FlowConsent
DiensteSo funktioniert’sPreiseBlogDokumentation
DiensteSo funktioniert’sPreiseBlogDokumentationAnmeldenFlowConsent testen
AnmeldenFlowConsent testen
FlowConsent

DSGVO-konforme Einwilligung, in der EU gehostet, in unter zehn Minuten live – ohne Cookie-Wall.

EU-HOSTED·RGPD·SOC 2
Produkt
  • Dienste
  • So funktioniert’s
  • Preise
  • Erweiterung
Unternehmen
  • Blog
  • Dokumentation
  • Lösungen
  • FlowConsent App
Rechtliches
  • Datenschutzerklärung
  • Nutzungsbedingungen
  • Rechtlicher Hinweis
  • Cookies
© 2026 FlowConsent von BeBranded. Alle Rechte vorbehalten.
EnglishFrancaisEspanol
Alle Systeme betriebsbereit

Nutzt Ihre Website Drittanbieter-Dienste? Werden Sie in wenigen Minuten DSGVO-konform.

FlowConsent testen
  1. Startseite
  2. Dienste
  3. CMS
  4. Sitecore

Sitecore

SonstigeWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Sonstige

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Sonstige
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Sonstige
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Sonstige

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Sonstige

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Sonstige
DSGVO-konform werden — FlowConsent kostenlos testen

mobileCta.note

Was macht Sitecore?

Sitecore ist eine Enterprise Digital Experience Plattform mit Sitz in Kanada. Klassisches Sitecore XP kann über xDB Besucher Analyse Cookies auf der öffentlichen Website setzen, während Sitecore XM Cloud headless ist und nur über xConnect oder Sitecore CDP/Personalize Cookies setzt, wenn diese Add ons aktiviert sind. Bei aktiven Tracking Funktionen ist ein Consent Management erforderlich.

Was Sitecore ist und wie es Inhalte ausliefert

Sitecore ist eine Enterprise Digital Experience Plattform der Sitecore Holdings (Toronto, Kanada). Die Produktfamilie umfasst Sitecore XP (klassisches CMS mit der xDB Analyse Datenbank), Sitecore XM und XM Cloud (modernes composable Headless), Sitecore CDP, Sitecore Personalize, Sitecore Content Hub und Sitecore Send. Seiten werden serverseitig in .NET gerendert oder im headless XM Cloud Modell über die Experience Edge GraphQL API abgerufen. Sitecore richtet sich an große Marken mit hohem Personalisierungsbedarf.

Cookies und Identifikatoren bei Besuchern

Sitecore XP mit aktiviertem xDB setzt SC_ANALYTICS_GLOBAL_COOKIE (persistenter Besucher Identifikator, standardmäßig 10 Jahre) und SC_ANALYTICS_SESSION_COOKIE (Session) auf der öffentlichen Website. Das Produkt Sitecore CDP setzt einen _sc_browser_id oder ähnlichen Identifikator, um Besucherverhalten zusammenzuführen. Sitecore Personalize nutzt _bx_uuid für Experimentation. Die Experience Edge Auslieferung in XM Cloud selbst ist cookielos, wenn keine Analytik oder Personalisierung darauf liegt. Die ASP.NET Backoffice Authentifizierungs Cookies sind strikt notwendig für Redakteure.

DSGVO und ePrivacy Implikationen

Die Funktionen xDB, CDP und Personalize erzeugen persistente Besucher Identifikatoren, die an Verhaltensprofile geknüpft sind, deshalb verlangt Artikel 5(3) der ePrivacy Richtlinie nach EDSA Leitlinien eine vorherige Opt in Einwilligung. Artikel 6(1)(a) DSGVO (Einwilligung) ist die Rechtsgrundlage. Der Kunde ist Verantwortlicher und Sitecore ist Auftragsverarbeiter nach Artikel 28 DSGVO. Eine unterzeichnete AV Vereinbarung ist Teil des Sitecore Master Subscription Agreement. Die Aufbewahrungsfrist in xDB und das Recht auf Löschung müssen konfigurierbar sein, Sitecore stellt für beide APIs bereit.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Datentransfers und Schrems II

Sitecore Cloud Dienste laufen auf Microsoft Azure und EU Kunden sollten in der Bestellung ausdrücklich ein Westeuropa oder Nordeuropa Deployment anfordern. Sitecore CDP und Personalize nutzen standardmäßig US Infrastruktur, sofern kein EU Pinning verhandelt wird. Die Sitecore Corporate Identity, Support Tools und Produktanalyse umfassen US und kanadische Anbieter, abgedeckt durch Standardvertragsklauseln und das EU US Data Privacy Framework. Dokumentieren Sie diese Transfers im VVT und in Ihrer Datenschutzerklärung.

