FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Arkose Labs
A

Arkose Labs

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Arkose Labs do?

Arkose Labs is a bot detection and fraud prevention platform that protects logins, sign ups and transactions from automated abuse. It combines device and behavioural signals with interactive challenges, known as Arkose MatchKey, that present a puzzle when a request looks risky. Because it uses first party cookies, local storage and device recognition, it raises ePrivacy and GDPR considerations even though it serves a security purpose. Arkose Labs acts as a processor and operates from the United States under the EU US Data Privacy Framework.

What Arkose Labs Is

Arkose Labs is a bot detection and fraud prevention platform that protects high value actions such as account creation, login and checkout from automated abuse. It blends passive signals about the device and behaviour with interactive challenges, branded as Arkose MatchKey, that ask a user to solve a short puzzle when a request looks suspicious. Acting as a processor for its customers, it scores each request and decides whether to allow it, challenge it or block it. The product is designed to frustrate attackers economically by making large scale automation slow and costly while keeping friction low for genuine users. Because protection sits in front of sensitive flows, it can touch a large share of traffic rather than only a single feature. This mix of device recognition, signal collection and challenge data is what gives the tool both its security strength and its privacy footprint.

Cookies and Data Collected

Arkose Labs relies on first party cookies and local storage to recognise a device across visits, an approach the company describes as more privacy preserving than purely static fingerprinting. It collects device and browser characteristics, connection level signals and behavioural signals such as how a user interacts with a page or a challenge. When a challenge is shown, the response data is also processed and used as ground truth to refine its detection models. The exact storage keys and durations depend on the customer configuration and the specific Arkose product in use, including its device recognition features. Together these signals support a persistent device reference and a real time risk decision. Because device recognition and stored identifiers are involved, the data can identify or single out individual devices and therefore counts as personal data.

GDPR and ePrivacy Implications

Under the GDPR the device and behavioural signals Arkose Labs processes are personal data, and the vendor positions itself as a processor acting on documented instructions from the website operator, who remains the controller. Fraud prevention and security are recognised as a legitimate interest under Article 6(1)(f), so the controller can often rely on that basis provided it carries out and records a balancing test. The ePrivacy Directive applies separately because reading from and writing to the device, including cookies, local storage and device recognition, generally needs consent unless it is strictly necessary for a service the user has explicitly requested. Many regulators, including the CNIL, treat device recognition and fingerprinting the same way as cookies. Whether the strictly necessary exemption covers all of the storage is fact specific and is usually read narrowly. The result is that legitimate interest can support the processing while ePrivacy may still require consent for some of the storage and access.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements and CMP Integration

Where Arkose Labs is used purely to secure a flow the user is actively trying to complete, such as protecting a login from credential stuffing, many operators treat the storage as strictly necessary and load it without prior consent. That stance only holds when the data is confined to security and not reused for analytics, advertising or profiling. Any collection that extends beyond protecting the requested service should be placed behind consent in your consent management platform. A workable approach is to classify Arkose Labs as a security control, document why each cookie, storage key and signal is necessary, and ensure your CMP presents that classification honestly to users. You should also disclose the device recognition and the possibility of a challenge in plain language so the cookie notice reflects what actually happens.

International Data Transfers

Arkose Labs is headquartered in San Mateo, California, and processes data in the United States, so signals and challenge responses from European visitors are transferred there. The company relies on the EU US Data Privacy Framework and uses the European Commission Standard Contractual Clauses for transfers between its group companies and to its providers. As the controller you should confirm the current Data Privacy Framework certification, record the transfer mechanism in your records of processing, and run a transfer impact assessment where your risk approach calls for one. You should also review the data processing agreement and any sub processor list so you understand where data flows. Keeping this evidence is important because transatlantic transfer rules have been challenged and revised several times.

Practical Compliance Steps

Begin by signing the Arkose Labs data processing agreement and mapping exactly which cookies, storage keys and signals are used on your site. Document a legitimate interest assessment for fraud prevention and decide, per flow, whether the strictly necessary exemption applies or whether consent is needed. Update your privacy notice and cookie policy to describe the device recognition, the behavioural signals and the possible challenge, and state that data is processed in the United States. Configure your consent management platform so that any non essential storage waits for consent. Confirm retention periods for challenge and signal data with the vendor and set expectations in your documentation. Finally, review the setup periodically so your records stay aligned with how the product is deployed.

GDPR consent category

Essential

Websites using Arkose Labs must obtain user consent under GDPR regulations.

