Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
MyCDN is a content delivery network that speeds up websites by serving files from a global network of edge servers. It typically sets no tracking cookies and relies on legitimate interest, though its global edge locations and IP processing mean transfers should still be considered under the GDPR.
MyCDN is a content delivery network that caches and serves a website's static files, such as images, scripts, and stylesheets, from edge servers close to the visitor. This speeds up page loading and improves reliability, and it can also provide basic security filtering against malicious traffic.
A CDN generally does not set tracking cookies. MyCDN may set a strictly necessary load balancing or security cookie, and it processes connection data such as the visitor IP address and request details to deliver content and protect the site. The IP address is personal data under the GDPR even though it is not used for advertising.
Strictly necessary cookies a CDN uses to deliver content or secure the site are exempt from consent under Article 5(3) of the ePrivacy Directive. The processing of connection data relies on legitimate interest in delivering the service securely, and a data processing agreement should cover the CDN as a processor.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because a CDN serves content from a global network, requests may be handled by edge servers outside the EU, and connection data can be processed there. Identify which regions are used, rely on a transfer mechanism where data leaves the EEA, and prefer EU edge locations or configuration options that keep traffic within the region where possible.
Sign a data processing agreement, confirm the edge regions and any transfer safeguard, and document legitimate interest as the basis. List any strictly necessary CDN cookie in your policy, keep logs only as long as needed for security, and review the configuration if you enable analytics features on top.
Websites using MyCDN must obtain user consent under GDPR regulations.
DPIA considerations
A standard CDN that only delivers content and processes connection data is low risk and rarely needs a DPIA. Consider transfers if edge servers outside the EU process connection data, and document the safeguards.
Sample consent text
We use MyCDN to deliver our website quickly and securely. It relies on strictly necessary processing of connection data and does not set advertising cookies.
Third-party domains contacted
mycdn.comedge.mycdn.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| mycdn_lb | Functional | Session | Routes the visitor to a consistent edge server for reliable delivery |
| mycdn_sec | Security | 1 hour | Helps detect and block malicious traffic to protect the site |
MyCDN collects user analytics data — you legally need a consent banner. Try FlowConsent free.
A CDN usually sets no tracking cookies. MyCDN may set a strictly necessary load balancing cookie to route you to a consistent edge server and a short lived security cookie to block malicious traffic.
No. The cookies a CDN uses to deliver content and secure the site are strictly necessary and exempt from consent under Article 5(3) ePrivacy. Consent only applies if you add analytics on top.
Processing connection data such as the IP address relies on legitimate interest under Article 6(1)(f) of the GDPR for secure and reliable content delivery. Document this in your records of processing.
It can, because a CDN serves from a global edge network. Identify the regions used, rely on a transfer mechanism where connection data leaves the EEA, and prefer EU edge locations where available.
A standard CDN is low risk and rarely needs a DPIA. Consider the transfer aspect if edge servers outside the EU process connection data, and document the safeguards.
Sign a data processing agreement, confirm the edge regions and any transfer safeguard, document legitimate interest, treat its cookies as strictly necessary, and keep security logs only as long as needed.
CDNs with EU only edge regions can keep connection data within the EEA. Any CDN that adds analytics features would need consent for those, but pure content delivery does not.
List any strictly necessary CDN cookies with their purpose and duration, note that connection data such as IP addresses is processed for delivery and security, and mention the edge regions and any transfer safeguard.