Why is Google Telling Website Owners to Change CAPTCHA Notices?
Google’s reCAPTCHA just changed its legal role. Is now a good time to talk about it?
I just received this and was tempted to file it away without another thought. Then I remembered that reCAPTCHA is too pervasive to not play a role in the vast data collection activities of its parent company, Alphabet.
Effectively, Google has started notifying site operators that, beginning April 2, 2026, reCAPTCHA is switching from Google acting as a “data controller” to acting as a “data processor”, which sounds like GDPR speak for a lot of the data collection that takes place behind the scenes when users complete those pesky tests to prove they’re human. Google says the features and functionality won’t change, only the legal roles and terms. That’s great, because those are the ones we’re concerned about.
To me, it sounds like Google just moved the privacy “blast radius” of reCAPTCHA onto website administrators and businesses. What does that mean? Quite likely, that ignorance of their data collection practices is not an excuse.
If you deploy reCAPTCHA, it becomes much harder to pretend the privacy risk belongs to “Google’s thing.”
It’s now your thing. On your site. Triggered by your choice. Which means: your accountability, your disclosures, your vendor governance, your risk.
And even if you “don’t use CAPTCHA,” you probably do, because half the anti-bot industry is CAPTCHA behind the scenes.
Why this matters for businesses
Canadian small businesses often operate with the emotional posture of a suburban raccoon: “Nothing bad will happen; I am fast and resourceful.” Meanwhile:
- Bad bots were ~37% of all internet traffic in 2024 (with roughly half being human traffic).
AI scraping is accelerating: one report found ~1 in 50 website visits in Q4 2025 came from AI scrapers, up from ~1 in 200 earlier in 2025. It may not seem like a lot, but that’s a four-fold increase in only a year.
In Canada, the average cost of a data breach hit CA$6.98M (2025), according to IBM/Ponemon.
And Canadian SMEs are not “too small to bother”: BDC has cited that 73% of small businesses experienced a cybersecurity incident (as referenced in an Insurance Bureau of Canada release).
So yes: you need bot defenses, which is really what CAPTCHA is designed to do. But you also need to understand what you’ve installed, because bot defenses can be surveillance infrastructure with better branding.
The five key impacts of Google’s notice
1) You become the obvious accountable party
Google is framing itself as a processor processing reCAPTCHA data on your behalf under its cloud-style processing terms.
Under PIPEDA, Canada’s federal privacy law, “accountability” is not vibes. The organization is responsible for personal information under its control and is expected to have governance and third-party management practices. That is to say, your organization.
2) Your site text must change
Google indicates end-user reCAPTCHA use will no longer be presented as subject to Google’s Privacy Policy and Terms of Use, and instructs operators to remove those references. That familiar footer text is becoming a compliance fossil, because they ain’t taking responsibility for you any longer.
3) Nothing changes… aside from who’s responsible
Google says functionality won’t be impacted. But whatever is impacted is on you.
Meaning, whatever reCAPTCHA was already doing behind the scenes is still in play. What changes is the legal framing and your burden to explain and justify it.
4) You will need a better answer to “what does this collect?”
Modern CAPTCHA and bot scoring tools can collect more than the average privacy policy admits: network identifiers, device/browser attributes, behavioral signals, and sometimes identifiers that increase linkability.
Researchers have argued reCAPTCHA v2 effectively operates as broad monitoring with limited security value: according to Google’s Gemini AI: “scientists from UC Irvine have argued that Google’s reCAPTCHA v2 primarily functions as a wide-scale user tracking and data harvesting mechanism, offering diminishing returns on security against modern, AI-driven bots. The research concludes that reCAPTCHA v2 acts as a “tracking cookie farm” masquerading as a security service.”
The 2023 study goes on to say that reCAPTCHA v2 provides “no realistic or measurable security”. In fact it lists:
1. Limited Security Value
Researchers found that reCAPTCHA v2 is no longer an effective barrier against advanced automation:
Easily Bypassed: Studies showed that image-based challenges can be defeated by AI 70% of the time, and the “I’m not a robot” checkbox can be bypassed 100% of the time using advanced bots.
Outdated Technology: The image recognition challenges used in v2 were solvable by computers years before they were implemented, making them ineffective against modern AI.
Human Labor Exploitation: Rather than stopping bots, researchers argue reCAPTCHA v2 uses human labor to train AI models (e.g., for autonomous vehicles) while providing minimal security.
2. Broad User Monitoring and Data Collection
Researchers found that reCAPTCHA v2 extensively monitors users, even before they click the checkbox:
Extensive Data Harvesting: The tool collects cookies, browsing history, and browser environment data, including canvas rendering, screen resolution, mouse movements, and user-agent data.
Cross-Site Tracking: The system uses third-party cookies for behavioral detection, which can be used to track users across different websites.
“Black Box” Operation: Because the method by which users are scored is opaque, it is considered highly privacy-invasive.
3. Societal and Economic Cost
Time Waste: A 2025 report indicated that reCAPTCHA v2 has cost society an estimated 819 million hours of human time, valued at over $6 billion in lost wages.
Environmental Impact: The calculations required for these challenges are estimated to produce 7.5 million kWh of energy consumption, resulting in 7.5 million lbs of CO₂.
5) We know that regulators hate invisible tracking
I can’t prove this change is caused by enforcement pressure , but it sure does rhyme with it.
For instance, France’s CNIL has repeatedly fined Google over consent/cookie practices, including a €325M fine announced September 2025 (and earlier cookie-related penalties in prior years).
If you’re thinking: “That’s Europe; we’re Canada,” remember: Canadian regulators may not copy/paste GDPR, but customers, procurement teams, insurers, and plaintiffs’ lawyers absolutely mimic those same expectations.
