Joomla: Use data protection functions and check extensions separately
Joomla comes with privacy features that help with requests, consent and checking installed extensions. However, this does not automatically mean that a Joomla site does not store any visitor IP.
Requirements
Joomla administration access as well as an overview of active extensions and upstream server or proxy services.
Use Privacy Dashboard
The privacy system can alert administrators to privacy features and extensions. For “We don’t save!” This is a checkpoint, not proof of a data-efficient configuration.
Check extensions individually
Forms, comments, security, statistics and newsletter extensions can add their own tables, cookies, logs or external resources. Therefore, inventory each active extension separately.
Server level remains independent
Even a minimally configured Joomla application does not automatically prevent IP addresses in web server, PHP, proxy or hoster logs.
Further check
For the overall technical check, also use the checking checklist for unnecessary visitor data and check extensions, browser memory, network requests and server logs separately.
Dismantling
If a deactivated function is required for operational purposes, just reactivate it and then check the resulting data flows and logs again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.