Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
VentryShield is a security and bot mitigation service. This page explains its cookies, your GDPR and ePrivacy obligations, data transfers and how to deploy it with valid consent.
VentryShield is a security and bot mitigation service operated by VentryShield. It sits in front of your website to filter malicious traffic, absorb denial of service attacks and challenge suspicious visitors before they reach your origin server.
To tell humans and bots apart, VentryShield processes connection metadata such as the visitor IP address, the user agent and request patterns, and it stores a strictly necessary cookie that records the result of a security challenge.
Filtering traffic means processing IP addresses, which are personal data under the GDPR, so you need a lawful basis. Most operators rely on legitimate interest in network and information security, recognised in Recital 49 GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The cookies VentryShield needs are strictly necessary for the service to work, so they are exempt from prior consent under the ePrivacy rules, but you must still inform visitors about them.
VentryShield filters traffic through globally distributed edge nodes, including locations in the United States, which is a country outside the European Economic Area. Map this transfer, identify the safeguard you rely on such as an adequacy decision or Standard Contractual Clauses, and document it in your records of processing.
Configure VentryShield so the security cookie is described in your cookie policy, keep challenge logs no longer than necessary, sign a data processing agreement with VentryShield and confirm where traffic is filtered so you can document any transfer.
Websites using VentryShield must obtain user consent under GDPR regulations.
DPIA considerations
A screening assessment is advisable for VentryShield, and a full DPIA may become necessary if you combine it with other tracking tools or process data on a large scale.
Sample consent text
We use VentryShield to protect the site against fraud and automated attacks. With your consent we store the cookies described in our cookie policy. You can accept, refuse or withdraw your choice at any time.
Third-party domains contacted
ventryshield.comcdn.ventryshield.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| __ventry_clear | Strictly necessary | 30 minutes | Confirms that the visitor passed the security challenge so the protected page can be served |
| __ventry_uid | Strictly necessary | 1 hour | Distinguishes individual clients to apply per client rate limiting and abuse detection |
VentryShield is an essential service, but transparency matters. Manage all your consent with FlowConsent.
VentryShield sets the following cookies: __ventry_clear, __ventry_uid. Each one is listed in the cookie table on this page with its type, duration and purpose, and you should mirror that list in your own cookie policy.
No prior consent is needed for the strictly necessary cookies VentryShield uses to function, but you must still describe them in your privacy and cookie policy under the transparency rules.
The lawful basis is Legitimate interest (Art. 6(1)(f) GDPR). Record this basis in your records of processing and state it in the privacy notice shown to visitors.
Yes, a transfer outside the European Economic Area can occur. VentryShield filters traffic through globally distributed edge nodes, including locations in the United States, which is a country outside the European Economic Area. Rely on an adequacy decision or Standard Contractual Clauses and document the safeguard.
A full DPIA is not always mandatory for VentryShield, but a documented screening assessment is wise, especially alongside other tracking tools.
Implement VentryShield through your consent layer: keep strictly necessary functions always on, gate optional ones behind consent, sign a data processing agreement with VentryShield where it acts as a processor and keep your cookie policy in sync with the real cookies.
Alternatives include other anti bot and denial of service providers such as Cloudflare, Akamai or self managed rate limiting. They follow the same legitimate interest logic, so the compliance steps are similar.
List every cookie VentryShield sets in your cookie policy with its name, purpose and retention, state the legal basis, name VentryShield where relevant, and update the policy whenever the tool changes so refusals in your banner are always honoured.