Markets

B2B visitor identification, market by market

Ten markets, ten different rulebooks. Each page sets out the law that applies, the authority that supervises it, and what a local buyer asks before signing off.

The mechanism does not change from country to country: identification resolves the organisation behind a visit, never an individual person. What changes is the legal framework it has to be documented against — the GDPR plus national law in the EU, the UK GDPR and PECR in Britain, the revised FADP in Switzerland, and separate PDPL regimes in the UAE and Saudi Arabia.

Pick the market you sell into. Every page describes its own framework and closes with the same five rules lead.box applies everywhere.

Germany

Company-level visitor identification under the GDPR and the BDSG, reviewed by DPOs and state authorities.

Framework:
GDPR + BDSG
Supervision:
BfDI and the state authorities
Read the market page

Austria

One national authority, one German-language documentation set: the GDPR plus the Austrian DSG.

Framework:
GDPR + DSG
Supervision:
Datenschutzbehörde (DSB)
Read the market page

Switzerland

Not the GDPR: the revised FADP has its own vocabulary, its own register duties and its own regulator.

Framework:
revFADP (revDSG)
Supervision:
FDPIC (EDÖB)
Read the market page

United Kingdom

Two regimes at once: the UK GDPR for the data and PECR for anything stored on a visitor's device.

Framework:
UK GDPR + PECR
Supervision:
Information Commissioner's Office (ICO)
Read the market page

Netherlands

A vocal regulator, a mature cookie debate and buyers who ask for the DPA before the demo.

Framework:
GDPR + UAVG
Supervision:
Autoriteit Persoonsgegevens (AP)
Read the market page

Spain

The LOPDGDD adds Spanish specifics on top of the GDPR, and the AEPD publishes detailed guidance.

Framework:
GDPR + LOPDGDD
Supervision:
Agencia Española de Protección de Datos (AEPD)
Read the market page

Denmark

Documentation-first buyers, a pragmatic regulator and a short path from question to written answer.

Framework:
GDPR + Databeskyttelsesloven
Supervision:
Datatilsynet
Read the market page

Finland

The Tietosuojalaki plus an ombudsman model: written reasoning matters more than checkbox compliance.

Framework:
GDPR + Tietosuojalaki
Supervision:
Office of the Data Protection Ombudsman
Read the market page

United Arab Emirates

A federal PDPL, free-zone regimes alongside it, and transfer rules that decide where data may sit.

Framework:
PDPL (Federal Decree-Law No. 45/2021)
Supervision:
UAE Data Office
Read the market page

Saudi Arabia

SDAIA's PDPL and its implementing regulations set the rules — including for transfers out of the Kingdom.

Framework:
PDPL
Supervision:
SDAIA
Read the market page

Italy

A regulator known for detailed tracking guidance — and why cookieless company-level identification sits outside it.

Framework:
GDPR + Codice Privacy
Supervision:
Garante per la protezione dei dati personali
Read the market page

Sweden

Documentation-led procurement, high SaaS maturity and a regulator that publishes its reasoning.

Framework:
GDPR + Dataskyddslagen
Supervision:
IMY (Integritetsskyddsmyndigheten)
Read the market page

France

The CNIL's strict cookie doctrine is exactly why cookieless company identification is worth explaining here.

Framework:
GDPR + Loi Informatique et Libertés
Supervision:
CNIL
Read the market page

Belgium

Two working languages, one framework act and a buyer base shaped by the EU institutions in Brussels.

Framework:
GDPR + national framework act
Supervision:
APD / GBA
Read the market page

Ireland

The DPC leads many cross-border cases — which raises the bar for vendor reviews on Irish soil.

Framework:
GDPR + Data Protection Act 2018
Supervision:
Data Protection Commission (DPC)
Read the market page

Poland

A fast-growing B2B services market where formal records of processing are actually checked.

Framework:
GDPR + Ustawa o ochronie danych osobowych
Supervision:
UODO
Read the market page

Norway

Not in the EU, fully inside the GDPR: how the EEA agreement settles the transfer question.

