What Is Website Deanonymization? How It Works, and What It Can Legally Identify
60-Second Summary
Website deanonymization links anonymous visits to companies or likely individuals so B2B teams can spot buying intent earlier in the buyer journey. Its usefulness depends on the identification methods, match accuracy and whether processing complies with laws like ePrivacy and GDPR.
Key takeaways: Company-level identification typically covers ~20–40% of traffic (top performers up to ~45%), while person-level rates are much lower; coverage and accuracy are distinct metrics and must both be measured on your own site.
Standout strategies & tactics: Combine IP-to-company matching with first-party signals, refresh IP maps regularly, filter ISP/bot and carrier‑grade NAT noise, run a ≥30‑day pilot with agreed denominators, and push matched accounts and activity into CRM for prioritized, timely outreach.
Real-world lessons & frameworks: Treat matches probabilistically (avoid assuming person-level certainty), use company IDs for account prioritisation and aggregate intent analysis for unmatched traffic, and in the EU/UK validate ePrivacy/GDPR lawful basis, notification duties and vendor DPA in writing before deployment.
*This summary was created with AI assistance, using our original content.
Deanonymizing website traffic can be a useful weapon in the B2B team’s arsenal because much of the buying journey now happens before a prospect speaks to sales. Gartner found that 67% of B2B buyers prefer a rep-free buying experience. Buyers also spend only around 17% of the purchase journey meeting suppliers. Because buyers will likely compare several vendors, each sales rep could get just 5% to 6% of their time.
Website visitor deanonymization gives businesses a way to spot potential intent earlier, but its value depends on what the technology can identify, how accurate the match is and whether the processing is lawful. In this guide, we’ll tell you everything you need to know about it.
What is website deanonymization?
Website deanonymization is a sales and marketing technology that connects anonymous website activity to a company or a likely individual. It is also known as visitor identification, reverse IP lookup or anonymous visitor tracking. Company-level identification can show the organisation behind a visit, while person-level identification attempts to resolve the individual and is far more restricted.
Deanonymization vs website analytics
It’s important to know the difference between deanonymization and other web analytics tools.
Website analytics show that sessions occurred, where the traffic came from, and what visitors did on the site. Website deanonymization tries to connect that activity to the organisation behind the visit.
Analytics gives you context. Deanonymization adds a possible company identity.
How does website deanonymization work?
Website deanonymization tools can use a combination of four methods to deanonymize website traffic at company (or in some cases, person) level. Those methods are:
IP-to-company matching
First-party signals
Third-party identity graphs
Probabilistic matching
1. IP-to-company matching
When a visitor loads a website, the request includes an Internet Protocol (IP) address. Your website visitor identification tool compares that address with known company network ranges built from regional internet registry allocations, internet service provider (ISP) ranges and first-party observations collected over time.
If the evidence is strong enough, the system returns a likely organisation. This is a probabilistic match based on the available data and assessed against the platform’s confidence thresholds. It’s an assessment rather than a definitive phone book lookup.
However, it’s not always as simple as that. The databases need to be updated regularly because companies change ISPs, move offices, restructure their networks and incorporate more remote or mobile connections. As a result, a visit from an office network linked to a manufacturing business may match that company, but it does not prove which employee made the visit.
2. First-party signals
First-party signals come from direct interactions with your business, including email links tagged with UTM parameters, product logins, form submissions and authenticated sessions. A uniquely tagged link can connect a click to the recipient who received an email, while a login or form fill links activity to someone who has already identified themselves.
For example, a prospect clicks a tracked link in an email and then visits your pricing page. You can connect that visit to the recipient using your own data. This creates a different legal situation from matching someone against a third-party identity graph they may not know exists.
3. Third-party identity graphs
Third-party identity graphs combine data from brokers, publisher and advertising networks, hashed email exchanges, loyalty programmes and registration records. They link identifiers such as email addresses, devices, and browser activity to build a possible identity profile.
For example, a graph may connect a hashed email used on one service with a browser seen elsewhere, then infer that the same person visited another website. The individual may never have interacted with that website or even heard of it, which creates a different legal and privacy position from first-party identification.
4. Probabilistic matching
Probabilistic systems combine device, network and behavioural signals, then apply a confidence threshold. The result is a likelihood rather than proof.
A system may infer that two sessions came from the same likely user based on device and browsing patterns. However, in outbound sales, a false positive can do more damage than a missed match. This is because a rep may contact the wrong person and refer to behaviour they never carried out. It’s not a good look.
Understanding these methods helps you judge how to deanonymize website visitors for sales without treating every match as equally reliable.
What percentage of website visitors can you actually identify?
So, how effective can deanonymization actually be? Leadfeeder analysis puts typical company-level identification between 20-40% of traffic, with a market average of around 27%. If your website identification is really performing, you could reach 35% to 45%, depending on the audience, geography, traffic mix and methodology.
