Skip to main content
UK GDPR

UK GDPR-compliant bot protection

Cookie-free verification keeps you on the right side of the UK GDPR and PECR – with EU processing the UK adequacy regulations recognize as safe.

  • No PECR consent needed
  • Adequacy-covered EU hosting
  • DPA on every plan

PECR-friendly, no cookies

The widget stores nothing on the visitor's device, so the PECR consent requirement for cookies is not triggered.

Adequacy-covered hosting

Data flows from the UK to our EU data centers are covered by the UK's adequacy regulations for the EEA – no extra transfer tools needed.

Processor with DPA

CaptchaFox acts as your processor under Art. 28 UK GDPR, with a Data Processing Agreement available on every plan.

UK GDPR compliance checklist

How CaptchaFox meets the UK GDPR and the Privacy and Electronic Communications Regulations (PECR).

  • No PECR consent requirement

    PECR Reg. 6

    PECR requires consent for storing or accessing information on a user's device. CaptchaFox sets no cookies and uses no localStorage, so verification works without a consent banner.

  • Transfers covered by adequacy

    Art. 45 UK GDPR

    All processing happens in EU data centers. The UK government has determined the EEA ensures adequate protection, so no International Data Transfer Agreement is needed.

  • Processor role with DPA

    Art. 28 UK GDPR

    You remain the controller; CaptchaFox processes visitor data exclusively on your instructions under a Data Processing Agreement.

  • Data minimization

    Art. 5(1)(c) UK GDPR

    Only the IP address and other technical signals needed to tell humans and bots apart are processed – never more than verification requires.

  • Appropriate security measures

    Art. 32 UK GDPR

    Identifying data is anonymized as early as possible, for example through hashing, and never stored permanently in plain text.

Frequently asked questions

Everything you need to know. Can't find your answer? Contact our support team.

Is CaptchaFox compliant with the UK GDPR?
Yes. CaptchaFox processes only minimal visitor data as your processor under Art. 28 UK GDPR, anonymizes identifying data right away and offers a Data Processing Agreement on every plan.
Can UK businesses use an EU-hosted CAPTCHA?
Yes. The UK's adequacy regulations recognize the EEA as providing adequate protection, so personal data can flow from the UK to our EU data centers without additional safeguards like an IDTA.
Does CaptchaFox require consent under PECR?
No. PECR's consent requirement applies to storing or reading information on a user's device. The CaptchaFox widget sets no cookies and stores nothing in the browser, so it does not trigger that requirement.
Is a DPA available for UK customers?
Yes, on every plan. The agreement covers the Art. 28 UK GDPR mandatory clauses, our subprocessor list and technical and organizational measures. Contact hello@captchafox.com to receive it.

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices