FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. OXID eShop Enterprise Edition
O

OXID eShop Enterprise Edition

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does OXID eShop Enterprise Edition do?

OXID eShop Enterprise Edition is the commercial enterprise grade variant of the OXID eShop platform developed by OXID eSales AG in Freiburg, Germany. It targets mid market and enterprise B2B, B2C and B2B2C retailers with advanced features (multi store, multi language, B2B workflows, advanced personalisation and the OXID Cloud Connector). The platform sets strictly necessary cart and session cookies; the enterprise modules add analytics, recommendation, A/B testing and marketing cookies that require prior consent.

What OXID eShop Enterprise Edition is

OXID eShop Enterprise Edition is the commercial enterprise grade variant of the German OXID eShop e-commerce platform developed by OXID eSales AG in Freiburg im Breisgau. It targets mid market and enterprise retailers needing advanced multi store, multi language and B2B workflow support, alongside a more integrated cloud connector and a long term support package. It is mainly deployed by manufacturers, wholesalers and B2B brands in Germany, Austria and Switzerland.

What data and cookies are collected

The platform sets strictly necessary cookies for PHP session (sid, sid_key), persistent basket (oxid_basket) and authentication. Enterprise modules add cookies for advanced personalisation, segmentation, A/B testing and integration with marketing automation. The back end processes the full order, customer account and B2B contract data with role based access control.

GDPR and ePrivacy implications

Session, cart and login cookies fall under the Article 5(3) ePrivacy strictly necessary exemption. Enterprise personalisation, segmentation, recommendation and marketing modules add non strictly necessary cookies that require prior consent under TTDSG in Germany and its equivalents elsewhere in the EU. Order, account and contract data are processed under contract performance and legitimate interest, with transparency obligations under Articles 13 and 14 GDPR.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements and legal basis

Strictly necessary cookies and core processing rely on contract performance (Article 6(1)(b) GDPR). Marketing, personalisation and analytics rely on consent (Article 6(1)(a) GDPR). Fraud prevention and security rely on legitimate interest (Article 6(1)(f) GDPR). Statutory retention for tax and invoicing relies on legal obligation (Article 6(1)(c) GDPR). The merchant is the controller; OXID eSales AG is a processor only for paid support and managed services contracts.

Data transfers and hosting

OXID eShop Enterprise Edition is typically deployed on private German or EU hosting, sometimes on certified hyperscaler EU regions. Transfers outside the EEA only occur if the merchant chooses non EU payment providers, analytics or marketing modules. In that case, Standard Contractual Clauses or the EU US Data Privacy Framework apply and must be reflected in the privacy notice.

Practical compliance steps

Inventory all modules installed on top of OXID eShop Enterprise Edition, classify the cookies they set in the CMP, keep cart and login cookies always on and gate the rest behind consent. Sign DPAs with all third party providers and document the EU hosting region. Run a DPIA when profiling, large scale B2C processing or sensitive product categories are involved, and align the deployment with the security and access control practices appropriate for enterprise data.

GDPR consent category

Preferences

Websites using OXID eShop Enterprise Edition must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for cart, login and order; consent (Art. 6(1)(a) GDPR) for analytics, marketing and personalisation modules; legitimate interest (Art. 6(1)(f) GDPR) for fraud prevention.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, TTDSG (Germany)

DPIA considerations

A DPIA is recommended for OXID eShop Enterprise Edition deployments because the enterprise modules are typically combined with profiling, recommendation engines, marketing automation and integration with CDPs, which raises the scale and profiling triggers of Article 35 GDPR. Sensitive product categories or B2B workflows that include employee data also push the deployment towards a documented DPIA.

Sample consent text

Our online shop runs on OXID eShop Enterprise Edition, a German platform by OXID eSales AG. Strictly necessary cookies operate the shopping cart, login and checkout without requiring your consent. With your permission we also activate optional enterprise modules for analytics, recommendation and marketing that can share aggregated browsing data with our third party providers.

Technical details

Tracking methodServer side PHP session, cart and authentication cookies; optional enterprise modules for personalisation, B2B workflows and marketing automation
Server locationSelf hosted or managed by certified OXID partners; the OXID eShop Enterprise Edition is developed by OXID eSales AG in Freiburg im Breisgau, Germany

Third-party domains contacted

oxid-esales.comenterprise.oxid-esales.comexchange.oxid-esales.comcloud.oxid-esales.com

Cookies placed

NameTypeDurationPurpose
sidfirst_partySessionPHP session identifier used by OXID eShop Enterprise to bind the visitor to a server side session holding cart and user state.
sid_keyfirst_partySessionValidation key paired with sid to prevent session fixation. Strictly necessary.
oxid_basketfirst_party30 daysPersistent shopping cart cookie that retains the basket between visits.
languagefirst_party12 monthsStores the language chosen by the visitor.
currencyfirst_party12 monthsStores the currency selected by the visitor in multi currency shops.
oxid_ee_personalizationfirst_party12 monthsSet by enterprise personalisation modules to store segment membership and personalised content choices. Requires consent.

OXID eShop Enterprise Edition uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does OXID eShop Enterprise Edition set?

The platform sets a PHP session cookie (sid, sid_key), a persistent basket cookie (oxid_basket) and an authentication cookie after sign in. Enterprise modules add cookies for personalisation, segmentation, A/B testing, recommendation and marketing automation, which are non strictly necessary.

Is user consent required for OXID Enterprise?

No consent is required for the strictly necessary cookies (session, basket, login). Consent is required for the cookies introduced by enterprise modules (personalisation, A/B testing, marketing) under the ePrivacy implementations across the EU.

What is the legal basis for OXID Enterprise?

Contract performance for cart, login and order processing; consent for marketing, personalisation and analytics modules; legitimate interest for fraud prevention; legal obligation for tax and invoicing retention.

Does OXID Enterprise transfer data outside the EEA?

Not by default. The platform is self hosted or partner hosted, typically in Germany or the EU. Third country transfers only occur if the merchant chooses non EU sub providers (PSP, analytics, marketing), in which case Standard Contractual Clauses or the EU US Data Privacy Framework apply.

Is a DPIA required?

Recommended, because enterprise modules often combine profiling, recommendation and CDP integration, which meets several Article 35 GDPR criteria. Sensitive product categories or B2B workflows with employee data also raise the threshold.

How do I implement OXID Enterprise compliantly?

Inventory all modules, classify cookies in your CMP, keep cart and login always on, gate the rest behind consent. Sign DPAs with third parties, document the EU hosting region, run a DPIA where appropriate, apply role based access control and align with security best practices.

What are the alternatives to OXID Enterprise?

SAP Commerce Cloud, Salesforce Commerce Cloud, Adobe Commerce, Spryker, commercetools, Shopware Enterprise (Germany). EU based alternatives such as Shopware Enterprise and commercetools simplify the transfer chain.

How do I update the cookie policy?

List the strictly necessary cookies with names and durations. List each module that introduces non strictly necessary cookies with purpose, retention and recipient. Reference the CMP for granular controls and mention any third country transfers triggered by the modules.