Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Kasada is a bot mitigation and anti-automation security platform that uses client-side challenge scripts to detect and block bots, credential stuffing attacks and automated threats. It sets KP_* cookies and collects device and behavioural signals processed on US and Australian infrastructure.
Kasada is a bot mitigation and anti-automation security platform developed by the Australian company Kasada Pty Ltd. It protects web applications and APIs against credential stuffing, account takeover, scraping, and other automated threats by injecting a client-side JavaScript challenge script into web pages. This script gathers device fingerprint signals, mouse and keyboard behavioural patterns, browser properties and network metadata, then submits them to Kasada cloud servers for real-time scoring. Requests assessed as bot-generated are blocked or challenged before they reach the protected application.
Kasada sets cookies in the KP_* namespace (for example KP_UIDz and KP_SESSIONID) to associate device sessions with bot-risk scores. The JavaScript challenge script also collects a broad set of device signals including browser version, installed fonts, canvas and WebGL fingerprints, screen resolution, hardware concurrency, touch capability and timing characteristics. Behavioural signals such as mouse movement entropy and keystroke cadence are sampled where available. These signals are transmitted to Kasada infrastructure for scoring and are not used for advertising or tracking purposes beyond bot detection and fraud prevention.
Device fingerprinting and the setting of storage identifiers on end-user devices is regulated by ePrivacy Directive Article 5(3), which requires either user consent or a strictly-necessary justification. Kasada and many security vendors argue that bot-detection cookies and fingerprinting are strictly necessary because they protect the security of the communication and prevent fraud. However, several EU Data Protection Authorities have taken the view that device fingerprinting that extends beyond pure session integrity into persistent device identification is not automatically exempt and may require consent. Under the GDPR, the data controller (your organisation) must document a legal basis for processing. Legitimate interest under Article 6(1)(f) is the most commonly relied-upon basis, supported by a Legitimate Interest Assessment that weighs security benefits against the privacy intrusion of fingerprinting all visitors.
Kasada acts as a data processor under Article 28 GDPR, meaning a Data Processing Agreement must be in place. Your Article 13/14 privacy notice must disclose Kasada as a recipient of device and behavioural data and explain the legal basis for the transfer. The risk level for this service is classified as medium because the fingerprinting scope is broad but the purpose is narrowly scoped to security.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The prevailing practice across EU operators is to classify Kasada as strictly necessary for security purposes and to rely on legitimate interest, not consent. This approach is defensible when: the script is deployed solely for bot and fraud prevention, no data is shared with advertising networks, the KP_* cookies are session-scoped or short-lived, and a Legitimate Interest Assessment is documented and retained. If the Kasada deployment involves persistent cross-session device identification or if data is used beyond bot detection, the strictly-necessary exemption weakens and consent may become advisable. Operators should monitor guidance from their lead supervisory authority and update their approach if DPA enforcement practice shifts.
Kasada is headquartered in Sydney, Australia and operates cloud infrastructure in the United States and Australia. The EU has not adopted an adequacy decision for Australia, so transfers of personal data from the EU to Kasada in Australia must rely on Standard Contractual Clauses or another Article 46 mechanism. Transfers to US infrastructure fall under the EU-US Data Privacy Framework if Kasada is certified, or alternatively under SCCs. Operators should verify Kasada''s current DPF certification status and ensure the Data Processing Agreement references appropriate transfer safeguards.
To deploy Kasada in a GDPR-compliant manner: sign a Data Processing Agreement with Kasada under Article 28, complete and document a Legitimate Interest Assessment for the bot-detection processing, disclose Kasada in your privacy notice as a security processor receiving device and behavioural data, list KP_* cookies in your cookie policy under the strictly-necessary category with a clear security purpose description, verify international transfer safeguards (SCCs for AU, DPF or SCCs for US), and consider a DPIA if Kasada is deployed on high-traffic consumer-facing pages where large-scale profiling of visitor devices could be inferred. Review your cookie audit at least annually or when Kasada updates its script.
Websites using Kasada must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is advisable for Kasada deployments where device fingerprinting is used at scale. Key risk factors include the systematic collection of device and behavioural signals from all visitors without prior consent, the transfer of that data to servers in the United States and Australia without an EU adequacy decision for Australia, and the ambiguity under ePrivacy Article 5(3) regarding whether fingerprinting-based bot detection qualifies as strictly necessary. The DPIA should assess whether a Legitimate Interest Assessment adequately mitigates risk, document the proportionality of fingerprinting relative to less-intrusive bot-detection alternatives, and review contractual arrangements with Kasada as a data processor under Article 28 GDPR.
