Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
WURFL by ScientiaMobile is a device detection solution that identifies device capabilities mainly from the User Agent on the server, classifying device type rather than tracking individuals and typically without tracking cookies.
WURFL, provided by ScientiaMobile, is a device detection solution that identifies the capabilities of the device making a request. It is used to adapt layouts, media and features to the screen and abilities of phones, tablets, televisions and other clients. Rather than following a person across the web, it answers a technical question about what the current device can do, which makes it a capability classification tool more than a behavioural tracker.
Detection happens mainly on the server by reading the User Agent string that the browser sends with every request, which means it can run without placing anything on the visitor device. There is also an optional client side script, wurfl.js, that can enrich detection in the browser when a site chooses to load it. In its server side form WURFL typically sets no tracking cookies, so it can operate in a largely cookieless way while still tailoring the experience to the device.
Although a User Agent describes a device rather than a named person, device attributes combined with an IP address can amount to personal data, so the processing still falls within data protection rules. ScientiaMobile is a US company, and when the cloud service or wurfl.js is used the User Agent and IP address can be processed in the United States, a third country under the GDPR served from domains such as wurfl.io, wurfl.com and scientiamobile.com. On premise or self hosted deployments can keep the lookup local and avoid that transfer.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For purely server side capability detection, consent is generally not required and legitimate interest is the usual basis, since the processing is limited and helps deliver a working experience on the right device. Transparency is still needed, and the picture changes if device data is combined with other identifiers for profiling or analytics, where consent may then be required. The dividing line is whether WURFL stays a technical detection step or becomes part of a tracking and profiling chain.
The risk ranges from low to medium. Pure server side detection without cookies is low risk, while the use of the US cloud service or the combination of device data with other signals raises it toward medium because of the transfer and the potential for profiling. The practical considerations are to prefer server side detection, document the legitimate interest, and decide carefully whether to load wurfl.js or to route data through the US cloud.
To use WURFL responsibly, keep detection on the server where possible, document the legitimate interest and the limited data involved, and tell visitors in the privacy notice that device capability detection takes place. If you adopt the cloud service or wurfl.js, address the United States transfer with a valid mechanism, and if you ever combine device data with profiling, move that activity behind consent. Handled this way, WURFL can improve the experience while staying a low impact, transparent piece of the stack.
Websites using WURFL (ScientiaMobile) must obtain user consent under GDPR regulations.
DPIA considerations
Purely server side device capability detection is low risk and usually does not require a DPIA, because WURFL classifies device characteristics rather than identifying individuals and typically sets no tracking cookies. A DPIA becomes more relevant if device attributes are combined with IP addresses or other identifiers for profiling, or where the US cloud service introduces an international transfer, so the assessment should focus on those combinations rather than on capability lookup alone.
Sample consent text
This site uses WURFL device detection to adapt content to your device. Capability detection runs on the server and does not set tracking cookies. Where device data is processed by the WURFL cloud service in the United States or combined for analytics, we rely on a lawful basis and, where required, your consent.
Third-party domains contacted
wurfl.iowurfl.comscientiamobile.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| No tracking cookie (server side) | First party | Not applicable | Server side WURFL detection reads the User Agent and typically sets no tracking cookies, so the default detection mode is cookieless. |
| WURFL.js cache | First party | Session or short lived | Optional, only if wurfl.js is loaded. May cache device capability results in the browser for the session so detection is not repeated on each page. |
| device_pref | First party | Up to 1 year | Optional first party cookie a site may set to remember a device adapted layout choice based on WURFL detection. |
WURFL (ScientiaMobile) collects user analytics data — you legally need a consent banner. Try FlowConsent free.
In its server side form WURFL typically sets no tracking cookies, because it detects device capabilities from the User Agent on the server. If you load the optional wurfl.js client script, review what it places in the browser, but capability detection itself does not depend on cookies.
For purely server side capability detection, consent is generally not required because the processing is limited and supports delivering the page on the right device. Consent becomes relevant if you combine device data with other identifiers for profiling or analytics, in which case you should obtain it.
Legitimate interest is the usual basis for server side device detection, since it is a narrow technical step that improves the experience. You still owe transparency in your privacy notice, and you should reassess the basis if the use case expands into profiling.
It can. ScientiaMobile is a US company, so using the WURFL cloud service or wurfl.js may process the User Agent and IP address in the United States, served from domains such as wurfl.io, wurfl.com and scientiamobile.com. On premise deployments can keep the lookup local and avoid that transfer.
A DPIA is usually not needed for pure server side detection, which is low risk and does not identify individuals. It becomes more relevant if device attributes are combined with IP addresses or other signals for profiling, or where the US cloud introduces a transfer, so focus any assessment there.
Prefer server side detection, document the legitimate interest and the limited device data involved, and mention device detection in your privacy notice. If you use the cloud service or wurfl.js, put a valid transfer mechanism in place for the United States and keep capability detection separate from any profiling.
Alternatives include other device detection libraries, client hints supported by modern browsers, and responsive design that adapts without server side detection. Each option has trade offs in accuracy and data flow, so choose based on how much device intelligence you genuinely need.
If you only run server side detection, state that device capability detection takes place and that it does not set tracking cookies. If you load wurfl.js or use the US cloud, describe any client side storage and the United States processing, and review the policy whenever your deployment changes.