FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CDN
  4. Mapbox GL JS
M

Mapbox GL JS

PreferencesWebsite

Related services

5centsCDN

5centsCDN is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 5centsCDN integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 5centsCDN helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Acquia Cloud Platform CDN

Acquia Cloud Platform CDN is a content delivery network (CDN) that accelerates website performance by distributing content across a global network of edge servers. It reduces latency, improves page load times, and handles traffic spikes by serving cached content from the nearest location. Acquia Cloud Platform CDN supports static and dynamic content acceleration, DDoS protection, and SSL/TLS encryption. With real-time analytics and purge capabilities, Acquia Cloud Platform CDN ensures fast, reliable delivery.

Other

Airee

Airee is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airee supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airee ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akamai

Akamai is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Akamai is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Akamai offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

Akamai Connected Cloud

Akamai Connected Cloud is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Akamai Connected Cloud provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Akamai Connected Cloud ensures optimal performance at scale.

Other
A

Akamai mPulse

Akamai mPulse is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Akamai mPulse enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Akamai mPulse empowers marketing teams to achieve measurable growth.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Mapbox GL JS do?

Mapbox GL JS is an open source JavaScript library for rendering interactive vector maps in the browser. It requests map tiles and styles from Mapbox servers and by default sends usage telemetry to Mapbox, storing an anonymous identifier in browser local storage. The IP exposure and telemetry trigger GDPR and ePrivacy compliance obligations.

What is Mapbox GL JS?

Mapbox GL JS is an open source JavaScript library published by Mapbox that renders interactive vector maps directly in the browser using WebGL. It requests map tiles, style definitions and glyph resources from Mapbox infrastructure servers (api.mapbox.com and a.tiles.mapbox.com) using an access token provided by the developer. By default, version 2 and later of the library also sends telemetry events to events.mapbox.com, including map load events, approximate visitor location and device information. Mapbox uses this telemetry data for billing and analytics. The library stores an anonymous identifier and telemetry preferences in browser local storage rather than classic cookies.

What Data and Storage Does It Use?

Every map tile request sends the visitor's IP address and the requested tile coordinates to Mapbox servers in the United States. The library stores a persistent anonymous identifier under the key mapbox.eventData in browser local storage, along with telemetry preferences and session tokens. Telemetry events sent to events.mapbox.com may include the map load count, approximate geographic location derived from the IP, browser and device characteristics. Mapbox sets few or no traditional cookies; the primary storage mechanism is local storage, which is nonetheless subject to Article 5(3) of the ePrivacy Directive.

GDPR and ePrivacy Implications

Using Mapbox GL JS creates several compliance obligations. Under Article 5(3) of the ePrivacy Directive, writing to or reading from browser local storage requires prior informed consent, because local storage is terminal equipment storage. Under GDPR, the IP address transferred with every tile request constitutes personal data processed by Mapbox in the US, requiring a legal basis and appropriate transfer safeguards. The telemetry function adds an analytics dimension: profiling map usage through events sent to Mapbox is processing of personal data for Mapbox's own purposes, which requires either consent or a documented legitimate interest with a balancing test.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements

Consent is required before loading Mapbox GL JS when telemetry is enabled, since the library writes to local storage on initialisation. If the developer disables telemetry programmatically (using the mapbox.telemetry opt out mechanism) and the map is strictly functional, some data protection authorities may accept legitimate interest as the basis, provided the IP transfer is disclosed and a balancing test is documented. However, consent remains the safest legal basis and is strongly recommended for public facing websites serving EU visitors. The consent must be freely given, specific and withdrawable.

Data Transfers Outside the EU

All map tile requests and telemetry events are processed by Mapbox, Inc. in the United States. This is an international data transfer under GDPR Chapter V. Mapbox relies on standard contractual clauses as the primary transfer mechanism and, where it qualifies, the EU US Data Privacy Framework. Website operators using Mapbox GL JS must reference these transfer safeguards in their privacy policy, identify Mapbox as a data processor or controller (depending on the data flow), and sign Mapbox Data Processing Terms where required.

Practical Compliance Steps

To implement Mapbox GL JS in a GDPR compliant manner: (1) Block the Mapbox script in your consent management platform and load it only after the visitor grants map or analytics consent. (2) If you choose legitimate interest for a functional map, disable telemetry using the Mapbox opt out API before map initialisation and document your balancing test. (3) Disclose Mapbox local storage use (mapbox.eventData) in your cookie and storage policy with its purpose and persistence. (4) Reference Mapbox US data transfer and standard contractual clauses in your privacy policy. (5) Sign Mapbox Data Processing Terms and keep a copy in your DPA records. (6) Revisit the legal basis if you upgrade the Mapbox GL JS version, as telemetry behaviours may change.

GDPR consent category

Preferences

Websites using Mapbox GL JS must obtain user consent under GDPR regulations.

Legal basisConsent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy for the telemetry and local storage identifier; legitimate interest may cover a strictly functional map without telemetry if the IP exposure to Mapbox is disclosed
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (2002/58/EC)

DPIA considerations

A DPIA should be considered where Mapbox GL JS is used on high traffic sites or in contexts where map interactions reveal sensitive information (e.g. health or location related services). Key risk areas include: (1) systematic transmission of visitor IP addresses to Mapbox in the United States with every tile request; (2) telemetry events sent to events.mapbox.com that log map interactions and approximate location; (3) an anonymous persistent identifier stored in local storage that can profile map usage patterns over time. Controllers should evaluate whether telemetry can be disabled and document the decision, whether the IP transfer is covered by adequate safeguards (SCCs), and whether the legitimate interest basis is tenable if telemetry is fully switched off.

