FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Medium

Medium

Other

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Medium do?

Medium is a US publishing platform whose embeds and widgets set cookies for analytics and personalization. Embedding Medium content requires prior consent under the ePrivacy Directive.

What Medium Is

Medium is an online publishing platform launched in 2012 by Evan Williams, co-founder of Twitter and Blogger. Operated by A Medium Corporation from San Francisco, California, Medium hosts articles written by individual authors and professional publications on a wide range of topics. Readers can browse for free with limits or subscribe to the paid Medium Member program for unlimited access. Authors can earn money through the Medium Partner Program based on reader engagement.

Beyond its native website and apps, Medium offers JavaScript embeds that allow third-party websites to display a Medium post, a follow button or a profile widget. These embeds are commonly used by company blogs, portfolios and newsletters that want to surface Medium content without rehosting it. The embedded scripts are served from medium.com and related domains and execute in the visitor''s browser as soon as the page loads.

Data and Cookies Set by Medium Embeds

When a Medium embed loads, the visitor''s browser establishes a direct connection to Medium servers. Medium can read existing cookies (such as a persistent visitor identifier uid and a session identifier sid) and may write new ones for personalization, preferences (pr), timezone (tz) and cross-site request protection (xsrf). Medium also relies on its internal analytics stack and historically on third-party analytics such as Mixpanel and Google Analytics.

In addition to cookies, Medium automatically receives the page URL where the embed appears, the visitor IP address, the user agent string and the language/timezone of the browser. When the visitor is logged into a Medium account, these signals can be linked to a known profile and used to refine the recommendation engine on medium.com. From a data protection standpoint this constitutes personal data processing by Medium and creates a joint or independent controller-processor relationship with the website operator.

GDPR and ePrivacy Implications

Because Medium embeds store and read information on the visitor''s terminal equipment, Article 5(3) of the ePrivacy Directive (as transposed in national law) requires prior, informed and freely given consent before any non-essential cookie is set. The GDPR adds a layer of obligations: the website operator must identify a lawful basis under Art. 6, perform a balancing test for any legitimate interest claim, inform users in a clear privacy notice and keep a record of processing activities.

For embeds that load advertising or profiling cookies, EDPB guidance and consistent case law from the CJEU (Fashion ID, Planet49) treat the website operator and Medium as joint controllers for the collection and transmission phase. The website is responsible for collecting valid consent; Medium is responsible for what it does with the data afterwards.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International Transfers to the United States

A Medium Corporation is established in the United States and processes the data collected through embeds on infrastructure located in the US (AWS and Google Cloud regions). Transfers from the EU/EEA to the US are subject to Chapter V of the GDPR. In practice, controllers must rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR or, where applicable, on a self-certification of Medium under the EU-US Data Privacy Framework. A Transfer Impact Assessment is required to evaluate US surveillance laws (FISA 702, EO 12333) and, when needed, implement supplementary measures.

Compliance Steps for Embedding Medium Content

To embed Medium content lawfully, integrate the embed script through a Consent Management Platform that blocks third-party JavaScript until the visitor opts in to the Statistics or Marketing category. Display a contextual placeholder (a click-to-load card) explaining that loading the content will transfer data to Medium in the United States. Update the cookie notice and privacy policy to list the cookies, the categories of recipients, the retention periods and the transfer mechanism. Keep a written assessment of joint controllership where the embed includes the follow button or other profiling elements.

Lower-impact alternatives include republishing the article on your own site under a canonical link, using Medium''s RSS feed to render static excerpts, or hosting your blog on a self-managed platform such as Ghost or WordPress when the editorial workflow allows it.

GDPR consent category

Other

Websites using Medium must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for embeds with cookies and for advertising and recommendation profiling
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), CCPA

DPIA considerations

A DPIA is recommended when Medium embeds are used at scale or combined with other tracking. Assess data minimisation, the risk of cross-site tracking, profiling for recommendations and the international transfer to the United States. Document mitigation measures such as conditional loading after consent and the use of Standard Contractual Clauses with a Transfer Impact Assessment.

