FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CDN
  4. unpkg
u

unpkg

OtherWebsite

Related services

5centsCDN

5centsCDN is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 5centsCDN integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 5centsCDN helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Acquia Cloud Platform CDN

Acquia Cloud Platform CDN is a content delivery network (CDN) that accelerates website performance by distributing content across a global network of edge servers. It reduces latency, improves page load times, and handles traffic spikes by serving cached content from the nearest location. Acquia Cloud Platform CDN supports static and dynamic content acceleration, DDoS protection, and SSL/TLS encryption. With real-time analytics and purge capabilities, Acquia Cloud Platform CDN ensures fast, reliable delivery.

Other

Airee

Airee is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airee supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airee ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akamai

Akamai is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Akamai is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Akamai offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

Akamai Connected Cloud

Akamai Connected Cloud is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Akamai Connected Cloud provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Akamai Connected Cloud ensures optimal performance at scale.

Other
A

Akamai mPulse

Akamai mPulse is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Akamai mPulse enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Akamai mPulse empowers marketing teams to achieve measurable growth.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does unpkg do?

unpkg is a fast, global content delivery network for everything published on npm. It was created by Michael Jackson, the maintainer of React Router and Remix, and runs on top of Cloudflare. Developers reference any npm package version with a URL such as https://unpkg.com/react@18/umd/react.production.min.js and get the file from the nearest Cloudflare edge. unpkg itself does not set marketing cookies, but Cloudflare may set __cf_bm and logs every request, raising the same GDPR considerations as any other US CDN.

What unpkg does and how it appears on a website

unpkg is a free content delivery network that serves any file from any package published on npm. It is widely used for quick prototyping, documentation pages, demos and learning materials. A URL such as https://unpkg.com/lodash@4 fetches the latest minor version of lodash from the closest Cloudflare edge. unpkg is operated by Michael Jackson, the maintainer of React Router and Remix, in collaboration with Cloudflare, who donates the infrastructure.

Cookies and data collected by unpkg

unpkg itself does not place marketing or analytics cookies. The Cloudflare edge can set the __cf_bm bot management cookie (30 minutes) on unpkg.com when suspicious traffic is detected. Every request is logged for caching and abuse prevention, including IP, User-Agent, requested URL and Referer.

GDPR and ePrivacy implications

As with cdnjs and jsDelivr, loading from unpkg transmits the visitor IP to a US provider. The Bonn Regional Court ruling on Google Fonts and similar decisions across EU member states show that prior consent is the safest interpretation when no other legal basis applies.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

Cloudflare Inc. is a US controlled provider certified under the EU-US Data Privacy Framework, providing an adequacy basis for transfers to the United States. unpkg itself is operated by a US natural person on Cloudflare infrastructure; the entity does not publish a DPA for free users.

Consent and legal basis

Production deployments should not rely on unpkg. The recommended pattern is to install packages through npm or pnpm, bundle them with the rest of the application, and serve from the same origin or an EU CDN. If unpkg is used in a prototype or demo, gather opt-in consent before each script tag, or place a clear notice next to it.

Practical compliance steps

Audit every script and link tag pointing to unpkg.com in the production codebase, replace them with bundled or self-hosted equivalents, add Subresource Integrity hashes for any unpkg URL that must remain in development tools, and document the choice in the privacy notice if unpkg is still used on customer facing pages.

GDPR consent category

Other

Websites using unpkg must obtain user consent under GDPR regulations.

Legal basisLegitimate interest under Article 6(1)(f) GDPR can be argued for fetching technical packages. Consent under Article 6(1)(a) is the safer route in EU jurisdictions that follow the Bonn Regional Court approach to third party scripts.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, German TTDSG / TDDDG, EU-US Data Privacy Framework, French CNIL 2020 cookie guidelines

DPIA considerations

A DPIA is rarely necessary for unpkg alone. Document a transfer impact assessment on Cloudflare Inc. and unpkg LLC covering IP logging, edge log retention, the EU-US Data Privacy Framework certification and supplementary measures. Where many packages are loaded, fold the assessment into a broader review of third party JavaScript.

Sample consent text

This website loads some scripts from unpkg, a content delivery network for npm packages operated on Cloudflare. Your IP address, User-Agent and the requested URL are processed by Cloudflare under the EU-US Data Privacy Framework. By clicking Accept, you authorise this technical request. You can also Reject and we will bundle the libraries with our own application code.

Technical details

Tracking methodContent delivery network for npm packages. Files are served on demand from the latest published versions; Cloudflare may set __cf_bm bot management cookie on the unpkg.com domain.
Server locationCloudflare global anycast edge network with EU points of presence. Origin operated by unpkg / Michael Jackson on Cloudflare infrastructure.
Data transferred outside the EUunpkg.com is fronted by Cloudflare Inc. (United States). Each fetch logs the visitor IP, User-Agent, requested URL and Referer. Cloudflare is certified under the EU-US Data Privacy Framework and signs Standard Contractual Clauses through its DPA.

Third-party domains contacted

unpkg.comcloudflare.com

Cookies placed

NameTypeDurationPurpose
__cf_bmHTTP cookie30 minutesCloudflare bot management cookie set on unpkg.com when suspicious traffic is detected.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does unpkg set?

unpkg itself sets no cookies. Cloudflare can place __cf_bm (30 minutes) on unpkg.com for bot management. Server logs capture IP, User-Agent, URL and Referer.

Do I need consent to use unpkg?

For production traffic, the safer approach is to avoid unpkg and bundle packages instead. If unpkg is kept, gather opt-in consent or document a legitimate interest assessment.

What is the legal basis?

Legitimate interest under Article 6(1)(f) GDPR is defensible for fetching essential libraries. Consent under Article 6(1)(a) is the safer route in jurisdictions following the Bonn approach.

Does unpkg transfer data to the US?

Yes. Cloudflare Inc. is US controlled and certified under the EU-US Data Privacy Framework. Avoid the transfer by bundling the packages.

Is a DPIA required?

Not for unpkg alone. A short transfer impact assessment is enough.

How do I implement unpkg compliantly?

Install npm packages locally, bundle them with the application, deploy from your own domain or an EU CDN, and remove every reference to unpkg.com from production HTML.

Are there alternatives to unpkg?

Bundling via Vite, Webpack, esbuild or Rollup. EU CDN alternatives: Bunny CDN, Scaleway Edge. jsDelivr offers a similar service over Cloudflare and Fastly.

How do I update my cookie policy for unpkg?

Mention Cloudflare Inc. as sub-processor, describe __cf_bm, the IP logging on every request, the EU-US Data Privacy Framework and link to the Cloudflare privacy policy.