Germany
Company-level visitor identification under the GDPR and the BDSG, reviewed by DPOs and state authorities.
- Framework:
- GDPR + BDSG
- Supervision:
- BfDI and the state authorities
Ten markets, ten different rulebooks. Each page sets out the law that applies, the authority that supervises it, and what a local buyer asks before signing off.
The mechanism does not change from country to country: identification resolves the organisation behind a visit, never an individual person. What changes is the legal framework it has to be documented against — the GDPR plus national law in the EU, the UK GDPR and PECR in Britain, the revised FADP in Switzerland, and separate PDPL regimes in the UAE and Saudi Arabia.
Pick the market you sell into. Every page describes its own framework and closes with the same five rules lead.box applies everywhere.
Company-level visitor identification under the GDPR and the BDSG, reviewed by DPOs and state authorities.
One national authority, one German-language documentation set: the GDPR plus the Austrian DSG.
Not the GDPR: the revised FADP has its own vocabulary, its own register duties and its own regulator.
Two regimes at once: the UK GDPR for the data and PECR for anything stored on a visitor's device.
A vocal regulator, a mature cookie debate and buyers who ask for the DPA before the demo.
The LOPDGDD adds Spanish specifics on top of the GDPR, and the AEPD publishes detailed guidance.
Documentation-first buyers, a pragmatic regulator and a short path from question to written answer.
The Tietosuojalaki plus an ombudsman model: written reasoning matters more than checkbox compliance.
A federal PDPL, free-zone regimes alongside it, and transfer rules that decide where data may sit.
SDAIA's PDPL and its implementing regulations set the rules — including for transfers out of the Kingdom.
A regulator known for detailed tracking guidance — and why cookieless company-level identification sits outside it.
Documentation-led procurement, high SaaS maturity and a regulator that publishes its reasoning.
The CNIL's strict cookie doctrine is exactly why cookieless company identification is worth explaining here.
Two working languages, one framework act and a buyer base shaped by the EU institutions in Brussels.
The DPC leads many cross-border cases — which raises the bar for vendor reviews on Irish soil.
A fast-growing B2B services market where formal records of processing are actually checked.
Not in the EU, fully inside the GDPR: how the EEA agreement settles the transfer question.
Its own law, its own register duty and its own transfer rules — GDPR-shaped, but not the GDPR.
No federal privacy act, a growing patchwork of state laws — and a European bar applied as the common denominator.
Asia's English-speaking B2B hub, with the PDPA and a regulator that publishes practical advisories.
For Chinese exporters: see which European and US companies visit your site, processed in the EU.
The Gulf’s first comprehensive privacy law, plus a financial free zone with its own rulebook.
An early regional legislator: registration duties and transfer rules that shape how vendors are reviewed.
A young regime with implementing regulations, next to an economy actively diversifying away from oil.
One national implementing act and one regulator, the CNPD, with documentation expected in Portuguese.
An engineering-heavy market where the ÚOOÚ expects records that match what the site actually does.
The NAIH is known for active, formal enforcement — documentation has to hold up to inspection.
A large software and outsourcing market where buyers run vendor reviews themselves every week.
Shipping, energy and travel tech under Law 4624/2019, supervised by the HDPA.
A compact export market where the AZOP sets the tone for how vendor documentation is read.
ZVOP-2 arrived only in 2023, which is why reviewers here check whether documents are current.
Digital-native buyers in e-Estonia ask technical questions, not marketing ones.
Small sales teams in logistics and manufacturing, supervised by the DVI.
Vilnius fintech pairs data protection review with regulatory vendor due diligence.
The US has no single federal privacy statute, so the applicable rules follow the state your buyer sits in. These pages belong to the United States market and each covers one state law, its enforcement, and how it treats business-to-business data.
B2B Lead Identification Platform
lead.box — Identify the companies visiting your website
lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.