What it does
Google’s current cookie disclosure says `__Secure-YNID` is replacing `VISITOR_INFO1_LIVE`. It describes these cookies as supporting YouTube functionality and problem detection, and also lists `VISITOR_INFO1_LIVE` among cookies used for analytics and, depending on settings, advertising and personalized recommendations. A declaration should reflect the current observed cookie and configuration rather than preserving a single historic purpose description.
It is third-party: set on YouTube’s domain rather than yours, by the iframe you embedded.
What to write in a cookie declaration
Name YouTube (Google) as the provider and describe the purpose as embedded video playback. Group the YouTube set together under the media category.
| Field | Value |
|---|---|
| Name | VISITOR_INFO1_LIVE |
| Provider | YouTube |
| Purpose category | media |
| Consent category | Media |
| Expiry | About six months (vendor default) |
| Storage | Third-party |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, in media. Use a locally hosted placeholder and explain that activation contacts Google. Load the iframe after media consent, or treat a click as a narrowly scoped request to play that video where applicable; the click is not blanket consent to unrelated Google advertising or future embeds.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Does youtube-nocookie.com prevent this cookie?
Google documents youtube-nocookie.com as Privacy Enhanced Mode: embedded views are not used to personalize the viewer’s YouTube experience or advertising, and ads in the player are non-personalized. Google does not describe it as a guarantee that this particular cookie—or all storage and requests—can never occur. Verify the current player behavior and treat the mode as a mitigation, not a blanket exemption.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- YouTube Help: privacy-enhanced embedded players
Vendor documentation
Checked
- Google: how Google uses cookies
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.