Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Arkose Labs is a bot detection and fraud prevention platform that protects logins, sign ups and transactions from automated abuse. It combines device and behavioural signals with interactive challenges, known as Arkose MatchKey, that present a puzzle when a request looks risky. Because it uses first party cookies, local storage and device recognition, it raises ePrivacy and GDPR considerations even though it serves a security purpose. Arkose Labs acts as a processor and operates from the United States under the EU US Data Privacy Framework.
Arkose Labs is a bot detection and fraud prevention platform that protects high value actions such as account creation, login and checkout from automated abuse. It blends passive signals about the device and behaviour with interactive challenges, branded as Arkose MatchKey, that ask a user to solve a short puzzle when a request looks suspicious. Acting as a processor for its customers, it scores each request and decides whether to allow it, challenge it or block it. The product is designed to frustrate attackers economically by making large scale automation slow and costly while keeping friction low for genuine users. Because protection sits in front of sensitive flows, it can touch a large share of traffic rather than only a single feature. This mix of device recognition, signal collection and challenge data is what gives the tool both its security strength and its privacy footprint.
Arkose Labs relies on first party cookies and local storage to recognise a device across visits, an approach the company describes as more privacy preserving than purely static fingerprinting. It collects device and browser characteristics, connection level signals and behavioural signals such as how a user interacts with a page or a challenge. When a challenge is shown, the response data is also processed and used as ground truth to refine its detection models. The exact storage keys and durations depend on the customer configuration and the specific Arkose product in use, including its device recognition features. Together these signals support a persistent device reference and a real time risk decision. Because device recognition and stored identifiers are involved, the data can identify or single out individual devices and therefore counts as personal data.
Under the GDPR the device and behavioural signals Arkose Labs processes are personal data, and the vendor positions itself as a processor acting on documented instructions from the website operator, who remains the controller. Fraud prevention and security are recognised as a legitimate interest under Article 6(1)(f), so the controller can often rely on that basis provided it carries out and records a balancing test. The ePrivacy Directive applies separately because reading from and writing to the device, including cookies, local storage and device recognition, generally needs consent unless it is strictly necessary for a service the user has explicitly requested. Many regulators, including the CNIL, treat device recognition and fingerprinting the same way as cookies. Whether the strictly necessary exemption covers all of the storage is fact specific and is usually read narrowly. The result is that legitimate interest can support the processing while ePrivacy may still require consent for some of the storage and access.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Where Arkose Labs is used purely to secure a flow the user is actively trying to complete, such as protecting a login from credential stuffing, many operators treat the storage as strictly necessary and load it without prior consent. That stance only holds when the data is confined to security and not reused for analytics, advertising or profiling. Any collection that extends beyond protecting the requested service should be placed behind consent in your consent management platform. A workable approach is to classify Arkose Labs as a security control, document why each cookie, storage key and signal is necessary, and ensure your CMP presents that classification honestly to users. You should also disclose the device recognition and the possibility of a challenge in plain language so the cookie notice reflects what actually happens.
Arkose Labs is headquartered in San Mateo, California, and processes data in the United States, so signals and challenge responses from European visitors are transferred there. The company relies on the EU US Data Privacy Framework and uses the European Commission Standard Contractual Clauses for transfers between its group companies and to its providers. As the controller you should confirm the current Data Privacy Framework certification, record the transfer mechanism in your records of processing, and run a transfer impact assessment where your risk approach calls for one. You should also review the data processing agreement and any sub processor list so you understand where data flows. Keeping this evidence is important because transatlantic transfer rules have been challenged and revised several times.
Begin by signing the Arkose Labs data processing agreement and mapping exactly which cookies, storage keys and signals are used on your site. Document a legitimate interest assessment for fraud prevention and decide, per flow, whether the strictly necessary exemption applies or whether consent is needed. Update your privacy notice and cookie policy to describe the device recognition, the behavioural signals and the possible challenge, and state that data is processed in the United States. Configure your consent management platform so that any non essential storage waits for consent. Confirm retention periods for challenge and signal data with the vendor and set expectations in your documentation. Finally, review the setup periodically so your records stay aligned with how the product is deployed.
Websites using Arkose Labs must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is recommended because Arkose Labs combines device recognition, behavioural signals and challenge response data to score every protected request, which can amount to systematic monitoring under Article 35. The assessment should document the necessity and proportionality of device recognition for fraud prevention, the use of first party storage, the retention of challenge and signal data, and the transfer of data to the United States. It should also record that Arkose Labs acts as a processor and weigh the legitimate interest in security against the impact on users who encounter the challenge.
Sample consent text
This site uses Arkose Labs to protect against bots and fraud. It stores an identifier on your device and analyses device and behaviour signals, and may show a verification challenge, to tell humans from automated traffic. These signals are processed in the United States.
Third-party domains contacted
arkoselabs.comfuncaptcha.comarkoselabs.ioarkose.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Arkose device recognition identifier (first party storage) | first party storage | Persistent (varies by configuration) | First party cookie or local storage entry that holds a device recognition identifier so the service can recognise a returning device and support its risk decision. The exact key name and duration depend on the deployment. |
| Arkose session and challenge token (first party storage) | first party security | Session | First party storage used during a verification session to carry the challenge state and a short lived token that confirms a request was assessed. |
Arkose Labs is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Arkose Labs uses first party cookies and local storage to recognise a device across visits, rather than relying on a single static fingerprint. The exact storage keys, names and durations depend on the customer configuration and the Arkose product in use, including its device recognition features. It also reads device and behavioural signals and may process challenge response data.
It depends on the scope. Where the storage and signals are strictly necessary to protect a flow the user explicitly requested, such as a login, many operators rely on the ePrivacy strictly necessary exemption and load it without consent. Where collection goes beyond that or is reused for other purposes, consent is required and the activity should be gated in your consent banner.
The processing is usually based on legitimate interest under Article 6(1)(f) for fraud prevention and bot detection, backed by a documented balancing test. The ePrivacy Directive separately governs reading and writing on the device, which can still require consent even when the underlying processing rests on legitimate interest. Arkose Labs acts as a processor on the controller behalf.
Yes. Arkose Labs is based in San Mateo, California, and processes data in the United States, so signals and challenge responses from European visitors are transferred there. Those transfers rely on the EU US Data Privacy Framework and on Standard Contractual Clauses for transfers within the group and to providers.
A Data Protection Impact Assessment is recommended because the tool combines device recognition, behavioural signals and challenge data to score every protected request, which can amount to systematic monitoring. The assessment should cover necessity, proportionality, retention and the US transfer, and record the processor relationship.
Sign the data processing agreement, map the cookies, storage keys and signals collected, and document your legitimate interest assessment. Update the privacy notice and cookie policy to describe device recognition, behavioural signals, the possible challenge and US processing, and configure your consent management platform so non essential storage waits for consent.
Other bot detection and fraud prevention options include Cloudflare Turnstile and Bot Management, hCaptcha, DataDome and PerimeterX by HUMAN Security. They differ in their use of challenges, fingerprinting, hosting region and consent posture, so weigh them against your data residency and user experience needs.
Describe the first party storage and device recognition, state their purpose and approximate duration, and explain that a verification challenge may appear and that behavioural signals are processed. Note that data is processed in the United States and identify the transfer mechanism, then revise the wording whenever the configuration changes.