Targetlytics.AI
GDPR & visitor ID

GDPR-compliant visitor identification

Most visitor-identification tools resolve anonymous traffic to a named individual. For companies with European visitors or European legal review, that model is a non-starter. Company-level identification is the defensible alternative.

The short answer

  • Identifying an anonymous EU visitor as a named person, without consent, processes personal data with no clear lawful basis under GDPR.
  • Identifying the visitor's company is not personal data in the same way — a limited company is not a data subject.
  • Targetlytics identifies the organisation, then suggests the likely buying-committee contacts by role and persona rather than de-anonymising the specific visitor.
  • This keeps the in-market signal a sales team needs while staying inside what a European DPO will approve.

Why person-level identification is a GDPR problem

GDPR governs the processing of personal data about identified or identifiable individuals. When a tool matches an anonymous visitor to a specific named person and their profile, that is processing personal data — and doing it without consent, without notice, and without the individual's knowledge is exactly the pattern regulators have acted against.

The common defence, legitimate interest, is weak here: the visitor has a strong expectation of privacy when browsing anonymously, and there is a less intrusive way to achieve the same commercial goal.

The company-level model

Company-level identification resolves the visitor's IP or network to an organisation. A company is a legal entity, not a data subject, so identifying it does not carry the same GDPR weight. You learn that a mid-size logistics firm in Rotterdam viewed your pricing page three times this week.

To make that actionable, Targetlytics then suggests contacts on the likely buying committee by persona — the Head of Operations, the RevOps lead — drawn from business-contact data with its own lawful basis, rather than claiming to know which individual was behind the anonymous session.

What you still get

The output a sales team actually uses is unchanged: an in-market account, the pages viewed, the intent trend, firmographics, and a shortlist of people to contact. What you give up is the false precision of a named visitor you were never lawfully entitled to identify — plus the risk that comes with it.

Person-level vs company-level under GDPR

The same commercial goal, two very different compliance positions.

AspectPerson-level IDCompany-level ID
What is identifiedA named individual + profileAn organisation
Is it personal data?YesNot in itself
Lawful basis neededConsent, realisticallyStandard legitimate interest for B2B
DPO approval in the EUUsually withheldRoutinely granted
Consent banner impactMaterialNone
Sales usefulnessHigh, if lawfulHigh

An in-market signal your DPO will sign off on

Identify the companies on your site and the buying-committee contacts to reach — without de-anonymising individuals.

See visitor identification

Frequently asked questions

Company-level identification for B2B marketing is widely operated on a legitimate-interest basis with a proper assessment and disclosure. Person-level de-anonymisation of consumers or unconsented individuals is the part that draws enforcement.

An IP address can be personal data when it is used to single out an individual. Used only to look up the organisation that owns the network range, and then discarded, the privacy impact is far lower — and that is how company-level identification is designed to work.

They come from business-contact datasets that carry their own lawful basis and opt-out handling, and they are presented as "people who likely influence this decision at this company", not as "the person who visited". You are not linking a named individual to the anonymous browsing session.

Yes — disclose that you identify visiting organisations for B2B marketing and how to object. That is a standard paragraph, not a consent gate, and your DPO can usually approve it quickly.

Yes. The company-level model runs the same everywhere; it simply removes the compliance blocker that stops EU-facing teams from using visitor identification at all.