FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Kirby

Kirby

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Kirby do?

German file based self hosted PHP CMS by Content Folder GmbH (Berlin). DSGVO friendly by design with no telemetry, no tracking and minimal cookies. Popular among German agencies and designers.

What Kirby is

Kirby is a self hosted file based PHP content management system created in 2009 by Bastian Allgeier and developed by Content Folder GmbH in Berlin, Germany. Unlike database driven platforms, Kirby stores all content as plain text files (Markdown, YAML and TXT) in a structured folder hierarchy directly on the customer server. It is distributed under a commercial licence with a free trial, and the controller installs and operates the application on their own infrastructure. Kirby is particularly popular with German agencies, designers and privacy conscious organisations that need a flexible CMS without external dependencies.

Why Kirby is DSGVO friendly by design

Kirby is one of the most DSGVO and GDPR friendly content management systems available. The core product contains no telemetry, no analytics call back, no third party tracking and no automatic font, map or video loading. Content is stored as flat files on infrastructure chosen by the controller, so there is no forced transfer to third countries. The only outbound call from the core is a one time licence validation request to Content Folder GmbH in Berlin when the licence key is activated. This minimal architecture means the controller keeps full sovereignty over the data and over the hosting region.

What data Kirby stores

In its default configuration Kirby processes only administrative data: editor accounts (email, hashed password, role), session and authentication cookies for the back office, server access logs created by the host and the content files themselves. Public visitors do not receive tracking cookies, no analytics identifier, no fingerprinting and no third party script is loaded by the core. Any additional personal data, such as form submissions, comments or membership profiles, only exists when the controller installs a dedicated plugin and is fully under the controller responsibility.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

GDPR and ePrivacy implications

Because the Kirby core does not set tracking cookies and does not call third party services, the ePrivacy and TTDSG cookie consent obligations do not apply to a default installation. The legal basis for processing administrative data is the performance of the contract with the editors and the legitimate interest of the controller to secure the back office (Art. 6(1)(b) and (f) GDPR). No international transfer is triggered by the core, so standard contractual clauses are not required for Kirby itself. Compliance obligations are limited to the editorial team accounts and the optional plugins chosen by the controller.

Practical compliance steps

Document the Kirby installation in the record of processing activities, choose an EU or local hosting provider, sign a data processing agreement with that hosting provider, enable TLS, configure strong password rules for editors and review every plugin or front end integration that loads external resources (web fonts, embedded videos, maps, captchas, analytics). Any such integration must be added to the cookie banner and to the privacy policy, and may require user consent. Keep Kirby and its plugins up to date and review server access logs retention.

Focus on the German market

Kirby is a strong fit for the German market and for any organisation that must comply with the DSGVO and the TTDSG. Its Berlin based publisher, its self hosted architecture, the absence of telemetry and the file based content model make it one of the safest choices for agencies serving public sector clients, healthcare providers, law firms and design studios that prioritise data sovereignty. Many German agencies have standardised on Kirby precisely because it allows them to deliver fast, design driven websites without inheriting the compliance burden of US hosted SaaS content platforms.

GDPR consent category

Other

Websites using Kirby must obtain user consent under GDPR regulations.

Legal basisPerformance of contract (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f) GDPR) for administrative authentication; no consent required for the core CMS because no tracking cookies are set
Risk levellow
Applicable regulationsDSGVO, ePrivacy Directive (Cookie Law)

DPIA considerations

A DPIA is rarely required for the Kirby core because it is self hosted, file based and ships with no telemetry, no analytics and no third party tracking. The default cookies are limited to administrative session and authentication cookies that are strictly necessary to operate the back office. A DPIA may become relevant when the controller adds plugins that process personal data (forms, comments, newsletters, member areas), connects external services (analytics, embeds, captchas) or processes special categories of data through Kirby driven applications.

Sample consent text

No prior consent is required to use the Kirby CMS core because it does not set tracking cookies and does not call third party services from the public website. Only strictly necessary cookies are used for the administrative panel. Consent must be collected separately for any optional plugin or front end feature that loads third party scripts, embeds or analytics.

Technical details

Tracking methodSelf hosted PHP CMS (file based, no built in tracking or telemetry)
Server locationSelf hosted (customer chosen) by Content Folder GmbH (Berlin) for licensing only
Cookieless tracking availableYes

Third-party domains contacted

getkirby.comlicenses.getkirby.com

Cookies placed

NameTypeDurationPurpose
kirby_sessionStrictly necessary (session)Session (deleted on browser close)Maintains the administrative session for editors logged into the Kirby back office. Not used for visitors of the public website.
kirby_authStrictly necessary (authentication)Session, or up to 2 weeks if the editor enables the remember me optionStores the authentication token that keeps the editor signed into the Kirby panel. Only set after a successful back office login and limited to administrative users.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does the Kirby CMS set tracking cookies on visitors?

No. The Kirby core does not set any tracking, analytics or marketing cookies. The only cookies created in a default installation are administrative session and authentication cookies (kirby_session and kirby_auth) that are limited to the back office and considered strictly necessary. Public visitors who never log in do not receive any cookies from the CMS itself.

Do I need user consent to run a website with Kirby?

No prior consent is required for the Kirby CMS core because it does not deposit tracking cookies and does not call third party services from the public site. Consent only becomes mandatory when the controller adds optional plugins or front end integrations that load external scripts, analytics, embedded videos, maps, captchas or web fonts, in which case the usual ePrivacy and TTDSG rules apply.

What is the legal basis for the administrative data processed by Kirby?

The administrative data processed by Kirby (editor accounts, session cookies, back office authentication) relies on the performance of the contract with the editors (Art. 6(1)(b) GDPR) and on the legitimate interest of the controller to secure the back office (Art. 6(1)(f) GDPR). No consent based legal basis is required because the system does not perform any tracking by default.

Does Kirby transfer personal data to third countries?

The Kirby core does not transfer personal data to third countries. It is installed on infrastructure chosen by the controller, who can keep the data entirely within Germany or the European Economic Area. The only outbound call is a one time licence validation request to Content Folder GmbH in Berlin, which stays inside the EU.

Do I need a DPIA for a website built with Kirby?

A DPIA is rarely required for the Kirby core because it is self hosted, file based and ships with no telemetry, no analytics and no third party tracking. A DPIA may become relevant if the controller installs plugins that process large volumes of personal data, special categories or systematically monitor users, or if Kirby is used as the basis of an application that triggers Art. 35 GDPR criteria.

What practical steps should I take to deploy Kirby in a GDPR friendly way?

Host Kirby with a provider located in the EU or your jurisdiction, sign a data processing agreement, enable TLS, enforce strong password and role policies for editors, keep Kirby and plugins up to date, log only what is needed and define a retention period for access logs. Review every plugin and front end integration that loads third party resources and add them to the cookie banner and privacy policy as required.

What are the main alternatives to Kirby for privacy first projects?

Privacy oriented alternatives to Kirby include Statamic (another flat file PHP CMS with optional database), ProcessWire, Craft CMS, Bludit (lightweight flat file), Grav (flat file PHP CMS) and October CMS. All of them can be self hosted, but Kirby remains particularly attractive for the German market thanks to its Berlin based vendor, its file based architecture and its strict no telemetry policy.

Do I need to mention Kirby in my cookie policy?

You do not need to declare Kirby itself in the cookie banner because its core only uses strictly necessary cookies for the administrative back office. The privacy policy should still describe the editorial accounts, the hosting provider acting as processor, the retention of access logs and any plugin or front end integration that loads external resources or sets additional cookies.