Cursive logo
Pricing
Book a CallGet Started
Cursive

We know who's searching for what

With Cursive

AI-powered lead generation and outbound automation for B2B companies.

Product

  • Platform Overview
  • Visitor Pixel
  • Visitor Identification
  • Custom Audiences
  • Audience Builder
  • Intent Data
  • Direct Mail
  • Integrations
  • Pricing

Industries

  • B2B Software
  • Agencies
  • Ecommerce
  • Financial Services
  • Education
  • Home Services
  • Franchises
  • Retail
  • Media & Advertising

Resources

  • Blog
  • Case Studies
  • Resource Hub
  • FAQ
  • What Is Visitor ID?
  • What Is Intent Data?
  • What Is an AI SDR?

Comparisons

  • Clearbit Alternatives
  • Apollo Alternatives
  • ZoomInfo Alternatives
  • 6sense Alternatives
  • Warmly Alternatives
  • Apollo vs Cursive
  • ZoomInfo vs Cursive
  • 6sense vs Cursive
  • Warmly vs Cursive

Company

  • About
  • Contact
  • Pricing
  • Privacy Policy
  • Terms of Service

Get Started

  • Get Started
  • Book a Demo

© 2026 Cursive. All rights reserved.

PrivacyTerms
Back to Blog
Compliance

GDPR-Compliant Website Visitor Identification: The Complete Guide (2026)

Most visitor identification tools are built for the US market — and when deployed globally, they either skip EU visitors entirely or quietly create GDPR liability. Here is how to do it right.

February 24, 2026
11 min read

Website visitor identification is one of the most powerful tools in modern B2B sales — resolving anonymous website traffic to named individuals and companies, so your team can follow up with genuine intent data. But in Europe, it comes with a compliance minefield that trips up most companies.

The uncomfortable truth: the majority of popular visitor identification tools either violate GDPR by default or sidestep it entirely by simply refusing to identify EU visitors at the person level. Neither approach is acceptable if you are a global company or an EU-based business trying to generate pipeline from your website traffic.

This guide explains exactly what GDPR requires, why so many tools fall short, what to look for in a genuinely compliant solution, and how to implement visitor identification without putting your legal team on edge.

Why Most Visitor Identification Tools Fail GDPR

GDPR (General Data Protection Regulation) applies whenever you process personal data of individuals in the European Economic Area — regardless of where your company is headquartered. An American SaaS company whose pixel fires on an EU resident's browser is subject to GDPR.

Most visitor identification tools were built by US companies for US companies, using data infrastructure built around US privacy norms — which are dramatically more permissive than the EU's. When these companies encounter GDPR, they typically take one of three approaches, all of which are problematic:

The Three Compliance Failure Modes

1. Fire everywhere, document nothing

The pixel runs unconditionally. No consent gate, no privacy policy disclosure, no DPA with customers. This is the most common — and most legally exposed — approach.

2. Just skip EU visitors (the “US-only” workaround)

Tools like RB2B explicitly limit person-level identification to US IP addresses. This technically avoids GDPR liability for person-level processing but completely destroys the value of the tool for EU traffic. You pay the same price and see nothing for European visitors.

3. Claim consent without proper gating

The privacy policy mentions “cookies and tracking” somewhere, but the pixel fires immediately on page load regardless of consent state. Recording a consent decision after the fact does not satisfy GDPR's prior consent requirement for non-essential tracking.

The US-Only Problem: A Legal and Commercial Trap

RB2B is the most prominent example of a tool that explicitly chose US-only person-level identification as its GDPR strategy. On their support documentation, they state this directly: person-level identification is limited to US-based visitors.

For a US-only company with exclusively US traffic, this is a usable solution. For everyone else, it creates two simultaneous problems:

  1. You still have GDPR exposure. Even though RB2B doesn't perform person-level EU identification, the pixel itself still fires on EU visitors' browsers. Depending on what signals it collects and transmits even at the company-level, there may still be GDPR obligations — particularly around IP address processing (which the CJEU has ruled constitutes personal data for dynamic IPs).
  2. You lose all EU pipeline. If 30–60% of your website traffic comes from Europe — which is typical for B2B SaaS companies with global markets — you are leaving that entire segment completely dark. No person-level identification, no outreach, no pipeline from a substantial portion of your total addressable market.

Real Cost Illustration

If your website gets 10,000 monthly visitors and 40% are from Europe, a US-only tool identifies visitors from 6,000 of them at best. Cursive's 70% identification rate across global traffic means identifying up to 7,000 visitors — including the 4,000 EU visitors the US-only tool ignores entirely. At typical B2B deal values, that's not a minor gap.

