Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Combodo iTop is an open source ITSM and CMDB platform for IT service desks, asset management and ITIL processes, self hosted or available as the EU based iTop Hub SaaS.
Combodo iTop is an open source IT Service Management and Configuration Management Database platform developed by Combodo SAS in Grenoble, France. It implements ITIL aligned processes such as incident, problem, change, service request, configuration and SLA management on top of a PHP and MySQL stack. The software is licensed under AGPL and is typically deployed on the customer's own infrastructure as an internal backoffice application used by IT staff. Combodo also offers iTop Hub, a SaaS variant hosted in the European Union, alongside consulting and support services.
iTop processes data that IT operations generate, including user accounts of IT staff and end users with tickets, incident and change records, configuration items in the CMDB, asset inventories, contracts and SLA metrics. From a web technology perspective the application only sets first party functional cookies, typically itop-cookie, PHPSESSID for the session, itop-user-prefs for user interface preferences and itop-token for CSRF protection. These cookies are server set, scoped to the iTop hostname and used solely to authenticate staff and maintain a working session. No advertising, profiling or cross site tracking technologies are loaded by default.
Under the GDPR the organisation operating iTop is the controller for the personal data stored in tickets, asset and user records, while Combodo acts as processor only for the iTop Hub SaaS variant. ePrivacy obligations are limited because iTop is not a public website tracker and its cookies are strictly necessary to authenticate staff and protect against CSRF, which falls under the Article 5(3) exception of the ePrivacy Directive. The main GDPR work consists of documenting records of processing, defining retention periods for incidents and audit logs, securing access and ensuring data subject rights for staff and end users referenced in tickets.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
No cookie banner consent is required for the functional session cookies used by iTop because they are strictly necessary to deliver the requested service to authenticated users. The lawful basis for processing through iTop is normally a combination of legitimate interest under Article 6(1)(f) for IT operations and information security, contract performance under Article 6(1)(b) where the data subject is an employee or customer of the operator, and national employment law. Where iTop captures employee performance data through ticket metrics, employers must observe local employment law and any works council consultation obligations.
When iTop is self hosted on the customer's own EU infrastructure there are no third country transfers, and the iTop Hub SaaS option is hosted on French and EU providers such as OVH and Scaleway by default, so transfers outside the EEA are not part of the standard configuration. Practical compliance steps include restricting administrator access, enabling LDAP or SSO with multi factor authentication, configuring retention rules to archive or purge closed tickets, recording iTop in the records of processing, signing an Article 28 contract with Combodo when using iTop Hub, and updating the internal privacy notice for IT staff.
Websites using Combodo iTop must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is generally not required just because iTop is deployed, since it is an internal backoffice ITSM tool used by IT staff under the controller's authority. A DPIA may still be appropriate when iTop stores special category data, very large volumes of incident or HR linked records, or when it is integrated with monitoring tools that produce systematic evaluation of employees. Document the records of processing, restrict admin access, log changes and review retention of incident and asset data.
Sample consent text
No cookie banner consent is required for the strictly necessary session cookies set by Combodo iTop. Inform IT staff in an internal privacy notice that iTop is used to manage incidents, changes, assets and user accounts, and explain the legal basis (legitimate interest and contract performance with the employer), the retention periods and their rights as data subjects.
Third-party domains contacted
combodo.comcombodo.fritophub.iocommunity.combodo.comsupport.combodo.comwiki.openitop.orgstore.itophub.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| PHPSESSID | functional | session | Standard PHP session identifier issued by the iTop server to keep the authenticated user logged in during a working session. Strictly necessary. |
| itop-cookie | functional | session | Application session cookie set by iTop to maintain login state and user context between page loads. Strictly necessary, first party. |
| itop-user-prefs | functional | 1 year | Stores per user interface preferences such as language, list filters and pagination so the agent finds the same configuration on next login. |
| itop-token | functional | session | Anti CSRF token used by iTop to protect form submissions and API calls from cross site request forgery. Strictly necessary security cookie. |
| XSRF-TOKEN | functional | session | Additional CSRF protection token that some iTop installations or reverse proxies set. Exact name depends on configuration. Strictly necessary. |
| itop-remember-me | functional | 30 days | Optional persistent authentication cookie issued when the user ticks the remember me option at login, so the session can be resumed without retyping credentials. |
Combodo iTop uses cookies for user preferences — inform visitors with a consent banner.
iTop sets only first party functional cookies on the application hostname: itop-cookie, PHPSESSID for the session, itop-user-prefs for interface preferences and itop-token for CSRF protection. There are no advertising or analytics identifiers by default.
No cookie banner consent is needed. The session and CSRF cookies are strictly necessary to authenticate IT staff, so they fall under the Article 5(3) ePrivacy exception. Inform users via the internal privacy notice instead.
The operating organisation typically relies on legitimate interest under Article 6(1)(f) for IT operations and security, contract performance under Article 6(1)(b) for staff and customers, and applicable employment law when iTop processes employee data.
No when the software is self hosted on EU infrastructure. The iTop Hub SaaS variant is hosted in France and the EU by default (OVH, Scaleway), so transfers outside the EEA are not part of the standard configuration.
Generally no, because iTop is an internal backoffice tool used by IT staff under the controller's authority. A DPIA may still be appropriate where iTop stores special category data, very large ticket volumes or feeds systematic employee evaluation.
Host iTop on EU infrastructure or use iTop Hub, enable SSO or LDAP with multi factor authentication, restrict admin roles, configure retention to archive or purge closed tickets, record iTop in your processing register and sign an Article 28 contract for the SaaS variant.
Yes. Open source alternatives include GLPI (French), Zammad (German), OTRS and OsTicket. Commercial SaaS options include Jira Service Management, ServiceNow and Freshservice. Pick based on hosting region, ITIL coverage and CMDB depth.
You usually do not need to mention iTop in a public cookie policy because it is a backoffice tool with strictly necessary cookies. Instead document iTop in the internal staff privacy notice and the records of processing, listing the data categories, retention periods and lawful basis.