Markets

B2B website visitor identification in Germany

German B2B websites carry a lot of unrecognised demand: procurement, engineering and management research vendors for weeks before anyone fills in a form. Company-level identification makes that research visible as a company name instead of an anonymous session, which is what turns a quiet week of traffic into a follow-up list.

  • FrameworkGDPR + BDSG (Bundesdatenschutzgesetz)
  • SupervisionBfDI at federal level, one authority per federal state
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

Germany is also the market where the data protection question is asked first and answered in writing. This page describes the legal framework that applies here, what buyers and data protection officers typically want to see, and how lead.box is set up for it.

At a glance

Framework
GDPR + BDSG (Bundesdatenschutzgesetz)
Supervision
BfDI at federal level, one authority per federal state
Usual legal basis
Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
Processing location
ISO-certified EU data centres

The legal framework in Germany

Regulation at a glance

  • FrameworkGDPR + BDSG (Bundesdatenschutzgesetz)
  • SupervisionBfDI at federal level, one authority per federal state
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

Two layers apply at the same time. The GDPR sets the substance — lawful basis, purpose limitation, data subject rights, processor contracts — and the Bundesdatenschutzgesetz (BDSG) fills in what German law is allowed to specify on top of it, including rules around the works council, employee data and the mandatory appointment of a data protection officer in many organisations. For a B2B website that means the documentation burden is real but predictable: a lawful basis you can explain, an entry in your record of processing activities, and a processor agreement on file.

Supervision is federal in structure. The BfDI oversees federal bodies and telecommunications, while each of the sixteen federal states runs its own authority for private companies — which is why guidance can differ in emphasis between, say, Bavaria and Hamburg even though the underlying law is identical. Practically, the authority relevant to you is the one where your company is established, and its published guidance is the reference your own documentation should be able to withstand.

German practice also treats the technical layer separately from the data layer. The TDDDG (formerly TTDSG) governs storing information on, or reading it from, a visitor's device, which is the rule that drives cookie banners. Company-level identification that does not store advertising identifiers on the device sits outside that consent logic — but the assessment of your own site, with everything else running on it, stays yours as the controller.

What the German market expects

In practice the deal-breaker is rarely the feature list. It is whether a data protection officer can sign the tool off without a long internal debate. Expect requests for a processor agreement under Art. 28 GDPR, a named list of sub-processors, a statement on where data is processed, and a plain description of what exactly is stored per visit. Those four documents settle most reviews.

The second expectation is language. German buyers read German documentation, and a legal text that only exists in English slows a review down for no good reason. lead.box ships its interface, its legal documents and this market page in German, so the internal review does not depend on someone translating a policy in a meeting.

The third is sobriety. Claims that a tool makes GDPR questions disappear tend to end the conversation with a serious reviewer. What holds up instead is a description of the mechanism: what is resolved, what is discarded, and where the customer's own responsibility begins.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

The pattern that benefits most is the German Mittelstand engineering and industrial sale: long research cycles, several people from the same company visiting over weeks, and a form that only gets filled in at the very end. Seeing the company early lets sales reach out while the evaluation is still open instead of after a shortlist has formed.

It also fits professional services, SaaS and manufacturing suppliers with a defined regional footprint, where a single recognised company is worth a phone call. Nothing here depends on volume: a site with a few hundred visits a week can still produce a workable weekly list of companies worth contacting.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

It is workable under the GDPR and the BDSG when identification stays strictly at company level and no individual person is singled out. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, documented with a written balancing test that weighs your business interest against the visitor's expectations, and the identification is disclosed in your privacy policy. Many German DPOs also want to see that the balancing test names the specific purpose — sales follow-up, not profiling — and that it is reviewed periodically rather than filed once and forgotten. The final assessment always stays with you as the controller; lead.box acts strictly as processor under a data processing agreement, and never resolves a visit to a named individual.

For private companies, it is the data protection authority of the federal state in which your company has its registered seat, not the state where your servers or your customers sit. The BfDI only supervises federal public bodies and telecommunications providers, so it will rarely be the relevant contact for a B2B website operator. The sixteen state authorities apply the same GDPR text but sometimes phrase guidance differently — Bavaria's LDA and Hamburg's HmbBfDI, for example, do not always word legitimate-interest guidance identically. In practice, your own state authority's published position is the benchmark your documentation should be measured against, and that is where a complaint would land first.

Company-level identification with lead.box does not create advertising identifiers, device fingerprints or cross-site profiles, so it does not rely on the storage-and-access consent logic in Section 25 TDDDG that drives cookie banners for tracking pixels and ad tech. That said, most German B2B sites already run analytics or marketing tags that do require consent, and whether your overall setup needs a banner, and whether you place the lead.box snippet inside or outside a consent category, remains your own documented assessment as the controller — lead.box's own mechanism is simply outside that particular question.

Personal and visitor data concerning EU visitors is processed in ISO-certified EU data centres, and that data is not moved outside the EU for this purpose, which removes the Chapter V transfer-impact-assessment question that otherwise slows down many German procurement reviews. The data processing agreement under Art. 28 GDPR and the versioned sub-processor list are published rather than sent only on request, so a data protection officer can complete a first review before a sales call is even booked, and can re-check the sub-processor list later without asking anyone for an updated copy.

Under Section 87(1) no. 6 BetrVG, a works council has a co-determination right over technical systems that are suited to monitoring employee behaviour or performance. Company-level website visitor identification resolves the visiting organisation, not the individual employee browsing the site, so most legal teams treat it differently from an employee-monitoring tool — but if your company has a works council, it is still sensible to inform it early, particularly if the resulting lists are later matched against a CRM that also tracks sales activity. lead.box provides the technical description your legal team needs to make that call, but the labour-law classification stays with your own HR and legal function.

German procurement and legal teams tend to work through a fixed checklist rather than a general conversation: the Art. 28 DPA, the current sub-processor list with a change-notification mechanism, a statement on the data processed per visit, confirmation that no individuals or device identifiers are captured, and an entry you can copy into your own Verzeichnis von Verarbeitungstätigkeiten. Because lead.box publishes these documents with version numbers, a Datenschutzbeauftragter can usually complete a first pass without a call, and the remaining questions in a kickoff meeting are typically about your own website setup rather than about the vendor.

Most German teams install the JavaScript snippet through a tag manager such as Google Tag Manager, which their IT department already governs, so no direct code deployment is needed and the change is auditable like any other tag. Identified companies appear in the dashboard within the same day, and from there they can be exported as CSV or Excel for a weekly Vertriebsmeeting, pushed by webhook into a CRM such as HubSpot or Salesforce, or handed to an account owner as a filtered list by industry, region or page visited — which matters in a Mittelstand sales process organised around named Betreuer rather than a shared queue.

lead.box is designed for self-service management: you can add or remove team seats as your Vertriebsteam changes, and cancellation happens directly in the account settings without a phone call or a written Kündigung sent by post, which German SaaS buyers increasingly expect after years of being locked into annual terms with paper cancellation processes. This also matters for a DPO sign-off, because a tool that is easy to switch off is easier to approve for a pilot: the commercial exit is as documented as the data protection entry, and neither depends on the other.

See which German companies are already on your site

Install a first-party snippet, watch the first companies appear, and hand your data protection officer the documents in the same week.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links