FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Hosting
  4. DigiCert

DigiCert

OtherWebsite

Related services

A

actionhero.js

actionhero.js is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. actionhero.js integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, actionhero.js helps organizations maintain robust websites that meet user expectations and technical requirements.

Other

Adminer

Adminer is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adminer supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adminer ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akka HTTP

Akka HTTP is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Akka HTTP integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Akka HTTP helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Alibaba Cloud Object Storage Service

Alibaba Cloud Object Storage Service is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Object Storage Service provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Object Storage Service ensures optimal.

Other

AlmaLinux

AlmaLinux is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlmaLinux supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlmaLinux ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

AlternC

AlternC is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlternC supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlternC ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does DigiCert do?

DigiCert is a major US-based Certificate Authority that issues the SSL/TLS, code-signing, document-signing and qualified eIDAS certificates many European websites rely on. The certificates themselves are entirely server-side and raise no consent issues. However, browsers contact DigiCert's OCSP and CRL responders to verify revocation status, and websites that display the optional DigiCert Smart Seal embed a JavaScript widget that sets tracking cookies and pings DigiCert servers, which does trigger ePrivacy and transfer obligations.

What is DigiCert

DigiCert is one of the largest Certificate Authorities in the world, issuing SSL/TLS certificates, EV (Extended Validation) certificates, code signing certificates, document signing certificates and qualified eIDAS certificates used by enterprises across Europe. It also operates the Smart Seal trust badge that some websites display to communicate their security posture.

What data DigiCert processes

DigiCert processes certificate purchase data (organisation name, contact details, billing), and on issuance the certificate''s subject information becomes public via Certificate Transparency logs. At runtime, the browser performs OCSP or CRL revocation checks against DigiCert''s servers; these requests reveal the visitor''s IP address and the certificate serial number. If the Smart Seal is embedded, it loads JavaScript that pings DigiCert, sets cookies and transmits referrer information.

GDPR and ePrivacy implications

OCSP and CRL checks are part of the TLS protocol and are necessary for secure HTTPS connections; they rely on legitimate interest and the legal obligation to maintain communications security. The Smart Seal is non-essential and requires prior consent under Art. 5(3) ePrivacy. DigiCert is a data processor for certificate orders and a controller for product analytics.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and OCSP stapling

OCSP requests reveal browsing destinations to DigiCert, which sits in the US. Enabling OCSP stapling on your web server (Nginx, Apache, IIS) ensures that the OCSP response is fetched by the server and stapled into the TLS handshake, so the visitor''s browser does not need to contact DigiCert directly. This is a simple privacy-enhancing measure that does not require user consent.

Smart Seal trust widget

The DigiCert Smart Seal is a JavaScript widget that displays a trust badge and validates the certificate in real time. It loads from seal.digicert.com, sets cookies and transmits visit data to DigiCert. Treat it as a non-essential marketing element and gate it behind your CMP. If you want a trust badge without the tracking, use a static image instead.

Practical compliance checklist

1. Enable OCSP stapling on your web server. 2. If you display the Smart Seal, block it behind your CMP. 3. Sign the DigiCert subscriber agreement and DPA. 4. Document DigiCert in your privacy notice as a sub-processor or processor (depending on the product). 5. For qualified eIDAS certificates, prefer EU-based Qualified Trust Service Providers (QTSPs) to keep processing in the EU. 6. Monitor Certificate Transparency logs for issued certificates referencing your domain.

GDPR consent category

Other

Websites using DigiCert must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) and legal obligation for OCSP/CRL revocation checking that is required for HTTPS security; Consent (Art. 6(1)(a) GDPR) for the optional Smart Seal trust widget loaded on the storefront
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, eIDAS (for qualified certificates), CA/B Forum baseline requirements

DPIA considerations

The core certificate issuance and revocation use of DigiCert raises minimal DPIA concerns: OCSP requests transmit the visitor's IP address and certificate serial number, which DigiCert processes for legitimate security purposes. However, the optional Smart Seal widget loads a JavaScript that sets cookies and transmits referrer and IP to DigiCert in the US for impression counting. Key considerations: (1) OCSP requests reveal browsing destinations to DigiCert; OCSP stapling can mitigate this; (2) the Smart Seal is non-essential and requires consent; (3) qualified certificates under eIDAS may involve EU-based qualified trust service providers (QTSPs) with different processing terms; (4) US transfer for Smart Seal data. A streamlined DPIA is sufficient unless the certificate is used in a high-sensitivity context like financial signing or healthcare.

