Best European Alternatives to reCAPTCHA
Looking for a European alternative to Google reCAPTCHA? reCAPTCHA sends user data to Google and has privacy implications under GDPR. European CAPTCHA solutions protect your site without compromising user privacy.
Privacy-friendly CAPTCHA services protect against bots while respecting user privacy and GDPR requirements.
How we rank these tools — 4-step process
-
1
European ownership, verified
The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.
-
2
Category fit and hands-on review
What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.
-
3
Compliance and pricing check
GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.
-
4
Position on this page
Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.
Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy
Why Choose a European Alternative to reCAPTCHA?
GDPR Protection
Your data stays in Europe, protected by the world's strongest privacy laws.
EU Data Centers
Data processed and stored exclusively within the European Union.
No US Surveillance
Free from CLOUD Act and other US data access laws.
Quality Alternatives
Comparable features with European quality and support.
Best European Alternatives to reCAPTCHA
Privacy-focused alternatives from European companies, evaluated for features, privacy, and GDPR compliance.
Friendly Captcha
Privacy-friendly CAPTCHA, GDPR compliant by design
mCaptcha
Open-source, proof-of-work based CAPTCHA
Key takeaways
- reCAPTCHA is lawful in Europe with consent, and unlawful without it — the problem is that consent has to be collected before the protection can load.
- reCAPTCHA sets a cookie called _GRECAPTCHA when it runs, which Google describes as necessary for its risk analysis — the classification that decides whether a banner is required.
- Austria's Federal Administrative Court ruled on 13 September 2024 that reCAPTCHA is not technically necessary, so legitimate interest cannot justify it.
- reCAPTCHA now lives inside Google Cloud Fraud Defense: free to 10,000 assessments a month, but Essentials requires a billing instrument and Premium charges above that.
- Only mCaptcha removes the third party entirely, which is why a government form is the case where it wins outright.
Why people leave reCAPTCHA
reCAPTCHA is on an enormous share of the web because it was free, it worked, and adding it took one script tag. None of those three is quite true any more, and the first one stopped being true in a way that catches people out.
The legal position is the part that matters most, and it is more specific than the internet suggests. reCAPTCHA is not banned in Europe.
What is at issue is whether it needs consent, and the mechanics point one way: Google’s own documentation says reCAPTCHA sets a cookie, _GRECAPTCHA, when it executes, in order to perform its risk analysis.
Google describes that cookie as necessary and answers its own question “Is reCAPTCHA GDPR Compliant?” with “Yes”. The Austrian Federal Administrative Court took the opposite view in September 2024, holding that reCAPTCHA is not technically necessary for a website to function, so legitimate interest does not cover it.
That produces an awkward result rather than an illegal one. A CAPTCHA that must wait for consent is protecting a form filled in by someone who has not consented to anything yet — and a bot certainly will not click accept. The compliant configuration is the one where the protection is not there when it is needed, which is why organisations look for a mechanism that never needed consent in the first place.
- Consent arrives too late to be useful The Austrian court reasoned that reCAPTCHA offers a security benefit but is not part of a website's basic functionality, so the processing cannot rest on the operator's legitimate interest and requires active, informed opt-in. Apply that honestly and the CAPTCHA loads only after the banner is accepted. Anyone who declines gets an unprotected form, and automated submissions do not interact with banners at all. The fix does not damage the paperwork; it damages the product.
- The vendor says one thing and a court said another Google's reCAPTCHA FAQ states that reCAPTCHA sets a cookie, _GRECAPTCHA, when executed, for the purpose of providing its risk analysis, and calls that cookie necessary. It also answers "Is reCAPTCHA GDPR Compliant?" with "Yes", resting on the commitments in the Cloud Data Processing Addendum. That is the supplier's reading of its own product, which is worth having in writing and is not the same thing as a regulator agreeing. The Austrian Federal Administrative Court reached the opposite conclusion on the necessity question in September 2024, and the gap between those two positions is the risk you are carrying, not a fine somebody has already paid.
- It stopped being a free widget reCAPTCHA now sits inside Google Cloud Fraud Defense with three tiers. Essentials is free up to 10,000 assessments per calendar month but requires a valid billing instrument on the account. Premium is free to the same 10,000, then $8 flat to 100,000 assessments a month, then $1 per 1,000 above that. Enterprise is a fixed monthly commitment at $1 per 1,000 with a twelve-month minimum, and the free allowance is counted per organisation across all accounts and sites rather than per site. The old developer documentation is marked deprecated and points at the Cloud pages.