GDPR Legal Bases for Visitor Identification

GDPR (Art. 6) requires a valid legal basis for any processing of personal data. For visitor identification, two bases are most relevant:

Option 1: Explicit Consent (Art. 6(1)(a))

The visitor must actively opt in before the pixel fires. This typically means a cookie consent banner that presents clear choices — and the identification pixel only loads after the visitor clicks “Accept.”

  • Must be freely given, specific, informed, and unambiguous
  • Granular — visitors must be able to accept analytics without accepting visitor identification, or vice versa
  • Withdrawal must be as easy as granting consent
  • You must maintain timestamped records of consent decisions
  • Silence, pre-ticked boxes, or continued browsing do NOT constitute valid consent

Option 2: Legitimate Interests (Art. 6(1)(f))

For B2B contexts, legitimate interests can be a valid basis for visitor identification — but only when you have properly documented it with a Legitimate Interests Assessment (LIA). The three-part test:

  1. Purpose test: Do you have a genuine, specific legitimate interest? (B2B marketing and lead generation — yes)
  2. Necessity test: Is the processing necessary for that purpose? (Visitor identification is the most direct method — yes)
  3. Balancing test: Do the individual's privacy interests override yours? For B2B professionals receiving relevant commercial outreach in their professional capacity, this is generally defensible — but you must document the reasoning

Important: Legitimate interests is harder to justify for B2C sites, sensitive categories of data, or systematic profiling. For standard B2B SaaS identifying business professionals visiting a commercial website, it is the most common and defensible approach — when documented properly.

What to Look for in a GDPR-Compliant Visitor Identification Tool

Not all tools market their compliance capabilities equally. Here are the six questions to ask before deploying any visitor identification pixel:

1

Do they provide a Data Processing Agreement (DPA)?

Required under GDPR Art. 28. Any vendor that processes personal data on your behalf must sign a DPA. If they can't or won't, that's a legal red flag.

2

Do they support Consent Management Platform (CMP) integration?

The pixel should be blockable via a CMP so it doesn't fire until consent is given. Standard with quality tools — absent from many US-only platforms.

3

Do they maintain Standard Contractual Clauses (SCCs) for EU→US transfers?

Personal data flowing from EU users to US servers requires SCCs or equivalent safeguards post-Schrems II. Verify your vendor has these in place.

4

Is a Legitimate Interests Assessment (LIA) available?

For customers relying on legitimate interests as their legal basis, the vendor should be able to provide documentation supporting this position.

5

Is there a right to erasure / opt-out mechanism?

GDPR grants individuals the right to object to data processing and request erasure. Your vendor must support this workflow.

6

Does it actually identify EU visitors at the person level?

This is the commercial test. A tool that achieves GDPR compliance by simply not identifying EU visitors has solved the legal problem by eliminating the product value.

GDPR Compliance Comparison: Major Visitor ID Tools

ToolGlobal Person IDCMP SupportDPA AvailableConsent RecordsEU-Ready
Cursive✓ Yes✓ Yes✓ Yes✓ Yes✓ Yes
RB2B✗ US-only~ Partial~ Limited✗ No✗ No person-level
Warmly~ Limited✓ Yes✓ Yes~ Partial~ Company-only EU
LeadfeederCompany only✓ Yes✓ Yes✓ YesCompany only
Lead ForensicsCompany only✓ Yes✓ Yes~ PartialCompany only

Notice the pattern: the tools that achieve broad EU compliance do so by only identifying companies — not individual people. Only Cursive provides both global person-level identification and the compliance infrastructure to support it legally. RB2B's approach is not GDPR compliance — it is GDPR avoidance by product design, at the cost of EU pipeline.

How Cursive Approaches GDPR Compliance

Cursive is built for global B2B teams. That means GDPR compliance is not an edge case — it is a core product requirement. Here is what we do:

🔒

Consent-gated pixel loading

Our marketing site uses a Consent Management Tool that blocks all non-essential tracking — Google Analytics, visitor identification pixels — until the visitor explicitly clicks Accept. The pixel never fires before consent.

📋

Timestamped consent records

We record the date, time, and version of the consent notice presented, stored in browser localStorage and available for audit on request.

📝

Data Processing Agreement on request

All Cursive customers can request a DPA covering our processing of personal data as part of the identification service.

