Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
ServiceNow is the leading enterprise SaaS platform for IT Service Management, Employee Experience, Customer Service Management and low code workflow automation. European organisations use ServiceNow portals to publish service catalogues, knowledge base articles, incident reporting forms, HR self-service and digital workflows. When a ServiceNow portal is embedded on a public website or linked from a corporate intranet, it sets first party cookies, sometimes loads analytics scripts (Adobe Analytics, Mixpanel, Pendo) and transfers user data to ServiceNow infrastructure.
ServiceNow Inc. is a publicly traded US software company that operates the Now Platform, a low code workflow engine that powers IT Service Management, Employee Experience, Customer Service Management, Field Service, GRC, HR and many vertical solutions. European enterprises use ServiceNow portals as public service catalogues (customer.service-now.com), employee self-service hubs and incident reporting interfaces. The portals are built on top of UI Builder, ServiceNow Service Portal or the newer Workspace experience.
ServiceNow sets first party cookies on the instance domain such as JSESSIONID, glide_user, glide_session_store and BIGipServer for session management and load balancing. Optional integrations add analytics cookies (Adobe Analytics, Mixpanel, Pendo, Glassbox). For embedded chat widgets and Virtual Agent, ServiceNow may set glide_va_session and other interaction cookies. Personal data collected through the portal flows into the underlying ServiceNow tables.
ServiceNow Inc. is processor for the data the customer puts into the platform and controller for its own customer support, sales and product telemetry. The ServiceNow DPA (Customer Data Processing Addendum) incorporates the European Commission Standard Contractual Clauses, lists sub-processors and binds ServiceNow to ISO 27001, ISO 27018, SOC 2, EU Cloud Code of Conduct and FedRAMP for US government workloads. Strictly necessary cookies for session and security are exempt from ePrivacy consent; optional analytics or marketing cookies require opt-in.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
ServiceNow Inc. is certified under the EU-US Data Privacy Framework. EU customers can choose to host their instance in Ireland, the Netherlands, Germany, the United Kingdom or Switzerland. The ServiceNow EU Cloud, generally available since 2024, contractually keeps customer data and most operational processing inside the EU, with EU based support engineers and EU only sub-processors. Personal data continues to be subject to US extraterritorial laws because the parent company is American.
Contractual necessity (Article 6(1)(b) GDPR) covers most customer and employee portal scenarios where the user has signed up for a service or is acting in an employment relationship. Legitimate interest (Article 6(1)(f)) covers security telemetry and ITSM operations. Consent (Article 6(1)(a)) is required for optional analytics, marketing and Pendo session replay style cookies.
Sign the ServiceNow DPA, opt into ServiceNow EU Cloud if the workload contains EU personal data, restrict instance access through role based controls, configure data retention plug-ins, encrypt sensitive fields with the Edge Encryption add on, list ServiceNow as a processor in the privacy notice, document the transfer impact assessment, and integrate every non strictly necessary cookie of the customer portal into the Consent Management Platform.
Websites using ServiceNow must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is required when ServiceNow holds employee personal data at scale, customer service records, HR cases or any sensitive workflow data. The DPIA must cover the chosen data centre region, the ServiceNow EU Cloud option, encryption, role based access controls, retention policies, the sub-processor list, and the response plan for US government access requests under the EU-US Data Privacy Framework and FISA 702.
Sample consent text
Our customer portal is powered by ServiceNow. ServiceNow may set technical cookies for session management and, if enabled, analytics cookies through Adobe Analytics or Mixpanel. Some data may transit through ServiceNow infrastructure in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses. By clicking Accept, you authorise the optional analytics cookies. You can also Reject and only the strictly necessary cookies will be set.
Third-party domains contacted
service-now.comservicenow.comnow.servicenow.comservicenowservices.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| JSESSIONID | HTTP cookie | Session | Java EE session cookie used by the ServiceNow application server. |
| glide_user | HTTP cookie | Session | Identifies the logged in ServiceNow user inside an instance. |
| glide_session_store | HTTP cookie | Session | Persists the user session state across instance nodes. |
| BIGipServer | HTTP cookie | Session | F5 BIG-IP load balancer cookie used in front of ServiceNow nodes. |
| glide_va_session | HTTP cookie | Session | Virtual Agent (chat) session state when the chat widget is enabled. |
ServiceNow uses cookies for user preferences — inform visitors with a consent banner.
ServiceNow sets first party session cookies on the instance domain: JSESSIONID, glide_user, glide_session_store, BIGipServer for the load balancer and glide_va_session when the Virtual Agent chat is enabled. Optional analytics tools (Adobe Analytics, Mixpanel, Pendo) add their own cookies.
Session and load balancing cookies are strictly necessary and exempt from consent. Optional analytics or session replay cookies need prior opt-in, channelled through the Consent Management Platform.
Article 6(1)(b) GDPR (contract) for customer or employee portal usage. Article 6(1)(f) for ITSM and security telemetry. Article 6(1)(a) consent for optional analytics, marketing and session replay cookies.
By default, EU customers can pin the instance to an EU data centre. The optional ServiceNow EU Cloud keeps customer data and most processing inside the EU. ServiceNow Inc. remains certified under the EU-US Data Privacy Framework and signs Standard Contractual Clauses for any residual transfer.
Yes when ServiceNow holds large scale personal data such as employee HR cases, customer service records or whistleblower channels. Document the region choice, EU Cloud option, encryption, retention and the FISA 702 response plan.
Sign the ServiceNow DPA, opt into the EU Cloud where applicable, restrict roles and access controls, configure data retention plug-ins, encrypt sensitive fields with Edge Encryption, list ServiceNow in the privacy notice and integrate optional cookies into the CMP.
For ITSM: Atlassian Jira Service Management, BMC Helix, ManageEngine ServiceDesk Plus, Freshservice. For low code: Microsoft Power Platform, OutSystems, Mendix. For employee experience: SAP SuccessFactors, Workday. EU sovereign alternatives include EasyVista and EFECTE.
List ServiceNow Inc. and the EU contracting entity ServiceNow Nederland B.V., describe the session and analytics cookies, mention the EU-US Data Privacy Framework, link to the ServiceNow DPA and add an explicit statement about the EU Cloud commitment if applicable.