Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Phabricator is an open source suite of web tools for code review, repository hosting, task management and project planning, originally developed at Facebook and now maintained as the Phorge fork after the original project was archived.
Phabricator is an open source collection of web applications for software engineering teams. It groups Differential for code review, Diffusion for repository hosting, Maniphest for issues, Phriction for wiki pages and several other tools. The original project was archived in 2021 and is now maintained as the Phorge community fork.
Phabricator sets first party cookies such as phsid for the authenticated session, phusr to store the user identifier and various CSRF tokens. Personal data processed includes account name, email address, code review comments, repository history, attached files and audit logs of every action performed in the interface.
Use of Phabricator inside a company is grounded on Article 6(1)(b) GDPR (the employment or service contract) and Article 6(1)(f) GDPR (legitimate interest in operating a secure development environment). Phabricator cookies are strictly necessary, so the consent obligation under Article 5(3) ePrivacy Directive does not apply.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Phabricator is fully self hosted. When the instance lives in the EU there is no transfer to a third country. If the operator chooses to run Phabricator on infrastructure outside the EU or to mirror repositories to a non EU SaaS, the usual transfer rules apply, including the Standard Contractual Clauses.
A formal DPIA is not generally required for a development tool, but the record of processing should describe accounts, code review history, retention of audit logs and access controls. Where Phabricator is used to monitor developer productivity, an Article 35 DPIA and works council consultation are recommended in EU jurisdictions.
Restrict access with strong authentication, log only what is needed, define retention of audit logs and revisions, mention Phabricator in the internal privacy notice, secure SSH and Git transport with up to date keys and apply security patches from the Phorge fork promptly.
Websites using Phabricator must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is not strictly mandatory for a self hosted developer tool, but the record of processing should describe accounts, repositories, code review comments, audit logs, retention and access controls. Where Phabricator is used to monitor performance or productivity of employees, a DPIA under Article 35 GDPR and consultation with the works council are recommended.
Sample consent text
This site uses Phabricator for internal code review and project management. Strictly necessary cookies (phsid, phusr) keep you logged in and protect the application. No consent is required, but you can read our privacy notice for more information.
Third-party domains contacted
phabricator.organization.examplewe.phorge.itsecure.phabricator.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| phsid | session | Session | Authenticated session identifier used by Phabricator to keep the user logged in across requests. |
| phusr | first_party | 30 days | Stores the username so the login screen can pre fill the field on returning visits. |
| phcid | first_party | 1 year | Client identifier used to bind a long lived session token to a specific browser. |
| phcsrf | session | Session | Cross site request forgery token that protects every form submission inside the Phabricator interface. |
Phabricator uses cookies for user preferences — inform visitors with a consent banner.
Phabricator sets first party session and account cookies, primarily phsid for the authenticated session, phusr for the user identifier and several CSRF tokens. No third party analytics or advertising cookies are loaded by the standard installation.
No. The cookies set by Phabricator are strictly necessary for authentication and CSRF protection, so the consent requirement of Article 5(3) ePrivacy Directive does not apply. An information notice is still required.
Inside a company the legal basis is Article 6(1)(b) GDPR for the employment or service contract, combined with Article 6(1)(f) GDPR (legitimate interest) in running a secure development platform. Specific monitoring use cases may require an additional basis.
Not by default. Phabricator is self hosted and was archived by Meta in 2021, so no telemetry is sent to the United States from the standard install. Transfers only occur if the operator hosts the instance outside the EU or mirrors data to a non EU service.
A DPIA is not required for ordinary developer use. It is recommended when Phabricator is used to systematically evaluate developer performance, monitor working time or process sensitive incident data, in which case Article 35 GDPR applies.
Use a hardened web server with TLS, enable strong authentication and SSO, restrict access by role, log only necessary events, define retention for audit logs and revisions and apply security patches from the Phorge community fork.
Modern alternatives include GitLab self managed, Gitea, Forgejo, Gerrit and SourceHut. Each offers code review and project management features with different hosting models, cookie footprints and integration ecosystems.
List Phabricator as an internal development platform under the controller, describe the categories of data (account, code review history, audit logs), the legal basis, retention, the absence of third country transfers in your setup and a contact for data subject rights.