Many websites publish embedded content, such as YouTube videos, that send data to Google and store cookies on the user’s device. If the consent management system is missing or misconfigured, this can mean placing cookies without the user’s consent.
YouTube cookies
When we use YouTube, we send Google a range of data that identifies our device and measures our activity, including our interactions with the video. This data is used for security purposes (e.g. limiting bots and artificial views of videos, including ads), as well as for statistical and advertising purposes – to measure ad conversions, profile the user and show them more relevant ads, including remarketing.
In general, there is nothing wrong with this, but under the law it cannot happen without our prior, explicit consent. When we go to YouTube, we are asked for consent to process data, including cookies. In the case of content embedded on a website, the obligation to obtain consent passes to the website that publishes that content.
Enhanced privacy mode (youtube-nocookie.com)
Google offers a special privacy-enhanced mode for YouTube, in which interactions with a given video do not affect the personalisation of other content on YouTube and are not used for profiling for advertising purposes, and any ads shown in that video will not use the data about the user’s earlier activity that Google holds.
Enabling this mode is very simple. In the existing embed code of the video, you just replace “youtube” with “youtube-nocookie” in the URL. These days, when you create a YouTube embed code, you can generate it in privacy mode straight away. (Not much) more information on this can be found in the YouTube help pages.
Using this privacy mode is in the spirit of the privacy by design principle, according to which we should aim to process as little information about the user as possible.
Unfortunately, Google does not provide precise information about the scope of data processing. The name “no cookie” might suggest that no cookies are stored, but that is not the case.

Google also receives information that a given page was visited by a given IP address, and it may use this, for example, for statistical purposes. Nor is there any certainty that this data cannot be associated with us if, for instance, we are logged in to Chrome, on the basis of separate consent.
That is why, despite using privacy mode, we should still ensure we have appropriate user consent.
Consent to cookies from embedded content
To comply with the GDPR and ePrivacy rules, you need to obtain explicit consent to transfer data to YouTube. If the user grants it on their first visit to the site by clicking “CONSENT (TO ALL)” in the consent management box – in which we have also declared YouTube – the matter is simple.
If, however, we do not have such consent, the display of the embedded content should be withheld until it is granted.
Most consent management platforms (CMPs) make it possible to block embedded content when the appropriate type of consent is missing. This requires a simple modification of the embedding script, comparable to setting the privacy mode – you just need to not be afraid to make a small edit in the HTML.
What if there is no consent?
If the page content refers in some way to the embedded video, or the video is relevant to the context of the content, blocking its display may make the content incomprehensible or simply look like an error (we write about a video, but it cannot be seen).
That is why, for users who have refused consent, it is worth displaying a message that in order to see the video they first have to give the appropriate consent – ideally providing, right away, a link or a button that triggers the consent management panel.
As a rule, this should be consent only to the files necessary to display the content, i.e. YouTube files, and we should have – or create ourselves – such a cookie category in the consent management platform.
Unfortunately, some platforms only allow consent to be given for rigidly defined categories, e.g. preferences/functional, statistics/analytics, marketing/advertising. In this situation, it is usually assumed that the condition is marketing consent, as the one that interferes most with privacy.
Giving consent to marketing means that the other scripts that install marketing cookies – e.g. Facebook or Criteo – will also be launched, because the user was forced to accept them.
This may give rise to an accusation of forcing consent to the processing of marketing data
In such a situation, one solution is to let the user watch the video directly on YouTube by sharing a link to it. Thanks to this, a user who does not want to give blanket consent to all marketing cookies will still be able to watch the content by going to YouTube. In this solution, when there is no consent, the user sees this message in place of the video (click the link to see how it works):
Most consent management platforms let you generate such objects (see what this solution looks like for the Cookiebot platform).
Even if your consent management lets you separate out a custom consent category, a link leading directly to the source of the embedded content will be useful for users of privacy-focused browsers (e.g. Brave), which may block the CMP and for which giving such consent will be impossible or inconvenient.
An analogous approach should be applied to other embedded social content, e.g. X (Twitter) or Instagram, since these scripts also place cookies in the user’s browser: