Company-level identification tells you which company visited your website. Person-level identification tries to tell you which person. The two use different data, work in different countries, and follow different rules under EU law. This guide covers what each one gives you, how each one works, and which one suits which kind of business.

Company-Level vs Person-Level Website Visitor Identification

— Company-Level vs Person-Level Website Visitor Identification

60-Second Summary

Company-level identification matches visitor IPs to the company that owns them and returns account-level behaviour; person-level matches browser signals to identity graphs and returns a named individual with a work email. Company-level works broadly and fits EU legal norms better, while person-level is strongest in the US but raises coverage, accuracy and legal hurdles.

  • Key takeaways: Company-level = company name + pages, works globally and usually relies on legitimate interest in the EU; Person-level = named person + work email, works best in the US, requires consent and a GDPR basis in the EU and has lower coverage outside the US. Measure match rates on your own traffic—vendor demos won’t show real coverage.

  • Standout strategies & tactics: Use company-level signals to filter, route to account owners, score, sync to LinkedIn Matched Audiences or CRM, and avoid claiming you "saw" an individual; reserve person-level for US-heavy traffic and high-volume outbound where a name materially shortens the sales path.

  • Real-world lessons & frameworks: Ask vendors for data provenance, legal basis for EU processing, match error rates, DPAs and storage locations; run an A/B holdback test to validate revenue claims and treat match rates as specific to your traffic mix.

  • Quick decision rules: If more than 25% of traffic is outside the US or purchases involve many stakeholders, choose company-level; if traffic is almost all US, buying cycles are single-decision and legal have signed off, person-level can be tested—always bring legal in early.

*This summary was created with AI assistance, using our original content.

Company-level identification matches a visitor's IP address to the company that owns it. You get the company name and what they looked at. Person-level identification matches a signal from the visitor's browser to a database of named people. You get a name and a work email.

The first works in any country where companies register IP addresses. The second works well in the US and poorly elsewhere. In the EU, both need a legal reason to run, and depending on the technology used also  the visitor's consent. If your traffic is all US and your team does high-volume outbound, person-level is often the better buy. If you sell into Europe, it will miss most of your visitors.

A note before we start: this article is for informational purposes only and does not constitute legal advice. For guidance specific to your organisation, consult a qualified legal professional.

What each one actually reveals

Company-level identification returns an account and its behaviour. Person-level identification returns a named human. That difference decides everything downstream.

Company-level identification shows you for example that someone at Acme GmbH read your pricing page twice this week, opened two case studies, and came from a LinkedIn ad. You also get the company details: industry, headcount, location, website. You do not get the name of the employee.

Person-level identification shows you a name and a work email, and sometimes a LinkedIn profile. You get less context about the company around that person. Outside the US, the match usually fails.

Vendors sell both under the same phrase: "identify your visitors". The output is where they split.

Company-level

Person-level

What you get

Company name, company details, pages viewed, traffic source, visit time

A named person, usually with a work email and sometimes a LinkedIn profile

Where the data comes from

The visitor's IP address, matched to a business database

A signal from the visitor's browser, matched to a database of named people

Where it works

Any country where companies register IP addresses

Mostly the US

What you do with it

Act on the account: route it, score it, add it to an ad audience

Act on the person: contact them

EU legal position

Needs a legal reason to process if GDPR requirements apply. Usually legitimate interest. On top, specific ePrivacy laws may set forth additional legal requirements 

Needs a legal reason, plus the visitor's consent

Who you are tracking

The buying group

One individual

"Which companies are in market" and "which person was on the page" are different questions. They lead to different workflows, different owners, and different definitions of a good week.

For the wider category and where these two fit within it, see our complete guide to website visitor identification.

One thing gets confused constantly in sales calls. Company-level tools often show you contact details for people who work at the companies they identify, and Leadfeeder does this too. That is not the same as identifying the visitor. As our guide to finding a company by IP address puts it: "These contacts aren't necessarily the exact individuals who visited your site, but they're likely to be involved in the buying process." The contact list helps you decide who to approach at a company you have identified. Whether the visitor is on it is a separate question.

How each approach actually works

Website visitor identity resolution starts with whatever the browser hands over, and where that data comes from decides everything else: how many visitors you can identify, how accurate the result is, and where you stand legally.

Company-level: reverse IP lookup

Every visitor's browser sends an IP address. Companies register blocks of IP addresses, and those records are public. The tool matches the visitor's address to the company that owns it, then adds company details from a business database. Leadfeeder has been building that database for over a decade, and it now covers more than 60 million companies.

Our post on how reverse IP lookup resolves a company walks through the steps.

Nothing in that chain points to a person. The tool has no way to know which employee was at the keyboard.

Person-level: identity graphs

You cannot get a name from an IP address. Person-level tools work a different way.