⚖️

Legitimate Interests Assessment available

For customers who rely on legitimate interests as their GDPR legal basis, we can provide supporting documentation for review by your legal team.

🌍

Global identification — not a US-only workaround

We identify visitors from the EU, UK, Canada, and APAC with the same person-level precision as US visitors, using infrastructure built to process international data with appropriate safeguards.

✉️

Opt-out and erasure support

Individuals can request removal from our identification database by emailing privacy@meetcursive.com. We honor these requests.

5 Steps to Make Your Visitor Identification GDPR Compliant

Whether you are implementing visitor identification for the first time or auditing an existing deployment, these five steps ensure you are covered:

Step 1

Install a CMP and gate your pixel behind consent

Deploy a Consent Management Platform (or use a tool with built-in CMP integration). Configure it so your visitor identification pixel only loads after the visitor clicks Accept on your cookie/tracking banner. Never fire the pixel on page load unconditionally.

Step 2

Update your privacy policy to disclose visitor identification

Add a specific section explaining that you use visitor identification technology, what data is collected, why (your legal basis), which third parties are involved, and how visitors can opt out. Generic 'we use cookies' language is not sufficient.

Step 3

Document your legitimate interests basis (or confirm you have consent)

Write a Legitimate Interests Assessment documenting your purpose, why it's necessary, and the balancing test outcome. Keep it on file — supervisory authorities can request it.

Step 4

Sign a Data Processing Agreement with your vendor

Request a DPA from your visitor identification provider. If they can't provide one, find a different vendor. This is a non-negotiable legal requirement under GDPR Art. 28.

Step 5

Implement an opt-out and erasure mechanism

Publish a clear opt-out path in your privacy policy (email address, web form, or browser-level mechanism). Test that it actually works — honoring the right to erasure is an enforceable obligation.

See Cursive's GDPR-Compliant Identification in Action

If your current visitor identification setup is US-only, lacks a DPA, or fires unconditionally without consent gating — you have both a compliance gap and a pipeline gap. Cursive solves both. Get a free visitor identification audit to see what you are missing from your EU and global traffic.

Frequently Asked Questions

Is website visitor identification legal under GDPR?▼

Yes, website visitor identification is legal under GDPR when you have the right legal basis in place. You can use either explicit consent (opt-in via a cookie/tracking banner) or legitimate interests (with a documented Legitimate Interests Assessment). The key is that you must disclose visitor identification technology in your privacy policy, provide an opt-out mechanism, and sign a Data Processing Agreement with your vendor. Doing it without these steps is where most companies run into compliance risk.

Does RB2B work in Europe and identify EU visitors?▼

No. RB2B is a US-only person-level identification tool. It explicitly does not perform person-level identification of EU or UK visitors. RB2B acknowledges this limitation themselves — they built the product for the US market under US privacy laws, which are far less restrictive than GDPR. If a significant portion of your website visitors come from the EU, UK, or other non-US regions, RB2B will show you nothing for that traffic at the person level. This is both a compliance shortcut and a massive data gap that costs you real pipeline.

Can I use legitimate interests as the legal basis for visitor identification?▼

Yes, legitimate interests (Art. 6(1)(f) GDPR) is a valid legal basis for B2B visitor identification when properly documented. The key conditions are: (1) you have a genuine legitimate interest in identifying business visitors for commercial outreach, (2) the processing is necessary for that purpose, and (3) the individual's privacy rights don't override your interests — which for B2B professionals receiving relevant business outreach, generally holds. You must document a Legitimate Interests Assessment (LIA) and make it available on request. For consumer/B2C sites, this basis is much harder to justify.

What is a Data Processing Agreement and do I need one for visitor identification?▼

A Data Processing Agreement (DPA) is a contract required under GDPR Art. 28 between you (the data controller) and any third-party vendor (the data processor) that handles personal data on your behalf. A visitor identification pixel absolutely constitutes processing of personal data, so yes — you need a DPA with your vendor. Reputable tools like Cursive provide a DPA on request. Tools that cannot provide a DPA or refuse to sign one are a legal liability.

Should I block the visitor identification pixel until consent is given?▼

For EU and UK visitors, yes — under GDPR's ePrivacy Directive (the 'cookie law'), non-essential tracking technologies generally require prior informed consent before they can fire. A Consent Management Platform (CMP) can automatically block the pixel until a visitor clicks Accept on your cookie banner. This is exactly how Cursive's own marketing site works: Google Analytics, RB2B pixel, and the AudienceLab SuperPixel are all blocked behind a consent gate and only load after the visitor explicitly accepts.

