Markets

B2B website visitor identification in France

On French B2B websites, most demand is invisible: a buyer, an engineer and a finance manager from the same company each read a few pages, compare a competitor, and leave without a trace in the CRM. Company-level identification turns that silent research into a named account, weeks before a form is ever filled in.

  • FrameworkGDPR + Loi Informatique et Libertés
  • SupervisionCNIL (Commission nationale de l'informatique et des libertés)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

France is also the market with the most demanding cookie doctrine in the EU, driven by the CNIL. This page sets out the legal framework that applies, what a French compliance review typically checks, and how lead.box is built around company-level detection that avoids the device layer entirely.

At a glance

Framework
GDPR + Loi Informatique et Libertés
Supervision
CNIL (Commission nationale de l'informatique et des libertés)
Usual legal basis
Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
Processing location
ISO-certified EU data centres

The legal framework in France

Regulation at a glance

  • FrameworkGDPR + Loi Informatique et Libertés
  • SupervisionCNIL (Commission nationale de l'informatique et des libertés)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

The GDPR is directly applicable, and the Loi Informatique et Libertés — France's own data protection act, repeatedly amended to align with the GDPR — sits alongside it, covering matters the GDPR leaves to member states: criminal record data, certain public-sector processing, and the sanction regime that lets the CNIL fine controllers and processors under conditions mirrored in Art. 82 of the national act. For a website operator, the practical consequence is a French-language record of processing activities (registre des traitements) that a data protection officer or an external counsel can produce on request.

The CNIL is the supervisory authority, and it is also the author of detailed guidance — the 'lignes directrices' and 'recommandations' on cookies and trackers — that goes further than the bare text of the ePrivacy rules. Its doctrine treats a control that lets a visitor refuse tracking ('refuser') as needing to be exactly as easy to use as the control that lets them accept, and it has issued sanctions under Art. 82 Loi Informatique et Libertés against sites where that balance was missing. None of this is legal advice, and it does not change what your own site must do elsewhere on the page; it only frames why the mechanism behind a given tool matters to a French reviewer.

Against that backdrop, a detection method that never writes to or reads from the visitor's device sits outside the consent architecture the CNIL polices so closely. Company-level identification of the kind lead.box performs resolves a company name from network-level signals, not from a cookie, a local identifier or a fingerprint stored on the browser — which is a different question from whether the rest of your site needs a consent banner, an assessment that remains yours as the data controller.

What the French market expects

A French buyer's compliance question rarely stops at 'is it legal'. It continues with a request for documentation in French: a data processing agreement, a sub-processor list, and a plain description of what is stored per visit, all readable without translation by whoever owns the registre des traitements internally. lead.box publishes those documents so a DPO or an external Délégué à la protection des données can review them before signing off.

The second expectation is precision about the cookie question specifically. Because the CNIL's cookie doctrine is unusually strict and unusually well known among French compliance teams, a vague answer ('we're GDPR-compliant') tends to raise more suspicion than it resolves. What holds up is a factual description: no cookie is set by the identification mechanism, no identifier is read from the device, and the resulting data is a company name, not a person.

The third is that no serious French buyer accepts a certification claim at face value. Compliance in France is understood as an ongoing responsibility of the controller, verified case by case, not a badge a vendor can hand over. The useful conversation is about the mechanism and the contract, not about a claimed status.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

The pattern that benefits most in France is the long, formal B2B sales cycle typical of industrial equipment, IT services and consulting: several stakeholders from the same grand compte research quietly over weeks before a request for proposal is issued. Seeing the company name early lets a sales team reach out during the evaluation instead of waiting for the appel d'offres.

It also suits regional SMEs (PME/ETI) selling into a defined sector, where a handful of recognised companies a week is enough to justify outreach. Nothing here depends on traffic volume — a modestly visited site can still produce a short, workable weekly list of French companies worth a call.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

It is workable under Regulation (EU) 2016/679, which applies directly, together with the Loi Informatique et Libertés n°78-17, repeatedly amended to stay aligned with the GDPR. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, documented through a written balancing test (mise en balance) that weighs the commercial interest in identifying a visiting company against the expectations of whoever browses the site, and the practice is disclosed in the politique de confidentialité alongside other processing already listed there. The CNIL has published guidance on legitimate interest in the context of commercial prospecting that a French compliance reviewer will often check a vendor against, rather than accepting a generic GDPR statement. lead.box acts strictly as processor under a data processing agreement; the final assessment of whether this basis fits your own site and audience always stays with you as controller, and nothing here should be read as legal advice.