The vendor owns, or pays for access to, an identity graph. That is a large database of person-level data linking browser and device signals to named people. It was built elsewhere, from ad networks, data-sharing deals, paid survey panels, and forms people filled in on other websites. When someone lands on your site, the tool checks a signal from their browser against that database. A match returns a name.

So the question to ask a person-level vendor is where the data came from: who agreed to this, on which website, and what they were told at the time. A vendor who will answer that in writing is worth taking seriously.

Why the two cover different amounts of traffic

Company-level identification works wherever a company owns its IP addresses. It struggles with remote work, because an employee at home looks like a home broadband customer.

Person-level identification works wherever the identity graph is deep, which mostly means the US. It struggles with VPNs, Safari's tracking protection and Apple Private Relay, all of which block the browser signal the match depends on.

Both lose coverage over time, for different reasons. Neither problem shows up in a demo, because a demo runs on the vendor's traffic rather than yours.

In the EU, person-level identification has to clear two separate legal hurdles rather than one: consent under the ePrivacy rules for anything read from or stored on a visitor's device, and a lawful basis under GDPR for processing the data. Many vendors clear neither and block EU traffic instead. In the US there is no single federal rule equivalent to the ePrivacy gate, but there is no free pass either. Several states require consent before you collect. 

Vendors usually answer this with one of two lines: that they do not collect EU data, or that you should check with your own lawyer. Neither tells you what you are allowed to do. Here is the detail, so you can take something specific to your legal team.

Company-level identification counts as processing personal data. You can do it lawfully, if you have a legal reason and the right safeguards. Our full treatment of that is in how GDPR and ePrivacy apply to B2B visitor tracking. Person-level sits differently, and that is the rest of this section.

None of this is theoretical. DLA Piper's January 2026 survey counts EUR 7.1 billion in cumulative GDPR fines since May 2018, EUR 1.2 billion of it in 2025 alone, reversing the previous downward trend.

The EU position: two hurdles

The first law is the ePrivacy Directive and the respective national laws implementing it. Article 5(3) says you need consent before you store anything on a visitor's device, or read anything already stored there. Most people know this as the cookie rule. It covers more than cookies.

The EDPB's guidelines on the technical scope of Article 5(3), adopted in final form on 7 October 2024, confirm it also reaches IP-based and cookieless tracking: "Unless the entity can ensure that the IP address does not originate from the terminal equipment of a user or subscriber, it has to take all the steps pursuant to the Article 5(3) ePD."

What triggers the rule is any information on the device, whether or not it counts as personal data. So "we only collect company data" does not get you past this one.

Enforcement on this specific point is active. CNIL issued 83 sanctions totalling EUR 486,839,500 in 2025, alongside 143 compliance orders. Twenty-one organisations were sanctioned specifically for breaches of the tracker rules: storing without consent, inadequate disclosure, and failing to respect refusals.

The second law is GDPR. Article 6 says you need a legal basis to process personal data. Where the IP address collected and processed for company-level website visitor identification qualifies as personal data under the GDPR, that legal basis is usually legitimate interest under the GDPR,  For company-level that legal basis is usually legitimate interest, under Article 6(1)(f), backed by a successful balancing test you write down. Person-level makes that balance much harder to argue, because the whole point of the product is to pick out one named person.

You cannot use legitimate interest to cover a consent you never asked for.

Why an IP address counts as personal data

In Breyer (Case C-582/14, 19 October 2016), the EU Court of Justice ruled that if a website operator has a lawful way to find out who is behind an IP address, that address counts as personal data in their hands. The case predates GDPR, but the reasoning carries over.

In EDPS v SRB (Case C-413/23 P, 4 September 2025), the same court applied that reasoning and developed it further. Whether data can be qualified as personal data  depends on the circumstances. The same data can be personal for one party and not for another.

That is the strongest legal ground the company-versus-person split has. A company that only knows "this corporate IP address read these pages" has no reasonable way to work out who the person is. A person-level tool is built to close exactly that gap.

Recital 14 adds that GDPR "does not cover the processing of personal data which concerns legal persons", so "Acme GmbH read the pricing page" is a business record. Two caveats: a one-person company's IP address points to an actual human, and the ePrivacy device rule covers any "subscriber or user".

The US position: disclosure and damages

US readers often assume person-level identification is simply legal at home. That changed recently and is still moving.

The CCPA used to exempt business contact data and employee data. Those exemptions expired at the end of 2022, as California's Attorney General confirms. Business contact data now gets treated like consumer data.

Enforcement followed. In September 2025 the California Privacy Protection Agency fined Tractor Supply Company USD 1,350,000, its largest penalty at the time, for failures including an opt-out mechanism that did not honour signals such as Global Privacy Control.

