Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Smash Balloon Instagram Feed is a popular WordPress plugin that displays Instagram feeds on your site. It fetches posts via the Instagram Graph API and caches them server side, but displayed images load from Instagram and Meta CDNs, exposing the visitor IP to Meta.
Smash Balloon Instagram Feed is a widely used WordPress plugin that connects to the Instagram Graph API to display Instagram posts, reels or stories on your website. The plugin fetches post data server side and caches it, but when a visitor views the page their browser loads media files directly from Instagram and Meta CDN domains, which exposes the visitor IP address to Meta.
The plugin itself sets no tracking cookies and performs API calls server side. However, when images are loaded directly from Meta CDNs, the visitor browser may receive Meta cookies including datr (a browser identifier used for security and advertising, lasting 2 years) and ig_did (an Instagram device identifier lasting 1 year). The visitor IP, browser and referrer are also exposed to Meta with every CDN image request. Enabling local image caching in the plugin eliminates these direct browser to Meta connections.
Where images are served directly from Meta CDNs, the ePrivacy Directive requires prior consent before Meta cookies can be placed on the visitor device. Under GDPR, the transfer of IP and device data to Meta in the United States requires a lawful basis and an appropriate transfer mechanism. If images are fully cached locally, the privacy risk drops significantly and legitimate interest may be a viable basis for the server side API calls.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
If Meta media is loaded directly in the visitor browser, consent must be obtained before the feed renders. Implement this by deferring the feed load behind a consent management platform check. If you enable full local image caching and serve all media from your own server, the need for prior consent is substantially reduced, though you must still disclose the server side Instagram API connection in your privacy policy.
Meta Platforms Inc. is headquartered in the United States. When visitor browsers load images from scontent.cdninstagram.com or fbcdn.net domains, their IP addresses and device data are transferred to the United States. Meta relies on the EU US Data Privacy Framework and standard contractual clauses as transfer mechanisms. Enabling local image caching eliminates this direct browser to US transfer.
To use Smash Balloon Instagram Feed compliantly: enable local image caching in the plugin settings to prevent direct browser to Meta connections; if caching is not used, gate the feed behind consent; add Meta and Instagram to your cookie policy; disclose the Instagram Graph API connection in your privacy notice; document the transfer mechanism for any remaining US data transfer; review the plugin settings after each update to confirm caching remains active.
Websites using Smash Balloon Instagram Feed must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered if your site attracts a large audience or serves vulnerable users and displays Instagram media loaded directly from Meta CDNs, as each page load exposes the visitor IP to Meta in the United States. Key risks include involuntary data transfer to Meta before any consent is given, potential Meta cookie setting, and the difficulty of obtaining meaningful consent for background CDN requests. Mitigation: enable local image caching in the plugin settings to eliminate direct browser to Meta connections. Document the caching configuration and any residual transfer mechanism.
Sample consent text
This section of the page loads Instagram photos directly from Meta servers. Meta may receive your IP address and may set cookies when these images load. Do you consent to loading Instagram content from Meta?
Third-party domains contacted
scontent.cdninstagram.com*.fbcdn.netgraph.instagram.comwww.instagram.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| datr | Marketing | 2 years | Meta browser identifier used for security purposes and advertising targeting, set when Meta CDN media is loaded in the visitor browser |
| ig_did | Tracking | 1 year | Instagram device identifier that persists to track the visitor device across Instagram and Meta properties |
| plugin_cache | Functional | Configured by admin | Server side cache entry used by Smash Balloon to store fetched Instagram post data locally, not set in the visitor browser |
Smash Balloon Instagram Feed collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The Smash Balloon plugin itself sets no tracking cookies. However, when images are loaded directly from Meta CDNs, the visitor browser may receive Meta cookies including datr (a browser identifier used for security and advertising lasting 2 years) and ig_did (an Instagram device identifier lasting 1 year). Enabling local image caching in the plugin settings prevents these Meta cookies from being set.
Consent is required if Instagram images are loaded directly from Meta CDNs, because Meta cookies may be set on page load. If you enable full local image caching so that all media is served from your own server, the direct browser to Meta connection is eliminated and prior consent may not be required, though you should still disclose the server side Instagram API connection.
Where Meta media is loaded directly in the visitor browser, the required legal basis is consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy. If images are fully self hosted via the plugin cache and no Meta cookies are set, legitimate interest under Article 6(1)(f) GDPR may be a viable basis for the server side Instagram API connection, provided you conduct a balancing test.
Yes, when images are loaded from Meta CDNs in the visitor browser. Meta Platforms Inc. is headquartered in the United States and visitor IP addresses and device data are transferred when the browser requests images from scontent.cdninstagram.com or fbcdn.net. Meta relies on the EU US Data Privacy Framework and standard contractual clauses. Enabling local image caching eliminates this direct browser to US transfer.
A DPIA should be considered for high traffic sites where Instagram images are loaded directly from Meta CDNs, as each page view exposes visitor data to Meta in the United States without prior consent. Key risks include the involuntary nature of the data transfer and the difficulty of obtaining informed consent for background CDN requests. Enabling local image caching substantially reduces this risk.
Enable local image caching in the plugin settings to prevent direct browser to Meta connections. If caching is not used, gate the Instagram feed behind a consent check using your consent management platform. Add Meta and Instagram to your cookie policy. Disclose the server side Instagram Graph API connection in your privacy notice. Document any remaining US data transfer and the applicable transfer mechanism.
Self hosting all Instagram images via the plugin cache is the most privacy friendly configuration and may eliminate the need for prior consent. Alternatively, display static screenshots of your Instagram posts hosted on your own server with a link to your Instagram profile. This eliminates all Meta CDN connections and Meta cookie risk entirely.
If Instagram images are loaded from Meta CDNs, add Meta and Instagram to your cookie policy listing datr (2 years, security and advertising identifier) and ig_did (1 year, Instagram device identifier). State that visitor IP and device data may be transferred to Meta in the United States under the EU US Data Privacy Framework. If you use full local image caching, note that no Meta cookies are set and describe the server side Instagram API connection.