Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
TYPO3 CMS is an open source enterprise content management system maintained by the TYPO3 community and the TYPO3 Association in Germany. It is self hosted on the publisher own server, so by default it makes no third party calls and performs no international transfers. It sets only first party session cookies when a session is genuinely needed, which makes it a privacy friendly, low risk foundation for European publishers.
TYPO3 CMS is a mature, open source enterprise content management system maintained by the TYPO3 community and the TYPO3 Association, which is based in Germany within the European Union. It is designed to be self hosted on the publisher own server or hosting environment, so the organisation keeps full control over the data. By default it makes no third party calls and involves no vendor cloud. This architecture makes TYPO3 a privacy friendly foundation, where the main compliance work concerns whatever extensions you choose to add.
TYPO3 sets a frontend session cookie named fe_typo_user only when a session is genuinely needed, for example when a visitor logs in, fills a basket or accesses protected content. Editors receive a backend session cookie named be_typo_user when they work in the administration area. These are first party cookies tied to the session and are not used to track visitors across sites. Standard server logs may record IP addresses, as on any web server, which the operator controls directly.
The TYPO3 session cookies are strictly necessary to provide the service the visitor has requested, so they are exempt from consent under article 5(3) of the ePrivacy Directive. The underlying processing relies on legitimate interest under article 6(1)(f) of the GDPR, or on contract under article 6(1)(b) where a logged in relationship exists. Because the platform is self hosted and first party, the GDPR footprint of the core is small. Risk grows mainly when extensions introduce analytics, marketing or external services.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because the core cookies are strictly necessary, no consent banner is required for TYPO3 itself, and the frontend cookie is only set when a session is actually required. You should still inform visitors about these cookies in your privacy notice for transparency. If you add extensions that set non essential cookies, such as analytics or embedded media, those must be placed behind a consent mechanism. Keeping the core lean is the simplest way to stay consent free for the platform.
As a self hosted CMS, TYPO3 performs no international transfers by default, since all processing happens on infrastructure that you control. Transfers only arise if you choose to host the site outside the European Union or to connect external integrations that send data abroad. To keep things simple, host within the EU and review any third party connector before enabling it. The update and extension services on the TYPO3 domains are used by administrators, not for visitor tracking.
Document TYPO3 in your records of processing as a self hosted platform under your own control, and note the strictly necessary session cookies in your privacy notice. Review every extension and integration you add, since this is where new cookies, processing or transfers usually appear. Host the site within the EU to avoid unnecessary transfers, and keep the core and its extensions updated for security. With this discipline, TYPO3 remains one of the most privacy friendly choices available.
Websites using TYPO3 CMS must obtain user consent under GDPR regulations.
DPIA considerations
The TYPO3 core is low risk and rarely needs a full data protection impact assessment, because it is self hosted, makes no third party calls by default and sets only strictly necessary session cookies. The real assessment focus is whatever extensions and integrations you add, such as analytics, forms or external services, which can introduce new processing, cookies or transfers. Review each added component and host the site within the EU to keep the footprint minimal.
Sample consent text
This site runs on TYPO3 and uses strictly necessary session cookies to keep you logged in and to maintain your session. These cookies are exempt from consent under the ePrivacy rules. Any optional features that set additional cookies will ask for your consent separately.
Third-party domains contacted
typo3.orgget.typo3.orgextensions.typo3.orgCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| fe_typo_user | strictly necessary | session | Frontend session cookie set only when a session is needed, for example login, basket or protected content |
| be_typo_user | strictly necessary | session | Backend session cookie for editors working in the TYPO3 administration area |
| staticfilecache | functional | varies by configuration | Optional functional cookie set only if a static file cache extension is installed, used to serve cached pages |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
TYPO3 sets a frontend session cookie called fe_typo_user, but only when a session is genuinely needed, such as login, a basket or protected content. Editors get a backend session cookie called be_typo_user when they work in the administration area. Some extensions, like a static file cache or a cookie consent tool, may add functional cookies if you install them.
No, not for the core. The TYPO3 session cookies are strictly necessary and therefore exempt from consent under article 5(3) ePrivacy. Consent only becomes relevant if you add extensions that set non essential cookies, such as analytics or embedded media, which must then be gated.
The strictly necessary session cookies are exempt from consent under ePrivacy, and the underlying processing relies on legitimate interest under article 6(1)(f) GDPR or on contract under article 6(1)(b) for logged in users. Because the platform is self hosted and first party, the basis is straightforward. Added extensions may require their own legal basis.
No, not by default. As a self hosted CMS, TYPO3 keeps processing on infrastructure you control and makes no third party calls out of the box. Transfers only arise if you host the site outside the EU or connect external integrations. Hosting within the EU keeps the platform free of international transfers.
The core rarely requires a full data protection impact assessment, given the low risk, self hosting and the absence of tracking cookies. The assessment focus should be the extensions and integrations you add. Review each new component for processing, cookies or transfers and document the outcome.
Host the site within the EU, keep the core lean and document the strictly necessary session cookies in your privacy notice. Review every extension before enabling it, and place any non essential cookies behind a consent mechanism. Keep the core and extensions updated to maintain security and compliance over time.
Other self hosted open source content management systems offer a similar privacy friendly model, where you control the data and add features through extensions. Hosted platforms are easier to start with but usually involve a vendor processing your data, sometimes outside the EU. TYPO3 is attractive because its association is EU based and the core is self hosted and first party.
List the strictly necessary session cookies fe_typo_user and be_typo_user as functional and explain that they are exempt from consent. If you install extensions that add functional or non essential cookies, document each one and its purpose. Keep the policy aligned with any consent banner you use for added components.