Overview
Joomla is an open-source content management system (CMS) used to build and manage websites. Unlike SaaS platforms, Joomla runs as self-hosted software on the site operator's server. Its core scripts handle page rendering, user authentication, content management, and extension loading. Joomla's privacy footprint is determined primarily by which third-party extensions the site operator installs.
What This Script Does
Joomla's core scripts are served from the site's own domain and provide:
- CMS framework: Loads JavaScript libraries (jQuery, Bootstrap, custom Joomla scripts) required for page interactivity, form handling, and component rendering.
- Authentication: Manages user login sessions via PHP session cookies and CSRF token validation. Session cookies are set upon login and maintained for authenticated navigation.
- Extension loading: Third-party Joomla extensions (plugins, modules, components) can load additional scripts with varying privacy implications — analytics trackers, marketing tools, social integrations, etc.
- Form handling: Core form components (contact forms, registration forms) process user-submitted data within the local Joomla installation and database.
- No external tracking: Joomla's core does not send data to external servers or set third-party cookies. Any external data transmission comes from installed extensions, not from Joomla itself.
Consent & Compliance
Joomla's core falls under the essential/functional consent category. The CMS framework scripts and authentication cookies are necessary for the website to function.
Under GDPR and ePrivacy, Joomla's core session cookies are "strictly necessary" for website operation and exempt from consent. The CMS scripts load from the site's own domain with no third-party involvement. Extensions that add analytics or marketing functionality would require their own consent assessment.
Under CCPA/CPRA, Joomla's core does not collect or share personal information with third parties. Data processing is limited to the site operator's own server and database.
Should You Block This Without Consent?
No. Joomla's core scripts are essential CMS infrastructure that the website requires to function. Blocking them would render the entire website non-functional. Any privacy-sensitive functionality comes from third-party extensions, which should be evaluated and consented independently.
Is Joomla GDPR compliant?
Joomla typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Joomla can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Joomla, not on Joomla itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
joomla.orgEssentialjoomla.org is an essential domain operated by Joomla, used to keep the site working, including security, load balancing, and sessions.
Frequently Asked Questions
Related Vendors
Manage consent for Joomla
ConsentStack automatically detects and manages Joomla trackers so your site stays compliant with global privacy regulations.