Markets

B2B website visitor identification in Ireland

Irish B2B sites see a lot of research traffic that never reaches a form: procurement and technical teams look at pricing, integrations and case studies for weeks, often from a company that is also evaluating three other vendors in parallel. Company-level identification turns that anonymous research into a named account, so a sales team can follow up while the decision is still open rather than after a shortlist has already been agreed internally.

  • FrameworkGDPR + Data Protection Act 2018
  • SupervisionData Protection Commission (DPC)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

Ireland is also the jurisdiction where much of the world's tech industry has its EU headquarters, which means Irish buyers are used to detailed vendor security and privacy reviews even for mid-size tools. This page sets out the legal framework that applies here, what an Irish procurement or legal review typically asks for, and how lead.box is set up to answer it.

At a glance

Framework
GDPR + Data Protection Act 2018
Supervision
Data Protection Commission (DPC)
Usual legal basis
Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
Processing location
ISO-certified EU data centres

The legal framework in Ireland

Regulation at a glance

  • FrameworkGDPR + Data Protection Act 2018
  • SupervisionData Protection Commission (DPC)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

The GDPR sets the substantive rules, and the Data Protection Act 2018 is the national law that gives it effect in Ireland, establishing the Data Protection Commission (DPC), setting out enforcement powers and fixing the domestic detail the GDPR leaves to member states, such as the rules on certain special categories of data and the age of digital consent. For a B2B website, the practical consequence is a lawful basis you can articulate, a record of the processing in your documentation, and a written agreement with any processor you rely on.

Separately, storing information on, or reading it from, a visitor's device is governed by the ePrivacy Regulations 2011 (S.I. No. 336 of 2011), which transpose the EU ePrivacy Directive and are the rule behind Irish cookie banners. Identification that resolves a visit to a company without placing advertising identifiers or tracking cookies on the device sits outside that consent requirement, though the assessment of everything else running on the site remains the controller's own responsibility.

Ireland's position as the European seat of many global technology companies also means the DPC frequently acts as lead supervisory authority under the GDPR's one-stop-shop mechanism, coordinating cross-border cases with other EU regulators on behalf of companies established in Ireland. That role has made Irish guidance on legitimate interest, data transfers and processor obligations unusually detailed and widely referenced, which is a useful reference point even for a company that is not itself established in Ireland.

What the Irish market expects

Irish B2B buyers, shaped by a market dense with regulated multinationals, tend to run a security and privacy review before signing off on a new tool, even for a lightweight website script. Expect a request for a data processing agreement under Art. 28 GDPR, a named sub-processor list, confirmation of where data is processed, and a plain statement of what is captured per visit and what is not.

Documentation in English is the default expectation, and Irish reviewers are generally comfortable working from GDPR terminology directly rather than needing it re-explained. What they do look for is precision: a vague privacy policy or an undocumented sub-processor slows a review down far more than a strict but clearly stated scope of processing.

As with any GDPR market, claims that a product removes the need for a legal assessment do not survive contact with an Irish data protection or legal reviewer. What holds up is a factual description of the mechanism — what is resolved to a company, what is discarded, and where the customer's own responsibility as controller begins.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

The pattern that benefits most in Ireland is the SaaS and technology vendor sale, where a prospect's technical and procurement staff research a product over several weeks before a call is booked, often anonymously through documentation or a pricing page. Seeing the company name early lets a sales team reach out during that evaluation window rather than waiting for an inbound form.

It also suits professional services and financial services firms selling into Ireland's dense concentration of regional and international headquarters, where a single identified visit from a known enterprise account is worth immediate attention. Traffic volume does not need to be large: a modest weekly visitor count from the right kind of company can already produce a workable follow-up list.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

Company-level identification is workable in Ireland under the GDPR together with the Data Protection Act 2018, provided the resolution stops at the visiting organisation and no individual employee is singled out, profiled or contacted based on the visit itself. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, supported by a documented balancing test that weighs the controller's interest in identifying commercial visitors against the limited privacy impact of resolving a company name from network-level signals, and the practice is disclosed in the site's privacy policy as one of the listed processing activities. Irish reviewers, used to detailed multinational vendor assessments, typically expect this balancing test to reference the specific mechanism rather than a generic GDPR statement copied from elsewhere. The final assessment of the site as a whole, and of how identified leads are subsequently used, always remains with the controller; lead.box acts strictly as a processor under a data processing agreement and does not make that determination on the customer's behalf.