Framework:
GDPR via the EEA + Personopplysningsloven
Supervision:
Datatilsynet (Norway)
Read the market page

Turkey

Its own law, its own register duty and its own transfer rules — GDPR-shaped, but not the GDPR.

Framework:
KVKK (Law No. 6698)
Supervision:
Kişisel Verileri Koruma Kurumu (KVKK)
Read the market page

United States

No federal privacy act, a growing patchwork of state laws — and a European bar applied as the common denominator.

Framework:
CCPA/CPRA and further state laws
Supervision:
FTC and state attorneys general
Read the market page

Singapore

Asia's English-speaking B2B hub, with the PDPA and a regulator that publishes practical advisories.

Framework:
PDPA 2012
Supervision:
PDPC
Read the market page

China

For Chinese exporters: see which European and US companies visit your site, processed in the EU.

Framework:
PIPL (2021)
Supervision:
Cyberspace Administration of China (CAC)
Read the market page

Qatar

The Gulf’s first comprehensive privacy law, plus a financial free zone with its own rulebook.

Framework:
PDPPL (Law No. 13 of 2016) + QFC regime
Supervision:
the competent data protection body of the ministry (NCGAA)
Read the market page

Bahrain

An early regional legislator: registration duties and transfer rules that shape how vendors are reviewed.

Framework:
PDPL (Law No. 30 of 2018)
Supervision:
Personal Data Protection Authority
Read the market page

Oman

A young regime with implementing regulations, next to an economy actively diversifying away from oil.

Framework:
PDPL (Royal Decree 6/2022)
Supervision:
MTCIT
Read the market page

Portugal

One national implementing act and one regulator, the CNPD, with documentation expected in Portuguese.

Framework:
GDPR + Lei n.º 58/2019
Supervision:
CNPD
Read the market page

Czechia

An engineering-heavy market where the ÚOOÚ expects records that match what the site actually does.

Framework:
GDPR + Act No. 110/2019 Coll.
Supervision:
ÚOOÚ
Read the market page

Hungary

The NAIH is known for active, formal enforcement — documentation has to hold up to inspection.

Framework:
GDPR + Infotv. (Act CXII of 2011)
Supervision:
NAIH
Read the market page

Romania

A large software and outsourcing market where buyers run vendor reviews themselves every week.

Framework:
GDPR + Law No. 190/2018
Supervision:
ANSPDCP
Read the market page

Greece

Shipping, energy and travel tech under Law 4624/2019, supervised by the HDPA.

Framework:
GDPR + Law 4624/2019
Supervision:
HDPA
Read the market page

Croatia

A compact export market where the AZOP sets the tone for how vendor documentation is read.

Framework:
GDPR + national implementing act
Supervision:
AZOP
Read the market page

Slovenia

ZVOP-2 arrived only in 2023, which is why reviewers here check whether documents are current.

Framework:
GDPR + ZVOP-2 (2023)
Supervision:
Informacijski pooblaščenec (IP)
Read the market page

Estonia

Digital-native buyers in e-Estonia ask technical questions, not marketing ones.

Framework:
GDPR + Isikuandmete kaitse seadus
Supervision:
AKI (Andmekaitse Inspektsioon)
Read the market page

Latvia

Small sales teams in logistics and manufacturing, supervised by the DVI.

Framework:
GDPR + national data protection act
Supervision:
DVI (Datu valsts inspekcija)
Read the market page

Lithuania

Vilnius fintech pairs data protection review with regulatory vendor due diligence.

Framework:
GDPR + national data protection act
Supervision:
VDAI (Valstybinė duomenų apsaugos inspekcija)
Read the market page

Inside the United States: state privacy laws

The US has no single federal privacy statute, so the applicable rules follow the state your buyer sits in. These pages belong to the United States market and each covers one state law, its enforcement, and how it treats business-to-business data.

United States market page

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links