This page explains how company-level identification fits into both, what the ICO expects in terms of transparency, and how a UK B2B review usually runs.
At a glance
- Framework
- UK GDPR + Data Protection Act 2018 + PECR
- Supervision
- Information Commissioner's Office (ICO)
- Usual legal basis
- Legitimate interests, with a documented legitimate interests assessment
- Processing location
- ISO-certified EU data centres
UK GDPR and PECR: two rulebooks, one website
Regulation at a glance
- FrameworkUK GDPR + Data Protection Act 2018 + PECR
- SupervisionInformation Commissioner's Office (ICO)
- Usual legal basisLegitimate interests, with a documented legitimate interests assessment
- Processing locationISO-certified EU data centres
Since leaving the EU, the UK operates its own retained version of the GDPR alongside the Data Protection Act 2018. Substantively it is close to the EU GDPR: the same principles, the same rights, the same accountability duties, and legitimate interests is still a valid lawful basis — the ICO expects it to be documented as a legitimate interests assessment covering purpose, necessity and the balance against individuals' rights.
PECR is the part vendors underplay. Regulation 6 requires consent for storing information on, or gaining access to information stored on, a visitor's terminal equipment, unless it is strictly necessary to provide the service the user requested. That rule is about the device, not about whether the data is personal — which is why cookie banners exist even for non-personal identifiers. It is also why the honest answer to "do we need consent?" depends on what a tool actually writes to the browser, and the ICO has been explicit that similar technologies to cookies fall under the same rule.
Company-level identification that resolves an organisation from network information, without placing advertising identifiers on the device and without building cross-site profiles, is not the activity PECR's consent rule is aimed at. But your website as a whole almost certainly runs things that are — analytics, ad pixels, chat widgets — so the banner question rarely disappears entirely, and the assessment of your own site stays yours as the controller.
Two more UK specifics are worth noting. Transfers: the UK maintains its own adequacy regulations, and the EEA is covered, so processing UK-related visitor data in EU data centres is a recognised route rather than an exception. And enforcement: the ICO publishes detailed, readable guidance and tends to signal its expectations before acting, which makes its own material the most useful reference for a UK review.
How UK buyers review it
UK B2B buyers usually run a shorter, more commercial review than their German or Dutch counterparts, but they ask sharper questions about PECR and about marketing follow-up. Expect to be asked whether the tool sets cookies, whether it profiles individuals, and how any follow-up email would sit with PECR's rules on electronic marketing to corporate subscribers.
The documents that settle it are a processor agreement, a sub-processor list, a statement of processing location, and a short description of what is stored per visit. Because the ICO's guidance is public and specific, mapping your answers onto its terminology — legitimate interests assessment, terminal equipment, strictly necessary — shortens the conversation considerably.
Restraint is also a UK virtue in this category. Saying plainly that not every visit resolves to a company, and that the tool identifies organisations rather than people, is more persuasive than a claim of total coverage.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
Professional services, B2B SaaS, industrial suppliers and agencies see the strongest effect, especially where marketing spend already drives traffic that never converts to a form. Turning that traffic into named companies gives a sales team a reason to call and a marketing team a way to prove which channels reach real buyers.
It is also useful for UK vendors selling across Europe: the same account list, the same weekly rhythm, and no separate tooling per country.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
It is workable under the UK GDPR when identification stays strictly at company level, with legitimate interests as the usual lawful basis, documented in a written legitimate interests assessment covering purpose, necessity and the balance against individuals' rights, and with the identification disclosed plainly in your privacy notice. PECR must be considered separately because it governs what is stored on, or read from, a visitor's device rather than whether data is personal, so the two assessments do not collapse into one. The final assessment always stays with you as the controller for your own site and its other tools; lead.box acts as processor under a written data processing agreement and does not make that determination on your behalf.
PECR requires consent for storing information on, or accessing information stored on, a visitor's terminal equipment unless it is strictly necessary for the service the visitor requested — and the ICO has been explicit that this applies to technologies similar to cookies, not only to cookies literally. Company-level identification with lead.box resolves an organisation from network-level information, does not place advertising identifiers on the device, and does not build cross-site profiles, so it sits outside the activity that regulation is aimed at controlling. That said, your site as a whole almost certainly runs other things PECR does target — analytics, advertising pixels, chat widgets — so the banner question rarely disappears entirely, and reviewing those separately remains your responsibility as controller.
Yes. The UK's own adequacy regulations, maintained independently of the EU's decisions since Brexit, cover the EEA states, so processing UK-related visitor data in ISO-certified EU data centres is a recognised transfer route rather than an exception requiring extra contractual clauses. That keeps the paperwork simple: a single data processing agreement covers the arrangement without a separate UK international data transfer addendum bolted on for this purpose. The agreement and the versioned sub-processor list are both published so your legal or procurement team can review the transfer chain, the retention periods and the named sub-processors before you commit to using the tool.
No notification is required specifically to use company-level identification. Standard UK obligations still apply to you as the controller regardless of this tool: registration with the ICO and payment of the data protection fee where your organisation is not exempt, an up-to-date record of your processing activities, a privacy notice that names the categories of processing you run, and personal data breach reporting to the ICO within 72 hours where the risk threshold under the UK GDPR is met. None of those obligations change because you have added a visitor-identification tool, and lead.box's own registration and breach-notification duties as processor sit alongside, not instead of, yours.
UK limited companies carry a unique Companies House registration number, and UK B2B buyers routinely expect vendor invoices, contracts and CRM records to reference the correct registered entity rather than a trading name or a parent group. Company-level identification matches visiting traffic against firmographic data drawn from public company registers, so a match against a UK visitor typically surfaces the registered company name and can be reconciled against Companies House filings when a sales team needs to confirm which legal entity within a group actually visited — useful in the UK's common holding-company and subsidiary structures, where the trading brand on a website rarely matches the name on the register.
UK B2B procurement and legal teams generally run a shorter, more commercial review than continental counterparts, but they expect a specific document set before sign-off: a data processing agreement referencing the UK GDPR and the Data Protection Act 2018, a named and versioned sub-processor list, a security overview covering where data is hosted and how it is encrypted, and a plain answer on cookies and PECR. Security questionnaires modelled on ISO 27001 or SOC 2 frameworks are common even for smaller UK vendors, and procurement teams increasingly ask how the newer Data (Use and Access) Act reforms to the UK's data protection regime are reflected in a supplier's documentation, so keeping that language current shortens the review.
UK B2B teams overwhelmingly run their pipeline through HubSpot, Salesforce or Pipedrive, and identified companies are handed over through webhooks or native integrations so a sales development representative sees a named account rather than an anonymous session in analytics. Marketing teams typically layer identified-company data into existing account-based marketing lists to prioritise outbound, while sales uses daily or weekly digests to time outreach against a prospect's actual research activity. Exports in CSV, Excel or JSON cover reporting to management or finance where a CRM sync is not required, and none of this requires the visitor-identification data to live anywhere other than in the tools your team already uses.
Most UK teams install a short JavaScript snippet on their primary marketing domain and see the first identified companies appear within a working day, usually reviewing an initial batch against known target accounts before extending the snippet to secondary domains or regional microsites. From there, webhooks or a direct CRM integration move new company matches into the sales pipeline automatically, while marketing pulls CSV or Excel exports for reporting cycles that do not need live CRM access. Additional team seats can be added as sales, marketing and revenue operations staff need visibility, and cancellation is self-service from within the account, without a retention call or notice-period clause to negotiate.
Find out which UK companies are reading your site
Add the snippet, see named companies within a day, and hand your reviewer the ICO-shaped answers in writing.