These figures come from Leadfeeder’s internal analysis dated July 31, 2026. The 27% figure is an estimate based on those five benchmark midpoints rather than a fixed industry average.
Person-level identification doesn’t tend to be as successful. We place typical performance in the US at 5%-20%, with materially lower rates in Europe. You might see published figures ranging from 20% to 80%, but those numbers often use different definitions, denominators and methods.
Why vendors quote wildly different numbers
The devil in the detail is the denominator. One vendor may measure matches against all website traffic, while another uses only B2B visitors, ICP traffic or sessions it already considers technically identifiable.
An 80% match rate can sound impressive without meaning 80% of everyone who visited the site. Plus, the same tool can appear to perform three times better in one source than in another. This is because they base the calculation on a completely different pool of traffic.
You also need to separate coverage from accuracy. Coverage measures how much traffic received a match. Accuracy measures how often those matches were correct. A platform can match more visitors and get more of them wrong. Another may identify fewer, but with far stronger confidence. Headline percentages can hide these detail
What makes match rates go down?
The main reason match rates go down is that visitors are more likely than ever to browse outside a recognisable company network. 2026 Eurostat data shows that the percentage of EU employees aged 15-64 who at least occasionally work from home went from 9.0% in 2019 to 14.2% in 2025. Around one in five now work remotely for two to four days a week.
Extra factors make identification harder:
Residential and mobile IP addresses: these tend to point to an ISP rather than a company.
Carrier-grade NAT: it places many users behind the same public IP address.
VPNs: Virtual private networks mask the visitor’s original connection.
ISP traffic/bots: these create misleading matches and must be filtered out.
Paid social traffic: visits often come from personal devices, so it tends to identify less reliably than direct or organic traffic.
Each of these factors reduces the amount of traffic a platform can confidently connect to a company.
How to verify a match rate on your own traffic
Do not accept a headline percentage without testing it on your own website. Here’s a sequence you can follow.
Agree the denominator in writing before the pilot starts.
Run a test for at least 30 days.
Review a sample of the matches and manually verify a representative subset.
Measure coverage and accuracy separately.
Coverage tells you how much traffic received a match. Accuracy tells you how often those matches were correct. Keeping those figures separate gives you a much clearer view of how the platform performs.
Person-level vs company-level deanonymization
This table shows the key differences between company-level and person-level deanonymization.
Comparison point
Company-level identification
Person-level identification
What it resolves
The organisation associated with a visit
A likely named individual
Main methods
IP-to-company mapping and first-party signals
First-party signals, identity graphs, cookies and probabilistic matching
Geographic coverage
Available across more markets
Mainly available in the US, with limited coverage in Europe
Typical match rate
20% to 40%
5% to 20% in the US and materially less in Europe
Legal exposure in the EU
Lower, although GDPR and ePrivacy laws may still apply
Higher and more difficult to justify
Useful for
Account prioritisation, intent analysis and sales timing
Individual outreach where lawfully available
There is one crucial distinction that vendors often blur. Finding a relevant decision-maker at an identified company is not the same as identifying the person who visited your website. A contact database may surface people with suitable job titles at the matched company. That does not prove that any of them completed the visit. Those contacts should not be counted as person-level website visitor identification.
Is website deanonymization legal?
Whether your website deanonymization efforts are legal depends on the technology you use, the data being processed, where you are, and how you use the results.
For European businesses, there are two separate legal questions. First, is the tracking technology lawful under ePrivacy rules? Second, is the identification and later processing lawful under the General Data Protection Regulation (GDPR)? A broad claim that a tool is “GDPR compliant” does not answer either question.
Let’s look deeper at both of these questions.
Question one: is the tracking script lawful?
The EU’s ePrivacy Directive and the UK Privacy and Electronic Communications Regulations (PECR) govern how websites store information on a user’s device, or access information already stored there. This is where cookies, similar identifiers and consent banners become relevant.
A company-level result does not automatically remove these obligations. The key question is what the script does on the device before any company match appears in the platform. Consent requirements depend on the technology and jurisdiction, so you should assess your specific deanonymization setup with your legal team.
Question 2: is the identification lawful?
GDPR Recital 30 recognises IP addresses and cookies as online identifiers that may count as personal data. The Court of Justice of the European Union reached a similar conclusion in Breyer (C-582/14), finding that a dynamic IP address may be personal data where the website operator has legal means reasonably likely to identify the person.
A business therefore needs a lawful basis for the processing. The two most relevant options are consent and legitimate interest. A legitimate-interest assessment should ask:
Does the business have a genuine purpose for the processing?
Is the processing necessary to achieve it?
Do the individual’s rights and interests override that purpose?
Some argue that company-level identification falls outside GDPR because the result names an organisation. That position remains contested because the process may still involve personal data before the company match appears.
The notification duty nobody mentions
GDPR Article 14 applies when a business obtains personal data from somewhere other than the person concerned. In most cases, the business must then tell that person about the processing within one month.
