Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Lead Forensics is a business to business website visitor identification service based in Portsmouth, United Kingdom, with United States operations. Its tracking script records each visitor IP address and browsing behaviour, then matches the IP address against a proprietary business database to reveal the company visiting the site. IP addresses are personal data and this profiling happens without the visitor being aware, so it carries a high risk. Because the script and the Ifuuid cookie are non essential, Lead Forensics must load only after the visitor has given consent.
Lead Forensics is a business to business website visitor identification service headquartered in Portsmouth, United Kingdom, with operations in the United States. It places a small tracking script on a customer website that records the IP address and browsing behaviour of every visitor, then matches that IP address against a proprietary business database to reveal the company that is browsing the site. The customer sees the identified organisation, along with contact suggestions, inside the Lead Forensics portal.
The tracking script captures the visitor IP address together with behavioural signals such as the pages viewed, the time spent on each page, the referring source and the journey through the site. The IP address is the core input: it is looked up against a business database so that the visiting company can be named. In its advanced configuration the script also sets a persistent first party cookie called Ifuuid, a random identifier that lasts about one year and improves the match rate by recognising returning devices. Because an IP address singles out an identifiable person or organisation under recital 30 of the GDPR, this is the systematic collection of personal data, carried out without the visitor being aware of it.
IP addresses are personal data, so capturing them and building a behavioural profile of a named company and its visitors is processing that falls squarely within the GDPR. Storing and reading the Ifuuid identifier on the visitor device also engages Article 5(3) of the ePrivacy Directive 2002/58/EC, enforced as the French TDDDG by the CNIL, as the German TDDDG, and through the Spanish LSSI CE by the AEPD, all of which require prior consent for any non essential tracker. Providers often present covert visitor identification as a legitimate interest, but European regulators contest that basis for profiling that the visitor cannot reasonably expect and cannot easily object to.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the Lead Forensics script loads, because the IP based identification and the Ifuuid cookie are not strictly necessary to deliver the page. That consent must be freely given, specific, informed and unambiguous under Article 6(1)(a) GDPR, and refusing must be as easy as accepting. Until the visitor accepts, the script must not run, the IP address must not be sent for matching and no cookie should be written. Transparency is essential: visitors should be told plainly that their company is being identified from their IP address.
Lead Forensics processes visitor data on United Kingdom infrastructure, a transfer covered by the United Kingdom adequacy decision adopted by the European Commission, so no additional safeguard is needed for that flow. Its United States operations and subprocessors mean data can also reach the United States, which is not covered by adequacy here, so those transfers require the EU Standard Contractual Clauses 2021/914 within the Lead Forensics data processing agreement, supported by a Transfer Impact Assessment that weighs United States surveillance law in line with the Schrems II ruling.
Gate the Lead Forensics script behind your consent management platform so it fires only after the visitor accepts the relevant category, and keep the IP address from being sent until then. Describe Lead Forensics in your cookie and privacy policy, naming the Ifuuid cookie, its lifetime and the IP based identification. Sign the data processing agreement, confirm the Standard Contractual Clauses for the United States element and complete a Transfer Impact Assessment. Carry out a Data Protection Impact Assessment before launch, apply a short retention period on visitor records and give visitors a clear way to object.
Websites using Lead Forensics must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is strongly recommended, and in many cases required, because Lead Forensics carries out systematic profiling of visitors from their IP addresses without their knowledge. Document the IP address capture and business database matching, the behavioural data collected, the persistent Ifuuid identifier, the transfer of data to United Kingdom infrastructure under adequacy and to United States subprocessors under the Standard Contractual Clauses, and the retention period applied to visitor records. Assess whether covert identification can be reconciled with the transparency and fairness principles, gate the script behind consent and offer a clear objection route.
Sample consent text
We use Lead Forensics, a business to business visitor identification service operated by Lead Forensics (United Kingdom), to recognise the companies that visit our website. It records your IP address and browsing behaviour and matches your IP address against a business database, and it may store an identifier called Ifuuid on your device for about one year. This data is processed in the United Kingdom and may be shared with subprocessors in the United States under the EU Standard Contractual Clauses. Lead Forensics will only load if you click Accept.
Third-party domains contacted
leadforensics.comsecure.leadforensics.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Ifuuid | HTTP cookie (first party) | 12 months | Stores a random GUID identifier set by the advanced Lead Forensics tracking code so that returning devices can be recognised and the match rate for identifying the visiting company from its IP address is improved. |
Lead Forensics collects user analytics data — you legally need a consent banner. Try FlowConsent free.
In its advanced configuration Lead Forensics sets a persistent first party cookie called Ifuuid, a random identifier that lasts about one year and improves the match rate for returning devices. The core tracking works from the visitor IP address, which the script sends for matching against a business database even where the cookie is not used.
Yes. The tracking script performs non essential IP based profiling and can write the Ifuuid identifier to the device, so under the ePrivacy rules and the GDPR you must obtain prior consent before it loads. The script should stay blocked and the IP address must not be sent until the visitor accepts.
The appropriate legal basis is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. IP addresses are personal data under recital 30, and European regulators contest legitimate interest as a basis for this covert visitor identification.
Lead Forensics processes data mainly in the United Kingdom, which is covered by the European Commission adequacy decision. Because it also operates in the United States and uses United States based subprocessors, data can reach the United States, and that transfer needs the EU Standard Contractual Clauses 2021/914 and a Transfer Impact Assessment.
A Data Protection Impact Assessment is strongly recommended and often required, because Lead Forensics carries out systematic profiling of visitors from their IP addresses without their knowledge. Assess the IP capture, the business database matching, the Ifuuid identifier and the United Kingdom and United States transfers.
Load the script only through your consent management platform after the relevant category is accepted, and keep the IP address from being sent until then. Describe Lead Forensics in your cookie policy, sign the data processing agreement, complete a Transfer Impact Assessment, apply a short retention period and give visitors a clear way to object.
Alternatives include Leadfeeder, Albacross, Leadinfo and Clearbit Reveal. They rely on similar IP based company identification, so they raise the same consent, personal data and transfer questions; evaluate each provider hosting location and data processing terms before assuming any is lighter on privacy.
Add a dedicated entry that names Lead Forensics as the provider, lists the Ifuuid cookie with its one year lifetime, explains that visitors are identified from their IP address, and discloses the United Kingdom processing and the United States transfer with its safeguard. Keep the entry in step with your consent categories.