FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Stellantis

Stellantis

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Stellantis do?

Stellantis is the automotive group behind Peugeot, Citroën, Fiat, Jeep, Opel and other brands. Its corporate and brand websites use a shared first party tracking pixel for cross brand analytics, marketing and audience segmentation, with EU based infrastructure.

What is Stellantis

Stellantis is a multinational automotive group created in 2021 from the merger of PSA and Fiat Chrysler Automobiles. It owns and operates more than a dozen brands including Peugeot, Citroën, DS, Opel, Fiat, Alfa Romeo, Lancia, Jeep, Maserati, Chrysler, Dodge, Ram and Vauxhall. The group runs a unified digital platform that powers the corporate site and most of the brand sites in the European Economic Area, with a shared first party tracking pixel used for cross brand analytics, marketing and audience segmentation.

What data and cookies Stellantis collects

Stellantis sites set strictly necessary session and security cookies, plus first party analytics, advertising and personalisation cookies once the visitor has accepted them. The shared tracking pixel sends page views, configurator interactions, dealer lookups, lead form submissions, IP address, user agent, device characteristics and a persistent visitor identifier to group servers. Lead forms also collect contact information, vehicle interest and consent records, which can be reconciled with offline CRM and dealer data.

GDPR and ePrivacy implications

Article 5(3) ePrivacy requires prior informed consent for all non strictly necessary cookies, which covers the cross brand analytics and advertising pixels. The cross brand reconciliation creates a single visitor profile spanning multiple brands and qualifies as profiling under Article 22 GDPR when used for advertising. National regulators such as the CNIL, the Garante and the AEPD have fined large automotive groups for cookie banners that did not allow refusal as easy as acceptance.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and user controls

The Stellantis pixel and any advertising tags should be blocked by the consent management platform until the visitor accepts an analytics or marketing category. The banner must name Stellantis as joint controller alongside the local brand entity, indicate the cross brand sharing, allow refusal in one click and offer granular controls per purpose. Visitors must be able to exercise their access, rectification, erasure, restriction, objection and portability rights through a dedicated privacy form.

Data transfers and hosting

The primary infrastructure is hosted in the European Union, mainly in France and Italy. Some advertising, programmatic and measurement partners selected by Stellantis operate from the United States or other third countries. In that case, the transfer is framed by the EU standard contractual clauses, by the EU US Data Privacy Framework where the partner is certified, and by a transfer impact assessment that takes US surveillance laws such as FISA 702 and Executive Order 12333 into account.

Practical compliance steps

Document the joint controllership between Stellantis NV and the local brand entity, gate every non essential tag behind a granular consent banner, configure short retention for raw event logs, maintain a register of partners with their hosting region and contractual safeguards, run a documented DPIA at group level, ensure data subject requests are answered within one month and update the privacy and cookie policy with a clear mention of Stellantis, the categories of data, the recipients, the cross brand reconciliation and the retention.

GDPR consent category

Other

Websites using Stellantis must obtain user consent under GDPR regulations.

Legal basisConsent (Article 5(3) ePrivacy Directive and Article 6(1)(a) GDPR) for analytics, advertising and cross brand audience cookies. Legitimate interest (Article 6(1)(f) GDPR) for strictly necessary security and fraud prevention cookies. Performance of a contract (Article 6(1)(b) GDPR) for car configurator, dealer locator and customer area features.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), national implementations such as the French Data Protection Act, the German TDDDG, the Italian Codice Privacy and the Spanish LSSI, plus EU consumer law, the Digital Services Act and the Digital Markets Act for large brand portals.

DPIA considerations

A DPIA is recommended at group level given the scale (millions of EU visitors), the cross brand audience reconciliation, the rich behavioural data linked to vehicle configurators and lead forms, and the combination with offline CRM and dealer data. Document the categories of data, the joint controllership between brands and Stellantis NV, the retention of analytics and lead data and the safeguards for any onward transfer to advertising partners.