So What DO CAPTCHA tools actually do behind the scenes?
Most people still picture CAPTCHA as “select all the traffic lights.” That’s the theater. The real show is risk scoring.
Many tools try to answer: “Is this request likely automated?” by collecting signals such as:
- Network identifiers: IP address, rough location inference, ASN, reputation signals
- Device and browser attributes: user agent, OS, language, screen/rendering characteristics
- Behavioral signals: mouse/touch patterns, timing, interaction cadence, focus changes
- Environmental signals: feature availability, script execution behavior, headless hints
- Identifiers & linkability: cookies/tokens that make devices easier to recognize over time (implementation-dependent)
This is why “invisible” CAPTCHAs are a privacy flashpoint: the user may never see a puzzle: just the quiet sensation of being somehow judged.
Why is the consensus that Google’s reCAPTCHA always sucks?
That’s easy: it’s completely opaque and it’s infinitely connected. For instance, do you know any site owners that can tell you precisely what signals are used, where they’re processed, what retention policies are in effect, and what secondary uses Google/Alphabet makes of the data?
No? Me neither.
And what about the fact that Google just needs to know where you are and what you’re doing? Think about the times when you try to use Google through a VPN. It often doesn’t go well, unless it can sniff you by the cookies on your system, in which case that VPN’s value is vastly reduced. Think about that next time you use Google through a VPN. You’ve just told them what exit node you use and established a pattern of use. Not that you have anything to hide, am I right?
Anyway, given that Google’s reCAPTCHA just seems to be accumulating criticism, competitors have smelled the blood in the water. Cloudflare Turnstile’s positioning, for example, explicitly leans into “less creepy” framing and publishes privacy documentation about bot detection signals/cookies. (Whether that’s true enough depends on your threat model and your due diligence.)
So What Do You Need To Do If You Already Use It?
1) Remove Google Privacy Policy and Terms references tied to reCAPTCHA
If your site displays the standard reCAPTCHA footer language pointing to Google’s Privacy Policy and Terms, plan to replace it with your own notice and a link to your privacy policy.
You do have your own notices and policies, don’t you?
2) Update your privacy policy so it actually describes the processing
If you think it’s sufficient to disclose something like “we use CAPTCHA to prevent spam” then you may as well write “We installed a black box that watches you for reasons.”
You’ll need to disclose categories of info collected and give actual reasons why you’re collecting that information, even if you don’t benefit from that collection. (And if neither you nor the visitor benefit, then why are you collecting it? Hmm?)
3) Treat reCAPTCHA like a service provider relationship
If Google is your processor, keep a basic vendor record: purpose, data categories, safeguards, cross-border notes. Google points reCAPTCHA processing to its cloud processing framework.
“But We don’t use CAPTCHA.”
Cool story. Inventory your scripts anyway.
Many sites think they’re avoiding CAPTCHAs while still deploying tools that do similar things:
- WAFs and bot managers running JavaScript challenges (you know those puzzle piece sliders a-la-Temu?)
- Invisible fraud scripts on checkout/login
- Third-party form plugins and marketing widgets with anti-abuse modules.
So what do you need to do regardless?
- Inventory third-party scripts on login/signup/checkout/contact pages.
- Identify which ones score behavior/device/network signals for “trust”. (That means you actually need to understand what you’re looking at)
- Disclose them the same way you’d disclose CAPTCHA, because functionally, they’re the same class of risk, so be sure to add the verbiage to your Privacy Policy.
Quick Comparison of the Key Players
- Google reCAPTCHA / reCAPTCHA Enterprise: widely deployed; criticism focuses on opacity/tracking concerns
- Cloudflare Turnstile: positions itself as a CAPTCHA alternative; publishes privacy documentation and markets away from ad-cookie style linkage. Your mileage may vary.
- hCaptcha & others: often marketed as more ethical/private, but still requires due diligence on collection, processing location, retention, and secondary uses, if only because you’re now both responsible and accountable for it. After all, that’s why you’ve read this far, right?
Cookie-Cutter Copypasta (for inspiration)
1) Privacy policy verbiage in plain English
Consider adding a heading such as: Bot protection and abuse prevention
We use bot and abuse prevention controls to protect our website and services from spam, fraud, and automated attacks. Depending on the page, these controls may collect and analyze network information (such as IP address), device and browser attributes, and interaction signals to determine whether activity appears legitimate. Where we use third party providers for these controls, they process this information on our behalf to provide the security service. Some processing may occur outside Canada.
2) Brief just-in-time notice near forms
Spam protection notice
This form is protected by automated abuse prevention. The service may collect device, browser, network, and interaction signals for security purposes. See our Privacy Policy for details.
3) Keep your own internal notes (because explainability is a good thing)
Provider: [Google reCAPTCHA or just about any other]
Purpose: prevent spam, fraud, and automated abuse
Data categories: network identifiers, device and browser attributes, interaction signals, risk assessment output
Role: service provider processing on our behalf, subject to provider terms and data processing addendum where applicable
Notes: cross border processing possible; retention governed by provider documentation and our internal log retention settings
Note to the reader
Google’s shift from controller to processor doesn’t make reCAPTCHA “private.” It makes the accountability picture clearer. And it clearly pins that accountability on you.
In essence, if you deploy a tool that silently evaluates your visitors, you should be able to answer:
- What signals or data (or hey, metadata) are collected
- Who receives them
- Why they’re needed
- Where they’re processed
- How long anything is kept
- How you can impact that retention period
- How you explain it to a real human who asks, because sooner or later, one will.
For a complete inventory of your CAPTCHA-like scripts and widgets, or more help managing your company’s privacy program, poke around on www.PrivacyManagement.ca and a certified privacy professional from MPC - a real human - will help you out.