- Your visitors do the work and someone else keeps it The image challenges are a labelling exercise as well as a test, and the output is useful to the company running them. That is a reasonable trade when the service is free and you chose it. It is a harder conversation when a citizen filling in a council form is asked to identify crossings on behalf of an advertising company before they can report a broken street light, which is the scenario that keeps appearing in public-sector procurement.
What you have to replace, not just match
Be precise about what reCAPTCHA is doing on your site, because the two tools here answer different halves and only one of them is a like-for-like swap.
On most sites it guards form submissions — registration, contact, password reset, checkout — against automated abuse in volume. That is what a proof-of-work challenge replaces well: the visitor's browser does a small computation that costs nothing once and a great deal ten thousand times, with nothing to click and nobody profiled.
What a proof-of-work challenge does not replace is the risk-scoring layer that reCAPTCHA Enterprise sells: account takeover detection, payment fraud signals, per-action scores fed into your own decisions. If you are using that, this page is not offering an equivalent and you should know it before you start rather than after.
The alternatives compared
| Position | Tool | Headquarters | Pricing | Jurisdiction |
|---|---|---|---|---|
| #1 | Friendly Captcha | Munich, Germany | Free tier / from €9 per month | EU (Germany) |
| #2 | mCaptcha | Self-hosted | Free and open source | Runs wherever you deploy it |
How each alternative compares to reCAPTCHA
- Which law reaches it. EU (Germany). reCAPTCHA is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
- Where the data sits. EU (Germany).
- Source code. Closed source, as reCAPTCHA is.
- Independently checked. GDPR, no cookies, no user tracking.
Best for: Sites that want reCAPTCHA's convenience without the consent problem it now carries
Friendly Captcha is the drop-in version of this decision. It slots into the same place in a form as reCAPTCHA, produces a token your server verifies the same way, and is supported by a company you can email — so switching is an afternoon rather than a project. Friendly Captcha GmbH operates from Munich under GDPR.
The mechanism is what removes the legal problem instead of managing it. Nobody is profiled and nobody identifies a traffic light. The browser quietly solves a small computational puzzle instead: negligible for one visitor, ruinous at scale. No cookies, no user tracking and nothing to click, which means there is no personal data processing for a banner to collect consent for — and no visitor left unprotected because they declined one.
Two limits deserve stating rather than burying. It is not open source, so the mechanism is verified through documentation rather than by reading it, and the free tier is for non-commercial sites with low traffic: one domain and 1,000 requests a month, with Starter at €9 a month on the same allowance.
If your requirement is contractual EU-only processing on dedicated infrastructure, that begins at the Advanced plan rather than at the entry level, and a self-hosted endpoint is an Enterprise arrangement.
What Friendly Captcha does better than reCAPTCHA
- No cookies and no user tracking, so the consent gate reCAPTCHA now needs simply does not arise
- Invisible to the visitor, where reCAPTCHA image challenges cost time on every submission
- Markedly more accessible than image challenges for screen reader and low-vision users
- German company under GDPR, rather than device data being sent to an advertising company
- A published price list rather than a Google Cloud billing account with a metered assessment counter behind it
Where Friendly Captcha is a step down from reCAPTCHA
- Not open source, so the mechanism is taken on documentation where mCaptcha can be read
- The free tier covers non-commercial low-traffic sites only, where reCAPTCHA Essentials allows 10,000 assessments a month
- Contractual EU-only dedicated infrastructure starts at the Advanced plan rather than the entry tiers
- Nothing resembling reCAPTCHA Enterprise risk scoring for account takeover or payment fraud
- A phone spends a little battery solving the puzzle, where an image challenge spends none
Standout against reCAPTCHA. It is the only option here that removes the consent question and still leaves somebody to call when a form stops accepting submissions.
- Which law reaches it. Runs wherever you deploy it. reCAPTCHA is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
- Where the data sits. Your own server.
- Source code. Open source, where reCAPTCHA is not: you can read what it does rather than take the description on trust.
- Independently checked. GDPR — you remain sole controller.
Best for: Public bodies and universities where the objection is the third party itself
mCaptcha answers the objection underneath the whole argument. The problem with reCAPTCHA is that a visitor's browser contacts Google and a cookie is set before anyone has agreed to anything. Serve the challenge from your own servers and nothing reaches anyone, which leaves you as the only controller in the picture. There is no processor to assess, no transfer to disclose and no banner entry to write, because there is no other party.
For a government form, that is a categorically stronger position than picking a more considerate supplier. The complaint about a citizen having to interact with an advertising company before reporting a pothole is not resolved by replacing the advertising company with a German one — it is resolved by there being nobody. mCaptcha is the only option on this page that reaches that.