Sample consent text

This page contains content embedded from Medium (A Medium Corporation, USA). Loading these embeds places cookies on your device used for analytics, personalization and recommendations, and transfers your IP address and browsing data to the United States. Do you accept the loading of Medium content?

Technical details

Tracking methodJavaScript embed (post embed, follow button, profile widget) and analytics cookies
Server locationUnited States (A Medium Corporation, San Francisco)
Data transferred outside the EUMedium processes data on infrastructure in the United States. International transfers are governed by Standard Contractual Clauses under Art. 46(2)(c) GDPR and require a Transfer Impact Assessment.

Third-party domains contacted

medium.com*.medium.comcdn-images-1.medium.commiro.medium.commedium.statuspage.io

Cookies placed

NameTypeDurationPurpose
uidtracking1 yearPersistent visitor identifier used by Medium to recognise returning readers across sessions and to feed the recommendation engine
sidfunctionalSessionSession identifier maintaining the visitor state while interacting with Medium embeds and pages
_gaanalytics2 yearsGoogle Analytics client identifier set when Medium loads its analytics stack; used to distinguish unique visitors
prfunctional6 monthsStores reader preferences such as content density and display options on the Medium interface
tzfunctional6 monthsStores the visitor timezone to display localised dates and times for articles and notifications
xsrfsecuritySessionCross-site request forgery token protecting authenticated actions performed against Medium services

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does a Medium embed set on my visitors devices?

A typical Medium embed can store or read several cookies including uid (persistent visitor identifier used to recognise returning readers), sid (session identifier), pr (preferences), tz (timezone) and xsrf (cross-site request forgery protection). Depending on the configuration, analytics cookies such as _ga (Google Analytics) and Mixpanel identifiers may also be set. None of these are strictly necessary for the website operator and therefore require consent.

Do I need user consent before loading a Medium embed?

Yes. Because the embed reads and writes information on the visitors device for purposes that are not strictly necessary, Article 5(3) of the ePrivacy Directive requires prior, informed and freely given consent. The embed script and any associated cookies must remain blocked until the visitor opts in through a compliant Consent Management Platform.

What is the appropriate legal basis under GDPR?

For non-essential cookies, ePrivacy already mandates consent and consent (Art. 6(1)(a) GDPR) is the most appropriate basis for the subsequent processing. Legitimate interest (Art. 6(1)(f) GDPR) is generally not available where profiling cookies are involved because the balancing test rarely favours the controller in light of the visitor s expectations.

Are visitor data transferred to the United States?

Yes. A Medium Corporation is headquartered in San Francisco and processes the data on US-based infrastructure (AWS, Google Cloud). Transfers from the EU/EEA rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where applicable, on a self-certification under the EU-US Data Privacy Framework. A documented Transfer Impact Assessment is required.

Do I need to carry out a Data Protection Impact Assessment?

A DPIA is not automatic but is strongly recommended when Medium embeds are widely deployed, when they are combined with other tracking technologies or when they appear on pages targeting children or vulnerable audiences. The DPIA must address profiling, the international transfer and the rights of data subjects.

How do I implement Medium embeds in a compliant way?

Wrap the Medium embed code in a script type "text/plain" or use the data-attribute pattern recognised by your CMP. Display a contextual placeholder explaining the data transfer and giving access to a granular consent choice. Activate the script only after the visitor opts into the relevant category. Document the implementation in your records of processing activities.

What are the alternatives to embedding Medium?

You can republish the article on your own website with a canonical link pointing back to Medium, use Medium s RSS feed to render static excerpts on the server side, or move to a self-hosted publishing platform. Substack, Ghost, Hashnode, Dev.to, WordPress and LinkedIn Articles are the most common alternatives, each with their own compliance trade-offs.

Must Medium be listed in my cookie policy and privacy notice?

Yes. Your cookie notice should list the Medium cookies with their name, purpose and retention, and your privacy policy should identify Medium as a recipient of personal data, describe the purpose of the processing, mention the transfer to the United States and the safeguards in place, and explain how visitors can exercise their GDPR rights.