First Page Sage puts B2B SaaS conversion at 1.1%, counting visitors who took a conversion action against total unique visitors, across its own client data from January 2022 to August 2025. It is one agency's book, so treat it as an order of magnitude rather than a census. The order of magnitude is the whole story: the visitor identification market operates almost entirely on people who completed no such action.
One disclosure before the argument, and it is a direct one. This publication is produced with support from Docket, which sells software for turning inbound demand into buyer conversations. That is the approach this piece ends up arguing for, which makes it a conflict rather than an adjacency. It is why the piece names no vendor in the identification market, scores no product, and describes approaches rather than ranking them. Weigh the conclusion knowing where it is written from.
The pitch for identification is arithmetic, and the arithmetic is fair. You paid for the traffic, the traffic left no name, so buy the name back. Our read is that it delivers the name and stops there, and the reason for the visit is the part that gets forecast.
The silence is not an instrumentation failure
It is tempting to treat anonymous traffic as a tracking problem, the kind of thing a better script tag fixes. The buyer research points somewhere else. Gartner reported in March 2026 that 67% of B2B buyers say they prefer a rep-free experience. In the same release, a survey of 646 B2B buyers fielded across August and September 2025 found 45% used AI during a recent purchase.
That is a statement about how buyers want to transact, not about whether they want to be known, and the two should not be merged. Plenty of rep-free buyers identify themselves freely: they start trials, pull down comparisons, and complete forms, all without wanting a call. Our inference is the narrower one. A market that prefers to evaluate without a rep spends most of its consideration cycle without triggering the events a funnel is built to catch. Non-conversion is not evidence that anyone wished for privacy, and a piece that claims otherwise has made the identification vendor's mistake in reverse.
What follows is a question about what you do next. A list assembled without the visitor's participation still gets worked the way a hand-raise gets worked, and that is where the damage happens.
What account-level identification actually delivers
Resolving traffic to a company is the defensible half of this market, legally and analytically. An organization is not a natural person, which keeps most of the personal-data question out of it. And the output is genuinely useful: it tells you which of your target accounts are moving, which is a prioritization input a marketing team cannot otherwise buy.
What it does not tell you is which person at that account was reading, or why. A buying group holds several people with different questions, and the account name does not separate them. It also does not separate a buyer from a competitor pricing you, someone about to interview there, or an analyst filling in a market map. The account is real. The intent attached to it is supplied by you.
Person-level identification meets a test it did not set
Resolving traffic to a named individual is a different activity carrying a different risk. The GDPR's Recital 30, which supplies interpretive context rather than a binding obligation, records that natural persons "may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers," and that the traces these leave, "in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them." A recital is not a rule. Our reading is that it still tells you how the drafters saw this activity, and a product whose stated purpose is identifying the natural person behind the traffic has already conceded the characterization that matters.
The instructive enforcement is not about website analytics either, and the distance matters. In December 2024 France's data protection regulator, the CNIL, fined KASPR 240,000 euros. KASPR sold access to a database of roughly 160 million professional contacts, assembled in part by a paid browser extension that collected details from LinkedIn profiles. The CNIL found breaches on several grounds. The one worth borrowing, and that ranking is ours rather than the regulator's, concerned expectation: the company had collected details of users who had expressly restricted their profile visibility, which the CNIL held "exceeded what could reasonably be expected from people who register on a professional social network." The order was closed in March 2026, after the company deleted the database, stopped collecting from LinkedIn, and rebuilt its notices in every official EU language. Note what compliance required.
That is not our case, and saying so is the point. KASPR is not a visitor identification vendor, and someone who read three pages and closed a tab set no privacy control the way those LinkedIn users had. What transfers is the shape of the question the regulator asked. Not whether the technique was clever, but whether the result was something the person had reason to expect. Person-level resolution of anonymous traffic has not had to answer that question in public yet. Our read is that it will.
The list is rarely the bottleneck
Our read, from the marketing and demand generation conversations behind this piece, is narrower than the market's pitch: buyers describe getting a list without the context to act on it. That is the disconnect they name. What follows from it is our own reasoning rather than theirs. If the reason for the visit is not in the data, the reason gets supplied at the desk, and a guess about the recipient is the one thing a recipient can always detect.
It is worth naming the two other standard responses to anonymous traffic here, because they are usually presented as alternatives when they make the same move. Retargeting reaches a device that visited. Outbound sequencing reaches a person at a company that visited. Both are addressing mechanisms. They decide where a message goes. Each inherits whatever the identification step got right, and neither adds a fact about the visitor's problem.
The only source of what a visitor wanted
The visitor. That is the whole answer, and it is unsatisfying precisely because it cannot be bought as a data feed.
What can be built is a reason to say it. Put a question in front of the visitor at the moment they have one of their own, and trade something real for the answer: a real price, or a straight response to the comparison question they were already typing somewhere else. A need the visitor stated is a different asset from a need you inferred for them, whatever the volumes, because a stated need survives being repeated back to the person who stated it. It is the same distinction this publication drew between a lead that qualified itself and one a model scored.
Which suggests a question worth asking of your own data rather than of a vendor. For the accounts that produced closed pipeline last quarter, how many of them, at any point, told you in their own words what they were trying to solve? Not which system sourced them. Which ones stated a need. If that number is small across a whole quarter of won deals, the identification spend is buying resolution on the question you could already partly answer, and the expensive question is still unpriced. That is not an argument to cut the line item. It is an argument that the line item was never the whole instrument.
