Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Bigware is a German open source e-commerce shop system. The storefront sets session and functional cookies to run the cart and checkout, and merchants can plug in third-party analytics and payment services. This makes it a self-hosted platform whose cookie footprint depends largely on the integrations a shop owner chooses to enable.
Bigware is a German open source e-commerce shop system that merchants install on their own hosting. It powers product catalogues, shopping baskets, and checkout, and is typically run on German or other European servers. Because it is self-hosted, the shop owner is the data controller and decides which additional services to connect.
By default Bigware sets a PHP session cookie to keep a visitor logged in and to remember the contents of the basket. Functional cookies may store preferences such as language and currency. Personal data such as name, address, and order details are processed to fulfil purchases. Analytics or advertising cookies appear only when the merchant adds external scripts.
Under the ePrivacy Directive and the German TDDDG, strictly necessary session and cart cookies may be set without consent because they are essential to deliver the service the customer requested. Any cookie that is not strictly necessary, such as analytics or marketing trackers, requires prior consent and must be documented in the records of processing under the GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A consent banner is only strictly required once a merchant enables non essential cookies. When that happens, consent must be freely given, specific, informed, and as easy to withdraw as to give. Reject options should be presented as prominently as accept options, and no analytics or marketing scripts should load before the visitor agrees.
The core Bigware installation keeps data within the EU when hosted on European servers, so no third country transfer is involved by design. Transfers to the United States or elsewhere only arise if the merchant integrates external providers such as US analytics or payment gateways, in which case an appropriate transfer mechanism like the EU US Data Privacy Framework or standard contractual clauses is needed.
Audit which cookies your shop actually sets, classify them as necessary or optional, and deploy a consent management tool that blocks optional scripts until consent is given. Maintain a clear cookie policy, keep your records of processing up to date, and review every third party integration for its own data transfer and retention terms.
Websites using Bigware must obtain user consent under GDPR regulations.
DPIA considerations
A full data protection impact assessment is rarely required for a standard Bigware shop, because the core processing relies on strictly necessary session and cart cookies. A DPIA becomes advisable when a merchant layers on profiling, large scale behavioural analytics, or marketing integrations that combine customer data across services.
Sample consent text
We use necessary cookies to run our shop and your basket. With your consent we also use analytics and marketing cookies to improve our store and show relevant offers. You can accept, reject, or manage these at any time.
Third-party domains contacted
bigware.debigware-shop.deCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| PHPSESSID | Strictly necessary | Session | Maintains the visitor session, login state, and basket contents during a visit. |
| language | Functional | 1 year | Stores the selected store language so the interface is shown in the preferred language. |
| currency | Functional | 1 year | Remembers the chosen currency for displaying prices. |
| cookie_consent | Strictly necessary | 1 year | Records the visitor cookie consent choices so the banner is not shown repeatedly. |
Bigware uses cookies for user preferences — inform visitors with a consent banner.
By default Bigware sets a strictly necessary PHP session cookie that keeps you logged in and remembers your basket, plus optional functional cookies for language and currency. Analytics or advertising cookies are only present if the merchant has added external tools.
No consent is needed for the strictly necessary session and cart cookies. Consent is required before any analytics or marketing cookies are set, so a consent banner is only mandatory once a merchant enables such non essential tools.
Strictly necessary cookies rely on contract performance and legitimate interest, since they are needed to run the shop and the basket. Non essential analytics and marketing cookies rely on consent under Article 6(1)(a) of the GDPR.
The core Bigware software is self-hosted and keeps data in the EU when run on European servers, so there is no US transfer by default. Transfers only occur if the merchant adds US based services, which then require an appropriate safeguard such as the EU US Data Privacy Framework or standard contractual clauses.
A DPIA is usually not required for a standard shop based on necessary cookies. It becomes advisable when the merchant introduces large scale profiling, behavioural analytics, or marketing integrations that combine customer data across services.
Audit the cookies your installation actually sets, classify them as necessary or optional, deploy a consent tool that blocks optional scripts until consent is given, publish a clear cookie policy, and document everything in your records of processing.
Other self-hosted European shop systems include Shopware, PrestaShop, and WooCommerce, while hosted options include Shopify and similar platforms. Each has a different cookie and data transfer profile, so review their defaults before choosing.
Re scan your shop after any change to plugins or integrations, update the cookie table with names, purposes, and durations, reflect new third parties and transfer mechanisms, and refresh your consent banner so visitors can re consent to the current set.