FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CDN
  4. cdnjs
c

cdnjs

Other

Related services

5centsCDN

5centsCDN is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 5centsCDN integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 5centsCDN helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Acquia Cloud Platform CDN

Acquia Cloud Platform CDN is a content delivery network (CDN) that accelerates website performance by distributing content across a global network of edge servers. It reduces latency, improves page load times, and handles traffic spikes by serving cached content from the nearest location. Acquia Cloud Platform CDN supports static and dynamic content acceleration, DDoS protection, and SSL/TLS encryption. With real-time analytics and purge capabilities, Acquia Cloud Platform CDN ensures fast, reliable delivery.

Other

Airee

Airee is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airee supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airee ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akamai

Akamai is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Akamai is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Akamai offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

Akamai Connected Cloud

Akamai Connected Cloud is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Akamai Connected Cloud provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Akamai Connected Cloud ensures optimal performance at scale.

Other
A

Akamai mPulse

Akamai mPulse is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Akamai mPulse enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Akamai mPulse empowers marketing teams to achieve measurable growth.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does cdnjs do?

cdnjs is a free, open source content delivery network operated by Cloudflare that hosts more than four thousand JavaScript and CSS libraries, including jQuery, Bootstrap, Font Awesome, lodash, Moment.js, popper.js and many others. Developers reach it through cdnjs.cloudflare.com and get the file from the nearest Cloudflare edge. cdnjs itself does not set marketing cookies, but the underlying Cloudflare network can set the __cf_bm bot management cookie and logs every HTTP request, which raises the same GDPR questions as any other US CDN.

What cdnjs does and how it appears on a website

cdnjs is a free, open source content delivery network maintained by Cloudflare that hosts more than four thousand JavaScript and CSS libraries. Developers paste a URL such as https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js into a script tag and Cloudflare serves the file from its global anycast edge. cdnjs is widely used for jQuery, Bootstrap, Font Awesome, lodash, Moment.js, anime.js, popper.js, Chart.js, Highlight.js and many more.

Cookies and data collected by cdnjs

cdnjs itself does not deploy analytics or marketing cookies. The underlying Cloudflare network can set the __cf_bm bot management cookie (30 minutes) on the cdnjs.cloudflare.com domain when it detects suspicious traffic. Every HTTP request is logged for cache statistics and abuse prevention, including the visitor IP, User-Agent header, requested URL and Referer header.

GDPR and ePrivacy implications

Article 5(3) ePrivacy applies because __cf_bm, even if classified as bot protection, is stored on the user device. Cloudflare argues that __cf_bm is strictly necessary, but several European supervisory authorities prefer informed consent. The transmission of the visitor IP to a US controlled provider also triggers GDPR rules on transfer and lawful basis.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

Cloudflare Inc. is a US company subject to the CLOUD Act and FISA 702. It is certified under the EU-US Data Privacy Framework, which provides an adequacy basis for transfers to the United States. Cloudflare signs Standard Contractual Clauses in its enterprise DPA and has launched a Data Localization Suite that pins logs to EU regions for paying customers; cdnjs as a free service does not benefit from that suite.

Consent and legal basis

Legitimate interest under Article 6(1)(f) GDPR is defensible for loading essential libraries, but the Bonn Google Fonts ruling and similar decisions suggest that prior opt-in consent is the safer route when the CDN is in a third country. Self-hosting on the website origin or on an EU CDN such as Bunny CDN, Scaleway Edge or jsDelivr Europe Edge eliminates the question.

Practical compliance steps

Inventory every cdnjs URL referenced in the codebase, decide whether each library is critical for the first render or can be lazy loaded, download the matching versions and host them on your own origin or an EU CDN, add Subresource Integrity hashes to keep the security guarantee, and mention Cloudflare in the privacy notice if cdnjs is still used. Where cdnjs is kept, integrate the script tags into the Consent Management Platform so they only fire after opt-in.

GDPR consent category

Other

Websites using cdnjs must obtain user consent under GDPR regulations.

