Tracker library

Vimeo embeds: what it is, what it sets, and how to gate it.

The usual alternative to YouTube, with a lighter tracking posture and the same structural issue: an embed is third-party code in your page.

Vendor
Vimeo
Scanner category
media
Consent category
Media
Control
Custom script or container tag

What it is

A Vimeo embed loads the player and its assets from Vimeo. Vimeo says its DNT parameter prevents new non-essential cookies during that viewing session. Previously stored Vimeo cookies are still sent by the browser, and essential security or bot-management cookies may still be set, so DNT is not equivalent to withholding the embed.

The catalogue classifies it as media, which is the category the default configuration reserves for embedded video, maps and third-party players.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Vimeo embeds is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • vimeo.com
  • vimeocdn.com

Controlling it with consent

No named adapter. Use the same click-to-load placeholder pattern as for YouTube, attached to the media category.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: video playback until media is allowed or the visitor clicks through.

Verifying it

Before consent there should be no request to vimeo.com or vimeocdn.com. If a placeholder image is served from vimeocdn.com, it is still a request. Host it yourself.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Is Vimeo more privacy-friendly than YouTube?

Vimeo offers a documented DNT parameter that prevents new non-essential cookies for the viewing session, while retaining essential security cookies and allowing previously stored cookies to be sent. That is a concrete control, but a broad ranking depends on the exact configuration and data flows. Both services remain third-party embeds that make browser requests.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.