Only load YouTube, maps and other embeds as needed
An embedded video, map or social widget can create connections to multiple third-party providers during a normal page view. A normal link doesn't do that.
Two-click principle
First display a locally delivered placeholder with a description and link. Only create the actual external iframe or widget after a conscious user action.
YouTube Privacy-Enhanced Mode
YouTube provides the youtube-nocookie.com host for enhanced privacy mode. This mode is still an external embed and therefore cannot be equated with a completely local preview.
Scanner must distinguish between loading and linking
A <a href> to an external card or a video does not create a connection to the destination when the page is simply accessed. iframe, script, img and similar resources can do this against this.
Check third-party connections
The technical basis for this can be found under Avoid external resources and unnecessary third-party connections. What is crucial is whether external hosts are contacted before a user action.
Requirements
Access to the integration of external media and a test page on which network requests can be compared before and after user interaction.
Dismantling
If a direct embed is required, only reload the specifically required content directly and check the resulting third-party connections again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.