Sample consent text

We use Mapbox to display interactive maps on this page. Mapbox will receive your IP address and may store an anonymous identifier in your browser. Do you agree to load the interactive map? [Load Map] [No thanks]

Technical details

Tracking methodBrowser JavaScript map rendering library that requests tiles and styles from Mapbox and sends usage telemetry events, storing an anonymous identifier in local storage
Server locationUnited States
Data transferred outside the EUMap tile requests, the visitor IP address and telemetry events are processed by Mapbox in the United States under standard contractual clauses and, where applicable, the EU US Data Privacy Framework

Third-party domains contacted

api.mapbox.comevents.mapbox.coma.tiles.mapbox.com

Cookies placed

NameTypeDurationPurpose
mapbox.eventDataFunctional / Analytics (local storage)Persistent (local storage)Anonymous telemetry identifier and session token stored by Mapbox GL JS to send usage events to events.mapbox.com
mapbox.eventData.uuidFunctional (local storage)Persistent (local storage)Anonymous UUID used to identify the browser session for Mapbox telemetry purposes
mapbox.tokenFunctional (session storage)SessionCached Mapbox access token used for authenticated tile and API requests during the browser session

Mapbox GL JS uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies or storage does Mapbox GL JS use?

Mapbox GL JS does not primarily use cookies. Instead it stores data in browser local storage. The key entry is mapbox.eventData, which contains an anonymous persistent identifier used for telemetry and a session token. These are written to local storage when the map initialises. Browser local storage is subject to Article 5(3) of the ePrivacy Directive in the same way as cookies, so prior consent is required before the library writes to it.

Is consent required to use Mapbox GL JS?

Yes, consent is generally required. When telemetry is enabled (the default), Mapbox GL JS writes an anonymous identifier to local storage on initialisation, which triggers Article 5(3) of the ePrivacy Directive. The subsequent IP address transfer to Mapbox in the US also requires a GDPR legal basis. If telemetry is programmatically disabled and the map is purely functional, some authorities may accept legitimate interest, but this is not guaranteed and varies by jurisdiction. Consent is the most straightforward and defensible approach.

What is the legal basis for using Mapbox GL JS?

Where telemetry is active, the legal basis must be consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive, because writing to local storage for analytics purposes goes beyond what is strictly necessary for the map to function. Where telemetry is fully disabled, legitimate interest under Article 6(1)(f) GDPR may be arguable for the residual IP transfer from tile requests, but this requires a documented balancing test showing that the visitor's interests do not override those of the operator. The safer and more common choice remains consent.

Does Mapbox GL JS transfer data to the United States?

Yes. Every map tile request and telemetry event is processed by Mapbox, Inc. in the United States, meaning the visitor IP address and interaction data are transferred to a third country under GDPR Chapter V. Mapbox relies on standard contractual clauses (SCCs) and, where applicable, the EU US Data Privacy Framework as transfer mechanisms. You must reference these safeguards in your privacy policy and ensure you have signed Mapbox's Data Processing Addendum if required for your usage tier.

Is a DPIA needed for Mapbox GL JS?

A DPIA should be considered when Mapbox GL JS is used on high traffic sites, when map interactions could reveal sensitive data (e.g. health facility searches, religious site maps), or when telemetry is active and profiles large numbers of users. Key DPIA triggers include: systematic processing of location related data, international transfer to a US processor, and analytics profiling via telemetry events. Consult your DPO and supervisory authority DPIA guidance to determine whether a formal assessment is mandatory for your specific use case.

How do I implement Mapbox GL JS in a GDPR compliant way?

Steps for compliant implementation: (1) Block the Mapbox GL JS script via your CMP and only load it after consent is granted. (2) If pursuing legitimate interest for a functional map, call the Mapbox telemetry opt out function before map.load to disable analytics events, and document your balancing test. (3) Disclose the mapbox.eventData local storage entry in your cookie and storage policy. (4) Add Mapbox US data transfer and SCCs to your privacy policy. (5) Sign the Mapbox Data Processing Addendum. (6) Display a static placeholder before the map loads. (7) Review compliance on each Mapbox GL JS library upgrade.

What are the privacy friendly alternatives to Mapbox GL JS?

If you want to avoid telemetry and US data transfers, consider: (1) Leaflet.js with OpenStreetMap tiles self hosted or served from an EU based tile provider, which avoids third party US data flows entirely. (2) MapLibre GL JS, the community maintained open source fork of Mapbox GL JS that does not include telemetry by default and does not require a Mapbox account. (3) Static map images generated server side from OSM data. (4) Mapbox GL JS with telemetry explicitly disabled and tiles proxied through your own server to avoid direct visitor to Mapbox connections. Each option has trade offs in feature richness and hosting effort.

How do I update my cookie policy to cover Mapbox GL JS?

Because Mapbox GL JS primarily uses local storage rather than cookies, your policy should be titled cookie and storage policy or similar. Add an entry for mapbox.eventData (local storage, Mapbox Inc., purpose: anonymous telemetry identifier and session token, duration: persistent until cleared). If you have disabled telemetry, note this and explain why only the tile request IP transfer remains. Reference the Mapbox US data transfer and the applicable SCCs. Review and update this entry whenever you upgrade the Mapbox GL JS library.