Because the source is open, you can read how the puzzle is actually computed instead of taking a vendor's word for it — something no commercial option here allows. The costs are the obvious ones and they are real: you deploy it, run it, monitor it and patch it, the project is small next to commercial vendors, there is no support contract to buy, and as with any proof-of-work it makes abuse expensive rather than impossible.
What mCaptcha does better than reCAPTCHA
- No third party at all, so no cookie is set by anyone else and no transfer needs a legal basis
- You stay the sole controller, with no processor agreement and no transfer to document
- Open source, so the challenge mechanism is inspectable rather than described
- Free at any traffic volume, where reCAPTCHA meters assessments above 10,000 a month
- Accessible by design, with no image challenge for a screen reader to fail on
Where mCaptcha is a step down from reCAPTCHA
- You deploy, host, monitor and update it, where reCAPTCHA is a script tag and nothing else
- No commercial support offering and a small project behind it
- No dashboard, analytics or risk scoring of the kind reCAPTCHA Enterprise sells
- Makes abuse expensive rather than impossible, which is true of every proof-of-work scheme
Standout against reCAPTCHA. It is the only choice here that a public body can defend without qualification, because the answer to "who else receives this" is nobody.
What actually breaks when you switch
Finding every integration takes longer than replacing any of them. Contact forms, registration, password reset, comments, newsletter signups and whatever a plugin wired up years ago each carry their own key and their own verification call. Grep the codebase for the site key before you plan the work, because the count is almost always higher than the one in your head.
Expect your spam numbers to move in both directions for a fortnight. A proof-of-work challenge stops a different population of abuse from an image challenge, so some categories drop to nothing and one or two rise. Keep the old protection running in parallel on a low-value form first, measure for a week, and tune before you touch checkout or password reset.
And write the privacy documentation down as you go. The value of the switch is being able to show what you now do and why no consent is required, which is worth nothing if the cookie policy still describes a Google cookie you no longer set. A migration that fixes the mechanism and leaves the old documentation in place is only half finished, and the half left undone is the half an auditor reads.
Is reCAPTCHA actually illegal in the EU?
No, and it is worth correcting because the claim circulates widely and it is wrong. No European regulator has prohibited reCAPTCHA. What has been decided is narrower and more consequential: that deploying it requires the visitor's consent, because the processing is not strictly necessary to deliver the service the visitor asked for.
The clearest ruling is Austrian: in September 2024 the Federal Administrative Court held that a security benefit does not make a component part of a website's basic functionality, so the processing cannot rest on legitimate interest and consent should have been sought. Google disagrees in its own documentation, which describes the _GRECAPTCHA cookie as necessary and states that reCAPTCHA is GDPR compliant. Both positions are on the record; only one of them is the one your supervisory authority will apply.
So you can keep reCAPTCHA lawfully. You have to put it behind a consent gate, disclose the transfer to Google, and accept that visitors who decline see an unprotected form. Whether that is a compliance solution or a security hole depends entirely on what the form does.
Does proof-of-work actually stop bots?
Neither tool claims to stop abuse outright; both say plainly that what they do is make it expensive. The browser performs a computation that is trivial once and expensive at scale, so a single visitor notices nothing and someone submitting ten thousand forms an hour has to pay for real compute to do it.
That handles the case almost every site actually has: volume spam, credential stuffing at scale, scripted signups. It does not handle a determined attacker with a budget who specifically wants your site, and it does not handle human-operated abuse at all, because a human doing something once is exactly the traffic you are trying to admit.
The practical comparison with reCAPTCHA is closer than it sounds. Image challenges are also defeated by anyone willing to pay a solving service, so what you are choosing between is two ways of making abuse expensive — one of which needs a consent banner and one of which does not.
What does switching involve technically?
Less than the legal discussion that preceded it. Both tools follow the same shape as reCAPTCHA: a widget or script on the page produces a token, your server verifies that token against an endpoint before accepting the submission. The client change is a script tag and a div; the server change is a different verification URL and a different response field to check.
The work that actually takes time is finding every form. Contact pages, registration, password reset, comment boxes, newsletter signups, and whatever a plugin added three years ago all carry their own integration, and on a site of any age the list is longer than anybody expects.
With mCaptcha there is a deployment step on top: you are running the service, so it needs somewhere to live, a certificate, monitoring and updates. That is an afternoon for a team that already runs infrastructure and a genuine obstacle for one that does not.
Is a CAPTCHA the right tool at all?
For a lot of forms, no, and it is worth asking before migrating something you could delete. A honeypot field, a timing check, rate limiting by IP and requiring an email confirmation before anything is published together remove most low-effort spam with no challenge, no third party and no consent question.
