FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. MTCaptcha

MTCaptcha

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does MTCaptcha do?

MTCaptcha is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. MTCaptcha integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, MTCaptcha helps organizations maintain robust websites that meet user expectations and technical requirements.

What is MTCaptcha

MTCaptcha is a CAPTCHA service designed as a GDPR friendly alternative to Google reCAPTCHA. It displays image or noPuzzle challenges that confirm a real human is interacting with a form. MTCaptcha is operated by a Hong Kong company with EU infrastructure in Germany and an explicit EU only mode that keeps every request inside the EEA.

Data and cookies collected

MTCaptcha loads a small JavaScript widget that talks to service.mtcaptcha.com (or eu.mtcaptcha.com in EU only mode). It processes the visitor IP, the user agent, the timing of the challenge and a short lived nonce, but does not set advertising cookies and does not build a behavioural profile across websites. A first party verification token is stored in the form during the challenge to validate it server side.

GDPR and ePrivacy implications

Because MTCaptcha is only used to secure a service explicitly requested by the user (submitting a form, creating an account), the EDPB exemption for strictly necessary storage applies. Article 5(3) of the ePrivacy Directive does not require consent for that scope. The IP processing is covered by legitimate interest under article 6(1)(f) GDPR.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and legal basis

No prior consent is required as long as MTCaptcha is used exclusively for anti spam and bot detection on the operator forms. The legal basis is article 6(1)(f) GDPR. If MTCaptcha is integrated together with marketing scoring or advertising attribution, the situation changes and consent must be collected.

Data transfers

The EU only mode pins MTCaptcha to eu.mtcaptcha.com, where data stays in Frankfurt. In the global mode, edge servers may be located outside the EEA. Pick the EU mode for Schrems II sensitive use cases and sign the MTCaptcha DPA to document the residency choice.

Practical compliance steps

Activate the EU only mode, sign the MTCaptcha DPA, list MTCaptcha as a security processor in the record of processing, mention it in the privacy notice with the legitimate interest basis and document the bot protection use case. No CMP category is needed for the default anti spam configuration.

GDPR consent category

Essential

Websites using MTCaptcha must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(f) GDPR: legitimate interest in protecting the website from spam, bots and abuse. MTCaptcha is considered a security technology and qualifies for the strictly necessary exemption of article 5(3) ePrivacy Directive when used solely for that purpose.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, German Federal Data Protection Act (BDSG)

DPIA considerations

A DPIA is not required for MTCaptcha in normal anti spam configuration. It is recommended when the service is deployed in sensitive flows such as account creation in the health, public sector or financial industries, or combined with risk scoring.

Sample consent text

We use MTCaptcha to detect bots and protect our forms. MTCaptcha runs in our EU only configuration and uses strictly necessary technical storage to validate the challenge. No tracking cookie is involved.

Technical details

Tracking methodJavaScript widget served from mtcaptcha.com that challenges human visitors with CAPTCHA puzzles; relies on first-party storage and HTTP requests, no behavioural advertising cookies
Server locationEuropean Union (Germany) with optional global edge; EU only mode available
Cookieless tracking availableYes

Third-party domains contacted

mtcaptcha.comservice.mtcaptcha.comeu.mtcaptcha.comservice2.mtcaptcha.com

Cookies placed

NameTypeDurationPurpose
mtcaptcha_verifiedtokenfirst-partysessionStrictly necessary token stored on the form during the challenge to validate the visitor anti spam check server side.

MTCaptcha is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does MTCaptcha set?

MTCaptcha does not set advertising cookies. It uses a short lived verification token passed through the form and ephemeral storage to coordinate the challenge. Some technical localStorage entries can be created to remember the last challenge state but they do not identify the visitor across sites.

Is consent required to load MTCaptcha?

No, when MTCaptcha is used strictly for anti spam and bot detection on user submitted forms. The strictly necessary exemption of article 5(3) ePrivacy Directive applies and the legal basis is article 6(1)(f) GDPR (legitimate interest in protecting the service).

What is the legal basis for processing data through MTCaptcha?

Article 6(1)(f) GDPR, legitimate interest in protecting the operator forms and services from abuse and bots. The balancing test is in favour of the operator because MTCaptcha is privacy oriented, does not profile users and is limited to the security purpose.

Does MTCaptcha transfer data to the United States?

In the EU only configuration data stays on eu.mtcaptcha.com infrastructure in Germany. In the default global configuration edge servers may be located in the US or APAC; check the regional setting in the MTCaptcha dashboard and sign the appropriate Standard Contractual Clauses if a transfer is involved.

Do I need a DPIA before using MTCaptcha?

No, a DPIA is not required for a standard MTCaptcha integration. It becomes relevant when MTCaptcha is part of a sensitive flow (health, finance, public sector account creation) or coupled with risk scoring that could produce decisions with legal effects.

How do I implement MTCaptcha in a GDPR compliant way?

Enable EU only mode, sign the MTCaptcha DPA, list MTCaptcha as a security processor in the record of processing, mention it in the privacy notice with the legitimate interest basis and disable the captcha on pages where it is not strictly necessary to keep the data minimisation principle.

Are there alternatives to MTCaptcha?

Privacy oriented CAPTCHA alternatives include Cloudflare Turnstile, hCaptcha, Friendly Captcha (EU based) and Altcha (open source). Each offers different trade offs in terms of accessibility, accuracy and data residency; Friendly Captcha is fully EU hosted.

How should I update the cookie policy for MTCaptcha?

State that MTCaptcha is used as a strictly necessary anti spam mechanism, that no advertising cookies are set, that the legal basis is legitimate interest, that the EU only mode is enabled and link to the MTCaptcha privacy notice. No CMP toggle is required.