Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Open source low code web framework behind ERPNext that is usually self hosted, so your data stays on your own server.
Frappe is an open source low code web framework that serves as the foundation for ERPNext and many custom business applications. It is usually self hosted, meaning the framework and its database run on infrastructure the operator controls. Because you build and run your own application on top of it, you are the data controller and decide what personal data the system processes.
Frappe sets a functional session cookie that keeps a signed in user authenticated as they move through the application. The personal data it stores depends entirely on what you build, whether that is customer records, employee data or order history. By default it does not load advertising trackers, and analytics are only present if you deliberately enable them.
The session cookie is strictly necessary for the application to function, so it falls under the ePrivacy exemption and does not require prior consent. Any personal data your application processes is governed by the GDPR and needs a lawful basis. As the operator you are the controller and remain responsible for transparency, security and the rights of the people in your data.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
You do not need consent for the essential session cookie that Frappe relies on. Consent only becomes necessary if you add non essential cookies such as third party analytics or marketing tools. In that case, gate those scripts behind a clear opt in and make sure the core application still works for visitors who decline.
Because Frappe is self hosted, there is no inherent transfer of data to third countries; your data lives where you run the server. Transfers only arise if you host outside the European Economic Area or connect external services such as email, payment or analytics providers. Hosting the installation within the European Union keeps most international transfer concerns away.
Map the personal data your application handles and assign a lawful basis to each use. Use the framework role and permission system to restrict access, set retention rules for old records and keep Frappe and its apps updated on secure infrastructure. If you enable analytics or integrations, document them, add a consent mechanism and reflect any transfers in your privacy notice.
Websites using Frappe must obtain user consent under GDPR regulations.
DPIA considerations
Because Frappe is a framework you build applications on, your assessment should focus on the specific data your application processes rather than the framework itself. Document the personal data your app handles, the lawful basis for each use, retention rules and access controls. Where you enable optional analytics or external integrations, assess those additions and any resulting transfers separately.
Sample consent text
This site uses a strictly necessary session cookie to keep you signed in, which does not require consent. If we enable optional analytics, we will ask for your consent first and you can decline without losing access to the core functionality of the site.
Third-party domains contacted
frappecloud.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| sid | Functional | Session | Stores the session identifier that keeps a signed in user authenticated. Strictly necessary and exempt from consent. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
When self hosted, Frappe sets a functional session cookie that keeps a signed in user authenticated. It does not set advertising cookies by default, and analytics cookies appear only if you choose to enable them in your application.
No consent is needed for the essential session cookie, which is strictly necessary under the ePrivacy exemption. Consent only becomes required if you add non essential cookies such as third party analytics or marketing tools.
Because you build your own application, the basis depends on what you process. Common bases are contract for delivering a service, legitimate interest for internal business records and consent for marketing. Assign and document a basis for each use.
Not by itself. As a self hosted framework the data stays wherever you run the server. Transfers only occur if you host outside the European Economic Area or connect external services such as email, payment or analytics providers.
A full assessment is rarely needed for the framework itself, but it depends on the application you build. Conduct one if your app processes large volumes of personal data or special categories, and document the data flows in any case.
Map the personal data your application handles, assign a lawful basis to each use, restrict access with roles and permissions and set retention rules. Keep Frappe and its apps updated on secure infrastructure and document any analytics or integrations you enable.
Other low code and ERP frameworks include Odoo, Django based builders and various open source platforms. The advantage of Frappe is that self hosting keeps your business data under your direct control.
List the functional session cookie as strictly necessary and explain that it keeps signed in users authenticated. If you enable analytics or other non essential cookies, list them separately and gate them behind consent.