There is also a wave of class actions under California's wiretapping law, Penal Code section 631 and section 638.51. A separate provision, section 637.2, lets someone sue for the greater of USD 5,000 per violation or three times their losses. That is what makes these cases worth filing.

Clear consent has beaten claims. In Lakes v. Ubisoft (N.D. Cal., 2 April 2025), the court found the visitors had agreed in three places: the cookie banner, the sign-up terms, and the checkout. It dismissed the case with prejudice.

The difference is structure, not timing. The EU applies basically one rule everywhere: a legal reason to process, and consent for what is read from the device. The US splits the same question across state wiretapping statutes, sector specific laws and twenty plus state privacy laws, several of which also require consent before you collect. What changes is which state your visitor sits in, and how the courts there are reading statutes written decades before pixels existed..

What "we do not collect EU data" actually means

Geofencing is the most common vendor answer to GDPR. It solves the vendor's problem and hands you a coverage problem. If a vendor blocks EU traffic, and you sell in Europe, you get nothing on a large share of your pipeline.

The rules are tightening rather than loosening. The EDPB adopted Guidelines 02/2026 on anonymisation on 7 July 2026, in a version 1.0 that is open for public consultation, and the text aims at providing clear rules on when someone can really claim that some data is anonymous. These recommendations can still change. As of August 2026 we have found no publicly documented investigation by a data protection authority into a named person-level vendor.

The market has already priced this in. In IAB's State of Data 2024, 95% of US data and advertising decision-makers said they expect continued legislation and signal loss, and 71% were growing their first-party datasets, up from 41% in 2022.

Why B2B teams ask for person-level, and where it breaks

A name saves your reps the guesswork of picking who to contact at an account. It turns a Slack alert into something someone can act on the same morning. If your team is measured on outbound volume, that is a real gain.

There is a tension worth naming first. Gartner's survey of 646 B2B buyers, published in March 2026, found that 67% prefer a rep-free buying experience. Buyers are researching anonymously on purpose. That is worth holding in mind before you build a motion around unmasking them.

4 Person-level identification limitations:

1. Person-level identification mostly works in the US

Coverage is concentrated there. As we put it in our comparison of Visitor Queue alternatives: "Person-level identification only works for US IPs, while visitors from Europe are not identified at an individual level." If you are a European business, or a US business selling into Europe, that usually settles it before any legal question comes up.

2. The outreach you can actually send

The person you identified never gave you their email address. In the EU, that makes your outreach a second legal question on top of the identification. Everywhere else, it still makes your email cold, whatever the law says. Expect the usual results: fewer replies, more complaints, and a worse sender reputation over time.

3. How often the match is wrong

The matching is a best guess, and guesses fail some of the time. That means part of your outreach lands on the wrong person, by name, about a page they never opened.

Ask a vendor how confident a match has to be before they show it to you, and how often they get it wrong. Very few publish that number, though most publish a match rate.

4. How to test the revenue claims

Plenty of vendors publish big revenue figures. Very few explain how they measured them.

The test is simple. Pick a random share of your identified visitors and do nothing with them, then compare the results against the group you did chase. Without that holdback, a revenue figure only shows that you identified visitors in a quarter that went well. It does not show that one caused the other.

Match rates: what the numbers mean

Match rates are the most quoted and least comparable numbers in this market.

Our published benchmark for company-level identification is 10 to 40% of total traffic, with more detail in our how to identify anonymous website visitors article. The same article puts real person-level accuracy at 5 to 20%. Warmly's own reporting puts its rate at around 15% of US traffic, a figure we cite in our EU-focused alternatives to Lead Forensics comparison.

These numbers count different things. A company-level rate is a share of your business traffic matched to a company. A person-level rate is a share of all your traffic matched to a named human. Putting them side by side invites a comparison the numbers cannot support.

The only match rate that matters is the one you get on your own traffic. Ask for a trial and measure it.

When each one is the right choice

Choose company-level if any of these are true

Start with the size of the decision. Forrester's State of Business Buying, 2026 puts a typical B2B purchase at 13 internal stakeholders and 9 external influencers, with procurement acting as a decision-maker in 53% of cycles. If 22 people touch the decision, one name is the wrong unit of analysis. Five people from one account over three weeks tell you far more together than any one of them does alone.

Beyond that:

  1. You have EU traffic, or you plan to. Person-level identification has to clear two legal hurdles in the EU rather than one, and many vendors block EU traffic rather than try.

  2. Your next step after identification is a workflow that runs on companies: territory routing, CRM account records, an ad audience, an alert to the rep who owns that account.

  3. You want the data to survive a review by your own legal or security team without a long argument.

When person-level genuinely wins

If your traffic is almost all US, your team runs high-volume outbound, one person decides whether to buy your product rather than a committee, and your legal team has looked at the approach and is comfortable with it, then person-level is a reasonable buy.

