This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →
Data protection
How can YouTube videos and Google Maps be embedded in a privacy-friendly way?
The cleanest way is a two-click solution: the visitor first sees only a preview image, and only their click loads the actual content from the third-party server. Our check recognises both states — it reports embeds that already load on page visit as a finding, and counts embeds with a two-click pattern or a consent loader as correctly solved.
What actually happens when embedding
An embedded video or map is a window into a third-party server. If it loads on page visit, every visitor's browser automatically contacts the provider — YouTube, Google Maps, Vimeo, Facebook, Instagram, Spotify, or SoundCloud — transmitting the IP address and device data in the process. That happens before the visitor even wanted to play the video. The check examines the state of the page before any consent and lists every piece of third-party content that was already loaded from the third-party server at that moment.
The two-click solution passes the check
With the two-click solution, only a placeholder from your own server sits where the video would be at first — usually a preview image with a play button and a brief notice. Only the visitor's click loads the content from the provider; that click is at the same time their consent for exactly this content. The check technically recognises this pattern and counts such embeds as met. The report lists them separately, so it stays visible which content is already correctly solved and which should still be switched over.
Even Like buttons load a third-party script
Embeds come in two forms: as an embedded frame and as a script. A Facebook Like button, for instance, isn't a frame — it loads a program directly from the Facebook server, and thereby also transmits visitor data on mere page visit. The check recognises known script embeds from Facebook, X, Instagram, TikTok, Pinterest, LinkedIn, and SoundCloud, and treats them like visible embeds. Anyone who wants to offer such buttons has them load the same way as videos: only after consent, or after a deliberate click by the visitor.
- Count which pages on your website embed videos, maps, or social media posts.
- Ask your agency to switch every embed to a two-click preview or a consent loader.
- Try replacing an embedded directions map with a static image and a link — that's often entirely enough.
- Also check Like and Share buttons: they load third-party scripts and count as embeds.
- After switching over, load your page in a private window and watch the network tab (F12) for whether third-party servers are still contacted before any click.
FAQ
Is YouTube's privacy-enhanced mode (youtube-nocookie) enough?
The check treats this variant as requiring consent too. The mode does forgo certain cookies, but the browser still contacts Google servers on loading and transmits the visitor's IP address in the process. Anyone who wants to be on the safe side combines the embed with a two-click preview — then this variant also loads only after the click.
What is a two-click solution?
A placeholder from your own server sits where the video or map will later appear — usually a preview image with a notice. The visitor's first click counts as consent and loads the content from the provider, the second click starts it. Before the first click, no visitor data flows to the provider. The check recognises this pattern and counts it as met.
Does an OpenStreetMap map also count as a consent-requiring embed?
The check doesn't classify OpenStreetMap embeds as requiring consent and deducts no points for them. Behind the service is a non-profit project with no advertising tracking. As with all classifications: this is a technical categorisation for the assessment, not legal advice — the transmission of the IP address to the map server happens here too.
Does a Facebook Like button count as an embed?
Yes. The button loads a script directly from the Facebook server, and that loading alone transmits visitor data — regardless of whether anyone actually clicks the button. The check recognises such script embeds and treats them like visible embeds: they should load only after consent or after a deliberate click by the visitor.