FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Social Media
  4. YouTube Embed
Y

YouTube Embed

Marketing

Related services

A

AddShoppers

AddShoppers is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. AddShoppers enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, AddShoppers empowers marketing teams to achieve measurable growth.

Marketing

AddThis

AddThis is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. AddThis integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, AddThis helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

AddToAny

AddToAny is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. AddToAny integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, AddToAny helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Cackle

Cackle is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Cackle supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Cackle ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Commento

Commento is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Commento integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Commento helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Douban

Douban is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Douban is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Douban offers reliable solutions that scale with organizational needs and evolving web standards.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does YouTube Embed do?

Embedding YouTube videos on websites causes Google's tracking code to load in visitors' browsers, setting advertising and analytics cookies that track viewing behaviour and build advertising profiles. This requires consent under the ePrivacy Directive. YouTube provides a privacy-enhanced embed domain (youtube-nocookie.com) that significantly reduces cookie placement. Alternatively, using a facade/thumbnail approach delays YouTube loading until users click play, reducing privacy impact.

What a YouTube embed actually does

YouTube is the video platform operated by Google Ireland Limited (controller of record for EU embedders) and Google LLC (sub processor in the United States). When a publisher embeds a YouTube video on its pages, the standard iframe is served from youtube.com and immediately loads JavaScript, fonts and player resources from ytimg.com, googlevideo.com and doubleclick.net. The player exchanges advertising signals with Google Marketing Platform, even when no advertising is displayed on the video.

Cookies and storage set by YouTube embeds

The standard youtube.com embed sets the cookies VISITOR_INFO1_LIVE (visitor identifier, 6 months), YSC (session identifier, browser session), PREF (preferences, 8 months) and IDE on doubleclick.net (advertising id, 13 months) as soon as the iframe loads. The privacy enhanced mode youtube-nocookie.com sets the same cookies only after the user clicks play, instead of on iframe load. Both modes also write localStorage entries to remember playback position and quality settings.

Lawful basis and consent

Consent under GDPR art. 6(1)(a) and ePrivacy art. 5(3) is required before loading any YouTube embed because the iframe drops advertising cookies on third party domains (doubleclick.net, google.com). The CJEU Fashion ID case (C 40/17, July 2019) confirms that the embedding website is joint controller for the data exchanged with the YouTube iframe. The CNIL has fined French organisations for loading YouTube content without consent (e.g. Carrefour 2020, Le Mans Université 2023). Even youtube-nocookie.com is not consent free because the lookup still discloses the visitor IP to Google.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers and Schrems II

Loading a YouTube embed transmits the visitor IP, user agent, referrer and cookies to Google LLC in the United States. Google LLC is certified under the EU US Data Privacy Framework since 10 July 2023 and the YouTube Terms incorporate the EU Standard Contractual Clauses (module 3). However, the EDPB binding decision against Google Analytics (1/2022) and several DPA fines confirm that the publisher must also implement supplementary measures, document a transfer impact assessment and inform users.

Practical compliance checklist

Replace the standard iframe with a click to load placeholder (poster image plus play button) that only loads the YouTube embed after consent. Use the youtube-nocookie.com domain instead of youtube.com to minimise cookie writes before play. Document Google Ireland Limited and Google LLC in your records of processing (GDPR art. 30) and in the privacy notice. List the cookies VISITOR_INFO1_LIVE, YSC, PREF and IDE in your cookie policy. Consider self hosting the most important videos with Plyr, Mux Video, Vimeo Pro or a Bunny.net stream for sensitive content. Refresh the consent every six months in line with CNIL deliberation 2020 091.

Alternatives

GDPR friendly alternatives include Vimeo Privacy Friendly Embed (US with EU residency), Cloudflare Stream, Mux Video (EU and US), Bunny Stream (Slovenia and global edge), PeerTube (open source self hostable), Dailymotion (France) and the self hosted Plyr or Video.js stack with HLS manifests on your own CDN.

GDPR consent category

Marketing

Websites using YouTube Embed must obtain user consent under GDPR regulations.

Legal basisConsent (GDPR art. 6(1)(a) and ePrivacy art. 5(3)) for the standard youtube.com embed because it sets advertising cookies (VISITOR_INFO1_LIVE, YSC, PREF, IDE) and DoubleClick identifiers before any interaction. Even the youtube-nocookie.com privacy enhanced mode reads cookies and writes localStorage on play, so a documented user action equivalent to consent is needed.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, CJEU C 40/17 Fashion ID, EDPB binding decision 1/2022 against Google Analytics, CNIL deliberation 2020 091, TTDSG, LOPDGDD, LIL

DPIA considerations

A DPIA is generally not required for standard YouTube video embedding with proper consent management. It may become relevant for large media platforms embedding many videos where Google's audience tracking creates systematic profiling of visitors.