Praktische Compliance Schritte

Verbinden Sie Sitecore mit Ihrer Consent Management Plattform über Google Consent Mode v2 oder IAB TCF Signale. Blockieren Sie xDB, CDP und Personalize Tags bis zur Einwilligung. Konfigurieren Sie die xDB Aufbewahrung auf das für den Analyse Anwendungsfall nötige Minimum. Fordern Sie die EU Region für Sitecore CDP und Personalize an. Unterzeichnen Sie die AV Vereinbarung. Dokumentieren Sie ein Verfahren zur Erfüllung von Auskunfts und Löschungsanfragen über die xConnect und CDP APIs. Beschränken Sie den Backoffice Zugriff auf ein Unternehmens VPN mit SSO und 2FA.

GDPR consent category

Sonstige

Websites using Sitecore must obtain user consent under GDPR regulations.

Legal basisConsent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy is required for xDB analytics cookies, Sitecore CDP visitor identifiers and Personalize experimentation tags because they go beyond strictly necessary processing. Strictly necessary cookies (ASP.NET session, antiforgery) for the editor backoffice can rely on legitimate interest.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, DSGVO, RGPD, LSSI, Canadian PIPEDA, Schrems II, EU US Data Privacy Framework, IAB TCF when integrated with consent management vendors

DPIA considerations

Eine DSFA wird in der Regel für Sitecore Installationen empfohlen, die xDB, Sitecore CDP, Sitecore Personalize oder Sitecore Send einsetzen, da diese Besucherprofilbildung ermöglichen. Dokumentieren Sie die Rechtsgrundlage jeder Funktion, die EU Region Auswahl, die Aufbewahrungsfristen in xDB oder CDP und die Integration mit einer Consent Management Plattform, die IAB TCF oder Google Consent Mode Signale liefert.

Sample consent text

Diese Website verwendet Sitecore als Digital Experience Plattform. Sitecore speichert Analyse und Personalisierungs Cookies (SC_ANALYTICS_GLOBAL_COOKIE, _sc_session), um Sie wiederzuerkennen und Inhalte anzupassen. Sie können diese Cookies über das Einwilligungs Banner annehmen oder ablehnen. Bei Ablehnung bleiben nur strikt notwendige Cookies aktiv.

Technical details

Tracking methodEnterprise digital experience platform combining content management, personalization and analytics. Sitecore Experience Platform (XP) and Sitecore Experience Manager (XM) set cookies on the public site by default (SC_ANALYTICS_GLOBAL_COOKIE, SC_ANALYTICS_SESSION_COOKIE) when xDB analytics is enabled. The modern Sitecore XM Cloud is headless and only sets cookies through xConnect or Sitecore CDP/Personalize when explicitly activated.
Server locationSitecore Holdings (Toronto, Canada and San Francisco) operates Sitecore XM Cloud, Sitecore Content Hub, Sitecore Send, Sitecore CDP and Sitecore Personalize on Microsoft Azure. EU customers can request Azure West Europe (Netherlands) or North Europe (Ireland) deployments. On premise Sitecore is hosted by the customer on Windows Server with SQL Server, typically in EU data centers.
Cookieless tracking availableYes
Data transferred outside the EUSitecore Cloud services can be pinned to Azure West Europe or North Europe but the Sitecore corporate identity provider, support tooling and product analytics include US and Canada based infrastructure. Sitecore CDP and Personalize process visitor identifiers in the United States by default unless an EU region is explicitly negotiated. Standard Contractual Clauses are signed in the master agreement.

Third-party domains contacted

sitecore.comsitecorecloud.ioexperienceedge.sitecorecloud.ioboxever.comcdp.sitecorecloud.iocdn.boxever.com

Cookies placed

NameTypeDurationPurpose
SC_ANALYTICS_GLOBAL_COOKIEfirst-party (Sitecore xDB)10 years (default)Persistent visitor identifier created by Sitecore xDB to merge sessions and build behavioral profiles. Requires consent under ePrivacy.
SC_ANALYTICS_SESSION_COOKIEfirst-party (Sitecore xDB)SessionSession identifier for the current visit in Sitecore xDB. Used together with the global cookie to capture page views and goals.
_sc_browser_idfirst-party (Sitecore CDP)1 yearBrowser identifier used by Sitecore CDP to merge cross device behavior. Requires consent.
_bx_uuidfirst-party (Sitecore Personalize)1 yearUUID assigned by Sitecore Personalize for experimentation and audience evaluation. Requires consent.
.ASPXAUTHfirst-party (backoffice only)SessionASP.NET authentication cookie for logged in editors of Sitecore XP. Strictly necessary, never set on the public site.

