FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Contentful

Contentful

Other

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Contentful do?

Contentful is a headless content management system founded in Berlin and used by enterprises around the world to deliver structured content to websites, mobile apps and connected devices. Editors author content in the Contentful web app while developers consume it through GraphQL or REST APIs. Contentful itself acts mostly as a backend service, so the consent footprint on the visitor browser is minimal, but the platform still processes editor data and content metadata on its EU or US infrastructure.

What Contentful is and how it fits in a website

Contentful is a Berlin headquartered headless content management system that has become a reference in the API first CMS category. Editors define content models, write entries and reference rich assets in the Contentful web app at app.contentful.com. Developers then consume the content through the GraphQL Content API, the REST Content Delivery API or the Preview API and render it in a Next.js, Nuxt, Astro or native mobile front end. The CMS layer sits behind the public website, so visitors typically interact with Contentful only indirectly.

What data Contentful processes

Contentful stores three categories of data: editor account information (name, email, organisation, role assignments, API keys), content entries and assets uploaded by editors (including any personal data deliberately embedded in articles such as author photos or testimonial quotes), and operational telemetry generated by the content APIs. The public front end does not typically receive cookies from Contentful, but the admin app at app.contentful.com sets session cookies, anti CSRF tokens and limited analytics cookies (Segment based) for editor authentication and product analytics.

GDPR and ePrivacy implications

Contentful GmbH is a processor for the content entries and editor accounts of its customers and acts as a controller for limited account, billing and product analytics purposes. Because the public website does not load Contentful scripts in the visitor browser, the ePrivacy consent rule is generally not triggered for end users. Legitimate interest under Article 6(1)(f) GDPR is the natural legal basis for backend content delivery. Editor data in app.contentful.com is processed on the basis of the Contentful Data Processing Addendum and the customer relationship.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

Contentful production spaces can be hosted on AWS in eu-central-1 (Frankfurt), us-east-1 (Northern Virginia) or ap-southeast-1 (Singapore), with the CDN spread across additional regions. Even for EU spaces, support staff and monitoring infrastructure in the United States can access metadata. Transfers rely on the Contentful Data Processing Addendum, the EU Standard Contractual Clauses under Article 46(2)(c) GDPR and the EU US Data Privacy Framework, with TLS 1.3 in transit, encryption at rest, ISO 27001, SOC 2 Type II and HIPAA controls for healthcare customers.

Practical compliance steps

Sign the Contentful Data Processing Addendum, choose an EU production space when EU residency matters, configure access controls and Single Sign On for editors, and define retention rules for content versions and uploaded assets. Document Contentful in your record of processing activities, mention Contentful GmbH and the AWS hosting region in the privacy notice, and audit which integrations (Algolia, Segment, Salesforce, OpenAI) may forward visitor data through Contentful webhooks or app actions.

GDPR consent category

Other

Websites using Contentful must obtain user consent under GDPR regulations.

Legal basisLegitimate Interest (Art. 6(1)(f) GDPR) for serving website content; consent (Art. 6(1)(a) GDPR) only if Contentful previews or experiments expose personal data to third parties
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), CCPA

DPIA considerations

A DPIA is generally not required for a public website that uses Contentful to deliver marketing or product content. A DPIA is recommended when Contentful is used to manage personalised content tied to identified visitors, when it serves regulated industries (financial services, health, public sector) or when integrations with Adobe Real Time CDP, Segment or Salesforce push personal data into the content delivery layer.

Sample consent text

This website is built with Contentful, a headless CMS operated by Contentful GmbH (Germany) on AWS infrastructure. Contentful processes the content you see on these pages. No marketing or analytics cookies are set by Contentful itself. Editorial features stored in your administrator account are subject to a separate Data Processing Addendum.

