FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Sitecore

Sitecore

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Sitecore do?

Sitecore is an enterprise digital experience platform headquartered in Canada. The classic Sitecore XP can set visitor analytics cookies on the public site through xDB, while Sitecore XM Cloud is headless and only sets cookies through xConnect or Sitecore CDP/Personalize when those add ons are enabled. Consent management is required when those tracking features are active.

What Sitecore is and how it serves content

Sitecore is an enterprise digital experience platform from Sitecore Holdings (Toronto, Canada). The product family includes Sitecore XP (classic content management with the xDB analytics database), Sitecore XM and XM Cloud (modern composable headless), Sitecore CDP, Sitecore Personalize, Sitecore Content Hub and Sitecore Send. Pages are rendered server side on .NET or fetched via the Experience Edge GraphQL API in the headless XM Cloud model. Sitecore is positioned for large brands needing deep personalization.

Cookies and identifiers set on visitors

Sitecore XP with xDB enabled sets SC_ANALYTICS_GLOBAL_COOKIE (persistent visitor identifier, default 10 years) and SC_ANALYTICS_SESSION_COOKIE (session) on the public site. The Sitecore CDP product sets a _sc_browser_id or similar identifier to merge visitor behavior across pages. Sitecore Personalize uses _bx_uuid for experimentation. The XM Cloud Experience Edge delivery itself is cookieless if no analytics or personalization is layered on top. The ASP.NET backoffice authentication cookies are strictly necessary for editors.

GDPR and ePrivacy implications

The xDB, CDP and Personalize features create persistent visitor identifiers tied to behavioral profiles, so Article 5(3) of the ePrivacy Directive requires prior opt in consent under EDPB guidelines. Article 6(1)(a) GDPR (consent) is the legal basis. The customer is controller and Sitecore is processor under Article 28 GDPR. A signed DPA is part of the Sitecore Master Subscription Agreement. The xDB retention period and the right to erasure must be configurable, Sitecore exposes APIs for both.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and Schrems II

Sitecore Cloud services run on Microsoft Azure and EU customers should explicitly request a West Europe or North Europe deployment in the order form. Sitecore CDP and Personalize default to US infrastructure unless an EU pinning is negotiated. Sitecore corporate identity, support tooling and product analytics include US and Canada based providers covered by Standard Contractual Clauses and the EU US Data Privacy Framework. Document these transfers in your record of processing activities and your privacy notice.

Practical compliance steps

Wire Sitecore into your consent management platform with Google Consent Mode v2 or IAB TCF signals. Block xDB, CDP and Personalize tags until consent is granted. Configure xDB retention to the minimum needed for the analytics use case. Request the EU region for Sitecore CDP and Personalize. Sign the DPA. Document a procedure to honour data subject access and erasure requests via the Sitecore xConnect and CDP APIs. Restrict backoffice access to a corporate VPN with SSO and 2FA.

GDPR consent category

Other

Websites using Sitecore must obtain user consent under GDPR regulations.

Legal basisConsent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy is required for xDB analytics cookies, Sitecore CDP visitor identifiers and Personalize experimentation tags because they go beyond strictly necessary processing. Strictly necessary cookies (ASP.NET session, antiforgery) for the editor backoffice can rely on legitimate interest.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, DSGVO, RGPD, LSSI, Canadian PIPEDA, Schrems II, EU US Data Privacy Framework, IAB TCF when integrated with consent management vendors

DPIA considerations

A DPIA is generally recommended for Sitecore deployments that use xDB analytics, Sitecore CDP, Sitecore Personalize or Sitecore Send because they enable visitor profiling. Document the legal basis for each feature, the EU region selection, the retention period in xDB or CDP and the integration with a consent management platform that emits IAB TCF or Google Consent Mode signals.

Sample consent text

This website uses Sitecore as its digital experience platform. Sitecore stores analytics and personalization cookies (SC_ANALYTICS_GLOBAL_COOKIE, _sc_session) to recognize you and to deliver tailored content. You can accept or refuse these cookies via the consent banner. Refusing leaves only strictly necessary cookies.