Sample consent text

This page embeds YouTube videos provided by Google Ireland Limited (operator) and Google LLC (sub processor in the United States). When you click play, YouTube sets advertising cookies (VISITOR_INFO1_LIVE, YSC, PREF, IDE) and transmits your IP address, user agent and the video viewed to Google in the United States under the EU US Data Privacy Framework and the EU Standard Contractual Clauses. We load each YouTube embed only after you accept the marketing or video category in our cookie preferences, and we use the youtube-nocookie.com privacy enhanced mode whenever possible.

Technical details

Tracking methodembedded_iframe_video_player_with_advertising_cookies
Server locationYouTube embeds are served from the Google global network (youtube.com, youtube-nocookie.com, ytimg.com, googlevideo.com). EU visitors typically connect to a European Google Cloud edge (Frankfurt, Ireland, Belgium, the Netherlands), but the back end resolution and advertising auction are global, with significant US infrastructure involvement.
Cookieless tracking availableYes
Data transferred outside the EUGoogle Ireland Limited is the contracting entity for EU embedders; Google LLC in the United States is the principal sub processor. Embedding YouTube content transmits the visitor IP, user agent, referrer and a set of advertising cookies to Google. Transfers rely on the EU US Data Privacy Framework certification of Google LLC and the EU Standard Contractual Clauses bundled with the YouTube Terms.

Third-party domains contacted

youtube.comwww.youtube-nocookie.comi.ytimg.com

Cookies placed

NameTypeDurationPurpose
YSCsessionSessionYouTube session identifier loaded on standard YouTube embed — tracks viewing session data
VISITOR_INFO1_LIVEpersistent6 monthsYouTube visitor identifier for tracking viewing history and personalising recommendations

YouTube Embed places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Does embedding YouTube require GDPR consent?

Standard YouTube embeds require consent as they set advertising cookies immediately on page load. Using youtube-nocookie.com reduces but may not fully eliminate consent requirements. The facade approach (thumbnail loading) is the most privacy-friendly and may not require a consent banner.

What is the youtube-nocookie.com embed?

youtube-nocookie.com is YouTube's privacy-enhanced embed domain. According to Google, it does not set cookies until the user plays the video. Enable it by replacing "youtube.com/embed/" with "www.youtube-nocookie.com/embed/" in your iframe src URL. WordPress' built-in YouTube block uses this by default.

What cookies does a standard YouTube embed set?

Standard YouTube embeds set VISITOR_INFO1_LIVE (YouTube visitor ID, 6 months), YSC (session, no expiry), and may set advertising cookies if the user is logged into Google. These require consent. The youtube-nocookie.com mode avoids setting these cookies until play.

Does YouTube transfer data outside the EU?

Yes. All YouTube (Google) processing occurs on US infrastructure. SCCs are required as part of Google's standard terms. Accept Google's data processing terms and disclose the US transfer in your privacy policy when embedding YouTube videos.

How do I implement the YouTube facade pattern?

Use the lite-youtube-embed library (available on npm and GitHub) which renders a thumbnail and loads the actual YouTube iframe only when clicked. This is semantic, accessible, dramatically faster, and privacy-respecting. Alternatively, use a custom implementation with a thumbnail image and onclick handler that replaces the image with the actual iframe.

Is the youtube-nocookie.com embed GDPR compliant without consent?

Legal opinions differ. Google says no cookies are set until play. Some DPAs consider even IP address transmission on iframe load to be personal data transfer requiring consent. The safest approach: use youtube-nocookie.com AND the facade pattern, so the YouTube domain only receives a request when the user actively clicks play.

What are EU-based alternatives to YouTube embedding?

Vimeo (US-hosted but with dnt=1 privacy mode), Wistia (US-hosted), and Dailymotion (French company) are alternatives. For self-hosted video, PeerTube (open-source, EU-hostable) provides a YouTube-compatible embed without Google's data practices.

Do I need to mention YouTube embeds in my privacy policy?

Yes. Disclose that the website embeds YouTube videos, that YouTube (Google) sets cookies when videos are loaded or played, that data is transferred to Google in the US, and provide a link to YouTube's Privacy Policy. If using youtube-nocookie.com, note that this reduces but may not eliminate data processing.