consentglass · GDPR scanner for websites

HomeGuides › Service

Using Google reCAPTCHA in a data-protection-compliant way

Google reCAPTCHA analyses user behaviour for bot detection and loads resources from Google (USA), often as soon as the form loads.

Is this a risk?

Protection against spam can be a legitimate interest (Art. 6 (1)(f) GDPR). However, if reCAPTCHA sets non-necessary identifiers or loads on all pages, § 25 TDDDG comes into play. The US transfer must be justified.

What you can do

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.