Website visitor identification, UK GDPR and PECR: what you need to know

Hand holding a brass padlock, symbolizing security and protection
Photo: Nathan Thomas on Pexels

This guide is general information, not legal advice. Data protection law depends on your circumstances. Speak to your data protection officer or a solicitor before you rely on any of it.

Website visitor identification can be used lawfully in the UK, but the responsibility sits mainly with you, the website owner. In practice that means four things: a lawful basis under UK GDPR (usually legitimate interests), a clear privacy notice, a decision on whether PECR requires consent for the tracking script, and care over how you contact people afterwards.

Company data or personal data?

Information about a company is not personal data, but the IP address used to find that company can be. So even a tool that only reports company names may involve processing personal data behind the scenes.

The ICO explains that a person can be identifiable from "online identifiers" such as IP addresses. That can happen on their own or in combination with other information, even if you can't link them to a name.1 An IP address from a large corporate network is unlikely to single anyone out. An IP address from a home broadband connection may well do so, especially for a sole trader or someone working from home.

This is why it matters how a tool handles IP addresses and non-corporate traffic:

  • Does it keep raw IP addresses, or discard or hash them?
  • Does it report individuals, or only companies?
  • Does it flag home broadband and mobile traffic, or present it as a company?

The UK and European tools in our comparison identify companies. Lead Forensics, for example, says its technology "reveals the company, not the person".10 Some US tools take a different approach. RB2B states that it "only tracks U.S.-based visitors, so GDPR doesn't apply" to its person-level tracking.11 If you are in the UK and have UK or European visitors, assume UK GDPR applies to you.

Legitimate interests: the usual lawful basis

Most organisations rely on legitimate interests as their lawful basis for visitor identification. To use it, you need to pass the ICO's three-part test and write down your reasoning in a legitimate interests assessment (LIA).23

The three parts are:

  1. Purpose. Do you have a legitimate interest? Understanding which businesses are interested in your products is a commercial interest that can qualify.
  2. Necessity. Is the processing necessary for that purpose, or could you achieve it in a less intrusive way?
  3. Balancing. Do the visitor's interests, rights and freedoms override your interest? Consider what people would reasonably expect, and any safeguards you have in place.

Safeguards that help the balancing test include: identifying companies rather than individuals, not keeping raw IP addresses, limiting how long data is kept, being open about the processing, and giving people an easy way to object.

Vendors generally act on your behalf, which makes you the controller. Lead Forensics says "the customer, as controller, is responsible for identifying and documenting the lawful basis for its use of Lead Forensics."9 Scout's privacy policy takes the same position: the customer is the controller and Swarm Labs IO Ltd is the processor.12

PECR: the tracking script, not just cookies

The Privacy and Electronic Communications Regulations (PECR) apply whenever a script stores information on, or reads information from, a visitor's device. The ICO's guidance covers cookies, and also scripts and tags, web storage, tracking pixels and fingerprinting.45

The general rule is that you need consent, unless an exception applies. The ICO's final guidance on storage and access technologies, published on 29 April 2026, reflects the changes made by the Data (Use and Access) Act 2025.7 It sets out the exceptions, including one for strictly necessary purposes and one for statistical purposes.6

The exceptions are narrow:

  • Strictly necessary covers storage that is essential to provide the service the user has asked for.6
  • Statistical purposes covers collecting information about how your website is used "with a view to making improvements" to it. You must give clear information and an easy way to object.6

Visitor identification is mainly used for sales and marketing, not for improving your website. So it is unlikely to fit neatly within either exception. Many organisations therefore load visitor identification scripts only after consent, through their cookie or consent banner. Others take a different view, based on how their tool works. This is the point where specific advice is most worth having.

In Scout's case, the Scout snippet keeps a random per-tab session identifier in the browser's sessionStorage, which it uses to de-duplicate page views within a visit. It is not a cookie, and it is cleared when the tab closes. Where identification is turned on for your workspace, the snippet also loads a third-party company-identification script from Scout's identification partner. That script processes the visitor's IP address and may set its own cookies or local storage on your site.12 Web storage is a storage technology under PECR.5 As the website owner, you are responsible for getting any consent your visitors need before the snippet loads, for example through your cookie banner; Scout acts as your processor for that data. Factor that into your decision, and configure your consent tool to match.

What to put in your privacy notice

Tell visitors, in plain language, that you use visitor identification, what it collects, why, your lawful basis and how to object. Transparency is required whichever lawful basis you use, and it supports the balancing test.

A good notice covers:

  • the name of the tool and the company that provides it;
  • what is collected (for example page addresses, referrer, session length and IP address) and what is not;
  • that the purpose is to identify visiting organisations, not individuals;
  • your lawful basis;
  • how long data is kept;
  • how to object or exercise other rights.

