FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Prismic

Prismic

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Prismic do?

Prismic is a French headless CMS founded in Paris. Editors author content with Slice Machine and the published JSON is delivered through a Content API. The public delivery is cookieless and GDPR friendly, only editor authentication and the optional Preview feature set cookies.

What Prismic is and how it serves content

Prismic is a headless CMS founded in Paris in 2013 by Prismic SAS. It uses a slice based composition model: developers define Slices (reusable components) in Slice Machine and editors arrange them in the page builder. The published content is served as JSON via the Content API. The frontend, often built with Next.js, Nuxt, SvelteKit or any framework, fetches the JSON server side or client side and renders the HTML.

Cookies and identifiers set on visitors

On the public website Prismic sets no cookies. The Content API and the asset CDN respond with JSON or media without writing identifiers on the visitor browser. Cookies appear in two editor contexts. The prismic.io application uses a session cookie to authenticate editors. The Preview feature, when an editor activates it from prismic.io, sets a short lived io.prismic.preview cookie on the customer site so that the editor sees the draft version of the page. That cookie disappears once preview is exited and is never set on a non editor session.

GDPR and ePrivacy implications

Because the Prismic public delivery does not store any identifier on the visitor terminal, Article 5(3) of the ePrivacy Directive does not require prior consent. Article 6(1)(f) GDPR (legitimate interest) covers the limited request logs at the CDN. Prismic SAS acts as processor under Article 28 GDPR with a DPA available in the dashboard. The Preview cookie used by editors is strictly necessary and falls under the ePrivacy carveout for technical cookies.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and Schrems II

Content is stored on AWS, by default in regions chosen during space creation, with EU options available on higher plans. The prismic.io editor application and customer login portal are operated from the US, which involves a transfer covered by Standard Contractual Clauses and the EU US Data Privacy Framework. The asset CDN is global via Cloudflare. For strict EU only requirements, contact Prismic about regional pinning options for content storage.

Practical compliance steps

Sign the Prismic DPA and document the processor in your RoPA. Enable SSO and 2FA for editor accounts. Limit Preview access to authorized editors and audit the io.prismic.preview cookie occurrences. Restrict API tokens by repository and permission scope. Make sure your frontend gates any third party tracker (Google Analytics, Meta Pixel, video) behind a consent management platform. Disclose the EU US data transfer for editor flows in your privacy policy.

GDPR consent category

Other

Websites using Prismic must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(f) GDPR (legitimate interest) for content delivery and abuse prevention. The preview cookie used by editors is strictly necessary. No consent required for the public delivery.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, DSGVO, RGPD, LSSI, Schrems II for editor flows routed through the US

DPIA considerations

A DPIA is generally not needed for public Prismic content delivery. It should be considered if Prismic is combined with personalization, profiling or user generated content, or when content storage is configured in the US region for European visitors. Document the EU region selection (if available on your plan), the DPA with Prismic SAS and the access controls on the editor interface.

Sample consent text

This website uses Prismic to deliver editorial content. The Prismic Content API does not set cookies on visitors. No consent is required. Authentication and preview cookies only apply to editors logged into prismic.io.

Technical details

Tracking methodHeadless CMS with content modeled in Slice Machine and delivered via a REST and GraphQL Content API over HTTPS. The frontend fetches JSON, no cookies are set on visitors. Editors use prismic.io which sets session cookies. Prismic also includes a Preview feature that, when activated, sets a temporary preview cookie for editors to see drafts on the live site.
Server locationPrismic SAS (Paris, France). Hosting on Amazon Web Services with deployment in EU (Frankfurt) and US (us east 1 Virginia) regions, plus a global Cloudflare CDN for asset delivery. Editorial backend at prismic.io is operated from the United States by default with EU regions available.
Cookieless tracking availableYes
Data transferred outside the EUPrismic content storage is multi region and editor login can route through US infrastructure. The asset CDN (cdn.prismic.io, images.prismic.io) is served globally by Cloudflare. The published content API serves data without setting any cookie on visitors. For European projects an enterprise plan offers EU region pinning.

Third-party domains contacted

prismic.iocdn.prismic.ioimages.prismic.ioasset.prismic.iostatic.cdn.prismic.io

Cookies placed

NameTypeDurationPurpose
io.prismic.previewfirst-party (editor preview only)Up to 30 minutesTemporary cookie set when a logged in editor activates Preview from prismic.io to render the draft version of the page. Removed when preview is exited. Strictly necessary.
prismic-authfirst-party (prismic.io only)SessionAuthenticates an editor on the prismic.io application. Not set on customer websites.
io.prismic.previewSessionfirst-party (preview UUID)SessionStores the preview session UUID used by the Prismic preview backend. Set only during an active Preview, never on anonymous visitors.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Prismic set cookies on website visitors?

No. The public Prismic Content API and asset CDN deliver JSON and media without setting cookies on visitors. The only cookies are io.prismic.preview (temporary, set for logged in editors when Preview is active) and session cookies on prismic.io for editor authentication.

Do I need consent for Prismic under GDPR and ePrivacy?

No consent is needed for the public Prismic delivery because no identifier is written on the visitor terminal. The editor only Preview cookie is strictly necessary. Consent only applies to third party scripts you embed in your frontend through Prismic content.

What is the legal basis for processing visitor data with Prismic?

Article 6(1)(f) GDPR (legitimate interest) covers the request logs needed for content delivery and abuse prevention. Prismic SAS is a processor under Article 28 GDPR with a DPA available in the dashboard.

Does Prismic transfer data to the United States?

The prismic.io editor application and customer portal are operated from the United States. Content storage runs on AWS in the region chosen during space creation. Transfers are covered by Standard Contractual Clauses and the EU US Data Privacy Framework. Disclose this transfer in your privacy policy.

Is a DPIA required for Prismic?

A DPIA is generally not required for a public editorial deployment because no visitor profiling happens. It is recommended when Prismic is combined with personalization, AI features, large volumes of user generated content or sensitive data.

How do I implement Prismic compliantly?

Sign the Prismic DPA, enable SSO and 2FA for editors, restrict API tokens by repository and scope, limit Preview access to authorized editors, document the processor in your RoPA and govern third party scripts in your frontend through a consent management platform.

What are the alternatives to Prismic?

EU headless CMS alternatives include Storyblok (Austria), Strapi (France), Contentful (Germany), Hygraph (Germany), Sanity (Norway), Directus (open source) and Payload CMS (open source).

How do I update the cookie policy for Prismic?

List Prismic as a content processor in your privacy policy with hosting region, purpose and DPA reference. Mention the editor only io.prismic.preview cookie if your privacy policy details strictly necessary cookies. The public site can omit Prismic from the cookie banner because no cookies are placed on regular visitors.