Sample consent text

This site uses DigiCert SSL certificates to encrypt your connection. To verify that the certificate has not been revoked, your browser may contact DigiCert's servers. If you see the DigiCert Smart Seal trust badge on this page, it sets a cookie and shares your visit data with DigiCert in the United States; we load it only after your consent.

Technical details

Tracking methodCertificate Authority (CA) issuing SSL/TLS, code signing and document signing certificates. The optional Smart Seal widget loads JavaScript from seal.digicert.com that pings DigiCert servers and may set tracking cookies
Server locationDigiCert, Inc., Lehi, Utah, United States. Global OCSP and CRL responder network including European edges
Cookieless tracking availableYes
Data transferred outside the EUOCSP and CRL requests (which include the visitor's IP and the certificate identifier they are validating) reach DigiCert's global network. Order data, customer details, and Smart Seal events are stored at DigiCert in the United States. Transfers covered by Standard Contractual Clauses and EU-US Data Privacy Framework certification.

Third-party domains contacted

digicert.comseal.digicert.comocsp.digicert.comcrl.digicert.comcacerts.digicert.comts-ocsp.ws.symantec.com

Cookies placed

NameTypeDurationPurpose
DC_VISITORMarketing / Analytics1 yearSet by the optional DigiCert Smart Seal trust badge to count widget impressions and recognise returning visitors.
seal_sessionFunctionalSessionMaintains the Smart Seal validation session during a visit.
_dc_consentStrictly necessary1 yearStores the visitor's consent status for the DigiCert Smart Seal widget on this site.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does DigiCert set cookies on my visitors' browsers?

Not directly from the certificate. Only the optional DigiCert Smart Seal widget, when embedded on the page, sets cookies such as DC_VISITOR and seal_session, and pings DigiCert servers from the visitor's browser.

Do I need consent to use DigiCert SSL?

No for the certificate itself: HTTPS encryption is a strictly necessary security measure. OCSP/CRL revocation checks rely on legitimate interest or legal obligation. The optional Smart Seal trust widget is non-essential and requires prior consent under ePrivacy.

What is the legal basis for OCSP and CRL processing?

Legitimate interest (Art. 6(1)(f) GDPR) and the legal obligation under Art. 32 GDPR to ensure the security of processing, combined with the CA/Browser Forum baseline requirements. OCSP stapling reduces the personal data flow.

Is data transferred to the United States?

Yes for OCSP, certificate orders and Smart Seal widget. DigiCert is headquartered in the United States. Transfers rely on the 2021 SCCs and EU-US Data Privacy Framework certification.

Do I need a DPIA for DigiCert?

A streamlined DPIA is sufficient for standard certificate use. A more detailed assessment is recommended when DigiCert qualified eIDAS certificates are used for high-trust signing (financial advice, public administration). For Smart Seal use, document the cookie placement and US transfer.

How do I deploy DigiCert in compliance?

Enable OCSP stapling, sign the subscriber agreement and DPA, mention DigiCert in your privacy notice as a processor, prefer EU-based QTSPs for eIDAS qualified certificates, gate the Smart Seal behind your CMP, and monitor Certificate Transparency logs for certificates referencing your domain.

What are EU-based alternatives to DigiCert?

EU-based or EU-friendly Certificate Authorities include Sectigo (UK / Romania), GlobalSign (originally Belgium, now Japan), Atos (France) for qualified eIDAS certificates, Buypass (Norway) and SwissSign (Switzerland with adequacy decision). Let's Encrypt (US non-profit) is free and the default for most low-trust deployments.

How do I update my privacy and cookie policies?

In your privacy notice, name DigiCert as a processor for certificate orders and a recipient for OCSP/CRL traffic; mention the US transfer and the legal basis. If the Smart Seal is embedded, add an entry in the cookie policy for DC_VISITOR / seal_session, describe the purpose and duration, and link to DigiCert's privacy statement.