The CNIL (Commission nationale de l'informatique et des libertés) is the French supervisory authority, and it is unusually active in publishing detailed positions — lignes directrices and recommandations on cookies and trackers, including the well-known délibération n°2020-091 — that go beyond the bare ePrivacy text. Its doctrine and its sanctions under Art. 82 of the Loi Informatique et Libertés target consent interfaces that make refusing tracking harder than accepting it, a question that only arises once something is stored on or read from the visitor's device. Company-level identification resolves an organisation from network-level signals without writing to or reading from that device, so it sits outside the specific mechanism the CNIL's cookie doctrine polices. Whether the rest of a given site needs a compliant consent banner for its own trackers remains a separate question the controller has to answer, independent of this tool.

French legal and DPO teams generally expect three documents before signing off: the written balancing test under Art. 6(1)(f) GDPR naming the specific purpose (prospection commerciale, not profiling), an entry ready to drop into the registre des traitements required under Art. 30 GDPR, and the data processing agreement under Art. 28 GDPR with its sub-processor list. Many French groups already run a similar balancing-test template for other BtoB prospecting tools, so a reviewer usually recognises the pattern rather than starting from scratch. Where a data protection officer has been appointed under Art. 37 GDPR — common in larger French groups and public-facing organisations — that person typically wants the balancing test to state a review date rather than being filed once and forgotten. lead.box provides the underlying facts needed to complete these documents, but drafting and approving them stays the controller's own responsibility.

lead.box resolves the name and domain of the visiting company from network-level signals associated with the visit; it does not set a cookie, does not read or write anything on the visitor's device, and does not build a cross-site advertising profile. Just as importantly for a French reviewer, it does not identify or attempt to identify the named individual behind a visit, does not scrape professional network profiles, and does not append an email address to a session the way some sales-intelligence tools marketed for BtoB prospecting do — a distinction French compliance teams are increasingly used to asking about given CNIL scrutiny of aggressive prospecting practices. The output is a company name and the pages viewed, not a person and not a contact record, which keeps the processing at the company level the entire way through, from collection to export.

French BtoB sales cycles, particularly for equipement industriel, services informatiques and consulting sold to grands comptes, tend to run through several stakeholders who research quietly for weeks before a comité de direction issues a formal appel d'offres, and the final purchase decision is often reserved for a directeur général even when a manager ran the evaluation. Commercial teams typically work Salesforce, HubSpot or Pipedrive, and identified companies are pushed there by webhook so an Account Executive following named grands comptes sees a new company appear without manual entry. For smaller PME/ETI, a simple weekly CSV or Excel export reviewed in the point commercial meeting is often more practical than a live dashboard, and it fits the more hierarchical, formally structured way French sales organisations tend to review pipeline.

The data processing agreement under Art. 28 GDPR and a versioned sub-processor list are published so a DPO or an external avocat spécialisé can review them in French before a contract is signed rather than requesting them mid-negotiation. Data concerning EU visitors, including visitors from France, is processed in ISO-certified EU data centres and is not transferred outside the EU for this purpose, which removes the international transfer question that has become particularly sensitive in France following the CNIL's own scrutiny of non-EU processing tools such as its 2022 position on Google Analytics. Because French procurement often wants documents in hand before a comité de direction meeting rather than after, having the DPA, the sub-processor list and the residency statement available upfront tends to shorten rather than lengthen the internal approval cycle.

Getting started means adding a first-party JavaScript snippet to the site, most often through a tag manager such as Google Tag Manager, which is the deployment method most French web teams and their prestataires already govern, so no direct code change is usually required. Identified companies typically start appearing within the first days of traffic, and from there they can be exported as CSV or Excel for a weekly commercial review, or pushed automatically by webhook into whichever CRM the sales team already runs. Seats can be added for colleagues as the commercial team grows, and cancellation is handled through self-service account settings rather than a written lettre de résiliation sent by post, which matches how French SaaS buyers increasingly expect to trial and exit tools without a long-term engagement.

Identification resolves companies from network-level signals, and its accuracy depends on how a visit reaches the internet: an employee on a fixed office connection from a major French operator such as Orange, SFR, Bouygues or Free is generally resolved reliably, while a visitor on a mobile network, a personal VPN, or a shared connection is harder or impossible to attribute correctly. Large immeubles de bureaux and business parks that house several unrelated companies behind a single shared internet connection can also produce a resolved name that reflects the building's main tenant rather than the actual visiting company, and holding structures where several filiales share one group-level egress IP present a similar risk. lead.box treats every match as a signal for a sales team to qualify, not a verified fact, and a French sales rep should always confirm the account before treating a resolved name as a qualified lead.

See which French companies are already visiting your site

Install a first-party snippet, watch the first companies appear, and hand your DPO the French-language documents the same week.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links