FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Graffiti CMS
G

Graffiti CMS

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Graffiti CMS do?

Graffiti CMS is an open source content management system built on the .NET framework, used to publish and manage websites and blogs. Because it is self hosted, it runs on the website owner infrastructure and sets only first party cookies, such as a session cookie and an authentication cookie for editors. It does not add third party tracking by default, so its privacy profile is low risk and centred on first party essentials.

What Graffiti CMS is

Graffiti CMS is an open source content management system built on the .NET framework. It is installed on your own server to publish and manage websites and blogs, which means you control the code, the data, and the hosting. Unlike a hosted platform, there is no vendor receiving data in the background.

What data and cookies it uses

Graffiti CMS sets first party cookies such as a session cookie and an authentication cookie for logged in editors. If you enable comments or contact forms, it stores the data those features collect. All of this is first party, served from your own domain, and it does not include third party advertising or analytics unless you add such tools yourself.

GDPR implications

You are the controller for any personal data the CMS handles, such as commenter names or contact submissions. Because the cookies are strictly necessary and first party, and there is no third party sharing by default, the GDPR footprint is small and focused on security, retention, and responding to data subject requests.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

The strictly necessary first party cookies do not require consent under the ePrivacy Directive. Consent becomes relevant only if you add analytics, embeds, or marketing tools to your Graffiti site, in which case those specific tools must be gated behind consent, not the CMS itself.

Data location and transfers

Because Graffiti CMS is self hosted, the data location is wherever you run the server. If you host within the European Economic Area, there is no international transfer. If you host elsewhere, the transfer rules apply to your hosting choice rather than to the CMS software.

Practical compliance steps

Keep the installation secure and updated, set retention for comments and form submissions, and document the first party cookies in your cookie policy as essential. Choose EU hosting if your users are European, and apply consent only to any third party tools you add on top of the CMS.

GDPR consent category

Other

Websites using Graffiti CMS must obtain user consent under GDPR regulations.

Legal basisLegitimate interest or contract for strictly necessary first party cookies
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

As a self hosted first party CMS, the data protection focus is on the cookies it sets, any comment or contact data it stores, the security of the server, and any third party tools you add yourself. A DPIA is rarely needed for the CMS alone.

Sample consent text

This site runs on Graffiti CMS and uses only strictly necessary first party cookies to function. Any analytics or marketing tools are listed separately and run only with your consent.

Technical details

Tracking methodSelf hosted .NET content management system, first party cookies, no third party tracking by default
Server locationSelf hosted on the website owner infrastructure

Cookies placed

NameTypeDurationPurpose
ASP.NET_SessionIdFunctionalSessionFirst party session cookie that maintains the visitor session on the server.
.GRAFFITI_AUTHFunctionalSessionFirst party authentication cookie that keeps logged in editors signed in to the admin area.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Graffiti CMS set?

It sets first party cookies such as a session cookie and an authentication cookie for editors. These are strictly necessary to run the site and the admin area, and they are served from your own domain.

Do I need consent for Graffiti CMS?

No, not for the strictly necessary first party cookies. Consent applies only to any analytics, embeds, or marketing tools you choose to add to your Graffiti site.

What is the legal basis for Graffiti CMS?

The essential cookies rely on the ePrivacy exemption, and any personal data the CMS stores, such as comments, relies on a basis you set such as consent or legitimate interest. You are the controller.

Does Graffiti CMS transfer data outside the EU?

Not by itself. As self hosted software it transfers nothing to a vendor, so the data location depends entirely on where you host the site. Host in the EU to avoid transfers.

Is a DPIA needed for Graffiti CMS?

Rarely for the CMS alone. A DPIA may be relevant if you build high risk features on top of it, such as large scale collection of sensitive data through forms.

How do I keep a Graffiti site compliant?

Keep it updated and secure, set retention for comments and form data, document the first party cookies as essential, and add consent only for third party tools. Honour data subject requests for any stored personal data.

Are there alternatives to Graffiti CMS?

Alternatives include WordPress, Ghost, and other self hosted content management systems. The privacy profile of any self hosted CMS is similar and depends mainly on what you add to it.

How do I update my cookie policy for Graffiti CMS?

List the first party session and authentication cookies as strictly necessary. There are no third party tracking cookies from the CMS itself, so only add entries for tools you integrate separately.