What is GDPR?
The General Data Protection Regulation (GDPR) is an EU law that protects the personal data of individuals in the European Union and the European Economic Area. It gives people five core rights over their own data:
- The right to be informed, and to give or withhold consent
- The right of access to their own data
- The right to rectification, correcting inaccurate data
- The right of erasure, having data deleted
- The right to data portability, taking data elsewhere
How does GDPR apply to a captcha?
Any service that identifies individuals or tracks their activity across a site takes on GDPR obligations, whether or not it was built with that in mind. That includes captcha services: a widget that reads a visitor’s IP address, sets tracking cookies, or profiles behavior to score whether someone is human is processing personal data, and needs to be able to explain what it collects, why, and where it goes, not just claim that it works.
MTCaptcha and GDPR
MTCaptcha is built privacy-first, not retrofitted for compliance. It does not collect or track personally identifiable information. IP addresses are anonymized non-reversibly rather than stored raw, and the cookies the widget sets are functional, not used to build a profile of an individual visitor across sites. Data is encrypted both in transit (HTTPS) and at rest. The widget’s own privacy terms are disclosed clearly, not buried in a separate document nobody reads.
For the full technical and legal detail, see the Captcha Plugin Privacy Policy and the Data Processing Agreement. For how this plays out across account takeover, form spam, and other real scenarios, see privacy and compliance without tracking.
Captcha and website profiling
A captcha widget sits on enough pages, across enough sites, that it could be used to build a picture of traffic across the web: geography, market intelligence, cross-site behavior, exactly the kind of profiling GDPR is largely about limiting. MTCaptcha does not sell, share, or make customer data accessible to third parties. What is collected exists to verify that a visitor is human, not to build a business around the byproduct.
Verifying the claims
MTCaptcha is SOC 2 Type 2 attested, certified under the EU-U.S., UK, and Swiss-U.S. Data Privacy Framework, and WCAG 2.1 AAA accessible. See the Trust Center for the SOC 2 attestation report, or the Data Privacy Framework registry to verify the DPF certification directly, rather than take these as claims on this page.
Talk to us about a GDPR review, or see how MTCaptcha handles privacy in practice.