FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Cloudflare Turnstile
C

Cloudflare Turnstile

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Cloudflare Turnstile do?

Cloudflare Turnstile is a free, CAPTCHA-free bot detection service from Cloudflare that verifies users are human through invisible proof-of-work challenges, browser signals, and behavioural analysis — without presenting visible CAPTCHA puzzles. It is designed to be privacy-preserving: no persistent tracking cookies, no advertising data sharing, and minimal personal data processing. Legitimate interest supports its use for security without requiring consent, making it one of the most GDPR-friendly CAPTCHA alternatives available.

What Cloudflare Turnstile actually does

Cloudflare Turnstile is the free CAPTCHA replacement launched by Cloudflare in 2022. Instead of asking users to identify traffic lights, Turnstile runs a series of non interactive JavaScript challenges (Private Access Tokens, browser integrity tests, behaviour signals) and returns a token that the publisher backend can verify against challenges.cloudflare.com/turnstile/v0/siteverify. The product is positioned as the privacy first alternative to Google reCAPTCHA: no Google or Cloudflare advertising cookie is set, the JavaScript widget is small, and the verification is local to the visitor browser whenever possible.

Cookies and storage set by Turnstile

In its default invisible mode, Turnstile does not write any cookie on the publisher domain. The widget script (challenges.cloudflare.com/turnstile/v0/api.js) only stores a transient nonce in sessionStorage to detect replay during the same page lifetime. When the visitor must complete a managed or interactive challenge, Cloudflare may set cf_chl_persist on .cloudflare.com (third party, 1 hour) and cf_chl_rc_n on the publisher domain (first party, 1 hour) to remember the successful pass. These cookies are strictly necessary for the security service.

Lawful basis and the security exemption

Turnstile relies on the legitimate interest of the publisher in protecting its forms, login and APIs against bots, scraping and credential stuffing (GDPR art. 6(1)(f)). The CNIL recommendation on cookies and the EDPB guidelines 2/2023 on art. 5(3) ePrivacy both recognise an exemption from consent for cookies and storage strictly necessary to provide a security service explicitly requested by the user. Turnstile fits inside that exemption as long as the publisher does not reuse the signals for marketing or analytics. The data minimisation principle (GDPR art. 5(1)(c)) is respected because no persistent visitor identifier is created.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

Cloudflare Inc. is established in the United States and adheres to the EU US Data Privacy Framework since 1 August 2023. Challenge signals are processed across the global anycast network, which includes the United States, even when the visitor connects to a European point of presence. Customers on Cloudflare Enterprise or Business with Regional Services can pin the data plane to the European Region to keep raw signals within the EU. The Cloudflare data processing addendum incorporates the EU Standard Contractual Clauses (module 2) and is auto signed by the customer when accepting the Cloudflare terms.

Practical compliance checklist

Limit Turnstile to genuine anti bot purposes; do not pipe the score into marketing analytics. Document Cloudflare as a processor in the GDPR art. 30 register and in the privacy notice. Activate Regional Services EU only when strict data residency is required. Review the configured action mode (managed, non interactive, invisible) to keep the user friction proportionate. Combine Turnstile with rate limiting and Web Application Firewall rules to reduce the number of challenges issued. Refresh the data processing addendum every year and verify the active DPF certification on dataprivacyframework.gov.

Alternatives

Privacy first alternatives include Friendly Captcha (German, GDPR designed), hCaptcha (with Privacy Pass), Altcha (open source proof of work) and MTCaptcha. Google reCAPTCHA remains the most popular but it sets behavioural cookies on doubleclick.net and is incompatible with the consent exemption for security cookies in most cases.

GDPR consent category

Essential

Websites using Cloudflare Turnstile must obtain user consent under GDPR regulations.

Legal basisLegitimate interest of the publisher in protecting the site against bots and abuse (GDPR art. 6(1)(f)). Under the CNIL exemption for security cookies and the EDPB guidelines 2/2023 on the scope of ePrivacy art. 5(3), a CAPTCHA strictly necessary to deliver the service requested by the user can run without consent, provided no advertising reuse occurs. Consent must be sought if the publisher activates the Turnstile cf_chl_persist cookie for non security purposes.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, EDPB guidelines 2/2023 on art. 5(3) ePrivacy, CNIL recommendation on security cookies, TTDSG (Germany), LOPDGDD (Spain), LIL (France)

DPIA considerations

A DPIA is generally not required for Turnstile because it is a security measure that processes only signals about the browser session. Document the legal basis and the data flow to Cloudflare.

Sample consent text

We use Cloudflare Turnstile, a privacy first CAPTCHA replacement, to detect bots and protect our forms. Turnstile runs a non interactive JavaScript challenge in your browser; no advertising cookie is set and no behavioural profile is built. Signals such as your IP, user agent and challenge timings are processed across the Cloudflare global network, including the United States, under the EU US Data Privacy Framework and the EU Standard Contractual Clauses. Because Turnstile is strictly necessary to protect this site against fraud, it runs without your consent under the security exemption recognised by the CNIL and the EDPB.

Technical details

Tracking methodinvisible_browser_challenge_javascript
Server locationCloudflare operates an anycast network of more than 320 points of presence. Turnstile challenges are issued and verified at the closest edge to the visitor; for EU visitors traffic stays in the European Region (Frankfurt, Paris, Amsterdam, Madrid) under the Cloudflare Regional Services configuration when activated by the customer.
Cookieless tracking availableYes
Data transferred outside the EUCloudflare Inc. is established in San Francisco, California. Challenge signals (browser fingerprints, IP, timing, behaviour signals) are processed across the global Cloudflare network including the United States, even when the EU edge is preferred. Cloudflare adheres to the EU US Data Privacy Framework since 1 August 2023 and signs the EU Standard Contractual Clauses through its Data Processing Addendum. Activate Regional Services EU only for stricter data residency.

