Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
This integration adds Google reCAPTCHA v2 to forms built with the Contact Form 7 WordPress plugin to block spam and automated abuse. It loads Google JavaScript that analyses device, browser, and behavioural signals and sets the _GRECAPTCHA cookie. Data is processed by Google LLC in the United States. The lawful basis is debated: legitimate interest is often relied on, but several supervisory authorities expect consent.
This is the integration that connects Google reCAPTCHA v2 with Contact Form 7, one of the most widely used form plugins for WordPress. Its purpose is to protect forms from spam and automated submissions by adding a challenge, typically the I am not a robot checkbox or an image task. When a form page loads, the integration injects Google reCAPTCHA JavaScript, which evaluates whether the visitor is likely human before the form can be submitted. It is a security and anti abuse measure rather than an analytics or marketing tool.
reCAPTCHA sets the _GRECAPTCHA cookie, usually on google.com or recaptcha.net, with a lifetime of about six months, used for the risk analysis that distinguishes humans from bots. To perform that analysis Google also collects the visitor IP address, browser and device information, screen and language settings, and behavioural signals such as mouse movement and interaction patterns. Google may combine these signals with other data it holds and processes them for its own security and product purposes.
The _GRECAPTCHA cookie and the signals collected are personal data under the GDPR, so a lawful basis and transparency are required. The lawful basis is genuinely debated. Many operators rely on legitimate interest under Article 6(1)(f) for the anti spam purpose, but because Google processes the data for its own purposes and the cookie is read from the terminal, Article 5(3) of the ePrivacy Directive points towards consent, and several data protection authorities expect it. The honest position is that the basis is uncertain and consent is the more defensible route.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Where you treat reCAPTCHA as strictly necessary you may argue that consent is not needed, but this is contested because the same protection can often be achieved with less invasive tools. The more cautious approach is to obtain consent, or at least to load reCAPTCHA only on the pages that contain forms and only when the form is about to be used. If you rely on legitimate interest, document a balancing test and offer a transparent privacy notice and, ideally, an alternative way to contact you.
Google LLC processes the data in the United States, so document the transfer under the EU US Data Privacy Framework and the Standard Contractual Clauses and reference Google as a recipient. In practice, load reCAPTCHA only on pages with forms rather than site wide, consider loading it after consent or after the user starts interacting with the form, disclose it clearly in your privacy and cookie notices, and evaluate lighter alternatives such as honeypots, hCaptcha, or Cloudflare Turnstile where appropriate.
Websites using reCAPTCHA v2 for Contact Form 7 must obtain user consent under GDPR regulations.
DPIA considerations
reCAPTCHA v2 collects the visitor IP address, device and browser data, and behavioural signals, sets the _GRECAPTCHA cookie for about six months, and sends data to Google in the United States for its own purposes. A DPIA or at least a documented legitimate interest assessment is advisable because the lawful basis is contested and the processing is hard for visitors to anticipate. It should weigh the anti spam benefit against the profiling by Google, consider less invasive alternatives, and assess the transfer and retention.
Sample consent text
To protect this form from spam, we use Google reCAPTCHA. reCAPTCHA analyses your interaction with the page and places a cookie on your device, and for this purpose your IP address and device information may be processed by Google in the United States. We load reCAPTCHA only on pages with forms. If you do not wish to use it, please contact us by email instead.
Third-party domains contacted
www.google.comwww.gstatic.comwww.recaptcha.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _GRECAPTCHA | security | About 6 months | Set by Google on the google.com or recaptcha.net domain to perform the risk analysis that distinguishes human visitors from bots when a reCAPTCHA protected form is loaded. |
| rc::a | security | Persistent (local storage) | A reCAPTCHA storage entry, often kept in browser local storage rather than as a classic cookie, used to support the bot detection and challenge logic. |
| rc::b | security | Session (local storage) | A reCAPTCHA storage entry used during the session to help assess interaction and support the challenge verification process. |
reCAPTCHA v2 for Contact Form 7 collects user analytics data — you legally need a consent banner. Try FlowConsent free.
reCAPTCHA v2 sets the _GRECAPTCHA cookie, usually on the google.com or recaptcha.net domain, with a lifetime of about six months. It is used for the risk analysis that tells humans apart from bots and is read whenever a protected form page loads.
It is contested. Some operators treat reCAPTCHA as strictly necessary and rely on legitimate interest, but because Google processes the data for its own purposes and reads a cookie from the device, several supervisory authorities expect consent. The cautious approach is to obtain consent or load reCAPTCHA only when the form is used.
Operators commonly rely on legitimate interest under Article 6(1)(f) of the GDPR for spam prevention, but the basis is debated. Because the cookie is read from the terminal and Google uses the data for its own purposes, Article 5(3) of the ePrivacy Directive points towards consent under Article 6(1)(a), and several authorities expect it.
Yes. Google LLC processes the IP address, device signals, and behavioural data in the United States. The transfer relies on the EU US Data Privacy Framework and Standard Contractual Clauses, which you should reference in your privacy notice along with Google as a recipient.
A full DPIA is not always mandatory, but at least a documented legitimate interest assessment is advisable. The lawful basis is contested, the behavioural analysis is hard for visitors to anticipate, and the data is shared with Google, so weigh the anti spam benefit against the privacy impact and record your reasoning.
Load reCAPTCHA only on pages that actually contain forms rather than across the whole site, and ideally only after consent or once the visitor begins to interact with the form. Disclose it in your privacy and cookie notices, name Google as a recipient, and offer an alternative contact method for visitors who decline.
Yes. Less invasive options include server side honeypots and timing checks, the privacy oriented hCaptcha, and Cloudflare Turnstile, which avoids visible challenges and reduces data sharing. The right choice depends on the volume of spam and how much friction and data sharing you are willing to accept.
List the _GRECAPTCHA cookie, its purpose as spam protection, and its duration, name Google LLC as a recipient, and disclose the transfer to the United States. Explain the lawful basis you rely on and keep the entry in sync with a regular cookie scan.