Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
The Bootstrap CSS and JavaScript framework delivered through a public CDN. The framework sets no cookies, but each CDN request exposes the visitor IP and user agent to the CDN operator.
Bootstrap is one of the most widely used front end frameworks for layout and components, and many sites pull its CSS and JavaScript from a public CDN. The framework sets no cookies and does no tracking, but fetching it from a third party CDN carries a privacy implication that is easy to miss.
A Bootstrap CDN serves the framework files from a globally distributed network such as jsDelivr or cdnjs; the older BootstrapCDN ran on StackPath. The benefit is caching and speed, but the visitor browser must reach a third party server to download the stylesheet and script.
Each request for the Bootstrap files carries the visitor IP address and user agent to the CDN operator. An IP address is personal data under the GDPR. This mirrors the German Google Fonts rulings, where loading an asset from a third party server without consent was found to infringe data protection rights.
CDN operators such as Cloudflare are United States linked and run global edge networks. Serving Bootstrap from them can therefore constitute a transfer of personal data to a third country, which needs an appropriate safeguard and a documented basis under the GDPR transfer rules.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Since no cookies are set, consent is not strictly mandated, but the IP transfer should rest on a documented legitimate interest assessment. In light of the German case law on third party assets, the risk is best rated medium until you self host or formally justify the CDN use.
Self host the Bootstrap CSS and JavaScript from your own domain. The requests then stay first party, no visitor IP leaves to a third party CDN, and the transfer question disappears. If you must use a CDN, document the legitimate interest and prefer an EEA based operator where possible.
Websites using Bootstrap CDN must obtain user consent under GDPR regulations.
DPIA considerations
The Bootstrap framework processes no personal data, so a full DPIA is rarely needed. The point worth assessing is the systematic disclosure of every visitor IP and user agent to the CDN operator, which for operators such as Cloudflare can amount to a transfer to the United States. Document a legitimate interest assessment for this transfer, or remove the issue entirely by self hosting the Bootstrap files.
Sample consent text
This site uses the Bootstrap framework for layout and styling. Where it is loaded from a public CDN, the CDN operator receives your IP address and browser details as part of delivering the files. Bootstrap itself sets no cookies. To avoid this, the framework can be hosted on this site own servers.
Third-party domains contacted
cdn.jsdelivr.netcdnjs.cloudflare.comstackpath.bootstrapcdn.commaxcdn.bootstrapcdn.comunpkg.comThis service may collect user data. Ensure GDPR compliance with FlowConsent.
No. The Bootstrap framework sets no cookies and does no tracking. The privacy concern is the network request itself, which exposes the visitor IP to the CDN operator, not any cookie.
Consent is not strictly mandated because no cookies are stored, but the IP transfer to the CDN operator should rest on a documented legitimate interest. Self hosting removes the question entirely.
Legitimate interest in fast, cached delivery of the framework, backed by a documented assessment that accounts for the visitor IP exposure. If that cannot be justified, self host to avoid needing any basis.
It can. Operators such as cdnjs (Cloudflare) and jsDelivr are United States linked with global edge networks, so the visitor IP and user agent may be processed in a third country, triggering the GDPR transfer rules.
A full DPIA is rarely required, since the framework processes no personal data beyond the IP disclosed by the request. A documented legitimate interest assessment for that transfer is usually enough.
Self host the Bootstrap CSS and JavaScript from your own domain. The requests then stay first party, no visitor IP leaves to a third party CDN, and the transfer question disappears. This is the simplest compliant approach.
Self hosting the framework is the main alternative. You can also build a trimmed Bootstrap bundle into your own assets, or use a lighter CSS framework such as Tailwind or Bulma served from your own domain.
If you load Bootstrap from a CDN, name the operator, state that your visitor IP and user agent are processed by it, and note any transfer outside the EEA. If you self host, no specific entry is needed.