Sample consent text

We use Stellantis tracking technologies to measure how visitors interact with our brand sites and to personalise product information across the group. This sets first party cookies and may share data with other Stellantis brands and advertising partners. We need your consent to enable these technologies. You can accept, refuse or withdraw your consent at any time.

Technical details

Tracking methodFirst party tracking pixel and JavaScript tag with cross brand identifiers
Server locationEuropean Union (group infrastructure, primarily France and Italy)
Data transferred outside the EUMost processing happens on EU infrastructure operated by the Stellantis group. Some analytics and marketing partners used by the group may process data in the United States or other third countries, in which case the transfer is framed by standard contractual clauses, the EU US Data Privacy Framework where applicable, and a documented transfer impact assessment.

Third-party domains contacted

stellantis.commedia.stellantis.comcareers.stellantis.cominvestors.stellantis.com

Cookies placed

NameTypeDurationPurpose
st_vidhttp_persistent13 monthsPersistent first party visitor identifier used by the Stellantis pixel for cross brand audience reconciliation.
st_sidhttp_sessionSessionSession identifier used to group page views and configurator interactions during a single visit.
st_cshttp_persistent6 monthsStores the consent choices made by the visitor on the cookie banner across Stellantis brand sites.
st_cfghttp_persistent90 daysRemembers the last vehicle configuration started by the visitor to ease return visits.
st_langhttp_persistent1 yearStores the language and country selected by the visitor on the Stellantis brand site.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies do Stellantis sites set?

Stellantis brand sites set strictly necessary session and security cookies, plus first party analytics, advertising and personalisation cookies once consent is given. The shared tracking pixel reads a persistent first party visitor identifier used for cross brand audience reconciliation, and exposes additional advertising cookies when partner tags are loaded.

Is consent required for the Stellantis pixel?

Yes. The cross brand analytics and advertising pixel are not strictly necessary, so Article 5(3) ePrivacy requires opt in consent before they are written. Strictly necessary cookies for security, load balancing and language preference may be set without consent.

What is the legal basis for processing?

Consent under Article 6(1)(a) GDPR for analytics, advertising and personalisation. Legitimate interest under Article 6(1)(f) GDPR for fraud and security cookies. Performance of a contract under Article 6(1)(b) GDPR for the configurator, dealer locator, brochure requests and customer area.

Are data transferred to the United States?

The primary infrastructure is in the EU, mainly France and Italy. Some advertising and measurement partners operate from the US or other third countries. In that case the transfer relies on standard contractual clauses, the EU US Data Privacy Framework where applicable, and a transfer impact assessment by the relevant Stellantis entity.

Do I need a DPIA for Stellantis sites?

Yes, a DPIA is appropriate at group level. The processing is large scale, combines behavioural data across brands, uses persistent identifiers and feeds CRM and advertising activation. This meets several criteria of Article 35 GDPR and the EDPB Guidelines on DPIA.

How do we implement Stellantis tags in a compliant way?

Document the joint controllership, deploy a granular consent management platform that blocks all non essential tags by default, configure short retention for raw event logs, maintain a register of partners with hosting and safeguards, document data subject request workflows and review the cookie banner regularly against CNIL, Garante and AEPD guidance.

Are there alternatives to the Stellantis stack?

For the analytics layer, brands can complement or replace the Stellantis pixel with EU based, consent friendly tools such as Matomo, Piwik PRO, Plausible, AT Internet (Piano Analytics) or Adobe Analytics with EU residency. The corporate cross brand reconciliation remains specific to the group.

How do I update my cookie policy for Stellantis sites?

List the Stellantis first party cookies and partner cookies, identify the brand entity and Stellantis NV as joint controllers, explain the cross brand audience reconciliation, mention the EU hosting and any US partners with the safeguards used, link to the Stellantis privacy notice and explain how visitors can refuse or withdraw consent.