FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Sanity

Sanity

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Sanity do?

Sanity is a Norwegian headless CMS built around a real time content lake. Editors work in Sanity Studio and content is delivered through REST and GROQ APIs over HTTPS. The public delivery API does not set cookies on visitors, so it is GDPR friendly by default when the EU dataset region is selected.

What Sanity is and how it serves content

Sanity is a headless content platform founded in Oslo, Norway in 2015 by Sanity.io AS. It is built around a real time content lake. Editors author structured content in Sanity Studio, a React based editing UI usually hosted by the customer or on sanity.studio. The published content is queried by the frontend via REST or the GROQ query language and delivered through the Sanity CDN. Like other modern headless platforms, the public delivery is stateless and cookie free.

Cookies and identifiers set on visitors

On the public website Sanity sets no cookies. The content delivery responses only contain JSON and standard cache headers. Cookies appear in three editor only contexts. The Sanity Studio uses a session cookie to authenticate editors. The sanity.io account portal sets an authentication cookie for the dashboard. Sanity Insights, when enabled in the Studio for project owners, may use Plausible Analytics for usage statistics, scoped to the Studio domain.

GDPR and ePrivacy implications

Because the public Sanity API does not place identifiers on the visitor terminal, Article 5(3) of the ePrivacy Directive does not require prior consent. Article 6(1)(f) GDPR (legitimate interest) covers the limited request metadata processed at the CDN edge. Sanity.io AS acts as a processor under Article 28 GDPR when storing the customer content. The DPA is available in the Sanity dashboard and the corporate entity in Oslo provides additional comfort regarding GDPR enforcement.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and Schrems II

Sanity offers a EU dataset region (Frankfurt) and a US dataset region (Iowa). For European projects, create the dataset with the EU region. The dataset region cannot be changed after creation without an export and import. The corporate sanity.io login portal and some support tools may route requests through the United States. Plausible Analytics used by Sanity Insights is operated from the EU (Germany) which avoids US transfers for that telemetry.

Practical compliance steps

Create the production dataset in the EU region. Sign the Sanity DPA. Document the processor in your RoPA with dataset name, region, retention and the asset CDN. Host the Sanity Studio on your own domain behind authentication (SSO via Google, GitHub, SAML). Restrict the API tokens by dataset and permission scope. Use the read only published view client for the public site instead of admin tokens. If you embed third party scripts in your frontend, gate them with a consent management platform, the Sanity delivery itself is out of scope.

GDPR consent category

Other

Websites using Sanity must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(f) GDPR (legitimate interest) for content delivery and abuse prevention. Strictly necessary cookies are used in Sanity Studio for editor authentication. No consent required for the public API.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, Norwegian Personal Data Act, DSGVO, RGPD, LSSI, Schrems II only when the US dataset region or US asset CDN endpoints are selected

DPIA considerations

A DPIA is not required for the public delivery API in most cases as no personal data is processed on visitors beyond standard request logs. A DPIA should be considered when Sanity is paired with Sanity Insights, personalization features, user generated content, or when special category data is stored in the content lake. Document the EU region selection, the DPA signed with Sanity.io AS and the access controls on Sanity Studio.

Sample consent text

This website uses Sanity to deliver editorial content. The Sanity API does not set cookies and does not track visitors. No consent is required. Authentication cookies only apply to editors signed into Sanity Studio.

Technical details

Tracking methodHeadless CMS with a real time content lake exposed via REST and GROQ APIs over HTTPS, plus the Studio (editor UI) that authenticates editors with an OAuth2 session cookie. The public API does not set cookies on website visitors. Optional Sanity Vision and Sanity Insights are admin tools and do not run on the public website.
Server locationSanity.io AS (Oslo, Norway). The content lake runs on Google Cloud Platform with regions in the EU (eu central 1 Frankfurt) and the US (us central 1 Iowa). Asset CDN by Google Cloud CDN with global PoPs. Sanity Studio is typically hosted by the customer or on sanity.studio.
Cookieless tracking availableYes

Third-party domains contacted

sanity.ioapi.sanity.ioapicdn.sanity.iocdn.sanity.iosanity.studiosanity.work

Cookies placed

NameTypeDurationPurpose
sanitySessionfirst-party (Sanity Studio only)SessionSession cookie used inside Sanity Studio to authenticate a logged in editor. Strictly necessary, never set on the public website.
sanity-management-tokenfirst-party (account portal only)Up to 30 daysAuthentication token for the sanity.io account portal. Strictly necessary for the customer dashboard, not present on public websites.
sb_anonfirst-party (Studio analytics)30 daysAnonymous identifier optionally set by Plausible Analytics inside Sanity Insights when the project owner enables Studio usage tracking. Scoped to the Studio domain.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Sanity set cookies on website visitors?

No. The public Sanity REST and GROQ APIs deliver JSON without any cookies. Cookies only appear in Sanity Studio (editor session), in the sanity.io account portal, and optionally in Plausible Analytics inside Sanity Insights, all of which are editor side and never visible to the website visitor.

Do I need consent for Sanity under GDPR and ePrivacy?

No consent is required for the public Sanity delivery because no identifier is stored on the visitor terminal. Consent only becomes relevant if your frontend embeds third party trackers whose content was fed by Sanity.

What is the legal basis for processing visitor data with Sanity?

Article 6(1)(f) GDPR (legitimate interest) covers the request metadata processed for content delivery and security. The customer is the controller of the content stored in Sanity. Sanity.io AS is a processor under Article 28 GDPR with a DPA available in the dashboard.

Does Sanity transfer data to the United States?

Not when the EU dataset region is selected, the content lake stays in Frankfurt and the asset CDN serves from Google Cloud EU regions. The US dataset region (Iowa) is optional. The sanity.io login portal may route through US infrastructure for the editor flow.

Is a DPIA required for Sanity?

A DPIA is not generally required for a public editorial deployment. It should be considered when Sanity stores sensitive content, when Sanity Insights is enabled, when personalization or A/B testing is layered on top, or when the US dataset region is used.

How do I implement Sanity compliantly?

Create the dataset in the EU region, sign the DPA, host Sanity Studio on your own domain with SSO, restrict API tokens by permission scope, document the processor in your RoPA, use a read only client for the public site and govern any third party scripts in the frontend through a consent management platform.

What are the alternatives to Sanity?

Other headless CMS options used in Europe include Storyblok (Austria), Strapi (France), Contentful (Germany), Hygraph (Germany), Directus (Germany, open source), Payload CMS (open source) and Wagtail (Python, open source).

How do I update the cookie policy for Sanity?

No Sanity specific cookie disclosure is needed for the public site when no cookies are set. List Sanity as the content processor in your privacy policy with the dataset region, purpose, retention and DPA reference. Editor only cookies inside Sanity Studio do not need to appear in the public cookie banner.