Third-party domains contacted

challenges.cloudflare.comchallenges.cloudflare.comcloudflare.comcloudflare.comstatic.cloudflareinsights.com

Cookies placed

NameTypeDurationPurpose
cf_clearancepersistent30 minutesCloudflare Turnstile clearance cookie confirming successful human verification — no advertising or tracking purpose
cf_clearanceFirst party (Cloudflare, optional)30 minutesSet only when the protected resource also uses Cloudflare Bot Management. Confirms the visitor has passed the bot challenge for the current session.
__cf_chl_*First party (Cloudflare)Few secondsShort lived challenge cookie used to coordinate the Turnstile challenge in the browser. Removed immediately after the challenge completes.

Cloudflare Turnstile is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Cloudflare Turnstile require consent?

Generally no. Turnstile is designed for bot prevention under legitimate interest. It does not set persistent tracking cookies, does not profile users for advertising, and collects minimal data. Legitimate interest for security is well-supported without requiring consent.

Is Cloudflare Turnstile really CAPTCHA-free?

Yes. Turnstile does not show image puzzles or checkbox challenges to most users. It runs JavaScript challenges and browser attestation invisibly. In cases where automated checks are insufficient, Turnstile may show a simple visual confirmation, but most users experience zero-friction verification.

What data does Cloudflare Turnstile collect?

Turnstile collects: JavaScript challenge results, browser characteristics (user agent, screen resolution), timing signals, and proof-of-work challenge responses. It does not collect persistent identifiers for tracking, does not set advertising cookies, and does not share data with third-party advertising platforms.

Does Cloudflare Turnstile transfer data outside the EU?

Cloudflare operates a global network including EU data centres. For EU-only data processing, Cloudflare offers data localisation options. Standard Turnstile deployment may use Cloudflare's global network. Cloudflare provides a GDPR DPA covering Turnstile. Accept the Cloudflare DPA before using Turnstile on EU-facing websites.

Is Cloudflare Turnstile free?

Yes. Cloudflare Turnstile has a free tier with no usage limits for most use cases. There is no cost for the standard Turnstile widget. Enterprise-level features and SLA guarantees are available on Cloudflare's paid plans.

How do I implement Cloudflare Turnstile?

Add the Turnstile script tag to your page, add the Turnstile widget div with your site key, and validate the Turnstile token on your server using Cloudflare's siteverify API. Turnstile provides drop-in compatibility with existing reCAPTCHA implementations via its explicit mode.

What is the difference between Cloudflare Turnstile and hCaptcha?

Both are privacy-friendly reCAPTCHA alternatives. Key differences: Turnstile is CAPTCHA-free (no visual puzzles for most users) while hCaptcha may show image grids. Turnstile is fully free with no limits; hCaptcha has a free tier but enterprise features are paid. Turnstile is hosted by Cloudflare with EU options; hCaptcha is US-hosted requiring SCCs. For GDPR simplicity, Turnstile's CAPTCHA-free design and minimal data collection are advantages.

How do I disclose Cloudflare Turnstile in my privacy policy?

State: that forms are protected by Cloudflare Turnstile for bot prevention, that Turnstile uses browser signals and JavaScript challenges to verify humanity, that this is processed under legitimate interest for security, that Cloudflare infrastructure is used, and link to Cloudflare's privacy policy.

What cookies does Cloudflare Turnstile set?

None by default. Turnstile is cookieless and uses only short lived browser signals. The cf_clearance cookie may appear if the protected resource is also behind Cloudflare Bot Management, but Turnstile itself does not depend on it.

Do I need consent for Cloudflare Turnstile?

No. Turnstile is a security technology necessary to provide the requested service (Recital 30 ePrivacy, Recital 49 GDPR). It can be loaded before consent like any anti abuse CAPTCHA. The CNIL and AEPD share this view.

What is the legal basis for Turnstile?

Legitimate interest (Art. 6(1)(f) GDPR) to protect a service from automated abuse, fraud, credential stuffing, scraping and spam. The interest is concrete and proportionate.

Does Cloudflare Turnstile transfer data to the US?

Cloudflare, Inc. is established in the United States. Most Turnstile challenges are evaluated at the closest edge node, often in Europe. Any transfer to the US is covered by the EU US Data Privacy Framework and EU SCCs in the Cloudflare DPA.

Do I need a DPIA for Turnstile?

A DPIA is generally not required because Turnstile is a security measure that processes only browser signals for a short time. Document the lawful basis in your records of processing.

How do I implement Turnstile compliantly?

Use it on the forms or actions where bot abuse is a real risk. Document it as a security measure. Sign the Cloudflare DPA. Verify server side. Use explicit or managed render mode to avoid surprising the user.

What are the alternatives to Turnstile?

Privacy first CAPTCHA alternatives include Friendly Captcha (Germany), Anubis (open source), MTCaptcha (Spain), Hcaptcha (Switzerland), Procaptcha (UK), Capy Puzzle Captcha (Japan), Geetest (China). For full Bot Management, consider Datadome (France) and Reblaze.

How do I update my cookie policy for Turnstile?

No mandatory cookie entry because Turnstile is cookieless. Mention Cloudflare Turnstile in the security section of your privacy policy: purpose (bot mitigation), legal basis (legitimate interest in security), processor (Cloudflare), data transfer (EU US Data Privacy Framework + SCCs).