FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Kasada

Kasada

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Kasada do?

Kasada is a bot mitigation and anti-automation security platform that uses client-side challenge scripts to detect and block bots, credential stuffing attacks and automated threats. It sets KP_* cookies and collects device and behavioural signals processed on US and Australian infrastructure.

What Is Kasada and How Does It Work

Kasada is a bot mitigation and anti-automation security platform developed by the Australian company Kasada Pty Ltd. It protects web applications and APIs against credential stuffing, account takeover, scraping, and other automated threats by injecting a client-side JavaScript challenge script into web pages. This script gathers device fingerprint signals, mouse and keyboard behavioural patterns, browser properties and network metadata, then submits them to Kasada cloud servers for real-time scoring. Requests assessed as bot-generated are blocked or challenged before they reach the protected application.

Data and Cookies Collected

Kasada sets cookies in the KP_* namespace (for example KP_UIDz and KP_SESSIONID) to associate device sessions with bot-risk scores. The JavaScript challenge script also collects a broad set of device signals including browser version, installed fonts, canvas and WebGL fingerprints, screen resolution, hardware concurrency, touch capability and timing characteristics. Behavioural signals such as mouse movement entropy and keystroke cadence are sampled where available. These signals are transmitted to Kasada infrastructure for scoring and are not used for advertising or tracking purposes beyond bot detection and fraud prevention.

GDPR and ePrivacy Implications

Device fingerprinting and the setting of storage identifiers on end-user devices is regulated by ePrivacy Directive Article 5(3), which requires either user consent or a strictly-necessary justification. Kasada and many security vendors argue that bot-detection cookies and fingerprinting are strictly necessary because they protect the security of the communication and prevent fraud. However, several EU Data Protection Authorities have taken the view that device fingerprinting that extends beyond pure session integrity into persistent device identification is not automatically exempt and may require consent. Under the GDPR, the data controller (your organisation) must document a legal basis for processing. Legitimate interest under Article 6(1)(f) is the most commonly relied-upon basis, supported by a Legitimate Interest Assessment that weighs security benefits against the privacy intrusion of fingerprinting all visitors.

Kasada acts as a data processor under Article 28 GDPR, meaning a Data Processing Agreement must be in place. Your Article 13/14 privacy notice must disclose Kasada as a recipient of device and behavioural data and explain the legal basis for the transfer. The risk level for this service is classified as medium because the fingerprinting scope is broad but the purpose is narrowly scoped to security.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements: Strictly Necessary vs Consent Debate

The prevailing practice across EU operators is to classify Kasada as strictly necessary for security purposes and to rely on legitimate interest, not consent. This approach is defensible when: the script is deployed solely for bot and fraud prevention, no data is shared with advertising networks, the KP_* cookies are session-scoped or short-lived, and a Legitimate Interest Assessment is documented and retained. If the Kasada deployment involves persistent cross-session device identification or if data is used beyond bot detection, the strictly-necessary exemption weakens and consent may become advisable. Operators should monitor guidance from their lead supervisory authority and update their approach if DPA enforcement practice shifts.

International Data Transfers

Kasada is headquartered in Sydney, Australia and operates cloud infrastructure in the United States and Australia. The EU has not adopted an adequacy decision for Australia, so transfers of personal data from the EU to Kasada in Australia must rely on Standard Contractual Clauses or another Article 46 mechanism. Transfers to US infrastructure fall under the EU-US Data Privacy Framework if Kasada is certified, or alternatively under SCCs. Operators should verify Kasada''s current DPF certification status and ensure the Data Processing Agreement references appropriate transfer safeguards.

Practical Compliance Steps

To deploy Kasada in a GDPR-compliant manner: sign a Data Processing Agreement with Kasada under Article 28, complete and document a Legitimate Interest Assessment for the bot-detection processing, disclose Kasada in your privacy notice as a security processor receiving device and behavioural data, list KP_* cookies in your cookie policy under the strictly-necessary category with a clear security purpose description, verify international transfer safeguards (SCCs for AU, DPF or SCCs for US), and consider a DPIA if Kasada is deployed on high-traffic consumer-facing pages where large-scale profiling of visitor devices could be inferred. Review your cookie audit at least annually or when Kasada updates its script.

GDPR consent category

Essential

Websites using Kasada must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Article 6(1)(f) GDPR) for fraud prevention and security; the strictly-necessary exemption under ePrivacy Directive Article 5(3) is argued for KP_* cookies on the basis that they are required to protect the integrity of the service and prevent credential stuffing. Device fingerprinting elements are debated: some DPAs treat fingerprinting-based bot detection as requiring consent if it is not genuinely indispensable. A documented legitimate-interest assessment (LIA) is strongly recommended.
Risk levelmedium
Applicable regulationsGDPR (Art. 6, Art. 13/14, Art. 28, Art. 46), ePrivacy Directive Art. 5(3) (strictly-necessary exemption), UK GDPR, CCPA/CPRA (if California visitors), EU-US Standard Contractual Clauses

DPIA considerations

A Data Protection Impact Assessment is advisable for Kasada deployments where device fingerprinting is used at scale. Key risk factors include the systematic collection of device and behavioural signals from all visitors without prior consent, the transfer of that data to servers in the United States and Australia without an EU adequacy decision for Australia, and the ambiguity under ePrivacy Article 5(3) regarding whether fingerprinting-based bot detection qualifies as strictly necessary. The DPIA should assess whether a Legitimate Interest Assessment adequately mitigates risk, document the proportionality of fingerprinting relative to less-intrusive bot-detection alternatives, and review contractual arrangements with Kasada as a data processor under Article 28 GDPR.

