Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
GeeTest is a behavioral CAPTCHA and bot detection service that analyses device fingerprint and interaction data to tell humans from bots, with processing that can occur in China.
GeeTest is a behavioral CAPTCHA and bot and fraud detection provider whose company is based in Wuhan, China. It offers slider and intelligent challenges that distinguish humans from automated bots, delivered through a global content delivery network.
GeeTest analyses device characteristics and behavioral interaction data such as mouse movements, touch dynamics, click patterns and solving speed, together with browser and system signals, to build a behavioral signal that separates humans from bots. It relies mainly on request parameters and browser local storage and uses minimal cookies, so much of its state is held outside traditional cookies.
Reading device and interaction signals from the browser engages Article 5(3) of the ePrivacy Directive, and processing this data is subject to the GDPR. Device fingerprinting and behavioral analysis are intrusive, so transparency, necessity and proportionality must be carefully assessed and documented.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A security CAPTCHA can sometimes rely on legitimate interest under Article 6(1)(f) for fraud and abuse prevention, which is a recognised interest. However, the behavioral data collection and the transfer to China weigh against that basis, so consent under Article 6(1)(a) is the safer and often necessary route. Weigh both options honestly and document your reasoning.
Data can be processed in China, which has no European Commission adequacy decision. Transfers from the EEA therefore rely on Standard Contractual Clauses plus a transfer impact assessment and supplementary measures, and carry elevated risk comparable to other China based processors. This is a central compliance concern for GeeTest.
Decide and document the legal basis, prefer consent where the analysis is intrusive, complete a DPIA and a transfer impact assessment, sign Standard Contractual Clauses, disclose the China transfer in your privacy notice and consider an EU based CAPTCHA alternative for lower risk deployments.
Websites using GeeTest must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended because GeeTest collects device fingerprint and behavioral interaction data such as mouse and touch dynamics, which is sensitive even if not formally biometric, and because data can be processed in China without an adequacy decision. Assess the necessity and proportionality of fingerprinting, the China transfer risk, the choice between legitimate interest and consent, and the supplementary measures applied.
Sample consent text
We use GeeTest to protect this form from bots and fraud. It analyses your device and interaction patterns and may transfer data to China. Do you consent to running the GeeTest security check?
Third-party domains contacted
geetest.comapi.geetest.comstatic.geetest.comgcaptcha4.geetest.combypass.geetest.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| local storage (gt token) | Third-party | Persistent (local storage) | GeeTest relies mainly on browser local storage rather than cookies to hold a challenge token and verification state used to distinguish humans from bots. This is a storage technology rather than a classic cookie but engages the same consent considerations. |
| request parameters (challenge) | Third-party | None (per request) | GeeTest passes much of its verification state through request parameters such as the challenge and gt identifiers rather than persistent cookies, so little is stored on the device between visits. |
| geetest_session | Third-party | Session | Where a cookie is used, it is typically a short lived session cookie supporting a single CAPTCHA challenge; GeeTest sets minimal cookies overall. |
GeeTest is an essential service, but transparency matters. Manage all your consent with FlowConsent.
GeeTest mostly uses request parameters and browser local storage rather than cookies, so its cookie footprint is minimal. Any cookies it does set are typically short lived and support the challenge session, while most state for fingerprinting and verification is held in local storage and request data.
It often is. While a security CAPTCHA may rely on legitimate interest, the behavioral data collection and the transfer to China make consent the safer basis, and reading device signals from the browser engages the ePrivacy Directive. Document your basis and prefer consent where the analysis is intrusive.
Two bases are possible. Legitimate interest under Article 6(1)(f) can support fraud and abuse prevention, but the intrusive behavioral analysis and the China transfer push toward consent under Article 6(1)(a). Assess both honestly, document the balancing test and choose consent where the risk is high.
Yes. Data can be processed in China, which has no European Commission adequacy decision. Transfers from the EEA must rely on Standard Contractual Clauses plus a transfer impact assessment and supplementary measures, and they carry elevated risk that should be clearly disclosed and assessed.
A DPIA is recommended. GeeTest collects device fingerprint and behavioral interaction data, which is intrusive even if not formally biometric, and data can be processed in China without an adequacy decision. Assess necessity, proportionality, the transfer risk and supplementary measures before deployment.
Decide and document the legal basis, prefer consent where the analysis is intrusive, complete a DPIA and a transfer impact assessment, sign Standard Contractual Clauses, disclose the China transfer in your privacy notice and limit data collection to what is needed for security.
Alternatives include EU based or privacy focused CAPTCHA options such as Friendly Captcha and hCaptcha, as well as Cloudflare Turnstile. For lower transfer risk, prefer providers that process data within the EEA and that minimise device fingerprinting.
Explain that GeeTest mainly uses request parameters and local storage with minimal cookies, describe the device and interaction data it processes for bot detection, disclose that data can be transferred to China under Standard Contractual Clauses and link to GeeTest privacy information.