A CAPTCHA earns its place where the cost of a successful automated submission is high — account creation, password reset, anything that sends an email on your behalf or costs money — and where rate limiting alone is not enough because the attacker is distributed.
Accessibility belongs in this decision too. Image challenges are genuinely hard for people using screen readers, and the invisible proof-of-work approach both tools here use is markedly better on that count. If you are replacing reCAPTCHA anyway, that is a real improvement rather than a consolation.
Which one to pick
If you run a commercial site and want this dealt with by Friday, Friendly Captcha is the answer: same integration shape, no consent gate, a German company under GDPR and a published price. Budget for a paid plan, because the free tier is for non-commercial sites and discovering that in production is an avoidable annoyance.
If you are a public body, a university or anyone whose complaint is that a visitor should not be talking to a third party at all, mCaptcha is the only option here that actually delivers that, and the fact that you can read the implementation makes it defensible in a way a vendor statement is not. It costs you an operations commitment, and that is the whole price.
If what you actually use is reCAPTCHA Enterprise risk scoring rather than a form challenge, neither of these replaces it, and this page will not pretend otherwise. Keep it, put it behind consent, disclose the transfer properly, and revisit when the fraud signals stop being the reason it is there.
Frequently Asked Questions
Friendly Captcha if you want a supported product with a vendor behind it and nothing to run. mCaptcha if the objection is that any third party is involved at all, which is the usual position for a public body or a university. Both use a background proof-of-work challenge rather than image puzzles, so neither needs the consent banner that reCAPTCHA now requires.
Google says yes and answers that question with that word in its own FAQ, on the basis of the commitments in its Cloud Data Processing Addendum.
The complication is that reCAPTCHA sets a cookie, _GRECAPTCHA, when it executes, and whether a cookie is strictly necessary is decided by what the visitor asked for rather than by what the supplier calls it. Austria's Federal Administrative Court held in September 2024 that reCAPTCHA is not technically necessary for a website to function, which puts it on the consented side of the line. Used lawfully means used visibly: disclosed, behind consent, with the transfer to Google documented.
Only up to a point, and the terms changed. reCAPTCHA now sits within Google Cloud Fraud Defense. Essentials is free up to 10,000 assessments per calendar month but requires a valid billing instrument on the account.
Premium covers the same first 10,000 free, then charges $8 flat up to 100,000 assessments a month and $1 per 1,000 beyond. Enterprise is a twelve-month commitment at $1 per 1,000. One footnote catches people out: Google states that the free 10,000 are per organisation, aggregated across every account and every site, so running ten small sites does not give you ten allowances.
Yes, and that is the compliant configuration. The consequence is that the protection only exists for visitors who accepted, so anyone declining submits your form with no challenge in front of it, and automated traffic never sees the banner at all. Whether that is acceptable depends on what the form does — a newsletter signup, probably; a password reset, probably not.
The visitor's browser solves a small computational puzzle in the background before the form submits. It costs a fraction of a second once and becomes expensive at thousands of submissions an hour. Nothing about the visitor is profiled, no cookie is set and no identifier is stored, so there is no personal data processing to consent to — which is a technical fact about the mechanism rather than a legal interpretation of it.
Friendly Captcha GmbH is a German company operating under GDPR, and that is the position most sites need. If your requirement is a contractual guarantee of EU-only processing on dedicated infrastructure, that is available from the Advanced plan upward rather than on the entry tiers, and an Enterprise agreement adds a self-hosted endpoint option. Worth confirming before you rely on it in a procurement document.
There is a free option for non-commercial sites with low traffic, covering one domain and up to 1,000 requests a month, and paid plans start at €9 a month for Starter with the same domain and request allowance. Higher tiers add domains, request volume and the dedicated infrastructure options. For a commercial site, budget for a paid plan from the start rather than expecting the free tier to apply.
Only if somebody already runs servers. It is free, open source and self-hosted, with no licence cost at any traffic volume, and the mechanism can be read rather than taken on trust. In exchange you deploy it, keep it running, monitor it and update it, and there is no commercial support to call. For a university or a public body with an operations team that is a fair trade; for a two-person agency it usually is not.
Substantially, and it is one of the clearest wins in this switch. Both tools run their challenge in the background with nothing to click, read or decipher, where reCAPTCHA's image challenges are difficult or impossible for people using screen readers and frustrating for anyone with low vision or a motor impairment. If accessibility is a legal duty for your organisation, this argument stands on its own.
Explore More European Alternatives
Discover privacy-focused European alternatives to other popular US tech services.