Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Graffiti CMS is an open source content management system built on the .NET framework, used to publish and manage websites and blogs. Because it is self hosted, it runs on the website owner infrastructure and sets only first party cookies, such as a session cookie and an authentication cookie for editors. It does not add third party tracking by default, so its privacy profile is low risk and centred on first party essentials.
Graffiti CMS is an open source content management system built on the .NET framework. It is installed on your own server to publish and manage websites and blogs, which means you control the code, the data, and the hosting. Unlike a hosted platform, there is no vendor receiving data in the background.
Graffiti CMS sets first party cookies such as a session cookie and an authentication cookie for logged in editors. If you enable comments or contact forms, it stores the data those features collect. All of this is first party, served from your own domain, and it does not include third party advertising or analytics unless you add such tools yourself.
You are the controller for any personal data the CMS handles, such as commenter names or contact submissions. Because the cookies are strictly necessary and first party, and there is no third party sharing by default, the GDPR footprint is small and focused on security, retention, and responding to data subject requests.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The strictly necessary first party cookies do not require consent under the ePrivacy Directive. Consent becomes relevant only if you add analytics, embeds, or marketing tools to your Graffiti site, in which case those specific tools must be gated behind consent, not the CMS itself.
Because Graffiti CMS is self hosted, the data location is wherever you run the server. If you host within the European Economic Area, there is no international transfer. If you host elsewhere, the transfer rules apply to your hosting choice rather than to the CMS software.
Keep the installation secure and updated, set retention for comments and form submissions, and document the first party cookies in your cookie policy as essential. Choose EU hosting if your users are European, and apply consent only to any third party tools you add on top of the CMS.
Websites using Graffiti CMS must obtain user consent under GDPR regulations.
DPIA considerations
As a self hosted first party CMS, the data protection focus is on the cookies it sets, any comment or contact data it stores, the security of the server, and any third party tools you add yourself. A DPIA is rarely needed for the CMS alone.
Sample consent text
This site runs on Graffiti CMS and uses only strictly necessary first party cookies to function. Any analytics or marketing tools are listed separately and run only with your consent.
Cookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ASP.NET_SessionId | Functional | Session | First party session cookie that maintains the visitor session on the server. |
| .GRAFFITI_AUTH | Functional | Session | First party authentication cookie that keeps logged in editors signed in to the admin area. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
It sets first party cookies such as a session cookie and an authentication cookie for editors. These are strictly necessary to run the site and the admin area, and they are served from your own domain.
No, not for the strictly necessary first party cookies. Consent applies only to any analytics, embeds, or marketing tools you choose to add to your Graffiti site.
The essential cookies rely on the ePrivacy exemption, and any personal data the CMS stores, such as comments, relies on a basis you set such as consent or legitimate interest. You are the controller.
Not by itself. As self hosted software it transfers nothing to a vendor, so the data location depends entirely on where you host the site. Host in the EU to avoid transfers.
Rarely for the CMS alone. A DPIA may be relevant if you build high risk features on top of it, such as large scale collection of sensitive data through forms.
Keep it updated and secure, set retention for comments and form data, document the first party cookies as essential, and add consent only for third party tools. Honour data subject requests for any stored personal data.
Alternatives include WordPress, Ghost, and other self hosted content management systems. The privacy profile of any self hosted CMS is similar and depends mainly on what you add to it.
List the first party session and authentication cookies as strictly necessary. There are no third party tracking cookies from the CMS itself, so only add entries for tools you integrate separately.