Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
v4Guard Checkpoint is a security and bot mitigation service. This page explains its cookies, your GDPR and ePrivacy obligations, data transfers and how to deploy it with valid consent.
v4Guard Checkpoint is a security and bot mitigation service operated by v4Guard. It sits in front of your website to filter malicious traffic, absorb denial of service attacks and challenge suspicious visitors before they reach your origin server.
To tell humans and bots apart, v4Guard Checkpoint processes connection metadata such as the visitor IP address, the user agent and request patterns, and it stores a strictly necessary cookie that records the result of a security challenge.
Filtering traffic means processing IP addresses, which are personal data under the GDPR, so you need a lawful basis. Most operators rely on legitimate interest in network and information security, recognised in Recital 49 GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The cookies v4Guard Checkpoint needs are strictly necessary for the service to work, so they are exempt from prior consent under the ePrivacy rules, but you must still inform visitors about them.
The v4Guard Checkpoint challenge is served from a global network that includes nodes outside the European Economic Area, so an IP address may be processed in a third country. Map this transfer, identify the safeguard you rely on such as an adequacy decision or Standard Contractual Clauses, and document it in your records of processing.
Configure v4Guard Checkpoint so the security cookie is described in your cookie policy, keep challenge logs no longer than necessary, sign a data processing agreement with v4Guard and confirm where traffic is filtered so you can document any transfer.
Websites using v4Guard Checkpoint must obtain user consent under GDPR regulations.
DPIA considerations
A screening assessment is advisable for v4Guard Checkpoint, and a full DPIA may become necessary if you combine it with other tracking tools or process data on a large scale.
Sample consent text
We use v4Guard Checkpoint to protect the site against fraud and automated attacks. With your consent we store the cookies described in our cookie policy. You can accept, refuse or withdraw your choice at any time.
Third-party domains contacted
v4guard.comcheckpoint.v4guard.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| __v4g_checkpoint | Strictly necessary | 1 hour | Records that the visitor completed the Checkpoint verification so the browser is not re challenged |
| __v4g_sess | Strictly necessary | Session | Links the verification result to the current browsing session for the duration of the visit |
v4Guard Checkpoint is an essential service, but transparency matters. Manage all your consent with FlowConsent.
v4Guard Checkpoint sets the following cookies: __v4g_checkpoint, __v4g_sess. Each one is listed in the cookie table on this page with its type, duration and purpose, and you should mirror that list in your own cookie policy.
No prior consent is needed for the strictly necessary cookies v4Guard Checkpoint uses to function, but you must still describe them in your privacy and cookie policy under the transparency rules.
The lawful basis is Legitimate interest (Art. 6(1)(f) GDPR). Record this basis in your records of processing and state it in the privacy notice shown to visitors.
Yes, a transfer outside the European Economic Area can occur. The v4Guard Checkpoint challenge is served from a global network that includes nodes outside the European Economic Area, so an IP address may be processed in a third country. Rely on an adequacy decision or Standard Contractual Clauses and document the safeguard.
A full DPIA is not always mandatory for v4Guard Checkpoint, but a documented screening assessment is wise, especially alongside other tracking tools.
Implement v4Guard Checkpoint through your consent layer: keep strictly necessary functions always on, gate optional ones behind consent, sign a data processing agreement with v4Guard where it acts as a processor and keep your cookie policy in sync with the real cookies.
Alternatives include other anti bot and denial of service providers such as Cloudflare, Akamai or self managed rate limiting. They follow the same legitimate interest logic, so the compliance steps are similar.
List every cookie v4Guard Checkpoint sets in your cookie policy with its name, purpose and retention, state the legal basis, name v4Guard where relevant, and update the policy whenever the tool changes so refusals in your banner are always honoured.