Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
StackPath was a content delivery network and edge platform that offered a web application firewall and bot protection to speed up and secure websites. It set first party security and load balancing cookies, mainly when a request triggered a challenge such as a captcha. Importantly, StackPath wound down its CDN and WAF in November 2023 and ceased all operations in 2024, with Akamai and Gcore acquiring parts of its technology. This guide is provided for reference and to help operators who still need to remove it and migrate to an active provider.
StackPath was a content delivery network and edge platform that helped websites load faster and stay protected by serving content from points of presence close to the visitor. Alongside caching it offered a web application firewall and bot protection that inspected requests at the edge and could block, rate limit or challenge suspicious traffic. It is important to state the current status plainly, because StackPath wound down its CDN and legacy Highwinds CDN in November 2023, discontinued its WAF at the same time, and ceased all operations in 2024. Akamai acquired select CDN assets and Gcore acquired the web application and API protection technology, but the StackPath service itself is no longer available. This page therefore serves as reference material and as guidance for operators who still need to remove StackPath and move to a supported provider. Treating it as a live integration would be inaccurate.
While it operated, the StackPath web application firewall could set a range of first party cookies, mostly in scenarios such as a captcha or JavaScript challenge or when load balancing was applied. Documented WAF cookies included names such as sp_lit, sbtsck, SPC, SPLB, cnfc, pvstr, DGCC and similar values used for handshake, challenge and routing purposes. The sbtsck cookie, for example, was associated with captcha and handshake handling and was typically short lived. As a CDN and edge security layer, StackPath also processed request metadata such as IP address, user agent and request headers to apply its security rules. These values can constitute personal data because they can identify or single out a visitor. Since the service has shut down, no new cookies are set, but legacy references should be cleaned up.
When StackPath was in use the request metadata and security cookies it handled were personal data under the GDPR, and StackPath acted as a processor for the website operator who remained the controller. Content delivery and network security are recognised legitimate interests under Article 6(1)(f), so that basis could support the processing provided a balancing test was documented. The ePrivacy Directive applied separately to the cookies, since storing and reading information on a device generally needs consent unless it is strictly necessary for a service the user explicitly requested. Strictly necessary security and load balancing cookies are often treated as exempt, while anything broader needs consent. Because the service has ended, the live ePrivacy question is largely moot for StackPath itself, but the same analysis must now be carried out for whatever replacement provider has taken over the role.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Historically many operators classified the StackPath security and load balancing cookies as strictly necessary and loaded them without prior consent, on the basis that they protected and delivered the requested site. That position was only sound where the cookies were genuinely limited to security and routing and not reused for other purposes. With the service discontinued the practical task is different, because your consent management platform should no longer list StackPath as an active vendor. You should remove StackPath entries from your cookie banner and cookie inventory, and add the replacement provider with an accurate classification. If any StackPath cookies are still being served by stale configuration, treat that as a defect to fix rather than a category to keep.
StackPath was a United States company based in Dallas, Texas, and ran a global edge network, so traffic from European visitors could be processed in the United States and at edge locations in other regions. Transfers to the United States during its operation would have needed an appropriate mechanism such as Standard Contractual Clauses or, later, the EU US Data Privacy Framework. Because the service has shut down, the live transfer question now attaches to the replacement provider rather than to StackPath. As the controller you should update your records of processing to remove StackPath, confirm the transfer mechanism for the new provider, and run a transfer impact assessment for that provider where your risk approach requires one. Keeping clear records of this transition helps demonstrate accountability.
Start by confirming whether StackPath is still referenced anywhere in your stack, including DNS records, CNAME entries, edge configuration and tag managers. Migrate to a supported content delivery and security provider such as Akamai, Cloudflare, Fastly or Gcore, and validate that traffic now routes correctly. Remove StackPath cookies, scripts and vendor entries from your cookie banner, cookie policy and records of processing. Carry out a fresh legitimate interest assessment and, where needed, a transfer impact assessment for the new provider, and sign its data processing agreement. Update your privacy notice and cookie policy to reflect the current provider rather than StackPath. Finally, monitor for any residual StackPath cookies and remove them so your published documentation matches reality.
Websites using StackPath must obtain user consent under GDPR regulations.
DPIA considerations
Because StackPath has been discontinued, the most pressing data protection task is migration rather than ongoing assessment. Where the service was still referenced, a focused review should confirm that StackPath cookies and DNS or edge configuration have been fully removed and that traffic now flows through a supported provider. For the active replacement, a Data Protection Impact Assessment may be appropriate where it applies large scale bot mitigation or behavioural analysis, covering necessity, retention and international transfers. Historic records of processing should be updated to reflect that StackPath is no longer a processor.
Sample consent text
This site previously used the StackPath content delivery network and web application firewall, which could set security cookies on your device to protect and speed up the site. StackPath has been discontinued, so please refer to the current provider listed in this notice.
Third-party domains contacted
stackpathcdn.comstackpathdns.comstackpath.comhwcdn.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| sp_lit | first party security | Session to short lived | Set by the StackPath web application firewall during security checks to help verify the visitor and apply protection rules. Set only when the service was active. |
| sbtsck | first party security | Approximately 1 day | Associated with captcha and handshake handling in the StackPath WAF to confirm a visitor passed a challenge. |
| SPLB | first party functional | Session | Load balancing cookie used by the StackPath edge to route a visitor consistently to a backend during their session. |
| SPC | first party security | Session to short lived | StackPath WAF cookie used as part of bot protection and request validation when a security action was triggered. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
While it operated, the StackPath web application firewall could set first party cookies such as sp_lit, sbtsck, SPC, SPLB, cnfc and pvstr, mainly during captcha or JavaScript challenges and for load balancing. The sbtsck cookie was tied to captcha and handshake handling and was usually short lived. Because StackPath has shut down, no new cookies are set, but old ones should be removed from stale configuration.
When StackPath ran, operators often treated the security and load balancing cookies as strictly necessary under the ePrivacy exemption and loaded them without consent, provided they were limited to security and routing. Anything broader needed consent. Since the service is discontinued, the live task is to remove StackPath from your consent banner and assess the replacement provider instead.
Content delivery and network security are recognised legitimate interests under Article 6(1)(f), which usually supported StackPath processing with a documented balancing test. The ePrivacy Directive separately governed the cookies. StackPath acted as a processor for the website operator, who remained the controller.
Yes. StackPath was a United States company based in Dallas and ran a global edge network, so European traffic could be processed in the United States and other regions. Those transfers needed a mechanism such as Standard Contractual Clauses or the EU US Data Privacy Framework. The transfer question now applies to your replacement provider.
Because StackPath has been discontinued, the priority is migration rather than a fresh assessment of the dead service. A focused check should confirm StackPath has been fully removed. A Data Protection Impact Assessment may be appropriate for the active replacement where it applies large scale bot mitigation or behavioural analysis.
Confirm StackPath is no longer referenced in DNS, CNAME records, edge configuration or tag managers, then migrate to a supported provider such as Akamai, Cloudflare, Fastly or Gcore. Remove StackPath cookies and vendor entries from your cookie banner and records of processing, and document the replacement with its own legal basis and transfer mechanism.
Following the shutdown, common alternatives include Akamai, which acquired StackPath CDN assets, Cloudflare, Fastly and Gcore, which acquired the StackPath web application and API protection technology. Choose based on your performance, security, hosting region and data residency needs.
Remove the StackPath cookies and vendor description from your cookie policy and replace them with the current provider. List the new provider security cookies, their purpose and duration, and note where data is processed and the transfer mechanism. Then check that no residual StackPath cookies remain so the policy is accurate.