Scout's privacy policy includes suggested wording customers can adapt.12

Contacting the companies you identify

Knowing a company visited your site doesn't change the rules for contacting its people. PECR and UK GDPR still apply to any email or call you make.

The ICO's business-to-business guidance says you can send marketing emails to people at limited companies and other corporate bodies without their prior consent. You must say who you are and give a simple way to opt out.8 Sole traders and some partnerships are treated as individuals. You can only email them if they have consented, or if the soft opt-in applies.8 UK GDPR also applies to the personal data you use, including contact details bought from a data provider.

In practice: don't tell someone you watched them browse, check whether the company is a sole trader before emailing, and honour opt-outs promptly.

How Scout approaches data protection

Scout is designed to identify companies, not people, and to keep as little data about visitors as it needs. These are the relevant points from Scout's privacy policy.12

  • Company-level only. Scout identifies organisations. It doesn't build profiles of individual visitors.
  • No raw IP addresses stored. The IP address is hashed immediately with a salted SHA-256 algorithm, and only the hash is kept.
  • No form capture or session replay. Scout does not record form submissions, keystrokes or session replays.
  • Contacts only on request. Contact details come from business databases, and only when a customer uses a credit to request them. They are never collected from the visit.
  • UK and EEA hosting. Infrastructure is hosted in the UK and the European Economic Area.
  • Non-company traffic flagged. Home broadband, mobile and VPN traffic is flagged and held in the low confidence band, so it isn't presented as a company. See how the confidence score works.

For the wider picture, read our UK guide to website visitor identification, or see how to see which companies visit your website step by step. To see what data Scout shows for your own site, start a free trial or view pricing.

Frequently asked questions

Is website visitor identification GDPR compliant? It can be used in a way that complies with UK GDPR, but compliance depends on how you use it, not only on the tool. You need a lawful basis (usually legitimate interests, with a written assessment), a clear privacy notice and a view on whether PECR requires consent for the tracking script.

Is an IP address personal data? It can be. The ICO says online identifiers such as IP addresses can identify a person on their own or combined with other information.1 Company-level reporting reduces the risk, but the processing behind it may still involve personal data.

Do I need cookie consent for visitor identification? It depends on what the script stores on or reads from the visitor's device and why. PECR covers scripts, web storage and similar technologies, not only cookies, and its exceptions are narrow.56 Many organisations put visitor identification behind consent. Take advice on your own set-up.

Can I email the people at companies that visited my website? UK rules let you email people at limited companies without prior consent, if you identify yourself and offer an easy opt-out. Sole traders and some partnerships are treated as individuals and need consent or the soft opt-in.8 UK GDPR still applies to the personal data you use.

This guide is general information and is not legal advice. Lead Forensics and RB2B are trade marks of their respective owners. Scout is not affiliated with either.

Frequently asked questions

Is website visitor identification GDPR compliant?

It can be used in a way that complies with UK GDPR, but compliance depends on how you use it, not only on the tool. You need a lawful basis (usually legitimate interests, with a written assessment), a clear privacy notice and a view on whether PECR requires consent for the tracking script.

Is an IP address personal data?

It can be. The ICO says online identifiers such as IP addresses can identify a person on their own or combined with other information. Company-level reporting reduces the risk, but the processing behind it may still involve personal data.

It depends on what the script stores on or reads from the visitor's device and why. PECR covers scripts, web storage and similar technologies, not only cookies, and its exceptions are narrow. Many organisations put visitor identification behind consent. Take advice on your own set-up.

Can I email the people at companies that visited my website?

UK rules let you email people at limited companies without prior consent, if you identify yourself and offer an easy opt-out. Sole traders and some partnerships are treated as individuals and need consent or the soft opt-in. UK GDPR still applies to the personal data you use.

Sources

  1. ICO, What are identifiers and related factors? ico.org.uk
  2. ICO, Legitimate interests ico.org.uk
  3. ICO, What is the "legitimate interests" basis? ico.org.uk
  4. ICO, Guidance on the use of storage and access technologies ico.org.uk
  5. ICO, What are storage and access technologies? ico.org.uk
  6. ICO, What are the exceptions? ico.org.uk
  7. ICO, Final storage and access technologies guidance published (April 2026) ico.org.uk
  8. ICO, Business-to-business marketing ico.org.uk
  9. Lead Forensics, Compliance customer FAQ leadforensics.com
  10. Lead Forensics, Website visitor identification leadforensics.com
  11. RB2B, Lead Forensics alternative page rb2b.com
  12. Scout, Privacy policy scoutmetrics.co.uk

Information checked .