show interest in your offering so you can follow up with the ones that matter and stop guessing about the rest. That is a recognised commercial interest, and it is the same reason trade fairs, account-based marketing and outbound calling exist.
What matters for the file is specificity. "Improving marketing" is too vague to test; "identifying companies that visit our pricing and product pages so sales can prioritise follow-up" is a purpose you can actually assess.
Step 2 — necessity
Necessity asks whether the processing is a reasonable way to reach that purpose, and whether a less intrusive route exists. Aggregate web analytics cannot tell you which company was interested; forms only capture the small share of visitors willing to fill them in. Company-level identification is the least intrusive option that still answers the question, because it stops at the organisation.
Necessity also constrains scope. Processing more than you need — for example resolving individuals, or keeping data far longer than your sales cycle — weakens the necessity argument even when the purpose is fine.
Step 3 — balancing
Balancing weighs the visitor's rights and reasonable expectations against your interest. Three properties of company-level identification move that balance in your favour: the output is a legal entity rather than a person, the data is not combined into cross-site profiles, and the processing happens in the EU on infrastructure you can review before you commit.
Transparency and control complete the picture. lead.box gives you a ready-made privacy-policy paragraph to disclose the processing, and there is a public opt-out page where a visitor can object; companies can additionally request a company-level opt-out. We keep a documented balancing test on file and share it on request, so your own assessment does not have to start from a blank page.
Related questions
Review it before you buy
The DPA, the sub-processor list and the privacy-policy paragraph are all public, so legal review can happen during the free 14-day trial — no credit card required.