The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's supervisory authority under the GDPR and the Data Protection Act 2018, and it is the body an Irish controller would contact in the event of a complaint or a data subject access request touching website processing. Because Ireland hosts the European headquarters of a large share of the world's technology sector, the DPC frequently sits as lead supervisory authority under the GDPR's one-stop-shop mechanism, coordinating cross-border investigations with other EU regulators on behalf of companies established there, which has made its published guidance on legitimate interest, transfers and processor obligations unusually detailed and closely followed even outside Ireland. An Irish legal or compliance reviewer will typically expect a vendor's documentation to already reflect that guidance rather than a lighter-touch approach from a smaller national authority. lead.box's own materials are written with that level of scrutiny in mind, though how a specific site's overall processing is described to the DPC remains the controller's responsibility.

lead.box relies on legitimate interest under Art. 6(1)(f) GDPR as implemented through the Data Protection Act 2018, supported by a written balancing test that sets out the purpose of company-level identification, the reasonable expectations of a business visitor researching a supplier's site, and the safeguards in place, such as the absence of individual-level profiling. Irish procurement and legal teams, used to reviewing vendor documentation for multinational parent companies, generally want to see this balancing test referenced directly in the customer's own record of processing activities rather than treated as an external add-on, and a data processing agreement under Art. 28 GDPR naming lead.box as processor sits alongside it. Because Irish reviewers tend to work comfortably in GDPR terminology without needing it re-explained, precise wording matters more than length: a vague description of the balancing exercise or an undocumented purpose tends to draw more follow-up questions during an Irish legal review than a tightly scoped, specific one. lead.box provides this documentation upfront so the review can proceed without a separate drafting exercise.

The service resolves the visiting organisation from network-level signals associated with a page view, such as the IP address range and its association with a known company network, and returns a company name, domain and the pages viewed; it does not identify, profile or track the individual person sitting at that device, and it does not build a cross-site advertising profile of any kind. No cookies, device fingerprints or persistent client-side identifiers are used to achieve this resolution, and no attempt is made to match a visit to a named employee, a personal email address or a LinkedIn profile. For a site that also runs analytics, marketing pixels or a chat widget, those tools are entirely separate processing activities under the ePrivacy Regulations 2011 (S.I. No. 336/2011) and remain the controller's own responsibility to assess and disclose. This narrow scope is deliberate: it is what allows the practice to sit on company-level legitimate interest rather than requiring the individual consent that device-level tracking would demand under Irish law.

Irish B2B sales teams, particularly in the SaaS, financial services and professional services firms clustered around Dublin's international business district, typically run structured pipelines in Salesforce, HubSpot or a similar CRM and expect a new data source to slot into that system rather than create a parallel spreadsheet. lead.box exports identified companies as CSV, Excel or JSON and can push them via webhook directly into the CRM already in use, tagging the account with the pages viewed so a rep can open a conversation with a specific, current reference point rather than a cold introduction. Given how many Irish B2B prospects are themselves technology or financial services firms running formal vendor evaluations over several weeks, seeing a named account appear while that evaluation is still underway lets a rep reach out before a shortlist has closed internally, rather than after the fact when the window has already narrowed. Teams still working with a smaller, relationship-driven account list can instead use a simple weekly export naming which companies looked at which pages.

lead.box operates as a processor under a data processing agreement drafted to Art. 28 GDPR standards, and a versioned list of sub-processors is published so an Irish legal or security reviewer can check it directly rather than requesting it mid-negotiation, which matters given how thoroughly Irish reviewers, shaped by regular exposure to multinational vendor audits, tend to scrutinise this material before sign-off. Personal and visitor data concerning EU traffic is processed in ISO-certified EU data centres and is not moved outside the EU for this purpose, which removes the international transfer analysis that would otherwise be required under Chapter V GDPR and avoids a question that often slows down an Irish review of vendors with non-EU infrastructure. The agreement also sets out retention periods, security measures and breach notification obligations consistent with the Data Protection Act 2018's enforcement framework. Having this documentation available before a contract is signed, rather than produced on request afterward, tends to shorten the internal approval cycle that Irish procurement teams typically run.

Getting started involves adding a first-party JavaScript snippet to the site; identified companies typically begin appearing within the first days as traffic accumulates, with no minimum contract term required before results are visible. Irish teams can add colleagues as additional seats, export the growing list as CSV, Excel or JSON at any point, and connect a webhook so qualified companies flow into whichever CRM the sales organisation already relies on, whether that is a large Salesforce deployment common among Ireland's multinational tech subsidiaries or a lighter HubSpot instance used by a smaller indigenous firm. No dedicated implementation project or consultant is required for the basic setup, which matches the lower-friction way many Irish SaaS buyers prefer to trial new tools before committing further budget. Cancellation is handled through self-service account settings rather than a written notice period, consistent with how Irish buyers generally expect to be able to exit a low-commitment tool without a renegotiation.

Company-level identification works by matching network-level signals against a database of known business IP ranges, and its accuracy depends on how a visitor connects: traffic from a company's own office network, including many of the corporate campuses around Dublin, Cork and Galway, resolves reliably, while traffic from a home broadband connection, a mobile network or a VPN may resolve to an internet service provider rather than the visiting company, or may not resolve at all. Shared office buildings and co-working spaces common in Dublin's tech scene can occasionally return the building's anchor tenant rather than a smaller company subletting space there, which is a known limitation of IP-range matching rather than a data quality defect. lead.box does not claim to identify every visitor, and a sales team should treat a resolved company as a strong signal worth investigating rather than a confirmed, individually verified lead ready for immediate contact. Irish buyers evaluating the tool are generally shown this limitation directly during onboarding so expectations are set correctly from the outset.

See which companies are already researching you in Ireland

Install a first-party snippet, watch the first companies appear, and hand your legal or security reviewer the documents in the same week.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links