Sample consent text

We use Kasada bot protection technology on this website. Kasada's client-side script collects device characteristics and behavioural signals to distinguish human visitors from automated bots and to prevent credential stuffing attacks. This processing is based on our legitimate interest in protecting the security and integrity of our services (Article 6(1)(f) GDPR). Kasada sets KP_* cookies that are technically required for this security function. Data is transferred to Kasada infrastructure in the United States and Australia under Standard Contractual Clauses. You may contact us at [[email protected]] for more information or to exercise your rights.

Technical details

Tracking methodClient-side JavaScript challenge script that collects device fingerprint signals, behavioural patterns and network metadata. Sets KP_* session and device cookies. Server-side signal aggregation and scoring via Kasada cloud infrastructure.
Server locationUnited States and Australia (Kasada is headquartered in Sydney, AU; cloud infrastructure distributed across US and AU regions)
Data transferred outside the EUData is processed on Kasada infrastructure in the United States and Australia. Transfers from the EU to the US are covered under Standard Contractual Clauses (SCCs). No adequacy decision exists for Australia; transfers rely on SCCs or equivalent safeguards.

Third-party domains contacted

kasada.ioips.kasada.iokasadapartners.com

Cookies placed

NameTypeDurationPurpose
KP_UIDzSecurity1 yearStores a device session identifier used by Kasada to associate the device with a bot-risk score across sessions. Enables persistent bot-risk profiling of the device.
KP_SESSIONIDSecuritySessionSession-scoped cookie that holds the current Kasada challenge session token. Cleared when the browser session ends.
KP_UIDz-oSecurity1 yearSecondary Kasada device identifier cookie used in conjunction with KP_UIDz for cross-session bot detection continuity.
KP_CHSecuritySessionKasada challenge response cookie set after a client-side JavaScript challenge is completed successfully. Verifies that the visitor passed the bot-detection challenge.

Kasada is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Kasada set on my website visitors' browsers?

Kasada sets cookies in the KP_* namespace, most commonly KP_UIDz and KP_SESSIONID. These cookies store a device session identifier and bot-risk score used by the Kasada challenge mechanism. They are not advertising cookies and are not shared with third-party ad networks.

Is user consent required to deploy Kasada under GDPR and ePrivacy rules?

In most EU deployments, Kasada is treated as strictly necessary for security purposes under the ePrivacy Directive Article 5(3) exemption, meaning consent is not collected before the script fires. This position is defensible when Kasada is used solely for bot detection and fraud prevention. However, some Data Protection Authorities view persistent device fingerprinting as outside the strictly-necessary exemption, so a documented Legitimate Interest Assessment is essential and the position should be reviewed against your lead supervisory authority's guidance.

What is the legal basis for processing data through Kasada?

The primary legal basis under GDPR is legitimate interest (Article 6(1)(f)), grounded in the need to protect the security and integrity of online services against bot attacks and credential stuffing. A Legitimate Interest Assessment should document that the security benefit outweighs the privacy intrusion of device fingerprinting, that the data is used only for security scoring, and that less-intrusive alternatives were considered.

Does Kasada transfer personal data outside the EU?

Yes. Kasada processes data on infrastructure in the United States and Australia. Transfers to the US may be covered by the EU-US Data Privacy Framework if Kasada holds a current DPF certification, or by Standard Contractual Clauses. Transfers to Australia must rely on Standard Contractual Clauses or another Article 46 mechanism because the EU has not issued an adequacy decision for Australia. Verify these safeguards in your Data Processing Agreement with Kasada.

Does deploying Kasada require a Data Protection Impact Assessment?

A DPIA is advisable, though not automatically mandatory, when Kasada is used for large-scale device fingerprinting of website visitors. The combination of systematic signal collection across all users, international data transfers to countries without EU adequacy decisions, and the ongoing legal debate about fingerprinting under ePrivacy Article 5(3) creates sufficient risk indicators to recommend a DPIA under Article 35 GDPR.

How do I implement Kasada in a GDPR-compliant way?

Sign a Data Processing Agreement with Kasada under Article 28 GDPR. Complete and document a Legitimate Interest Assessment. Disclose Kasada in your privacy notice as a security processor. List KP_* cookies in your cookie policy under the strictly-necessary category with a clear security purpose. Confirm international transfer safeguards (SCCs for Australia, DPF or SCCs for the US). Consider a DPIA for high-traffic consumer sites. Review your cookie audit at least annually.

Are there privacy-friendlier alternatives to Kasada for bot detection?

Alternatives include server-side bot detection using IP reputation, rate limiting and anomaly detection without client-side fingerprinting (for example Cloudflare Bot Management in certain configurations, or CAPTCHA-based challenges). These options may be less accurate but carry a lower ePrivacy footprint. If fingerprinting-based solutions are required for efficacy, document in your LIA why less-intrusive alternatives are insufficient.

How do I keep my cookie policy up to date when using Kasada?

Audit your cookie scan at least once per year or whenever Kasada updates its script. Ensure KP_* cookies are listed individually by name, with accurate duration, purpose and controller information. If Kasada introduces new cookie names or extends cookie lifetimes, update your policy within a reasonable period. Subscribe to Kasada's change notification communications and maintain a version history for your cookie policy.