Website visitor identification and GDPR: what is allowed in Belgium and the Netherlands

Tips

The short answer

Identifying the companies that visit your website is lawful in Belgium and the Netherlands when three things hold: the tool works at company level and does not try to name the person, you have a legal basis for processing the network address it starts from, and your cookie and privacy notices cover the script that does the work. The visitor's IP address is personal data under European law even though the output is a company name, so GDPR applies from the first step, and the European rules on reading information from a visitor's device apply to more than cookies. None of this is a reason not to do it; it is a reason to do it at company level, with a vendor that says where the data goes, and to keep your notices honest. This page is the practical version; your DPO or lawyer decides for your situation.

Why GDPR applies even though you only see a company

Visitor identification starts from an IP address. In 2016 the Court of Justice of the EU ruled in Breyer (case C‑582/14) that a dynamic IP address is personal data for a website operator when the operator has legal means to have the visitor identified through the internet provider (Court of Justice of the EU, C‑582/14, judgment of 19 October 2016). The Belgian and Dutch authorities treat it that way. So the fact that the tool shows you "a logistics company in Antwerp" rather than a name does not take the processing outside GDPR. It makes it a low-risk processing of personal data, which is a much better place to be than a high-risk one, but it still needs a legal basis, a purpose, a retention period and a mention in your notice.

The second layer is the ePrivacy rule on terminal equipment. Article 5(3) of the ePrivacy Directive, implemented in Belgium in the Electronic Communications Act and in the Netherlands in article 11.7a of the Telecommunicatiewet, restricts storing information on, or reading information from, a visitor's device. The European Data Protection Board's Guidelines 2/2023, adopted in final form on 16 October 2024, confirm that this covers tracking pixels, tracking links, device fingerprinting and certain forms of tracking based on IP addresses alone, not only cookies (EDPB Guidelines 2/2023). A vendor's line that it "uses no cookies" is true and useful, and it does not by itself settle the question.

The legal basis vendors rely on

For the company-level processing, the basis most vendors name is legitimate interest under article 6(1)(f) GDPR: a business has a legitimate interest in knowing which organisations show interest in it, the processing is limited to the network address and the pages viewed, and the visitor is shown as a company, not a person. Leadfeeder states on its GDPR page that it processes personal data on the basis of legitimate interest and that its data is hosted and processed on AWS in Ireland (Leadfeeder GDPR page, retrieved 21 September 2026). Bizzy identifies the company and never the person, shows visitors as pseudonymous sessions under the company, and stores data primarily on servers in the EU.

Legitimate interest is not a free pass. It requires the three-step test: a real interest, processing that is necessary for it, and a balance against the visitor's rights that comes out in your favour. Company-level identification of business visitors passes that test far more comfortably than anything that reaches the individual, which is why the single most important question to ask a vendor is whether it ever tries to name the person. If it does, you are in consent territory, and for a plain page visit you do not have it.

Belgium: what the Data Protection Authority says

The Belgian Gegevensbeschermingsautoriteit (GBA/APD) reads the cookie rule broadly. Its guidance states that "cookies and other technologies" include other methods of transport and storage, naming trackers, beacons, invisible pixels, local storage and session storage, and that consent is required unless a technique is strictly necessary for a service the visitor asked for or for the communication itself. It adds that a cookie for analytical purposes does not in principle meet those two conditions (Gegevensbeschermingsautoriteit, cookies en andere traceringsmiddelen). Since 2024 it has moved from warnings to fines, including for smaller companies.

The practical reading for visitor identification in Belgium: if the tool's script stores or reads an identifier on the device, treat it like an analytics cookie and put it behind consent; if it works from the network address alone, document the legitimate-interest assessment and list the tool in your privacy notice. Belgium also has the "Bel me niet meer" list for calling, which matters the moment an identified company becomes a phone call.