In that situation a name really does shorten the path from signal to conversation, and most of the objections in this article do not apply to you. We do not sell person-level identification, and we would still tell you to look at it properly.

A quick way to test it before you buy

Pull last month's traffic by country. If more than a quarter of it sits outside the US, a person-level tool will miss most of your visitors, and no trial will fix that. Then look at your last ten closed deals and count how many people from the buying company you spoke to. If the answer is usually more than two, company-level is your unit of work.

What to do with a company-level signal

Identification on its own changes nothing. Filter the feed to the companies that match your customer profile, route those to the account owner while the visit is fresh, and judge campaigns on the companies they bring rather than the sessions. The cleanest activation example is syncing identified companies into LinkedIn as a Matched Audience: the company goes in, LinkedIn decides which of its members to show the ad to, and you never identify anyone yourself. Our guide to retargeting companies on LinkedIn covers the setup.

One thing not to do: never tell someone you saw them on your website. It reads as surveillance whatever the law says. Use the signal to decide who to contact and when, then write the email about their business.

Which tools do which

The market splits along the same line. Company-level tools include Leadfeeder, Lead Forensics, Leadinfo and Albacross. Person-level tools are a smaller group, focused on the US. Several have changed what they offer in the past two years, so ask the vendor where they stand today rather than trusting a comparison written six months ago.

Where we stand: Leadfeeder does company-level identification. We do not do person-level. By default we show you company visits, not individuals. If you need names, this is not the tool, and it is better to find that out now than after a trial.

For a full comparison, we look at these tools in detail in our guide to the best website visitor identification software, and at the person-level options in our alternatives to RB2B for global traffic comparison.

Questions to ask any vendor, including us

  • For one identified visitor, what do I get back: a company, or a person's name?

  • Your match rate is a percentage of what?

  • Where did your data come from, and will you show me that in writing?

  • Do you process EU traffic, and under what legal basis?

  • Will you sign a data processing agreement, and where do you store the data?

  • How often do you get a match wrong, and how do you measure that?

  • If someone you identified asks what data you hold on them, what happens?

Frequently Asked Questions

What is the difference between company-level and person-level visitor identification?

Company-level identification tells you which company visited, along with its details and what it looked at. Person-level identification tells you which person visited, usually with a work email. They use different data and follow different rules.

Is person-level website visitor identification legal in the EU?

It has to clear two hurdles. The ePrivacy rules require consent before you store or read anything on a visitor's device, and GDPR requires a legal reason to process their data. Legitimate interest is harder to argue for person-level, because the product exists to pick out one person. Many vendors block EU traffic rather than try.

Can you identify individual website visitors without their consent?

At least not in the EU. Reading a signal from the visitor's browser needs consent under the ePrivacy rules on your site, and consent someone gave on another website does not carry over. Separately you need to know whether the original collection covers this use, and you need to be able to prove it.

Does Leadfeeder do person-level identification?

No. We identify the companies visiting your website. Leadfeeder also shows contact details for people who work at those companies, though they may or may not include whoever was on the page.

Why do person-level tools only work for US traffic?

The databases behind these tools hold far more US people than European ones, and EU consent rules make building and using such a database much harder. Many vendors decided that blocking EU traffic was easier.

What match rate should I expect?

Our published benchmark for company-level identification is 10 to 40% of total traffic. For person-level, real accuracy sits nearer 5 to 20%. The two are not comparable, because they count different things. The only number worth acting on is what you measure on your own traffic during a trial.

Is an IP address personal data under GDPR?

It can be. In Breyer, the EU Court of Justice ruled that a dynamic IP address counts as personal data for a website operator who has a lawful way to find out who is behind it. That is why company-level identification needs a legal reason, and why you should be careful with anyone who tells you it sits outside GDPR.

How to decide

If you have EU traffic, company-level is the option that works. The legal ground is well established.

If your traffic is US-only and your team runs high-volume outbound, look at person-level properly. Bring your legal team in from the start.

If several people at a company decide together, the company is your unit of work. One name adds less than it looks like it will.

If you are still mapping the category, start with our complete guide to website visitor identification.

Choose the approach that answers the question your team is actually asking.

You can see what company-level identification gives you on your own site with a 14-day free trial of Leadfeeder. Our general terms and conditions apply. No credit card required.

Hana-profile-pic

Head of Web & Creative @ Leadfeeder

Hana Banacka leads Web & Creative at Leadfeeder, where she focuses on improving website performance and optimizing the digital buyer journey. With more than 10 years of experience in B2B SaaS marketing, she specializes in conversion optimization, experimentation frameworks, and data-driven website strategy.

Hana has led global CRO programs, managed cross-functional web teams, and implemented testing strategies that significantly improve funnel performance. Her experience optimizing complex B2B websites informs her perspective on how companies can reduce friction in the buying journey and turn website visitors into qualified leads

Related articles