Sample consent text
We use Kasada bot protection technology on this website. Kasada's client-side script collects device characteristics and behavioural signals to distinguish human visitors from automated bots and to prevent credential stuffing attacks. This processing is based on our legitimate interest in protecting the security and integrity of our services (Article 6(1)(f) GDPR). Kasada sets KP_* cookies that are technically required for this security function. Data is transferred to Kasada infrastructure in the United States and Australia under Standard Contractual Clauses. You may contact us at [[email protected]] for more information or to exercise your rights.
Third-party domains contacted
kasada.ioips.kasada.iokasadapartners.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| KP_UIDz | Security | 1 year | Stores a device session identifier used by Kasada to associate the device with a bot-risk score across sessions. Enables persistent bot-risk profiling of the device. |
| KP_SESSIONID | Security | Session | Session-scoped cookie that holds the current Kasada challenge session token. Cleared when the browser session ends. |
| KP_UIDz-o | Security | 1 year | Secondary Kasada device identifier cookie used in conjunction with KP_UIDz for cross-session bot detection continuity. |
| KP_CH | Security | Session | Kasada challenge response cookie set after a client-side JavaScript challenge is completed successfully. Verifies that the visitor passed the bot-detection challenge. |
Kasada is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Kasada sets cookies in the KP_* namespace, most commonly KP_UIDz and KP_SESSIONID. These cookies store a device session identifier and bot-risk score used by the Kasada challenge mechanism. They are not advertising cookies and are not shared with third-party ad networks.
In most EU deployments, Kasada is treated as strictly necessary for security purposes under the ePrivacy Directive Article 5(3) exemption, meaning consent is not collected before the script fires. This position is defensible when Kasada is used solely for bot detection and fraud prevention. However, some Data Protection Authorities view persistent device fingerprinting as outside the strictly-necessary exemption, so a documented Legitimate Interest Assessment is essential and the position should be reviewed against your lead supervisory authority's guidance.
The primary legal basis under GDPR is legitimate interest (Article 6(1)(f)), grounded in the need to protect the security and integrity of online services against bot attacks and credential stuffing. A Legitimate Interest Assessment should document that the security benefit outweighs the privacy intrusion of device fingerprinting, that the data is used only for security scoring, and that less-intrusive alternatives were considered.
Yes. Kasada processes data on infrastructure in the United States and Australia. Transfers to the US may be covered by the EU-US Data Privacy Framework if Kasada holds a current DPF certification, or by Standard Contractual Clauses. Transfers to Australia must rely on Standard Contractual Clauses or another Article 46 mechanism because the EU has not issued an adequacy decision for Australia. Verify these safeguards in your Data Processing Agreement with Kasada.
A DPIA is advisable, though not automatically mandatory, when Kasada is used for large-scale device fingerprinting of website visitors. The combination of systematic signal collection across all users, international data transfers to countries without EU adequacy decisions, and the ongoing legal debate about fingerprinting under ePrivacy Article 5(3) creates sufficient risk indicators to recommend a DPIA under Article 35 GDPR.
Sign a Data Processing Agreement with Kasada under Article 28 GDPR. Complete and document a Legitimate Interest Assessment. Disclose Kasada in your privacy notice as a security processor. List KP_* cookies in your cookie policy under the strictly-necessary category with a clear security purpose. Confirm international transfer safeguards (SCCs for Australia, DPF or SCCs for the US). Consider a DPIA for high-traffic consumer sites. Review your cookie audit at least annually.
Alternatives include server-side bot detection using IP reputation, rate limiting and anomaly detection without client-side fingerprinting (for example Cloudflare Bot Management in certain configurations, or CAPTCHA-based challenges). These options may be less accurate but carry a lower ePrivacy footprint. If fingerprinting-based solutions are required for efficacy, document in your LIA why less-intrusive alternatives are insufficient.
Audit your cookie scan at least once per year or whenever Kasada updates its script. Ensure KP_* cookies are listed individually by name, with accurate duration, purpose and controller information. If Kasada introduces new cookie names or extends cookie lifetimes, update your policy within a reasonable period. Subscribe to Kasada's change notification communications and maintain a version history for your cookie policy.