UK
- PECR covers storing or reading information on a visitor's device: cookies, pixels and similar technologies.
- The ICO updated its guidance on 29 April 2026. It repeated that technologies used for online advertising, including frequency capping and ad measurement, need consent.
- An exception for statistical purposes applies only when the technology is used for that purpose alone.
- UK GDPR still applies to any personal data you process, including IP addresses in some contexts.
US
- No federal equivalent of PECR, but a growing number of state privacy laws give residents rights to know and to opt out.
- Describe company identification and ad measurement in your privacy notice.
- Honour opt-out signals where state law requires.
Practical safeguards
- Load identification and ad scripts after consent where consent is required.
- Identify companies, not individuals.
- Keep data for a defined period.
- Sign a data processing agreement with every provider.
- Ask your legal adviser to confirm your basis.
Person-level identification
Some US tools try to identify individual visitors. That raises much bigger privacy questions, especially in the UK and EU. Company-level identification is the safer default. The difference explained.
What to put in your privacy notice
- That you identify the companies that visit, using network data.
- Which providers do it, by category or name.
- How long you keep the data.
- How visitors can object or opt out.
Questions
Do we need consent for company identification in the UK?
If it uses cookies, pixels or similar technologies for advertising or ad measurement, PECR requires consent. Ask your legal adviser about your exact setup.
Is an IP address personal data?
In the UK and EU it can be, depending on context. That's why UK GDPR may apply even when you only want company names.
What about visitors from the EU?
EU rules are similar to the UK's. If you target EU buyers, apply the same consent approach.
Start here: Company identification from AI. More articles in Company signals.