Dieser Dienst erhebt möglicherweise Nutzerdaten. Stellen Sie die DSGVO-Konformität mit FlowConsent sicher.

Kostenlos startenWebsite scannen

Häufig gestellte Fragen

Setzt Sitecore Cookies bei Website Besuchern?

Ja, wenn xDB Analyse, Sitecore CDP oder Sitecore Personalize aktiviert sind. SC_ANALYTICS_GLOBAL_COOKIE (persistent, standardmäßig 10 Jahre) und SC_ANALYTICS_SESSION_COOKIE (Session) stammen aus xDB. Sitecore CDP und Personalize fügen eigene Identifikator Cookies hinzu. Ohne diese Add ons ist die headless XM Cloud Auslieferung cookielos.

Ist für Sitecore eine Einwilligung nach DSGVO und ePrivacy erforderlich?

Ja für xDB Analyse, Sitecore CDP und Personalize, da sie persistente Besucherprofile erstellen. Artikel 5(3) ePrivacy und EDSA Leitlinien fordern eine vorherige Opt in Einwilligung. Die strikt notwendigen Backoffice Cookies für Redakteure benötigen keine Einwilligung.

Welche Rechtsgrundlage gilt für die Verarbeitung mit Sitecore?

Artikel 6(1)(a) DSGVO (Einwilligung) für xDB, CDP, Personalize und Send. Artikel 6(1)(f) (berechtigtes Interesse) für den Backoffice Betrieb und Sicherheitsprotokolle. Der Kunde ist Verantwortlicher, Sitecore ist Auftragsverarbeiter mit AV Vereinbarung im Master Subscription Agreement.

Überträgt Sitecore Daten in die USA?

Sitecore hat den Hauptsitz in Kanada mit US Infrastruktur. EU Kunden müssen ausdrücklich Westeuropa oder Nordeuropa Azure Deployments für XM Cloud und Content Hub anfordern. Sitecore CDP und Personalize nutzen standardmäßig US Infrastruktur, sofern kein EU Pinning verhandelt wird. SCCs und das EU US Data Privacy Framework decken Restüberträge ab.

Ist eine DSFA für Sitecore erforderlich?

Eine DSFA wird empfohlen, sobald xDB, Sitecore CDP, Personalize oder Send genutzt werden, da sie Besucherprofiling durchführen. Dokumentieren Sie Rechtsgrundlage, Aufbewahrungsfristen, EU Pinning für CDP und Personalize und die Integration ins Consent Management.

Wie binde ich Sitecore DSGVO konform ein?

Verbinden Sie Sitecore mit Ihrer Consent Management Plattform, blockieren Sie xDB/CDP/Personalize Tags bis zur Einwilligung, konfigurieren Sie die xDB Aufbewahrung konservativ, fordern Sie EU Pinning für CDP/Personalize an, unterzeichnen Sie die AV Vereinbarung, dokumentieren Sie ein DSAR Verfahren über die xConnect und CDP APIs, sichern Sie das Backoffice mit VPN, SSO und 2FA ab.

Welche Alternativen zu Sitecore gibt es?

Andere Enterprise DXP Plattformen sind Adobe Experience Manager, Optimizely Content Cloud, Acquia (Drupal), Contentstack, Storyblok und Salesforce Experience Cloud. Für leichtere Anforderungen kommen Strapi, Sanity, Prismic, Kontent.ai oder Umbraco in Frage.

Wie aktualisiere ich die Cookie Richtlinie für Sitecore?

Listen Sie SC_ANALYTICS_GLOBAL_COOKIE, SC_ANALYTICS_SESSION_COOKIE, Sitecore CDP und Personalize Identifikatoren in Ihrer Cookie Erklärung mit Aufbewahrung, Zweck und Informationen zum EU Pinning auf. Weisen Sie den EU US Datentransfer in Ihrer Datenschutzerklärung aus. Aktualisieren Sie die Erklärung bei jeder Aktivierung eines weiteren Sitecore Add ons.