DataDome

DataDome

Bot detection and protection platform that operates as a client-side signal collector. The DataDome script runs behavioral checks in the browser — mouse movement patterns, keystroke timing, JS environment fingerprinting — and submits signals to DataDome's servers to classify traffic as human or automated in real time.

Overview

DataDome is a bot detection and protection platform that runs client-side behavioral analysis to classify traffic as human or automated in real time. It protects sites against scraping, credential stuffing, and other automated attacks.

What This Script Does

The DataDome script runs behavioral checks in the browser — analyzing mouse movement patterns, keystroke timing, scroll behavior, and JavaScript environment characteristics. These signals are submitted to DataDome's servers, which classify the traffic as human or bot in real time. The script sets a cookie to persist the classification result so verified humans are not re-challenged on subsequent requests. It acts as a security layer that may trigger CAPTCHAs or block requests identified as automated.

Consent & Compliance

  • Consent Category: Essential
  • Applicable Regulations: GDPR, ePrivacy Directive
  • Opt-In Required: No — security and fraud prevention are strictly necessary

DataDome provides essential security functionality. The behavioral signals it collects are used exclusively for bot detection, not for marketing, analytics, or user profiling. Under GDPR and ePrivacy, security measures are classified as strictly necessary.

Should You Block This Without Consent?

No. DataDome is essential security infrastructure for bot detection and fraud prevention. Blocking it would leave your site vulnerable to automated attacks. The data it collects is used exclusively for security classification, not user tracking. It is strictly necessary and must load without consent.

Visit website

Consent Categories

Essential

Also Known As

DataDomebot detectionbot protection platformanti-scrapingcredential stuffing protectionfraud prevention script

Industries

Computer SecurityComputers Electronics and Technology

Tracked Domains (1)

datadome.coEssential

Frequently Asked Questions

Is consent required for DataDome on my website?

No. DataDome is a bot detection platform that collects behavioral signals — mouse patterns, keystroke timing, browser fingerprinting — to classify traffic as human or automated. This security function is essential to protect site integrity and is exempt from consent under GDPR and CCPA.

What does DataDome collect in the browser?

DataDome runs behavioral analysis in the browser, examining mouse movement patterns, keystroke timing, scroll behavior, and JavaScript environment characteristics. These signals are submitted to DataDome's servers to generate a bot risk score. No persistent advertising cookies are set.

How does ConsentStack handle DataDome bot detection scripts?

ConsentStack classifies DataDome as an essential vendor. Bot detection and security are strictly necessary to protect websites from automated abuse. ConsentStack allows DataDome scripts to load without requiring user consent and does not subject them to marketing or analytics consent gates.

Related Vendors

Firebase
Firebase
Firebase is Google's mobile and web application development platform offering authentication, real-time database, cloud functions, and analytics. Web SDK scripts initialize Firebase services and may track app events via Firebase Analytics, which is powered by Google Analytics 4. Widely used in single-page apps and PWAs for backend infrastructure and usage tracking.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Google Tag Manager
Google Tag Manager
Google Tag Manager is a tag management system that lets marketers deploy and update analytics and marketing scripts without code changes. The GTM container script loads synchronously in the page head and injects configured tags, triggers, and variables on behalf of other vendors. No data collection of its own — acts as a loader for other scripts.
Google Fonts
Google Fonts
Google Fonts is a free font hosting service that serves hundreds of typeface families via a global CDN. Stylesheets and font files load from fonts.googleapis.com and fonts.gstatic.com to deliver web fonts to visitors. No advertising or tracking functionality is included.
reCAPTCHA
reCAPTCHA
Google reCAPTCHA is a bot detection and spam prevention service protecting web forms, login pages, and checkout flows. Scripts analyze user behavior, mouse movements, and browser fingerprints to distinguish humans from bots. The invisible reCAPTCHA v3 scores interactions without requiring user challenges.
Sign in with Google
Sign in with Google
Sign in with Google is an OAuth-based authentication service that enables users to log into websites using their Google account credentials. Scripts load the Google Identity Services library, display sign-in buttons, and handle token exchange for secure authentication. Stores session tokens and authentication cookies to maintain login state across page visits.

Manage consent for DataDome

ConsentStack automatically detects and manages DataDome trackers so your site stays compliant with global privacy regulations.