Captcha and bot-detection services decide whether a visitor is a person or an automated script. They protect login forms, registrations, checkouts and contact forms against spam, credential stuffing and scraping. Methods range from visible puzzles to invisible checks based on behaviour, device signals and risk scoring.
Every protected page load can send behavioural and device data to the provider, which makes the service a processor of personal data on your site. Reading information from a visitor's device can fall under consent rules in the GDPR and ePrivacy framework, and the provider's own purposes, such as improving its models or building advertising profiles, can change that assessment. A captcha is also a single point of failure: if the provider is unavailable, blocked or changes its terms, your forms stop working. Alternatives for people who cannot solve puzzles deserve attention as well.
When choosing a European option, look at whether the vendor documents what is collected and for how long, whether the service works without cookies or third-party identifiers, whether proof-of-work or privacy-preserving checks are offered, whether it can be self-hosted, and whether accessible alternatives exist.