Overview
Drupal is an open-source content management system used to build and manage websites. Like WordPress and Joomla, Drupal runs as self-hosted software on the site operator's server. Its core scripts handle page rendering, form processing, user authentication, and content management. The privacy footprint of a Drupal site depends primarily on which contributed modules the site operator installs.
What This Script Does
Drupal's core scripts are served from the site's own domain:
- CMS framework: Loads core JavaScript libraries for UI interactions, AJAX requests, form enhancements, and content administration tools.
- Form handling: Processes contact forms, registration forms, and custom data collection forms with CSRF protection and server-side validation.
- Authentication: Manages user session cookies for authenticated access to protected content and administrative interfaces.
- Module integration: Drupal's contributed module ecosystem can add any functionality — analytics tracking, marketing pixels, social media integrations — each with its own privacy implications.
- No external tracking: Drupal's core does not send data to external servers or set third-party cookies. All core operations happen on the site operator's own server.
Consent & Compliance
Drupal's core falls under the functional consent category. The CMS framework scripts and authentication cookies are necessary for the website to function.
Under GDPR and ePrivacy, Drupal's core session cookies are "strictly necessary" for website operation. The CMS scripts load from the site's own domain. Contributed modules that add analytics, marketing, or social media functionality require their own consent assessment.
Under CCPA/CPRA, Drupal's core does not collect or share personal information with third parties.
Should You Block This Without Consent?
No. Drupal's core scripts are essential CMS infrastructure. Blocking them would render the entire website non-functional. Privacy-sensitive functionality from contributed modules should be evaluated and consented independently.
Is Drupal GDPR compliant?
Drupal typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Drupal can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Drupal, not on Drupal itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
drupal.orgFunctionaldrupal.org is a functional domain operated by Drupal, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Drupal
ConsentStack automatically detects and manages Drupal trackers so your site stays compliant with global privacy regulations.