Technical details

Tracking methodEnterprise digital experience platform combining content management, personalization and analytics. Sitecore Experience Platform (XP) and Sitecore Experience Manager (XM) set cookies on the public site by default (SC_ANALYTICS_GLOBAL_COOKIE, SC_ANALYTICS_SESSION_COOKIE) when xDB analytics is enabled. The modern Sitecore XM Cloud is headless and only sets cookies through xConnect or Sitecore CDP/Personalize when explicitly activated.
Server locationSitecore Holdings (Toronto, Canada and San Francisco) operates Sitecore XM Cloud, Sitecore Content Hub, Sitecore Send, Sitecore CDP and Sitecore Personalize on Microsoft Azure. EU customers can request Azure West Europe (Netherlands) or North Europe (Ireland) deployments. On premise Sitecore is hosted by the customer on Windows Server with SQL Server, typically in EU data centers.
Cookieless tracking availableYes
Data transferred outside the EUSitecore Cloud services can be pinned to Azure West Europe or North Europe but the Sitecore corporate identity provider, support tooling and product analytics include US and Canada based infrastructure. Sitecore CDP and Personalize process visitor identifiers in the United States by default unless an EU region is explicitly negotiated. Standard Contractual Clauses are signed in the master agreement.

Third-party domains contacted

sitecore.comsitecorecloud.ioexperienceedge.sitecorecloud.ioboxever.comcdp.sitecorecloud.iocdn.boxever.com

Cookies placed

NameTypeDurationPurpose
SC_ANALYTICS_GLOBAL_COOKIEfirst-party (Sitecore xDB)10 years (default)Persistent visitor identifier created by Sitecore xDB to merge sessions and build behavioral profiles. Requires consent under ePrivacy.
SC_ANALYTICS_SESSION_COOKIEfirst-party (Sitecore xDB)SessionSession identifier for the current visit in Sitecore xDB. Used together with the global cookie to capture page views and goals.
_sc_browser_idfirst-party (Sitecore CDP)1 yearBrowser identifier used by Sitecore CDP to merge cross device behavior. Requires consent.
_bx_uuidfirst-party (Sitecore Personalize)1 yearUUID assigned by Sitecore Personalize for experimentation and audience evaluation. Requires consent.
.ASPXAUTHfirst-party (backoffice only)SessionASP.NET authentication cookie for logged in editors of Sitecore XP. Strictly necessary, never set on the public site.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Sitecore set cookies on website visitors?

Yes when xDB analytics, Sitecore CDP or Sitecore Personalize are activated. SC_ANALYTICS_GLOBAL_COOKIE (persistent, default 10 years) and SC_ANALYTICS_SESSION_COOKIE (session) come from xDB. Sitecore CDP and Personalize add their own identifier cookies. Without these add ons, the headless XM Cloud delivery is cookieless.

Do I need consent for Sitecore under GDPR and ePrivacy?

Yes for xDB analytics, Sitecore CDP and Personalize because they create persistent visitor profiles. Article 5(3) ePrivacy and EDPB guidelines require prior opt in consent. The strictly necessary backoffice cookies for editors do not require consent.

What is the legal basis for processing visitor data with Sitecore?

Article 6(1)(a) GDPR (consent) for xDB, CDP, Personalize and Send. Article 6(1)(f) (legitimate interest) for the backoffice operation and security logs. The customer is the controller, Sitecore is the processor with a DPA in the Master Subscription Agreement.

Does Sitecore transfer data to the United States?

Sitecore is headquartered in Canada with US infrastructure. EU customers must explicitly request West Europe or North Europe Azure deployments for XM Cloud and Content Hub. Sitecore CDP and Personalize default to US infrastructure unless an EU pinning is negotiated. SCCs and the EU US Data Privacy Framework cover residual transfers.

Is a DPIA required for Sitecore?

A DPIA is recommended whenever xDB, Sitecore CDP, Personalize or Send are used because they perform visitor profiling. Document the legal basis, retention period, EU pinning of CDP and Personalize and the consent management integration.

How do I implement Sitecore compliantly?

Wire Sitecore into your consent management platform, block xDB/CDP/Personalize tags until consent, configure xDB retention conservatively, request EU pinning for CDP/Personalize, sign the DPA, document a DSAR procedure via xConnect and CDP APIs, secure the backoffice with VPN, SSO and 2FA.

What are the alternatives to Sitecore?

Other enterprise digital experience platforms include Adobe Experience Manager, Optimizely Content Cloud, Acquia (Drupal), Contentstack, Storyblok and Salesforce Experience Cloud. For lighter needs consider Strapi, Sanity, Prismic, Kontent.ai or Umbraco.

How do I update the cookie policy for Sitecore?

List SC_ANALYTICS_GLOBAL_COOKIE, SC_ANALYTICS_SESSION_COOKIE, Sitecore CDP and Personalize identifiers in your cookie disclosure with retention, purpose and EU pinning information. Mention the EU US data transfer in your privacy notice. Update the disclosure whenever an additional Sitecore add on is activated.