FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. DataDome

DataDome

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does DataDome do?

DataDome is a French edge bot protection platform. Detects and blocks malicious bots, credential stuffing, scraping and fraud through a JavaScript challenge and a strictly necessary first party cookie. Operates on legitimate interest with no consent required for the core security use case.

What DataDome does

DataDome is a real time bot detection and online fraud protection platform. The product is deployed as a CDN or web server module (Cloudflare Workers, Fastly Compute@Edge, AWS Lambda@Edge, Akamai EdgeWorkers, Nginx, Apache, Cloudflare integration, native cloud connectors) and as a client side JavaScript tag. Each request is scored in 2 milliseconds based on more than 5 trillion signals per day; bots are challenged, allowed, blocked or sent to a CAPTCHA. The platform also offers Account Protection (continuous authentication), API Protection and Online Fraud detection on top of the base bot mitigation.

Cookies and fingerprint

DataDome writes a single first party cookie named datadome (1 year, HTTPOnly, Secure) on the publisher domain. The cookie stores an encrypted session token that the DataDome edge uses to recognise the visitor across requests. The JavaScript tag collects a device fingerprint (canvas, user agent, screen, audio context, WebGL) and sends it to DataDome detection servers, where it is processed for the bot decision. The fingerprint and the IP are kept only for the duration needed for the security decision and the threat intelligence analytics.

Legitimate interest and the ePrivacy exemption

The datadome cookie and the fingerprint qualify for the strictly necessary exemption of ePrivacy art. 5(3) under the CNIL guidance (2020) on security cookies and the EDPB guidelines 2/2023. The processing is grounded in GDPR art. 6(1)(f) legitimate interest, because protecting the site from bots, credential stuffing, scraping and fraud is a legitimate goal of the publisher and the visitor has a reasonable expectation that such a measure is in place. Consent is only required when DataDome is used beyond pure security, for example to feed an analytics or ad fraud dashboard.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

EU residency and US transfers

DataDome offers an EU only deployment where the detection cluster, the logs and the threat intelligence aggregation stay inside the EU (Paris, Frankfurt, Ireland). Customer success and threat research teams in New York and Singapore may access anonymised bot signatures. The 2021 Standard Contractual Clauses cover any incidental transfer, and DataDome is listed under the EU US Data Privacy Framework. As a French company, DataDome is directly under GDPR jurisdiction with the CNIL as the lead authority.

How to deploy DataDome compliantly

Sign the DataDome Data Processing Addendum, request the EU only deployment, list the datadome cookie in the privacy notice under the strictly necessary category, document the legitimate interest balancing test, integrate the DataDome challenge page with your branding for transparency, configure the log retention to the minimum needed and document the bot detection processing in your record of processing under GDPR art. 30.

GDPR consent category

Essential

Websites using DataDome must obtain user consent under GDPR regulations.

Legal basisLegitimate interest of the publisher in protecting the site against bots, credential stuffing, scraping and fraud (GDPR art. 6(1)(f)). The DataDome cookie (datadome) and the JavaScript fingerprint qualify as strictly necessary security measures and are exempt under ePrivacy art. 5(3) per the CNIL guidance on cookies (2020) and the EDPB guidelines 2/2023. Consent is required only if DataDome is used for non security purposes such as audience analytics or ad fraud reporting beyond the strict bot detection use case.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidance on security cookies (2020), EDPB guidelines 2/2023, French Loi Informatique et Libertés, NIS 2 Directive, EU US Data Privacy Framework, German TTDSG

DPIA considerations

A DPIA is generally not required for the standard bot detection use case because the data flow is limited and the cookie is strictly necessary. A DPIA is recommended when DataDome is used in conjunction with the Account Protection module that performs continuous authentication, with the Online Fraud module or when bot signatures feed an external SIEM. The DPIA should cover the device fingerprint scope, log retention, the EU only deployment commitment and any export of bot scores to advertising systems.