Technical details

Tracking methodContent Delivery API and Preview API consumed by the website backend or frontend; optional Contentful App Framework JS bundles embedded in the admin or in custom widgets
Server locationAmazon Web Services (Contentful GmbH, Germany; production hosted in AWS EU, US East and Asia Pacific regions depending on space)
Cookieless tracking availableYes
Data transferred outside the EUContentful is operated by Contentful GmbH (Berlin, Germany) with subsidiaries in the United States and Switzerland. Spaces can be provisioned in the EU (eu-central-1), US (us-east-1) or APAC. Even for EU spaces, support, monitoring and metadata operations can reach US infrastructure. Transfers are governed by the Contentful Data Processing Addendum, the EU Standard Contractual Clauses under Article 46(2)(c) GDPR and the EU US Data Privacy Framework.

Third-party domains contacted

contentful.comapp.contentful.comcdn.contentful.compreview.contentful.comimages.ctfassets.netassets.ctfassets.netvideos.ctfassets.net

Cookies placed

NameTypeDurationPurpose
_contentful_sessionStrictly necessary (admin only)SessionSet inside app.contentful.com for authenticated editors. Maintains the admin login session and is not present on public websites built with Contentful.
ajs_anonymous_idAnalytics (admin only, after consent)12 monthsSet inside app.contentful.com when the Segment based product analytics is loaded. Used to attribute editor actions to a pseudonymous user. Not present on the public website.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Contentful set cookies on the visitor browser?

No. On a public website built with Contentful, content is rendered server side or at build time and the visitor browser does not load Contentful scripts. Contentful only sets cookies inside app.contentful.com (the editor admin) for authentication, CSRF protection and limited product analytics.

Is visitor consent required for Contentful under GDPR and ePrivacy?

For standard headless usage (server side rendering, static site generation or backend API calls), no visitor consent is required because nothing is stored or read on the device. Consent becomes necessary if Contentful is paired with experiments, personalisation or analytics scripts that store identifiers in the browser.

What is the legal basis for processing data through Contentful?

For backend content delivery, the legal basis is legitimate interest under Article 6(1)(f) GDPR. For editor accounts and customer support, processing relies on the performance of the customer contract under Article 6(1)(b) GDPR and on the Contentful Data Processing Addendum. Personal data deliberately embedded in entries inherits the legal basis chosen by the publishing customer.

How are data transfers to the United States protected?

Contentful signs the EU Standard Contractual Clauses under Article 46(2)(c) GDPR via its Data Processing Addendum, confirms participation in the EU US Data Privacy Framework and offers EU production spaces hosted in AWS eu-central-1. Supplementary measures include TLS 1.3, encryption at rest, ISO 27001, SOC 2 Type II, HIPAA controls and tightly scoped access to customer data.

Is a DPIA required for Contentful?

A DPIA is not required for a typical informational or marketing website. A DPIA is recommended when Contentful is used to deliver personalised content to identified visitors, when the customer is in a regulated sector (financial services, health, public sector) or when integrations propagate personal data to third party systems through webhooks or app actions.

How do I implement Contentful in a GDPR compliant way?

Sign the Contentful Data Processing Addendum, choose an EU production space if EU residency is required, enable Single Sign On for editors, configure granular roles and audit logs, define retention rules for content versions and assets, document Contentful as a processor in your record of processing activities and review every connected integration that exits the EU.

What are the alternatives to Contentful in Europe?

European or self hosted alternatives include Storyblok (Austria), Hygraph (Berlin), Sanity (Norway, US delivery), Strapi (France, self hosted or Strapi Cloud), Payload CMS (open source, self hosted), Directus (open source, self hosted) and Magnolia (Switzerland). The right choice depends on content modelling needs, EU residency requirements and developer experience.

How do I update the cookie policy when using Contentful?

List Contentful GmbH as a processor of the content delivery infrastructure, state that the public website does not load Contentful cookies on the visitor browser, mention that the editor admin (app.contentful.com) sets its own cookies for authenticated administrators, and link to the Contentful privacy statement. No cookie line item is normally needed for end users.