Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
GetSimple CMS is a lightweight, self hosted, flat file content management system that stores content in XML files rather than a database. By default the public website sets no tracking or analytics cookies, so a consent banner is generally not required. The only cookie is a strictly necessary administrator authentication cookie used in the backend, which is exempt from consent under the ePrivacy Directive. Because it is self hosted, there is no transfer of visitor data to third parties by default.
GetSimple CMS is a lightweight, self hosted content management system written in PHP that stores all content in flat XML files instead of a database. It is designed for small websites that need simple page management without the overhead of a database driven platform. Because the site owner installs and runs it on their own server, they remain the sole controller of the content and of any visitor data the server processes.
By default the public website served by GetSimple sets no analytics or marketing cookies and runs no third party tracking. The only cookies are backend administrator cookies, historically including a cookie that stores the administrator username in a GS_ADMIN_USERNAME style value and a hashed authentication cookie that keeps the administrator logged in. These cookies are set only for logged in administrators in the control panel and never for ordinary public visitors.
The administrator authentication cookie is strictly necessary to provide a service the user has explicitly requested, namely logging in to the admin area, so it falls under the Article 5(3) ePrivacy exemption and does not require consent. Since the public site sets no other cookies and performs no tracking, there is normally no personal data processing of visitors beyond standard server logs, which can usually be handled on the basis of legitimate interest with appropriate retention limits.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A consent banner is generally not required for a plain GetSimple site. It becomes necessary only if the site owner adds third party embeds such as web fonts, maps, analytics, or video, because those services set their own cookies and carry their own consent and transfer duties. In that case the consent obligations come from the embedded third parties, not from GetSimple itself, and each added service should be assessed separately.
The main privacy duties for a GetSimple site are operational security rather than consent management. Protect the admin area with strong credentials and HTTPS, restrict access to the data directory that holds the XML files and backups, keep the installation and any plugins updated, and document server log retention in a short privacy notice. If you later add third party content, gate it behind a consent mechanism and disclose any resulting transfers.
Websites using GetSimple CMS must obtain user consent under GDPR regulations.
DPIA considerations
GetSimple CMS is low risk from a data protection perspective. The public website sets no tracking cookies, performs no profiling, and transfers no visitor data to third countries by default, so a DPIA is not normally required. Any assessment should focus on the security of the administrator area and the XML data directory, the retention of server logs, and the separate review of any third party embeds the site owner later adds, since those would introduce their own cookies and transfers.
Sample consent text
This website runs on GetSimple CMS and does not use tracking or analytics cookies. The only cookie is a strictly necessary login cookie used by administrators to access the management area, which does not require your consent. We do not share your browsing data with third parties. If we later add embedded content from other providers, we will ask for your consent before it loads.
Third-party domains contacted
get-simple.infoCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| GS_ADMIN_USERNAME | necessary | Session | Strictly necessary backend cookie that stores the administrator username to support authentication in the GetSimple control panel. Set only for logged in administrators, never for public visitors. |
| GetSimple auth cookie | necessary | Session | Strictly necessary hashed authentication cookie that keeps the administrator logged in to the backend. Exempt from consent under the ePrivacy Directive as it is required for the requested login service. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
By default GetSimple sets no cookies for public visitors. It sets only backend administrator cookies, historically a cookie storing the administrator username in a GS_ADMIN_USERNAME style value and a hashed authentication cookie that keeps the administrator logged in. These are session cookies used only inside the control panel.
Generally no. The public site sets no tracking cookies, and the only cookie is a strictly necessary administrator login cookie that is exempt from consent under Article 5(3) of the ePrivacy Directive. Consent becomes relevant only if you add third party embeds such as fonts, maps, analytics, or video.
The administrator authentication cookie is strictly necessary to provide the login service the administrator has requested, so it relies on the ePrivacy exemption rather than consent. Any limited processing of visitor data, such as server logs, can normally rely on legitimate interest under Article 6(1)(f) of the GDPR with appropriate retention limits.
No, not by default. GetSimple is self hosted, so visitor data stays on your own server and is not sent to third parties or third countries. The only external connection is an optional update check and the extend plugin repository on get-simple.info, which is initiated from the admin backend, not by public visitors.
No, a DPIA is not normally required for a plain GetSimple site because it sets no tracking cookies, performs no profiling, and makes no international transfers. A short risk note is enough, and you should only revisit the assessment if you add third party embeds that introduce their own cookies and transfers.
Focus on operational security rather than consent banners. Use strong administrator credentials and HTTPS, restrict access to the data directory that holds the XML files and backups, keep the core and any plugins updated, and publish a short privacy notice covering server log retention. Add a consent mechanism only if you later embed third party content.
Other lightweight or flat file systems include WordPress for a database driven option with a large ecosystem, and Kirby or Grav for flat file content management similar in spirit to GetSimple. The right choice depends on whether you prefer a simple flat file setup or a richer plugin ecosystem, and on your maintenance capacity.
For a default installation you can simply state that the site uses only a strictly necessary administrator login cookie and no tracking. You only need to expand the cookie policy if you add third party embeds, in which case list each added service, its cookies, durations, and any data transfers it introduces.