FlowConsent
DiensteSo funktioniert’sPreiseBlogDokumentation
DiensteSo funktioniert’sPreiseBlogDokumentationAnmeldenFlowConsent testen
AnmeldenFlowConsent testen
FlowConsent

DSGVO-konforme Einwilligung, in der EU gehostet, in unter zehn Minuten live – ohne Cookie-Wall.

EU-HOSTED·RGPD·SOC 2
Produkt
  • Dienste
  • So funktioniert’s
  • Preise
  • Erweiterung
Unternehmen
  • Blog
  • Dokumentation
  • Lösungen
  • FlowConsent App
Rechtliches
  • Datenschutzerklärung
  • Nutzungsbedingungen
  • Rechtlicher Hinweis
  • Cookies
© 2026 FlowConsent von BeBranded. Alle Rechte vorbehalten.
EnglishFrancaisEspanol
Alle Systeme betriebsbereit

Nutzt Ihre Website Drittanbieter-Dienste? Werden Sie in wenigen Minuten DSGVO-konform.

FlowConsent testen
  1. Startseite
  2. Dienste
  3. CMS
  4. Sanity

Sanity

SonstigeWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Sonstige

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Sonstige
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Sonstige
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Sonstige

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Sonstige

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Sonstige
DSGVO-konform werden — FlowConsent kostenlos testen

mobileCta.note

Was macht Sanity?

Sanity ist ein norwegisches Headless CMS, das um einen Echtzeit Content Lake aufgebaut ist. Redakteure arbeiten in Sanity Studio und der Inhalt wird über REST und GROQ APIs per HTTPS ausgeliefert. Die öffentliche Auslieferungs API setzt keine Cookies bei Besuchern und ist DSGVO konform, wenn die EU Dataset Region gewählt wird.

Was Sanity ist und wie es Inhalte ausliefert

Sanity ist eine Headless Content Plattform, die 2015 in Oslo, Norwegen, von Sanity.io AS gegründet wurde. Sie basiert auf einem Echtzeit Content Lake. Redakteure erstellen strukturierte Inhalte in Sanity Studio, einer React Editor Oberfläche, die typischerweise vom Kunden oder auf sanity.studio gehostet wird. Der veröffentlichte Inhalt wird vom Frontend per REST oder der GROQ Abfragesprache abgefragt und über das Sanity CDN ausgeliefert. Wie andere moderne Headless Plattformen ist die öffentliche Auslieferung zustandslos und cookielos.

Cookies und Identifikatoren bei Besuchern

Auf der öffentlichen Website setzt Sanity keine Cookies. Die Antworten der Auslieferungs API enthalten nur JSON und Standard Cache Header. Cookies erscheinen nur in drei redakteursbezogenen Kontexten. Sanity Studio nutzt ein Session Cookie zur Authentifizierung der Redakteure. Das sanity.io Kontoportal setzt ein Authentifizierungscookie für das Dashboard. Sanity Insights kann, wenn im Studio für Projektinhaber aktiviert, Plausible Analytics für Nutzungsstatistiken einsetzen, beschränkt auf die Studio Domain.

DSGVO und ePrivacy Implikationen

Da die öffentliche Sanity API keine Identifikatoren auf dem Endgerät des Besuchers ablegt, ist nach Artikel 5(3) der ePrivacy Richtlinie keine vorherige Einwilligung erforderlich. Artikel 6(1)(f) DSGVO (berechtigtes Interesse) deckt die begrenzten Anfrage Metadaten an der CDN Edge. Sanity.io AS agiert als Auftragsverarbeiter nach Artikel 28 DSGVO für die Speicherung der Kundeninhalte. Die AV Vereinbarung ist im Sanity Dashboard verfügbar, und die in Oslo ansässige Gesellschaft bietet zusätzliche Sicherheit hinsichtlich der DSGVO Durchsetzung.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Datentransfers und Schrems II

Sanity bietet eine EU Dataset Region (Frankfurt) und eine US Region (Iowa). Für europäische Projekte legen Sie das Dataset in der EU Region an. Die Region des Datasets kann nach der Erstellung nur über Export und Import geändert werden. Das sanity.io Login Portal und einige Support Werkzeuge können Anfragen über die USA leiten. Plausible Analytics, das von Sanity Insights verwendet wird, wird aus der EU (Deutschland) betrieben, was US Transfers für diese Telemetrie vermeidet.

Praktische Compliance Schritte

Erstellen Sie das Produktions Dataset in der EU Region. Unterzeichnen Sie die Sanity AV Vereinbarung. Dokumentieren Sie den Auftragsverarbeiter im VVT mit Datasetname, Region, Aufbewahrung und Asset CDN. Hosten Sie Sanity Studio auf Ihrer eigenen Domain hinter Authentifizierung (SSO über Google, GitHub, SAML). Beschränken Sie API Tokens nach Dataset und Berechtigungsbereich. Verwenden Sie für die öffentliche Website einen Read Only Client auf der veröffentlichten Ansicht statt Admin Tokens. Wenn Sie Drittanbieter Skripte in Ihr Frontend einbinden, steuern Sie diese über eine Consent Management Plattform, die Sanity Auslieferung selbst bleibt außerhalb dieses Scopes.

GDPR consent category

Sonstige

Websites using Sanity must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(f) GDPR (legitimate interest) for content delivery and abuse prevention. Strictly necessary cookies are used in Sanity Studio for editor authentication. No consent required for the public API.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, Norwegian Personal Data Act, DSGVO, RGPD, LSSI, Schrems II only when the US dataset region or US asset CDN endpoints are selected

DPIA considerations

Eine DSFA ist für die öffentliche Auslieferungs API in den meisten Fällen nicht erforderlich, da keine personenbezogenen Besucherdaten über Standard Anfrageprotokolle hinaus verarbeitet werden. Eine DSFA ist sinnvoll, wenn Sanity mit Sanity Insights, Personalisierungsfunktionen, nutzergeneriertem Inhalt kombiniert wird oder wenn besondere Datenkategorien im Content Lake gespeichert werden. Dokumentieren Sie die Auswahl der EU Region, die mit Sanity.io AS unterzeichnete AV Vereinbarung und die Zugriffskontrollen für Sanity Studio.