Legal basisLegitimate interest under Article 6(1)(f) GDPR can be argued for fetching technical assets, but the Bonn Regional Court ruling on Google Fonts and similar decisions across the EU have made consent the safer path when a third party US CDN receives the visitor IP.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, German TTDSG / TDDDG, EU-US Data Privacy Framework, French CNIL 2020 cookie guidelines

DPIA considerations

A standalone DPIA is rarely required for cdnjs. A transfer impact assessment focused on Cloudflare Inc. is recommended, covering the EU-US Data Privacy Framework certification, IP logging, retention of edge logs and the supplementary measures applied by Cloudflare. When several libraries are loaded from cdnjs in production, the assessment is best embedded in a wider review of third party JavaScript.

Sample consent text

This website loads some JavaScript and CSS libraries from cdnjs, a content delivery network operated by Cloudflare Inc. When your browser fetches a file, your IP address, User-Agent and the requested URL are processed by Cloudflare under the EU-US Data Privacy Framework. By clicking Accept, you authorise this technical request. You can also Reject and we will serve the libraries from our own EU server.

Technical details

Tracking methodContent delivery network hosting open source JavaScript and CSS libraries. Operates through HTTP requests; Cloudflare bot management cookie __cf_bm may be set on the cdnjs.cloudflare.com domain.
Server locationGlobal Cloudflare anycast edge network with more than 300 cities including Frankfurt, Amsterdam, Paris, Madrid, Stockholm, Warsaw and Milan. Origin servers are operated by Cloudflare Inc.
Data transferred outside the EUcdnjs.cloudflare.com is operated by Cloudflare Inc. (San Francisco, USA). Each request logs the visitor IP, User-Agent, requested file and referrer. Cloudflare is certified under the EU-US Data Privacy Framework and signs Standard Contractual Clauses through its customer DPA.

Third-party domains contacted

cdnjs.cloudflare.comcdnjs.comcloudflare.com

Cookies placed

NameTypeDurationPurpose
__cf_bmHTTP cookie30 minutesCloudflare bot management cookie set on cdnjs.cloudflare.com when suspicious traffic is detected.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does cdnjs set?

cdnjs itself does not set marketing or analytics cookies. The underlying Cloudflare network can set __cf_bm (30 minutes) on cdnjs.cloudflare.com for bot management. Server side logs capture IP, User-Agent, requested URL and Referer.

Do I need consent to use cdnjs?

Best practice for European websites is to gather opt-in consent before loading any third party script from cdnjs, especially in jurisdictions following the Bonn Regional Court approach. Self-hosting is the simplest alternative.

What is the legal basis?

Legitimate interest under Article 6(1)(f) GDPR can be argued for fetching essential libraries. Consent under Article 6(1)(a) is the safer route, particularly in Germany and France, and is required if __cf_bm is treated as non strictly necessary.

Does cdnjs transfer data to the US?

Yes. Cloudflare Inc. is US controlled and certified under the EU-US Data Privacy Framework. Edge logs may be replicated to US datacentres. Self-hosting on an EU origin or an EU CDN avoids the transfer.

Do I need a DPIA?

A standalone DPIA is rarely needed. A transfer impact assessment on Cloudflare Inc. is recommended, embedded in a broader review of third party JavaScript if many libraries are loaded.

How do I implement cdnjs compliantly?

Inventory the cdnjs URLs, self-host the libraries on your own origin or an EU CDN, add Subresource Integrity hashes and a Content Security Policy. If cdnjs is retained, integrate the script tags into the Consent Management Platform.

Are there alternatives to cdnjs?

Self-hosting is the simplest. EU alternatives include Bunny CDN, Scaleway Edge and jsDelivr Europe Edge. Many libraries also ship via npm and can be bundled directly into the application.

How do I update my cookie policy for cdnjs?

List Cloudflare Inc. as a sub-processor, describe the __cf_bm cookie and its purpose, mention the IP logging for every request, the EU-US Data Privacy Framework certification and link to the Cloudflare privacy policy.