What it is
An embedded YouTube iframe causes the visitor’s browser to contact Google and can use cookies or similar identifiers according to the player state, the visitor’s Google settings and whether playback begins. It should therefore be documented as a third-party media integration rather than neutral page furniture.
Google calls the `youtube-nocookie.com` option Privacy Enhanced Mode. Its documented effect is that an embedded view is not used to personalize the viewer’s YouTube experience or advertising, and ads in that player are non-personalized. It is not a promise of no Google request or no storage, so it does not by itself answer the site operator’s storage, disclosure or lawful-basis analysis.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so YouTube embeds is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- youtube.com
- youtube-nocookie.com
- youtu.be
- ytimg.com
Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.
| Cookie | What it is for |
|---|---|
| __Secure-YNID / VISITOR_INFO1_LIVE | YouTube functionality, analytics and, depending on settings, advertising or personalization; Google says __Secure-YNID is replacing VISITOR_INFO1_LIVE |
| YSC | Session security used to ensure requests are made by the user |
| PREF | Player preferences |
| __Secure-YENID / __Secure-YEC | YouTube security and invalid-ad-interaction detection; Google says __Secure-YENID is replacing __Secure-YEC |
Controlling it with consent
No named adapter. Use a click-to-load placeholder: show a locally hosted thumbnail and explain that activating the player contacts Google. Create the iframe after media consent, or treat the click as a narrowly scoped request to load that video where applicable; a click is not blanket consent to unrelated Google advertising or future embeds.
The runtime supports blocked-frame handling with its own copy (a title explaining that the content is blocked by the visitor’s privacy choices, and an action to allow and view it), which is exactly the click-to-load shape.
No named adapter: choose the appropriate control
The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.
What breaks if it is refused: the video will not play until the visitor allows media or clicks through the placeholder. With a good placeholder this is barely noticeable.
Verifying it
Before consent there should be no request to youtube.com or ytimg.com at all. A thumbnail loaded from ytimg.com is itself a request to Google, so a placeholder should use a locally hosted image.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Does youtube-nocookie.com remove the need for consent?
Not by itself. Privacy Enhanced Mode limits how the embed view is used for personalization, but the iframe still contacts Google and playback can involve cookies or similar technologies. Treat it as a useful mitigation and assess the remaining storage and data transfer under the rules that apply to your site.
Is a video thumbnail a tracker?
A thumbnail served from ytimg.com is a request to a Google domain that necessarily discloses the visitor’s IP address and can include a Referer header subject to browser and site policy. If the intended pre-choice state has no Google contact, host the placeholder image yourself.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- YouTube Help: privacy-enhanced embedded players
Vendor documentation
Checked
- Google: how Google uses cookies
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.