← All guides

Only load YouTube, maps and other embeds as needed

An embedded video, map or social widget can create connections to multiple third-party providers during a normal page view. A normal link doesn't do that.

Two-click principle

First display a locally delivered placeholder with a description and link. Only create the actual external iframe or widget after a conscious user action.

YouTube Privacy-Enhanced Mode

YouTube provides the youtube-nocookie.com host for enhanced privacy mode. This mode is still an external embed and therefore cannot be equated with a completely local preview.

Scanner must distinguish between loading and linking

A <a href> to an external card or a video does not create a connection to the destination when the page is simply accessed. iframe, script, img and similar resources can do this against this.

Check third-party connections

The technical basis for this can be found under Avoid external resources and unnecessary third-party connections. What is crucial is whether external hosts are contacted before a user action.

Requirements

Access to the integration of external media and a test page on which network requests can be compared before and after user interaction.

Dismantling

If a direct embed is required, only reload the specifically required content directly and check the resulting third-party connections again.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