Sample consent text

Diese Website verwendet Sanity zur Auslieferung redaktioneller Inhalte. Die Sanity API setzt keine Cookies und verfolgt Besucher nicht. Es ist keine Einwilligung erforderlich. Authentifizierungscookies gelten nur für Redakteure, die in Sanity Studio angemeldet sind.

Technical details

Tracking methodHeadless CMS with a real time content lake exposed via REST and GROQ APIs over HTTPS, plus the Studio (editor UI) that authenticates editors with an OAuth2 session cookie. The public API does not set cookies on website visitors. Optional Sanity Vision and Sanity Insights are admin tools and do not run on the public website.
Server locationSanity.io AS (Oslo, Norway). The content lake runs on Google Cloud Platform with regions in the EU (eu central 1 Frankfurt) and the US (us central 1 Iowa). Asset CDN by Google Cloud CDN with global PoPs. Sanity Studio is typically hosted by the customer or on sanity.studio.
Cookieless tracking availableYes

Third-party domains contacted

sanity.ioapi.sanity.ioapicdn.sanity.iocdn.sanity.iosanity.studiosanity.work

Cookies placed

NameTypeDurationPurpose
sanitySessionfirst-party (Sanity Studio only)SessionSession cookie used inside Sanity Studio to authenticate a logged in editor. Strictly necessary, never set on the public website.
sanity-management-tokenfirst-party (account portal only)Up to 30 daysAuthentication token for the sanity.io account portal. Strictly necessary for the customer dashboard, not present on public websites.
sb_anonfirst-party (Studio analytics)30 daysAnonymous identifier optionally set by Plausible Analytics inside Sanity Insights when the project owner enables Studio usage tracking. Scoped to the Studio domain.

Dieser Dienst erhebt möglicherweise Nutzerdaten. Stellen Sie die DSGVO-Konformität mit FlowConsent sicher.

Kostenlos startenWebsite scannen

Häufig gestellte Fragen

Setzt Sanity Cookies bei Website Besuchern?

Nein. Die öffentlichen Sanity REST und GROQ APIs liefern JSON ohne Cookies. Cookies erscheinen nur in Sanity Studio (Redakteurssession), im sanity.io Kontoportal und optional in Plausible Analytics innerhalb von Sanity Insights, sämtlich redakteursseitig und für Besucher nicht sichtbar.

Ist für Sanity eine Einwilligung nach DSGVO und ePrivacy erforderlich?

Für die öffentliche Sanity Auslieferung ist keine Einwilligung erforderlich, da keine Identifikatoren auf dem Endgerät des Besuchers gespeichert werden. Eine Einwilligung wird nur relevant, wenn Ihr Frontend Drittanbieter Tracker einbindet, deren Inhalt von Sanity stammt.

Welche Rechtsgrundlage gilt für die Verarbeitung mit Sanity?

Artikel 6(1)(f) DSGVO (berechtigtes Interesse) deckt die Anfrage Metadaten für Auslieferung und Sicherheit. Der Kunde ist Verantwortlicher für die in Sanity gespeicherten Inhalte. Sanity.io AS ist Auftragsverarbeiter nach Artikel 28 DSGVO, die AV Vereinbarung ist im Dashboard verfügbar.

Überträgt Sanity Daten in die USA?

Nicht wenn die EU Dataset Region gewählt ist, der Content Lake bleibt in Frankfurt und das Asset CDN liefert aus Google Cloud EU Regionen aus. Die US Dataset Region (Iowa) ist optional. Das sanity.io Login Portal kann den Editor Flow über US Infrastruktur leiten.

Ist eine DSFA für Sanity erforderlich?

Eine DSFA ist für eine öffentliche redaktionelle Installation in der Regel nicht erforderlich. Sie ist sinnvoll, wenn Sanity sensible Inhalte speichert, wenn Sanity Insights aktiviert ist, wenn Personalisierung oder A/B Tests integriert sind oder wenn die US Dataset Region genutzt wird.

Wie binde ich Sanity DSGVO konform ein?

Dataset in der EU Region anlegen, DPA unterzeichnen, Sanity Studio auf eigener Domain mit SSO hosten, API Tokens nach Berechtigungsbereich einschränken, den Auftragsverarbeiter im VVT dokumentieren, für die öffentliche Website einen Read Only Client verwenden und alle Drittanbieter Skripte im Frontend über eine Consent Management Plattform steuern.

Welche Alternativen zu Sanity gibt es?

Weitere in Europa genutzte Headless CMS sind Storyblok (Österreich), Strapi (Frankreich), Contentful (Deutschland), Hygraph (Deutschland), Directus (Deutschland, Open Source), Payload CMS (Open Source) und Wagtail (Python, Open Source).

Wie aktualisiere ich die Cookie Richtlinie für Sanity?

Für die öffentliche Website ist keine Sanity spezifische Cookie Erklärung nötig, wenn keine Cookies gesetzt werden. Listen Sie Sanity als Auftragsverarbeiter für Inhalte in Ihrer Datenschutzerklärung mit Region des Datasets, Zweck, Aufbewahrung und Verweis auf die AV Vereinbarung. Editorbezogene Cookies in Sanity Studio müssen nicht im öffentlichen Cookie Banner erscheinen.