FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. GeeTest

GeeTest

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does GeeTest do?

GeeTest is a behavioral CAPTCHA and bot detection service that analyses device fingerprint and interaction data to tell humans from bots, with processing that can occur in China.

What GeeTest is

GeeTest is a behavioral CAPTCHA and bot and fraud detection provider whose company is based in Wuhan, China. It offers slider and intelligent challenges that distinguish humans from automated bots, delivered through a global content delivery network.

Data and how it works

GeeTest analyses device characteristics and behavioral interaction data such as mouse movements, touch dynamics, click patterns and solving speed, together with browser and system signals, to build a behavioral signal that separates humans from bots. It relies mainly on request parameters and browser local storage and uses minimal cookies, so much of its state is held outside traditional cookies.

GDPR and ePrivacy obligations

Reading device and interaction signals from the browser engages Article 5(3) of the ePrivacy Directive, and processing this data is subject to the GDPR. Device fingerprinting and behavioral analysis are intrusive, so transparency, necessity and proportionality must be carefully assessed and documented.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and legal basis

A security CAPTCHA can sometimes rely on legitimate interest under Article 6(1)(f) for fraud and abuse prevention, which is a recognised interest. However, the behavioral data collection and the transfer to China weigh against that basis, so consent under Article 6(1)(a) is the safer and often necessary route. Weigh both options honestly and document your reasoning.

Data transfers

Data can be processed in China, which has no European Commission adequacy decision. Transfers from the EEA therefore rely on Standard Contractual Clauses plus a transfer impact assessment and supplementary measures, and carry elevated risk comparable to other China based processors. This is a central compliance concern for GeeTest.

Practical compliance steps

Decide and document the legal basis, prefer consent where the analysis is intrusive, complete a DPIA and a transfer impact assessment, sign Standard Contractual Clauses, disclose the China transfer in your privacy notice and consider an EU based CAPTCHA alternative for lower risk deployments.

GDPR consent category

Essential

Websites using GeeTest must obtain user consent under GDPR regulations.

Legal basisA security CAPTCHA can sometimes rely on legitimate interest under Article 6(1)(f) for fraud and abuse prevention, but the behavioral data collection and the transfer to China make consent under Article 6(1)(a) the safer and often necessary basis.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive (2002/58/EC), Standard Contractual Clauses for transfers to China, national cookie consent rules (TTDSG in Germany)

DPIA considerations

A DPIA is recommended because GeeTest collects device fingerprint and behavioral interaction data such as mouse and touch dynamics, which is sensitive even if not formally biometric, and because data can be processed in China without an adequacy decision. Assess the necessity and proportionality of fingerprinting, the China transfer risk, the choice between legitimate interest and consent, and the supplementary measures applied.

Sample consent text

We use GeeTest to protect this form from bots and fraud. It analyses your device and interaction patterns and may transfer data to China. Do you consent to running the GeeTest security check?

Technical details

Tracking methodBehavioral CAPTCHA collecting device fingerprint and interaction data (mouse and touch dynamics), using request parameters and browser local storage with minimal cookies
Server locationChina (Wuhan) with global CDN delivery
Data transferred outside the EUData can be processed in China, which has no European Commission adequacy decision. Transfers from the EEA therefore rely on Standard Contractual Clauses plus a transfer impact assessment and supplementary measures, and carry elevated risk comparable to other China based processors.

Third-party domains contacted

geetest.comapi.geetest.comstatic.geetest.comgcaptcha4.geetest.combypass.geetest.com

Cookies placed

NameTypeDurationPurpose
local storage (gt token)Third-partyPersistent (local storage)GeeTest relies mainly on browser local storage rather than cookies to hold a challenge token and verification state used to distinguish humans from bots. This is a storage technology rather than a classic cookie but engages the same consent considerations.
request parameters (challenge)Third-partyNone (per request)GeeTest passes much of its verification state through request parameters such as the challenge and gt identifiers rather than persistent cookies, so little is stored on the device between visits.
geetest_sessionThird-partySessionWhere a cookie is used, it is typically a short lived session cookie supporting a single CAPTCHA challenge; GeeTest sets minimal cookies overall.

GeeTest is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does GeeTest set?

GeeTest mostly uses request parameters and browser local storage rather than cookies, so its cookie footprint is minimal. Any cookies it does set are typically short lived and support the challenge session, while most state for fingerprinting and verification is held in local storage and request data.

Is consent required to use GeeTest?

It often is. While a security CAPTCHA may rely on legitimate interest, the behavioral data collection and the transfer to China make consent the safer basis, and reading device signals from the browser engages the ePrivacy Directive. Document your basis and prefer consent where the analysis is intrusive.

What is the legal basis for GeeTest?

Two bases are possible. Legitimate interest under Article 6(1)(f) can support fraud and abuse prevention, but the intrusive behavioral analysis and the China transfer push toward consent under Article 6(1)(a). Assess both honestly, document the balancing test and choose consent where the risk is high.

Does GeeTest transfer data to third countries?

Yes. Data can be processed in China, which has no European Commission adequacy decision. Transfers from the EEA must rely on Standard Contractual Clauses plus a transfer impact assessment and supplementary measures, and they carry elevated risk that should be clearly disclosed and assessed.

Is a DPIA needed for GeeTest?

A DPIA is recommended. GeeTest collects device fingerprint and behavioral interaction data, which is intrusive even if not formally biometric, and data can be processed in China without an adequacy decision. Assess necessity, proportionality, the transfer risk and supplementary measures before deployment.

How do I implement GeeTest compliantly?

Decide and document the legal basis, prefer consent where the analysis is intrusive, complete a DPIA and a transfer impact assessment, sign Standard Contractual Clauses, disclose the China transfer in your privacy notice and limit data collection to what is needed for security.

What are alternatives to GeeTest?

Alternatives include EU based or privacy focused CAPTCHA options such as Friendly Captcha and hCaptcha, as well as Cloudflare Turnstile. For lower transfer risk, prefer providers that process data within the EEA and that minimise device fingerprinting.

How do I update my cookie policy for GeeTest?

Explain that GeeTest mainly uses request parameters and local storage with minimal cookies, describe the device and interaction data it processes for bot detection, disclose that data can be transferred to China under Standard Contractual Clauses and link to GeeTest privacy information.