Sample consent text

Our site is protected by DataDome, a French bot detection service. DataDome sets a strictly necessary cookie (datadome) on your device to recognise legitimate visitors and challenge suspicious traffic. This cookie is exempt from consent under the CNIL guidance on security cookies. Your data is processed in the European Union under the legitimate interest basis (GDPR art. 6(1)(f)). DataDome does not use this data for advertising or profiling.

Technical details

Tracking methodedge_bot_detection_with_javascript_challenge_device_fingerprint_and_strictly_necessary_cookie
Server locationDataDome is operated by DataDome SAS, a French company headquartered in Paris with offices in New York and Singapore. The DataDome detection servers run on a multi cloud infrastructure with primary regions in the European Union (eu-west-3 Paris, eu-central-1 Frankfurt, eu-west-1 Ireland) and additional regions in the United States and Asia for low latency global coverage. EU customers can request EU only processing where requests for European traffic stay inside the EU.
Data transferred outside the EUDataDome SAS is a French company under GDPR jurisdiction. Although EU traffic stays on the EU detection clusters, DataDome support and customer success teams operate from Paris, New York and Singapore. The DataDome Threat Research team analyses anonymised bot signatures globally. DataDome offers an EU only deployment contractually. Limited transfers to the United States and Singapore may occur for support and threat intelligence under the 2021 Standard Contractual Clauses and the EU US Data Privacy Framework.

Third-party domains contacted

datadome.coapi.datadome.cojs.datadome.cocaptcha-delivery.comct.captcha-delivery.comgeo.captcha-delivery.com

Cookies placed

NameTypeDurationPurpose
datadomeFirst party (DataDome bot protection)1 yearStrictly necessary security cookie containing an encrypted session token used by DataDome to recognise legitimate visitors across requests and to bypass the bot challenge for previously validated sessions

DataDome is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does DataDome set?

A single first party cookie named datadome (1 year, HTTPOnly, Secure) on the publisher domain. The cookie stores an encrypted session token used by DataDome to recognise the visitor across requests. No marketing cookie, no third party identifier.

Is consent required for DataDome?

No. The datadome cookie and the fingerprint qualify for the strictly necessary exemption of ePrivacy art. 5(3) under the CNIL guidance on security cookies (2020) and the EDPB guidelines 2/2023. The processing is grounded in GDPR art. 6(1)(f) legitimate interest. Consent is only required if DataDome is used beyond pure security.

What is the legal basis for DataDome?

Legitimate interest under GDPR art. 6(1)(f), because protecting the site from bots, credential stuffing, scraping and fraud is a legitimate goal of the publisher with a reasonable visitor expectation. Article 28 GDPR governs the processor relationship between the publisher and DataDome SAS.

Are data transferred outside the EU?

By default, no with the EU only deployment. DataDome detection clusters in Paris, Frankfurt and Ireland process the traffic. Customer success and threat research in New York and Singapore may access anonymised bot signatures. 2021 SCCs and the EU US Data Privacy Framework cover any incidental transfer.

Do I need a DPIA for DataDome?

Usually no for the standard bot detection. Recommended for Account Protection (continuous authentication), Online Fraud detection or when bot scores feed an external SIEM or advertising system. The DPIA should describe the device fingerprint scope and the log retention.

How do I deploy DataDome compliantly?

Sign the DPA, request EU only deployment, list the datadome cookie in the privacy notice under strictly necessary, document the legitimate interest balancing test, customise the DataDome challenge page with your branding, set the minimum log retention and document the processing in your record of processing.

What are the alternatives to DataDome?

Cloudflare Bot Management, Akamai Bot Manager Premier, Imperva Advanced Bot Protection, Human Security (formerly White Ops), PerimeterX (now Human), Kasada, Castle and Arkose Labs. For self hosting: CrowdSec (France, open source), Fail2Ban, ModSecurity. DataDome and CrowdSec are the most EU centric players.

How do I update my cookie policy after adding DataDome?

Add a strictly necessary section describing the datadome cookie (1 year, security), state the legal basis (legitimate interest), mention DataDome SAS in Paris as the processor, link to the DataDome Privacy Policy and explain why this cookie cannot be refused without breaking the security service.