Legal basisLegitimate Interest (GDPR Article 6(1)(f)) for fraud prevention, account protection and bot detection, supported by a documented Legitimate Interest Assessment. Consent (Article 6(1)(a)) may be required under the ePrivacy Directive where storage and device signals go beyond what is strictly necessary for a service the user explicitly requested.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidelines on fingerprinting, TTDSG (Germany), LOPDGDD (Spain), EU US Data Privacy Framework

DPIA considerations

A Data Protection Impact Assessment is recommended because Arkose Labs combines device recognition, behavioural signals and challenge response data to score every protected request, which can amount to systematic monitoring under Article 35. The assessment should document the necessity and proportionality of device recognition for fraud prevention, the use of first party storage, the retention of challenge and signal data, and the transfer of data to the United States. It should also record that Arkose Labs acts as a processor and weigh the legitimate interest in security against the impact on users who encounter the challenge.

Sample consent text

This site uses Arkose Labs to protect against bots and fraud. It stores an identifier on your device and analyses device and behaviour signals, and may show a verification challenge, to tell humans from automated traffic. These signals are processed in the United States.

Technical details

Tracking methodFirst party cookies and local storage for device recognition combined with privacy preserving device and browser signals, behavioural signals and interactive challenges (Arkose MatchKey), scored server side to tell humans from bots
Server locationUnited States (Arkose Labs, Inc., San Mateo, California), delivered over a global content delivery network
Data transferred outside the EUSignals and challenge responses are processed in the United States. Transfers from the EEA, UK and Switzerland rely on the EU US Data Privacy Framework and on Standard Contractual Clauses, with Arkose Labs acting as a processor for its customers.

Third-party domains contacted

arkoselabs.comfuncaptcha.comarkoselabs.ioarkose.com

Cookies placed

NameTypeDurationPurpose
Arkose device recognition identifier (first party storage)first party storagePersistent (varies by configuration)First party cookie or local storage entry that holds a device recognition identifier so the service can recognise a returning device and support its risk decision. The exact key name and duration depend on the deployment.
Arkose session and challenge token (first party storage)first party securitySessionFirst party storage used during a verification session to carry the challenge state and a short lived token that confirms a request was assessed.

Arkose Labs is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Arkose Labs set?

Arkose Labs uses first party cookies and local storage to recognise a device across visits, rather than relying on a single static fingerprint. The exact storage keys, names and durations depend on the customer configuration and the Arkose product in use, including its device recognition features. It also reads device and behavioural signals and may process challenge response data.

Is consent required to use Arkose Labs?

It depends on the scope. Where the storage and signals are strictly necessary to protect a flow the user explicitly requested, such as a login, many operators rely on the ePrivacy strictly necessary exemption and load it without consent. Where collection goes beyond that or is reused for other purposes, consent is required and the activity should be gated in your consent banner.

What is the legal basis for Arkose Labs?

The processing is usually based on legitimate interest under Article 6(1)(f) for fraud prevention and bot detection, backed by a documented balancing test. The ePrivacy Directive separately governs reading and writing on the device, which can still require consent even when the underlying processing rests on legitimate interest. Arkose Labs acts as a processor on the controller behalf.

Does Arkose Labs transfer data to the United States?

Yes. Arkose Labs is based in San Mateo, California, and processes data in the United States, so signals and challenge responses from European visitors are transferred there. Those transfers rely on the EU US Data Privacy Framework and on Standard Contractual Clauses for transfers within the group and to providers.

Is a DPIA needed for Arkose Labs?

A Data Protection Impact Assessment is recommended because the tool combines device recognition, behavioural signals and challenge data to score every protected request, which can amount to systematic monitoring. The assessment should cover necessity, proportionality, retention and the US transfer, and record the processor relationship.

How do I implement Arkose Labs compliantly?

Sign the data processing agreement, map the cookies, storage keys and signals collected, and document your legitimate interest assessment. Update the privacy notice and cookie policy to describe device recognition, behavioural signals, the possible challenge and US processing, and configure your consent management platform so non essential storage waits for consent.

What are the alternatives to Arkose Labs?

Other bot detection and fraud prevention options include Cloudflare Turnstile and Bot Management, hCaptcha, DataDome and PerimeterX by HUMAN Security. They differ in their use of challenges, fingerprinting, hosting region and consent posture, so weigh them against your data residency and user experience needs.

How do I update my cookie policy for Arkose Labs?

Describe the first party storage and device recognition, state their purpose and approximate duration, and explain that a verification challenge may appear and that behavioural signals are processed. Note that data is processed in the United States and identify the transfer mechanism, then revise the wording whenever the configuration changes.