Is company-level identification subject to GDPR?▼

Company data by itself is not personal data under GDPR — GDPR protects natural persons, not legal entities. Tools that identify visiting companies (IP-to-company resolution) generally operate in a lower-risk compliance zone than tools that identify specific individuals. Person-level identification — resolving a visit to a named individual with their email address and job title — is clearly personal data and requires a valid legal basis. This is why RB2B's EU 'workaround' of only showing company data for European visitors technically sidesteps GDPR, but also completely eliminates the primary value of person-level identification.

How does Cursive handle GDPR compliance for visitor identification?▼

Cursive is built with GDPR compliance as a core requirement, not an afterthought. Our marketing site uses a Consent Management Tool that blocks all non-essential tracking (analytics, RB2B pixel, AudienceLab SuperPixel) until the visitor explicitly accepts. We maintain timestamped consent records per visitor. We provide a Data Processing Agreement (DPA) to all customers on request. We have a documented Legitimate Interests Assessment available for B2B use cases. We support full opt-outs via privacy@meetcursive.com. And critically, we perform global identification including EU, UK, and APAC visitors — not by bypassing GDPR, but by doing it properly with the right infrastructure.

Get Your Free Visitor Identification Audit

your pipeline starts here

See exactly how many visitors you're missing — from the EU, UK, and beyond. No commitment, full insight.

Get My Free Audit
No commitment required
Setup in 5 minutes
See results in 24 hours
Cursive
Cursive
Credits
8,420 / 10,000

Welcome back, Adam!

Admin Workspace

hey@meetcursive.com
A
+12%
2,847
Total Leads
+3
12
Active Campaigns
+8%
42%
Response Rate
+15
87
Meetings Booked

Recent Leads

ContactCompanySourceValueStatus
Sarah Chen
VP Sales
SalesforceWebsite$85KHot
Michael Rodriguez
Director Marketing
DatadogLinkedIn$120KWarm
Jessica Park
Head of Growth
CloudflareWebinar$65KHot
David Kim
VP Operations
Monday.comDirect Mail$95KContacted
Amanda Foster
Chief Revenue Officer
HubSpotWebsite$150KHot

Related Articles

Cursive vs RB2B: Full Comparison

Why global B2B teams choose Cursive over RB2B's US-only approach.

International Visitor Identification Guide

Identify EU, UK, and APAC visitors — not just US traffic.

Best RB2B Alternatives (2026)

10 GDPR-ready tools that outperform RB2B for global teams.

## Page Overview

Comprehensive guide to GDPR-compliant website visitor identification for B2B companies. Covers legal requirements, tool comparison (Cursive vs RB2B and others), and implementation steps.

## Key Finding

Most visitor identification tools fail GDPR in one of three ways: fire everywhere without consent, skip EU visitors entirely (RB2B's approach), or claim consent without proper gating. Only Cursive combines global person-level identification with full GDPR compliance infrastructure.

## GDPR Legal Bases for Visitor Identification

  • Explicit Consent (Art. 6(1)(a)): Visitor must opt in before pixel fires; requires CMP integration
  • Legitimate Interests (Art. 6(1)(f)): Valid for B2B marketing with documented LIA; three-part test: purpose, necessity, balancing

## Why US-Only Tools Fail EU Teams

RB2B explicitly limits person-level identification to US IP addresses. For companies with 30-60% EU traffic, this means paying for a tool that delivers zero person-level pipeline from a major market segment. It is also not a complete GDPR solution — the pixel itself still fires on EU visitors' browsers.

## How Cursive Handles GDPR

  • Consent-gated pixel: tracking only loads after explicit visitor acceptance
  • Timestamped consent records maintained per visitor
  • DPA available to all customers on request
  • Legitimate Interests Assessment available for legal review
  • Global person-level identification: EU, UK, Canada, APAC coverage
  • Opt-out via privacy@meetcursive.com

## 5 Implementation Steps

  • Install a CMP and gate your pixel behind consent
  • Update your privacy policy to disclose visitor identification technology
  • Document your legitimate interests basis or confirm consent workflow
  • Sign a Data Processing Agreement with your vendor
  • Implement an opt-out and erasure mechanism

## Related Resources

  • Cursive vs RB2B: Full Comparison
  • International Visitor Identification Guide
  • Best RB2B Alternatives (2026)
[Get a free visitor identification audit](/free-audit)[Cursive visitor identification platform](/visitor-identification)[Cursive Privacy Policy (with consent management details)](/privacy)