Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
MichiJS is an open source JavaScript framework for building user interfaces and web components. As a client side library it sets no tracking cookies of its own. The main privacy consideration is how it is delivered, since loading it from a public CDN exposes visitor IP addresses to that provider. Self hosting removes this exposure and means no consent is required.
MichiJS is an open source JavaScript framework used to build user interfaces and reusable web components. It runs entirely in the visitor browser and is included in a page like any other script. As a rendering library it has no analytics, advertising or tracking functionality and does not, by itself, identify or profile users.
In a standard deployment MichiJS sets no cookies and stores no personal data. It does not transmit information to its maintainers. Any cookies present on a site that uses MichiJS come from other components such as analytics, advertising or session tools, not from the framework. The only data flow attributable to MichiJS is the network request that fetches the library file.
Because MichiJS sets no cookies and reads nothing from the device, Article 5(3) of the ePrivacy Directive is generally not engaged by the library itself. The GDPR becomes relevant only through delivery, when a third party content delivery network receives the visitor IP address to serve the file. An IP address is personal data, so that disclosure should be accounted for.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
No consent is required to use MichiJS when it is self hosted and sets no cookies, since loading a rendering library is strictly necessary to display the page the user requested. If the library is served from a public CDN, the IP disclosure is best addressed through transparency in the privacy notice rather than a consent banner, provided no tracking takes place.
If MichiJS is loaded from a CDN whose servers sit outside the European Economic Area, the visitor IP address may be transferred to a third country such as the United States. To avoid this transfer entirely, self host the library or choose a CDN with European endpoints, and where a transfer remains, rely on Standard Contractual Clauses or an adequacy mechanism.
Prefer self hosting MichiJS from your own domain to keep delivery within your control and avoid third party IP exposure. If you use a CDN, document it in your privacy notice, confirm its server locations and transfer safeguards, and pin a specific version with integrity checks. Confirm that no other cookies are introduced alongside the library.
Websites using MichiJS must obtain user consent under GDPR regulations.
DPIA considerations
A full data protection impact assessment is rarely needed for MichiJS itself because it sets no tracking cookies and processes no personal data on its own. The relevant consideration is delivery, if the library is served from a third party CDN, the visitor IP address is disclosed to that provider. Document the CDN used, its location and safeguards, or self host the library to avoid the transfer entirely.
Sample consent text
This site uses the MichiJS framework to render its interface. The library itself sets no tracking cookies. If it is loaded from a content delivery network, your IP address is shared with that provider purely to deliver the file. No consent is required where the library is self hosted and sets no cookies.
Third-party domains contacted
cdn.jsdelivr.netunpkg.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _cf_bm | Strictly necessary / CDN | 30 minutes | Set by the content delivery network that may serve MichiJS to distinguish legitimate traffic from automated requests. Not set by MichiJS itself. |
| __cfduid_legacy | Strictly necessary / CDN | Session | Operational cookie that some CDNs use for security and delivery when hosting static assets such as the MichiJS library file. |
| michijs_selfhost_none | Informational | Not applicable | When MichiJS is self hosted from your own domain it sets no cookies at all, this entry documents that no tracking storage is created by the library. |
MichiJS collects user analytics data — you legally need a consent banner. Try FlowConsent free.
No. MichiJS is a client side rendering library and sets no cookies and stores no tracking data of its own. Any cookies on a site using it come from other tools. If you load it from a CDN, that provider may technically set its own operational cookies, so review the CDN documentation.
No consent is required where MichiJS is self hosted and sets no cookies, since loading the library is strictly necessary to render the requested page. If served from a third party CDN, address the resulting IP disclosure with transparency in your privacy notice rather than a consent banner.
Where it is self hosted and cookieless, no ePrivacy consent applies because delivering the page the user requested is strictly necessary. For any IP disclosure to a CDN, the appropriate basis is legitimate interest under Article 6(1)(f) GDPR, supported by transparency, since the data is used only to deliver the file.
The framework itself transfers nothing. A transfer can occur only if you load MichiJS from a CDN whose servers are in the United States, in which case the visitor IP reaches that provider. Self host the library or use a European CDN endpoint to avoid the transfer.
A DPIA is generally not needed for MichiJS because it sets no cookies and processes no personal data on its own. A short note in your records of processing covering any CDN delivery and the resulting IP disclosure is usually sufficient.
Self host MichiJS from your own domain so no third party receives visitor IP addresses, pin a specific version with subresource integrity, and confirm it introduces no cookies. If you must use a CDN, document it and prefer a provider with European servers and clear transfer safeguards.
Other open source UI frameworks and web component libraries serve the same purpose. From a privacy standpoint the choice matters less than the delivery method, any of them is privacy neutral when self hosted and cookieless. Evaluate bundle size, maintenance and licensing alongside delivery.
If MichiJS is self hosted and cookieless, your cookie policy needs no entry for it, though you may note that the interface relies on it. If you load it from a CDN, mention that provider and the IP disclosure in the privacy notice, and review the entry if you change CDNs.