Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Open source constituent relationship management software for nonprofits that is usually self hosted, so personal data stays on your own server.
CiviCRM is an open source constituent relationship management system built for nonprofits, associations and advocacy groups. It is most often self hosted alongside a content management system such as WordPress or Drupal, which means the software and its database run on infrastructure that the organisation controls. Because of this model the site operator is the data controller and keeps full ownership of the constituent records.
CiviCRM processes personal data about members, donors and contacts, including names, addresses, contribution history and any custom fields you configure. For logged in users it sets a functional session cookie that keeps the user authenticated while they work. It does not load advertising trackers or share data with external networks unless you deliberately add such integrations.
The session cookie is strictly necessary to provide the service, so it falls under the ePrivacy exemption and does not require prior consent. The processing of constituent personal data, by contrast, is governed by the GDPR and must rest on a valid lawful basis. As controller you remain responsible for transparency, data minimisation and the rights of the people whose data you hold.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
You generally do not need cookie consent for the essential session cookie that CiviCRM uses. You do, however, need a lawful basis for storing and using contact data, which is often legitimate interest for existing members or explicit consent for marketing communications. Keep clear records of how and when each contact opted in so you can demonstrate compliance.
Because CiviCRM is self hosted, there is no inherent transfer of data to third countries; the data simply lives where you run the server. If you choose hosting outside the European Economic Area or connect optional services such as email or payment providers, you must assess those transfers separately. Keeping the installation within the European Union avoids most international transfer concerns.
Document your lawful basis for each type of constituent data and set sensible retention rules using the built in scheduled jobs. Restrict access with CiviCRM permission groups, keep the platform and its extensions updated and host the database on secure infrastructure. Provide a clear privacy notice and a straightforward route for people to exercise their access and erasure rights.
Websites using CiviCRM must obtain user consent under GDPR regulations.
DPIA considerations
A full data protection impact assessment is rarely mandatory for a standard self hosted CiviCRM, but you should document the categories of constituent, member and donor data you store, the lawful basis for each, retention periods and access controls. Pay attention to special category data such as health or political affiliation if your organisation records it, and assess the security of your hosting environment.
Sample consent text
We store the contact details you provide in our CiviCRM database to manage your membership, donations and our relationship with you. We process this data on the basis of our legitimate interest or your consent and never sell it. You can ask us to access, correct or erase your data at any time.
Third-party domains contacted
download.civicrm.orgCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| CIVICRM session cookie | Functional | Session | Keeps an authenticated user logged in while they work in the CiviCRM back office. Strictly necessary and exempt from consent. |
CiviCRM places tracking cookies for advertising — comply with GDPR using FlowConsent.
When self hosted, CiviCRM sets a single functional session cookie for logged in users so they stay authenticated while working. It does not set advertising or analytics cookies by default, and no tracking happens for anonymous visitors unless you add it.
No. The session cookie is strictly necessary for the service to function, so it falls under the ePrivacy exemption and does not require prior consent. You do still need a lawful basis for processing the personal data you store.
The most common bases are legitimate interest for managing existing members and donors, contract for fulfilling a membership, and explicit consent for marketing communications. Choose and document the appropriate basis for each processing activity.
Not by itself. As a self hosted application the data stays wherever you run the server. Transfers only occur if you host outside the European Economic Area or connect external services such as email or payment providers.
A full data protection impact assessment is rarely mandatory for a standard installation, but it becomes advisable if you process large volumes of data or special categories such as health or political opinions. Document your data flows and risks either way.
Document a lawful basis for each data type, set retention rules with scheduled jobs, restrict access using permission groups, keep the software updated and host on secure infrastructure. Publish a clear privacy notice and offer easy access and erasure routes.
Other constituent and donor management options include Salesforce Nonprofit Cloud, Blackbaud, and EU based tools. The key advantage of CiviCRM is that self hosting keeps personal data under your direct control.
List the functional session cookie as strictly necessary, explain that it keeps logged in users authenticated, and note that no advertising trackers are used. Describe separately, in your privacy notice, how you process constituent personal data.