FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. reCAPTCHA
r

reCAPTCHA

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Google reCAPTCHA do?

Google reCAPTCHA is a free bot and spam protection service from Google that verifies users are human through challenge tests (v2) or invisible behavioural analysis (v3). It sets Google cookies and sends browser fingerprinting data to Google's US servers. European DPAs and courts have questioned reCAPTCHA's GDPR compliance due to its persistent Google cookies and opaque data processing. hCaptcha and Cloudflare Turnstile are privacy-focused alternatives.

What is Google reCAPTCHA?

Google reCAPTCHA is a free CAPTCHA service from Google that protects websites from bots and spam. reCAPTCHA v2 presents visible challenges (''I am not a robot'' checkbox, image selection). reCAPTCHA v3 operates invisibly in the background, assigning a risk score to every user session without visible interaction. reCAPTCHA Enterprise offers enhanced privacy controls for larger deployments.

GDPR concerns: cookies and data processing

reCAPTCHA sets several Google cookies (NID, _GRECAPTCHA) and sends browser fingerprinting data to Google. Under the ePrivacy Directive, setting non-essential cookies on user devices requires consent. The German Landesdatenschutzbeauftragte Baden-Württemberg has specifically raised concerns about reCAPTCHA''s GDPR compliance. The key tension: reCAPTCHA is a security measure (legitimate interest) but sets cookies that may be used for Google advertising purposes (requiring consent).

reCAPTCHA v3 and transparency

reCAPTCHA v3 presents particular GDPR challenges: it runs invisibly on every page without user interaction, users cannot opt out or complete an alternative challenge, and the data it sends to Google for scoring is not fully disclosed. The GDPR transparency principle requires clear disclosure of all data processing. If reCAPTCHA v3 is deployed site-wide, users must be informed in the privacy policy.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

GDPR-compliant alternatives

hCaptcha is a privacy-focused CAPTCHA alternative that does not use Google''s infrastructure and provides clearer GDPR terms. Cloudflare Turnstile is a CAPTCHA-free challenge that minimises data collection. Both provide bot protection without the Google data-sharing concerns. For non-public forms, honeypot techniques provide bot protection with zero data collection.

Practical compliance steps

Disclose reCAPTCHA in your privacy policy including Google''s data processing and US transfer. Sign Google''s data processing agreement. Consider whether legitimate interest covers the security use case or whether consent is needed. For v3, ensure site-wide disclosure. Consider switching to hCaptcha or Cloudflare Turnstile for simpler GDPR compliance.

GDPR consent category

Essential

Websites using Google reCAPTCHA must obtain user consent under GDPR regulations.

Legal basisThe legal basis for reCAPTCHA is contested in Europe. Legitimate interest (Art. 6(1)(f)) may support bot prevention as a security measure, but reCAPTCHA also sets persistent Google cookies (NID, _GRECAPTCHA) on user devices. Under the ePrivacy Directive, setting non-essential cookies requires consent. The German DPA and others have questioned reCAPTCHA's GDPR compliance. hCaptcha is a privacy-focused alternative.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, SCCs for US transfers. reCAPTCHA v3 runs invisibly and raises particular transparency concerns.

DPIA considerations

A DPIA is generally not required for standard reCAPTCHA security implementations. However, reCAPTCHA v3 runs on all pages invisibly, constituting broader monitoring that may warrant a risk assessment, particularly if Google uses the data for advertising purposes beyond bot detection.

Sample consent text

This website uses Google reCAPTCHA to protect forms from spam and abuse. reCAPTCHA uses cookies and sends data to Google in the US for security analysis. By using forms on this website you accept Google reCAPTCHA data processing.

Technical details

Tracking methodJavaScript widget, browser fingerprinting, behavioural analysis, risk scoring, Google account signals, persistent cookies
Server locationUnited States (Google infrastructure)
Data transferred outside the EUGoogle reCAPTCHA (v2 and v3) processes visitor browser data, IP addresses, cookies, and behavioural signals on Google's US infrastructure for fraud and bot detection purposes. EU personal data transfers require Standard Contractual Clauses. Google reCAPTCHA Enterprise has enhanced privacy controls.

Third-party domains contacted

www.google.comwww.gstatic.comrecaptcha.net

Cookies placed

NameTypeDurationPurpose
_GRECAPTCHApersistent6 monthsGoogle reCAPTCHA security token used for bot risk scoring and challenge verification

Google reCAPTCHA is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Google reCAPTCHA require GDPR consent?

The legal basis is contested. reCAPTCHA sets Google cookies (NID, _GRECAPTCHA) on user devices. Under ePrivacy, setting cookies requires consent. However, legitimate interest may support the security use case. German DPAs have raised concerns. The safest approach: use reCAPTCHA only on form pages (not site-wide), disclose in privacy policy, and consider whether consent or legitimate interest is documented.

What cookies does Google reCAPTCHA set?

reCAPTCHA sets _GRECAPTCHA (security token, 6 months) and may read the NID cookie (Google identifier, 6 months) if already present. These are Google cookies stored on the user's device, requiring an ePrivacy legal basis.

What is the difference between reCAPTCHA v2 and v3 for GDPR?

reCAPTCHA v2: visible challenge on specific pages (checkbox or image), only fires when user interacts with the form. reCAPTCHA v3: runs invisibly on every page visit without user interaction. v3 raises stronger GDPR concerns due to site-wide monitoring without user awareness.

Does reCAPTCHA transfer data to the US?

Yes. All reCAPTCHA processing occurs on Google's US infrastructure. SCCs are required. Accept Google's reCAPTCHA terms which include data processing terms. Disclose the US transfer in your privacy policy.

What are GDPR-compliant alternatives to Google reCAPTCHA?

hCaptcha: privacy-focused CAPTCHA with clearer GDPR terms, no Google data sharing. Cloudflare Turnstile: CAPTCHA-free challenge with minimal data collection, EU option available. Honeypot technique: invisible hidden form field that only bots fill — zero data collection. All three provide bot protection without Google's data sharing concerns.

Is reCAPTCHA v3 a problem for transparency under GDPR?

Yes. reCAPTCHA v3 runs invisibly on every page without user awareness. GDPR's transparency principle requires clear disclosure of all data processing. If deployed site-wide, visitors must be clearly informed in the privacy policy that their browsing behaviour is analysed by Google for security purposes.

Does reCAPTCHA Enterprise resolve GDPR issues?

reCAPTCHA Enterprise offers enhanced privacy controls including the ability to not send data to Google for advertising purposes and clearer contractual terms. It is more GDPR-compliant than standard reCAPTCHA but still involves US data transfer and Google processing. Consult your DPO.

How do I disclose reCAPTCHA in my privacy policy?

State: that forms on the website are protected by Google reCAPTCHA, that reCAPTCHA collects hardware and software information and behavioural data and sends it to Google for analysis, that this data is processed in the US under SCCs, and link to Google's Privacy Policy and Terms of Service.