Privacy

Every company your site shares visitors with is one you know about

privacy.third-party-cookies

Why this matters

A cookie stored against another company's domain means that company saw the visit — the address of the page, the browser, the address it came from — and can recognise the same person on any other site it is embedded in. Under UK data protection law the site owner is responsible for that sharing and has to tell people it happens, whether or not the cookie itself needed consent. Most owners are unaware of half the list, because the companies arrive attached to a plugin or an embedded video rather than by decision.

Who fixes it

You can, usually

Roughly how long

1–2 hours

Care needed

Low risk to change

How to fix it

Go through the list and decide, for each one, whether you still want it. Embedded YouTube videos can use the youtube-nocookie.com address; social share buttons can be plain links instead of scripts; a tag left behind by an old agency can simply go. Whatever stays has to be named in your cookie policy, with what it does and how long it lasts.

How we score it

Failing this check takes up to 10 points off your privacy score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.

Does your site pass this one?

This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.

Check my site

Other privacy checks

See all 107 checks