Markets

B2B website visitor identification in Croatia

Croatian B2B sites, especially in software and export-oriented industrial manufacturing, see a steady flow of anonymous research from buyers who compare vendors quietly, often across several EU markets at once, before a form is ever submitted. Company-level identification names the account behind that visit while the comparison is still open, rather than only once a request lands by email.

  • FrameworkGDPR + Zakon o provedbi Opće uredbe o zaštiti podataka
  • SupervisionAZOP (Agencija za zaštitu osobnih podataka)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

Croatia is a smaller market with a software and industrial export sector disproportionate to its size, and a meaningful share of B2B projects there run on EU co-funding, which brings its own procurement and reporting habits. This page sets out the legal framework that applies here, what a Croatian vendor review typically checks, and how lead.box is set up to answer it.

At a glance

Framework
GDPR + Zakon o provedbi Opće uredbe o zaštiti podataka
Supervision
AZOP (Agencija za zaštitu osobnih podataka)
Usual legal basis
Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
Processing location
ISO-certified EU data centres

The legal framework in Croatia

Regulation at a glance

  • FrameworkGDPR + Zakon o provedbi Opće uredbe o zaštiti podataka
  • SupervisionAZOP (Agencija za zaštitu osobnih podataka)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

The GDPR provides the substantive rules, and Croatia's Zakon o provedbi Opće uredbe o zaštiti podataka (Act on the Implementation of the GDPR) fills in the national gaps: it establishes AZOP (Agencija za zaštitu osobnih podataka) as the supervisory authority, sets out administrative offence procedure and fines, and specifies rules on processing in areas such as employment and video surveillance that the GDPR leaves open. For a B2B website this means a defensible lawful basis, an internal record of processing activities, and a signed processor agreement before a script goes live.

AZOP is a smaller authority than its counterparts in larger member states, and it tends to act on complaints and sector-specific guidance rather than run continuous large-scale sweeps; its published opinions on legitimate interest and video/website monitoring are a useful reference point for how it reads the balancing test in practice. That makes a clearly reasoned, documented assessment more valuable than volume of paperwork when a Croatian counterpart asks how a visitor-identification tool is justified.

Cookie and electronic-communications rules sit in the Croatian Zakon o elektroničkim komunikacijama (Electronic Communications Act), which transposes the ePrivacy Directive and governs storing information on, or reading it from, a visitor's device. Identification that resolves a visit to a company without placing advertising identifiers or persistent tracking cookies falls outside that consent requirement, while everything else running on the site remains the controller's own assessment.

What the Croatian market expects

As a smaller market with an outsized software and industrial export sector, Croatian vendor review tends to be handled by a compact legal or IT team rather than a dedicated procurement department: expect a direct request for a data processing agreement under Art. 28 GDPR, a named sub-processor list, and a plain statement of where data is processed, rather than a long formal questionnaire.

A significant share of Croatian B2B projects, particularly in manufacturing modernisation and digital infrastructure, are co-funded through EU programmes, and teams running such projects are used to documentation-heavy reporting; they tend to ask precisely for evidence that a tool's processing fits within an already-approved data protection framework rather than accepting general assurances. Documentation available in Croatian, alongside English, speeds up internal sign-off in teams that review contracts without external counsel.

Claims that a vendor's tool removes the need for a legal assessment do not hold up with an AZOP-literate reviewer. What holds up is a precise account of the mechanism — what is resolved to a company, what is discarded, and where the customer's own responsibility as controller begins.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

Croatia's software companies and industrial exporters sell heavily into other EU markets, and their buyers — often procurement or technical teams abroad — research a vendor's site and documentation over weeks before making contact, usually without filling in a form. Seeing the company behind that visit early lets a sales team follow up while the evaluation is still live.

The same applies to suppliers involved in EU-funded modernisation and infrastructure projects, where a single identified visit from a known partner organisation or contractor is worth immediate, targeted outreach rather than waiting on a tender notice or inbound enquiry that may never arrive.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

It is workable under the GDPR and the Zakon o provedbi Opće uredbe o zaštiti podataka, so long as the output stays at company level and does not identify a person. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, backed by a written balancing test weighing your commercial interest in recognising researching accounts against the visitor's reasonable expectations, and disclosed in your privacy policy. AZOP tends to act on complaints and published guidance rather than run broad proactive sweeps, so a compact but well-reasoned assessment usually matters more here than a lengthy compliance binder. lead.box operates as your processor under a signed Art. 28 agreement, but the final lawfulness call for your specific site remains yours as controller, and it is worth having your own legal advisor confirm the basis fits your setup, particularly if other tracking tools already run alongside it.

