Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Open source HTML5 video player library. It sets no cookies and tracks nothing by default, but loading it from a third party CDN exposes the visitor IP to the CDN operator.
Video.js is a widely used open source HTML5 video player library. It renders video entirely in the visitor browser and, in its default self hosted form, sets no cookies and performs no tracking. The main privacy questions arise from how the library is delivered and which optional integrations are enabled.
Video.js provides a consistent player skin and controls across browsers and devices. The core library is first party JavaScript that you bundle or host yourself. It does not phone home, profile users or store identifiers, so a plain self hosted setup is cookieless and privacy friendly.
Many sites load Video.js from a public CDN such as jsDelivr or cdnjs. Each such request reveals the visitor IP address and user agent to the CDN operator. German courts have treated comparable third party asset loading, notably Google Fonts served from Google servers, as a processing and transfer event that needs a legal basis. Self hosting the player files avoids this exposure entirely.
Video.js can play streams from third party platforms through plugins such as the YouTube tech. When these are enabled, the third party provider may set cookies, build profiles and transfer data outside the EEA. That moves the player from a purely functional tool into territory that requires prior opt in consent under the ePrivacy Directive.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For a self hosted, cookieless player, legitimate interest is a sound basis and the risk is low. Once a third party CDN or an external streaming integration is involved, you should document a legitimate interest assessment for the IP transfer or, for tracking integrations, obtain consent. Risk then ranges from low to medium depending on configuration.
Self host the Video.js files, serve your own video where possible, and gate any external embeds behind a consent step. This keeps the player cookieless, avoids leaking visitor IP addresses to third parties and keeps your privacy policy simple and accurate.
Websites using Video.js must obtain user consent under GDPR regulations.
DPIA considerations
A full DPIA is rarely required for a self hosted Video.js player, because the library sets no cookies and performs no tracking. A documented assessment becomes useful when the player is loaded from a third party CDN, since the visitor IP and user agent reach the CDN operator, or when integrations such as the YouTube tech are enabled, which introduce third party tracking and possible transfers outside the EEA.
Sample consent text
This site uses the Video.js player to show video content. The core player runs in your browser and sets no cookies. Where video is embedded from third party platforms, those providers may set cookies and process your data; we ask for your consent before loading them.
Third-party domains contacted
vjs.zencdn.netcdn.jsdelivr.netcdnjs.cloudflare.comunpkg.comwww.youtube.comVideo.js uses cookies for user preferences — inform visitors with a consent banner.
No. The core Video.js library is client side JavaScript and sets no cookies of its own. Cookies only appear if you enable a third party streaming integration, such as embedding YouTube, where the external provider sets them.
For a self hosted, cookieless player no prior consent is needed. Consent becomes necessary when you embed third party sources that set cookies or track users, because those fall under the ePrivacy opt in rule.
A self hosted player can rely on legitimate interest, since it only delivers functionality. If you load it from a third party CDN, document that legitimate interest for the IP transfer; tracking integrations require consent instead.
The library itself does not. If served from a public CDN such as jsDelivr or cdnjs, the visitor IP and user agent reach the CDN operator, whose edge nodes may sit in the United States. Streaming integrations add further transfers.
Usually not for a plain self hosted player. A short assessment is sensible if you load it from a third party CDN or enable tracking integrations, since those involve IP transfers or profiling.
Self host the player files instead of loading from a public CDN, serve your own video where possible, and place any external embeds behind a consent gate so no third party loads before the visitor agrees.
Other privacy friendly options include Plyr and the native HTML5 video element. All of them are cookieless when self hosted; the main difference is features and styling rather than tracking behaviour.
If self hosted, note that a cookieless video player is used and sets no cookies. If you load it from a CDN, mention the CDN operator and the IP transfer; if you embed external video, list those providers and their cookies.