The notice usually needs to explain:
Who is processing the data?
Why the data is being processed?
What is the lawful basis?
What are the categories of personal data involved?
Where did the data come from?
What are the person’s rights?
There are limited exemptions, but this duty still creates a practical challenge for person-level identification. If a third-party identity graph links a visitor to a named individual who didn’t provide their details to the website, the business may also have a duty to notify them
What this means in practice for EU traffic
Some person-level technologies are restricted to the United States or switched off for European visitors. If your web traffic includes visitors from the European Union or United Kingdom, ask your vendors:
Is person-level identification available in every market I target?
What changes for EU and UK visitors?
What lawful basis supports your processing?
Can I see the Data Processing Agreement?
Make sure you get the answers in writing before you buy.
What do you do with the visitors you cannot identify?
Even if 20% to 40% of your traffic is the realistic ceiling for company-level identification, the remaining 60% to 80% that are unidentified still matters. That traffic still shows which pages attract interest, how visitors move through the site and which campaigns bring them in.
You can use those signals for aggregate intent analysis, campaign attribution, conversion-path analysis and audience building for retargeting (where lawful). Unmatched traffic still has value, even when you cannot associate it with a company or person.
How to evaluate a website deanonymization tool
When you’re comparing the best website visitor deanonymization tools, you’ll read and hear all sorts of claims from vendors. The right tool for you is the one that performs accurately on your traffic and can explain how it gets there. Make sure you ask these questions before you buy:
What denominator do you use when quoting your match rate?
Is person-level identification available in every region I target?
Where does your identity data come from?
What is your accuracy rate, separate from your coverage rate?
Will you run a 30-day pilot on my traffic and share the raw match log?
How do you filter bots and internet service provider traffic?
What lawful basis supports the processing, and can I see your Data Processing Agreement?
How often do you refresh your IP-to-company mappings?
What happens identification-wise when a visitor uses a mobile network?
Can I see the visits you failed to match as well as the ones you identified?
Ask for these answers in writing. A polished demo cannot tell you how the tool will perform on your own audience.
Frequently Asked Questions
What is website deanonymization?
Website deanonymization connects anonymous website activity to a company or, in more limited cases, a likely individual. Company-level identification is more widely available and shows the organisation associated with a visit.
Is website deanonymization legal?
Website deanonymization can be lawful, but the answer depends on the technology, jurisdiction, data involved and legal basis. ePrivacy and PECR govern the tracking script, while GDPR covers the identification and later processing.
Can deanonymization identify the actual person, or just the company?
Company-level tools identify the organisation associated with a visit. Person-level systems may attempt to identify a likely individual. This is only commonly available in the US. Finding a decision-maker at the company does not prove that person visited the website.
What is a realistic match rate for B2B website deanonymization?
Leadfeeder’s analysis puts the typical company-level identification rate at 20% to 40%, with an estimated market average of around 27%. Person-level identification usually has a 5% to 20% success rate in the US, materially less in Europe.
Do I need a cookie banner for a visitor identification script?
It depends on what the script does and where your visitors are based. If it stores information on a device or accesses information already there, ePrivacy or PECR consent rules may apply.
Do I have to tell someone that I identified them?
Under GDPR Article 14, you may need to notify someone when you obtain their personal data from another source. The notice generally has to arrive within one month, although limited exemptions apply.
Does website deanonymization work outside the US?
Company-level website deanonymization works across more markets. Person-level identification is primarily available in the US. It may be restricted or disabled for European traffic due to higher legal exposure.
How is deanonymization different from Google Analytics?
Google Analytics shows sessions, traffic sources and website behaviour. Website deanonymization tries to connect that activity to a company or, in more limited cases, a likely individual.
Turning identified companies into pipeline
Website deanonymization for B2B lead generation is a powerful tool. But it only creates value when your team can act on what it finds. You need to be able to:
Sync identified accounts and activity into your CRM
That’s where Leadfeeder comes in.
Leadfeeder is an AI-enabled B2B website intent and activation platform that turns visitor intent signals into leads and action.
It identifies up to 45% of B2B website visitors at company level. Public category benchmarks generally place conventional company-level identification at approximately 20% to 40%, depending on geography, traffic mix and methodology.
Its company-level approach is deliberate and shaped by its European data heritage. Leadfeeder identifies the organisation associated with the visit rather than claiming to reveal the employee browsing. Relevant decision-makers can then be found through a separate contact-enrichment process.
Hana Banacka leads Web & Creative at Leadfeeder, where she focuses on improving website performance and optimizing the digital buyer journey. With more than 10 years of experience in B2B SaaS marketing, she specializes in conversion optimization, experimentation frameworks, and data-driven website strategy.
Hana has led global CRO programs, managed cross-functional web teams, and implemented testing strategies that significantly improve funnel performance. Her experience optimizing complex B2B websites informs her perspective on how companies can reduce friction in the buying journey and turn website visitors into qualified leads