AZOP, the Agencija za zaštitu osobnih podataka, is Croatia's supervisory authority under the GDPR and the national implementation act, and it is a comparatively small body that acts primarily on complaints and issues sector guidance rather than running continuous large-scale audits of the kind seen in some larger member states. Its published opinions on legitimate interest and on video or website monitoring are a practical reference for how it applies the balancing test, and Croatian legal reviewers frequently cite them directly rather than working from GDPR text alone. Because AZOP's approach favours a clearly reasoned position over a thick paper trail, having a plain, specific explanation of what lead.box resolves and discards tends to satisfy a reviewer faster than a generic compliance statement, though your counsel should confirm this against your own risk tolerance and site setup.

Company-level identification through lead.box does not place advertising identifiers, device fingerprints or persistent tracking cookies, so on its own it falls outside the consent requirement in the Zakon o elektroničkim komunikacijama, Croatia's implementation of the ePrivacy Directive that governs storing or reading information on a visitor's device. Most Croatian B2B sites run other tools, such as analytics platforms or advertising pixels, that do trigger this requirement, and your existing banner configuration for those should not need to change just because lead.box is added. HAKOM, the national electronic communications regulator, is not typically the enforcement contact for cookie consent in practice, which sits with AZOP under the GDPR framework instead, but whether your specific implementation needs adjustment and how you document the snippet remains your own assessment as controller, ideally confirmed with legal advice familiar with current practice.

Data concerning EU visitors is processed in ISO-certified EU data centres and is not routed or stored outside the EU for this purpose, which matters to Croatian IT and legal teams that often ask this question first, before moving on to legal basis, given how compact these reviews tend to be. Retention is limited to what is needed to resolve and deliver company-level matches rather than kept indefinitely, and the versioned sub-processor list is published so it can be checked before approval rather than requested separately partway through negotiation. A signed data processing agreement under Art. 28 GDPR is available upfront, which tends to matter more to Croatian buyers than a long formal questionnaire, since review here is usually handled directly by a small legal or IT team rather than a dedicated procurement function with its own standard process.

There is no separate legal regime specifically for EU-co-funded projects, but a meaningful share of Croatian B2B activity, particularly in manufacturing modernisation and digital infrastructure, runs on EU programme funding, and the teams managing such projects are used to documentation-heavy reporting requirements that extend to vendor selection. They tend to ask precisely for evidence that a tool's processing fits within an already-approved data protection framework, rather than accepting a general assurance that everything is compliant, since that evidence often needs to be filed alongside the project's own reporting. lead.box's published processor agreement and sub-processor list are structured to make that kind of check straightforward, and it is worth confirming with your project's compliance officer exactly what form of evidence their specific funding body expects to see filed.

Croatian companies are identified for tax and invoicing purposes by their OIB (Osobni identifikacijski broj, personal identification number, which also applies to legal entities), and a subscription contract should reference the correct OIB together with the registered company name from the sudski registar, since Croatian finance teams generally will not process a supplier invoice with a mismatched OIB. For cross-border B2B services within the EU, VAT is typically handled through the reverse-charge mechanism rather than charged directly on the invoice, but your own finance or tax advisor should confirm the applicable treatment for your entity, since this can depend on registration status and how your business is structured. Getting the OIB and legal entity name correct at contracting stage avoids the invoice-matching delays that Croatian accounting teams commonly flag during procurement.

Company-level identification resolves a website visit to the organisation behind it, typically through IP-to-company matching combined with first-party signals collected on your own site, and it deliberately stops before identifying, profiling or contacting the individual browsing, which is the distinction a Croatian reviewer will focus on given how AZOP's guidance treats personal-level monitoring versus aggregate business signals. No name, email address or individual browsing history tied to a specific person is produced or retained as part of the process; the result is a company name with firmographic context for your sales team to act on, not a personal profile of the visitor. This is also the reasoning behind treating legitimate interest under Art. 6(1)(f) GDPR as a workable basis here, though your own data protection officer or counsel should confirm this fits your specific configuration and any other data sources you combine it with.

Timelines vary, but because Croatian vendor review is typically handled directly by a compact in-house legal or IT team rather than a dedicated procurement department, having documentation ready upfront tends to matter more than in larger markets with formal multi-step approval chains. Supplying the Art. 28 data processing agreement, the sub-processor list and a plain-language description of the mechanism before the first call removes several rounds of clarifying questions that otherwise stretch a review out over weeks. Since AZOP's own guidance favours a clearly reasoned position over volume of paperwork, being able to state precisely what is resolved to a company, what is discarded, and where your own responsibility as controller begins is usually the single factor that most shortens approval for Croatian teams evaluating lead.box against their internal criteria.

See which companies are already researching you in Croatia

Install a first-party snippet, watch the first companies appear, and hand your legal or procurement reviewer the documents in the same week.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links