The Netherlands: what the law says

Article 11.7a of the Telecommunicatiewet requires consent for storing or reading information on a visitor's device, with three exceptions in paragraph 3: purely technical storage needed to carry the communication, storage needed for a service the visitor asked for, and reading information "to obtain information about the quality or effectiveness of a delivered information society service", provided this has no or only minor consequences for the visitor's privacy (Telecommunicatiewet, artikel 11.7a). That third exception is the analytics exception, and its condition, "no or minor consequences", is the test a visitor identification script has to meet if it wants to run without consent. The Autoriteit Persoonsgegevens has been actively checking cookie consent on Dutch websites since 2024.

For calling, the Netherlands replaced its do-not-call register in 2021 with an opt-in regime that also covers sole traders and partnerships. Is B2B cold outreach legal in Europe? goes through both countries channel by channel.

Six things to do on your side

  1. Confirm it is company-level, in writing. Ask the vendor whether the product ever attempts to identify an individual from a page visit. The answer you want is no.

  2. Write the legitimate-interest assessment. One page: the interest, why the processing is necessary, why the balance favours you (business visitors, company-level output, short retention). Keep it with your records of processing.

  3. Put the script in your notices. Name the tool in the privacy notice with its purpose, and place it in the cookie notice in the category your assessment supports. If it stores or reads an identifier on the device, that category is "behind consent".

  4. Ask where the data lives and sign the processing agreement. Leadfeeder says Ireland; Bizzy says primarily the EU; ask the others. A vendor that will not say is telling you something.

  5. Set a retention period. A visit from eighteen months ago is not a signal. Keep what a sales cycle needs and delete the rest.

  6. Separate identification from outreach. Knowing that a company visited does not give you the right to email everyone who works there. The moment a visit becomes a call or an email, the rules for that channel apply, including a legal basis for the person's data and an easy way to opt out.

What this means for the tool you choose

The category is safest when it is boring: company in, company out, a stated hosting location, a short retention, a mention in your notice. That is how Bizzy's website visitor tracking is built, and it is the standard to hold any vendor to. Which companies are visiting my website? explains what the identification can and cannot tell you, and website visitor identification tools for the Benelux compared puts the five main tools side by side, hosting statements included.

Frequently asked questions

Is website visitor identification GDPR compliant? It can be, and most of it is your responsibility as controller. The processing starts from an IP address, which is personal data under the Breyer judgment, so you need a legal basis (usually legitimate interest), a purpose, a retention period and a mention in your privacy notice. A tool that identifies companies and never people keeps the risk low.

Do I need cookie consent for a visitor identification script? It depends on what the script does. If it stores or reads an identifier on the visitor's device, Belgian guidance treats it like an analytics cookie and requires consent, and Dutch law allows it without consent only where the privacy impact is nil or minor. If it works from the network address alone, document your legitimate-interest assessment and still name it in your notices.

Is an IP address personal data? Yes, for a website operator that has legal means to have the visitor identified, per the Court of Justice in Breyer (C‑582/14, 2016). That is why GDPR applies even when the tool only shows you a company.

Can I contact the people at a company that visited? Only under the normal rules for that channel. Identification tells you the company is interested; it does not create a legal basis for emailing or calling its employees. Belgium's do-not-call list and the Dutch opt-in regime apply to calls; consent or legitimate interest with an opt-out applies to email.

Where is the data stored? It depends on the vendor. Leadfeeder states AWS in Ireland; Bizzy stores data primarily on servers in the EU. Ask every vendor for the location in writing and sign a data processing agreement before you install the script.

Ready to join the sales utopia?

Make your sales team 10x more effective, so they can focus on the real fun: building connections and closing deals

No credit card required • Integrates with your CRM • Cancel anytime

Ready to join the sales utopia?

Make your sales team 10x more effective, so they can focus on the real fun: building connections and closing deals

No credit card required • Integrates with your CRM • Cancel anytime

Ready to join the sales utopia?

Make your sales team 10x more effective, so they can focus on the real fun: building connections and closing deals

No credit card required • Integrates with your CRM • Cancel anytime