Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Contentder is a content and advertising delivery platform that loads third party JavaScript on websites. In a standard deployment it sets first and third party cookies and uses browser and device identifiers to deliver, personalise and measure content and ads. Because this involves non essential tracking, it triggers consent obligations under European data protection and ePrivacy rules.
Contentder is a content and advertising delivery platform embedded in websites through a third party JavaScript tag. It loads and personalises editorial or promotional content and, in many configurations, advertising creatives. To deliver, target and measure that content it typically relies on cookies and on browser and device identifiers that allow it to recognise visitors across page views and sessions.
A standard Contentder integration sets first party cookies for state and measurement and may load third party cookies tied to advertising and analytics partners. It commonly processes IP addresses, user agent strings, referrer data, on page interactions and pseudonymous identifiers. Where advertising is involved this data can be shared with external networks for targeting and attribution, which expands the set of parties processing personal data.
Storing or reading non essential cookies and identifiers is governed by Article 5(3) of the ePrivacy Directive, which requires prior consent. The subsequent processing of personal data such as IP addresses and behavioural signals falls under the GDPR. Identifiers used for personalisation and advertising are personal data, so a valid legal basis, transparency and data subject rights must all be addressed before the tag fires.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because Contentder loads non essential tracking, you should obtain freely given, specific, informed and unambiguous consent before the script executes. The platform should be blocked until the user accepts the relevant category, consent should be as easy to withdraw as to give, and a record of consent should be retained. Pre ticked boxes and implied consent from continued browsing are not sufficient under European rules.
Content and advertising platforms often use infrastructure and partners located in the United States and other third countries. Any resulting transfer of personal data outside the European Economic Area requires a valid transfer mechanism such as the EU US Data Privacy Framework or Standard Contractual Clauses, supported by a transfer impact assessment that considers government access risks and supplementary measures.
Inventory every cookie and identifier Contentder sets, integrate it behind a consent management platform, and document the legal basis and purposes in your records of processing. Sign data processing terms with the vendor, confirm transfer safeguards, set retention limits, and test that declining or withdrawing consent fully prevents the script and its partners from collecting data.
Websites using Contentder must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is recommended where Contentder is used for advertising personalisation or large scale behavioural tracking. Assess the categories of identifiers collected, the role of downstream advertising partners, retention periods, the legal basis for each purpose, international transfers to the United States and the effectiveness of consent capture and withdrawal mechanisms.
Sample consent text
We use Contentder to deliver and personalise content and advertising. This sets cookies and reads identifiers from your device for these purposes. These cookies load only with your consent, which you can withdraw at any time in cookie settings.
Third-party domains contacted
cdn.contentder.comads.contentder.comtrack.contentder.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _cd_uid | Tracking / advertising | 12 months | Pseudonymous user identifier used to recognise the visitor across sessions for personalisation and ad measurement. |
| _cd_session | Functional | Session | Maintains delivery state and content session continuity during the visit. |
| _cd_consent | Strictly necessary | 6 months | Stores the visitor consent choices for content and advertising cookies. |
| _cd_ads | Advertising | 90 days | Supports ad targeting, frequency capping and attribution with advertising partners. |
Contentder uses cookies for user preferences — inform visitors with a consent banner.
In a standard deployment Contentder sets first party cookies for session state and measurement and may load third party cookies linked to advertising and analytics partners. The exact names depend on your configuration, so audit the live tag to confirm which cookies and identifiers are actually placed.
Yes. Because Contentder loads non essential cookies and identifiers used for content personalisation and advertising, prior consent is required under Article 5(3) of the ePrivacy Directive before the script runs. The tag should stay blocked until the user accepts.
For setting and reading non essential cookies the lawful basis is consent under Article 6(1)(a) GDPR combined with Article 5(3) ePrivacy. Legitimate interest is generally not appropriate for advertising and personalisation tracking that requires consent at the cookie layer.
It can. Content and advertising platforms commonly use infrastructure and partners in the United States and other third countries, so personal data such as IP addresses and identifiers may be transferred outside the EEA. Confirm transfer safeguards such as the EU US Data Privacy Framework or Standard Contractual Clauses with the vendor.
A DPIA is advisable where Contentder supports advertising personalisation or systematic behavioural tracking at scale, since such processing can present a high risk to individuals. Document the data collected, downstream recipients, transfers and the consent mechanism as part of the assessment.
Load the tag only through a consent management platform so it fires after the user accepts the relevant category. Disclose it in your cookie policy, sign data processing terms, verify transfer safeguards, set retention limits and test that refusal and withdrawal fully stop data collection.
Alternatives include privacy focused content and advertising solutions that offer cookieless or contextual modes, server side delivery with no client identifiers, or self hosted content tools. Any alternative still requires consent if it sets non essential cookies, so evaluate its data flows before switching.
List every Contentder cookie with its name, purpose and duration, name the controller and any advertising partners, state the legal basis as consent, describe international transfers and link to your consent settings. Review the policy whenever the integration or its partners change.