FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Amazon Cognito

Amazon Cognito

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Amazon Cognito do?

AWS identity service that handles user sign up, sign in, multi factor authentication, password recovery and federation with social or enterprise identity providers for web and mobile apps.

What Amazon Cognito does

Amazon Cognito is the identity service of AWS. It provides user pools to sign up and authenticate end users with email, phone, social logins (Google, Facebook, Apple, SAML, OIDC), multi factor authentication and password recovery, and identity pools that grant temporary AWS credentials to authenticated users so an app can call AWS APIs on their behalf.

Data and cookies handled

Cognito processes account attributes (email, phone, custom claims), passwords, MFA secrets, OAuth and OIDC tokens, IP addresses, device fingerprints (when advanced security is enabled) and login activity. The hosted UI sets first party cookies on the auth domain (XSRF token, session cookie) and the client app typically stores ID, access and refresh tokens in cookies or browser storage.

GDPR and ePrivacy implications

Cookies and tokens used to keep a user signed in are strictly necessary under Article 5(3) of the ePrivacy Directive and do not require prior consent. AWS acts as a processor under the AWS Data Processing Addendum, which includes Standard Contractual Clauses and references the EU US Data Privacy Framework. Advanced security features (adaptive authentication, compromised credentials check) involve risk based profiling that should be disclosed in the privacy notice.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

You do not need consent to authenticate a user with Cognito. You do need consent when the login flow loads third party social federation widgets that set tracking cookies (Google, Facebook, Apple), and you must inform users that signing in via a social provider shares some identifiers with that provider.

Data transfers and EU regions

Cognito user pools and identity pools store data in the AWS region you choose. To minimise transfers, deploy in eu west 1 (Ireland), eu central 1 (Frankfurt), eu west 3 (Paris), eu south 1 (Milan), eu north 1 (Stockholm) or eu west 2 (London). Administrative metadata, support tickets and operational telemetry can still be processed by AWS staff in the United States under SCCs and the EU US Data Privacy Framework.

Practical compliance steps

Sign the AWS DPA, select an EU AWS region, enforce strong password policy and MFA, set token validity to a reasonable lifetime, restrict admin actions through IAM roles, log CloudTrail and Cognito events for accountability, document data subject rights workflows (export, deletion via AdminDeleteUser API), and run a DPIA when advanced security features or large scale identity processing are activated.

GDPR consent category

Essential

Websites using Amazon Cognito must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(b) GDPR (contract performance) for user authentication and account management; Article 6(1)(f) GDPR (legitimate interest) for security and fraud prevention. Consent is only required for optional social or marketing federation that triggers third party tracking.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, German TTDSG, French CNIL guidance on identity providers, Spanish LOPDGDD

DPIA considerations

A DPIA is recommended when Cognito is used for large scale authentication, when it processes sensitive categories (health, public sector identity), when it federates with multiple third party identity providers, or when advanced security features perform risk based profiling of user devices and IP addresses.

Sample consent text

We use Amazon Cognito (Amazon Web Services) to manage user accounts, sign in and authentication. Authentication cookies and tokens are strictly necessary to keep you signed in. If you choose to log in with a third party provider (Google, Facebook, Apple), those providers may receive your identifiers under their own terms.

Technical details

Tracking methodOAuth 2.0 / OpenID Connect authentication tokens (JWT), session cookies, identity tokens, optional federation cookies
Server locationConfigurable AWS region (EU regions available: eu-west-1 Ireland, eu-central-1 Frankfurt, eu-west-3 Paris, eu-south-1 Milan, eu-north-1 Stockholm, eu-west-2 London)
Data transferred outside the EUAmazon Cognito is operated by Amazon Web Services, Inc., a US based company. Customer data stays in the AWS region you select, but administrative metadata, support requests and operational telemetry can be processed in the United States. AWS provides Standard Contractual Clauses and is self certified under the EU US Data Privacy Framework.

Third-party domains contacted

auth.<region>.amazoncognito.comcognito-idp.<region>.amazonaws.comcognito-identity.<region>.amazonaws.comamazoncognito.comamazonaws.com

Cookies placed

NameTypeDurationPurpose
XSRF-TOKENhttpSessionCSRF protection for the Cognito Hosted UI login forms.
cognito-flhttpSessionFlag cookie used by the Hosted UI to track multi step login flows.
csrf-statehttp10 minutesStores the state parameter used during OAuth and federation flows to prevent replay attacks.
CognitoIdentityServiceProvider.<clientId>.<sub>.idTokenhttp1 hour (configurable)Stores the OpenID Connect ID token issued to the authenticated user.
CognitoIdentityServiceProvider.<clientId>.<sub>.accessTokenhttp1 hour (configurable)Stores the OAuth 2.0 access token used to call protected APIs.
CognitoIdentityServiceProvider.<clientId>.<sub>.refreshTokenhttp30 days (configurable, up to 10 years)Allows the client to obtain new access and ID tokens without re authentication.
CognitoIdentityServiceProvider.<clientId>.LastAuthUserhttpPersistentStores the username of the last user signed in on this device.

Amazon Cognito is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Amazon Cognito set?

The Hosted UI sets XSRF-TOKEN, csrf-state and a flow cookie on its own auth.<region>.amazoncognito.com domain. Once authenticated the client app stores ID, access and refresh tokens, typically as CognitoIdentityServiceProvider.* cookies or browser storage entries.

Do I need consent to use Cognito?

No for authentication itself: session cookies and tokens are strictly necessary. Yes for any social login button that loads Google, Facebook or Apple SDKs that set their own tracking cookies, and yes if advanced security features build a behavioural profile beyond what is required for security.

What is the legal basis for processing identity data?

Article 6(1)(b) GDPR (contract performance) covers account creation, login and password management. Article 6(1)(f) (legitimate interest) covers fraud prevention, abuse mitigation and security audit logs. Consent (Article 6(1)(a)) is needed for optional federation that exposes data to third parties.

Does Cognito transfer data to the United States?

Customer data stays in the AWS region you select. Administrative metadata, support requests, and operational telemetry can be processed in the United States by AWS staff, under Standard Contractual Clauses and the EU US Data Privacy Framework as described in the AWS DPA.

Do I need a DPIA?

A DPIA is recommended (and may be mandatory under Article 35 GDPR) for large scale identity processing, public sector identity, sensitive sectors (health, finance), or when adaptive authentication and risk based profiling are enabled.

How do I implement Cognito compliantly?

Pick an EU AWS region, sign the AWS DPA, enforce MFA, restrict token lifetimes, manage admin access via IAM roles, log via CloudTrail, expose data subject rights flows (export and AdminDeleteUser), and limit the user attributes collected to what is strictly required.

What are the alternatives?

Other identity providers include Auth0, Okta Customer Identity, Microsoft Entra External ID, Keycloak (self hosted), FusionAuth, Ory Hydra/Kratos, Clerk, WorkOS and Supabase Auth. Each has its own residency, pricing and integration model that must be evaluated separately.

How do I update the cookie policy?

Run a cookie scan focused on the auth and callback pages, list the strictly necessary Cognito cookies (XSRF-TOKEN, csrf-state, token storage), note that they are first party on your auth domain, and document any third party social login cookies that are loaded on user action.