Checked on 9/24/2026 · https://www.heise.de/
Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.
Grade F: no clearly critical issues in the delivered HTML, but tracking services are embedded — whether they only load after consent needs checking — open items: 2.
| Advertising/tracking service: Google Ads (DoubleClick) | -22 |
| Third-party CDN: Cloudimage (Bild-CDN) | -5 |
| Third-party CDN: Cloudimage (Bild-CDN) (additional) | -2 |
| Social plugin / pixel: Meta Pixel | -20 |
| Tag manager: Google Tag Manager | -12 |
| Tag manager loads further scripts unchecked | -6 |
| Cookie banner detected (Sourcepoint) | +5 |
| 5 detected services not found in the privacy policy | -6 |
| Result | 32 / 100 |
Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.
A banner is embedded. Whether the services really load only after consent cannot be determined conclusively from the initial HTML.
What you should do: Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.
On the linked privacy page no mention of Google Ads (DoubleClick), Cloudimage (Bild-CDN), Cloudimage (Bild-CDN), YouTube (No-Cookie), Google Tag Manager was found. Automated text match — they may be referred to differently there.
What you should do: Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.
Art. 13 (1) GDPR — duty to inform about recipients and purposes of processing.
These services generally work without consent.
| Service | Purpose | Vendor | Country | Legal basis |
|---|---|---|---|---|
| Google Ads (DoubleClick) doubleclick.net |
Ad targeting and conversion tracking | Google LLC | US ⚠ | Consent required |
| Cloudimage (Bild-CDN) heise.cloudimg.io |
Delivery of libraries or maps via third-party servers | Scaleflex SAS | FR | Grey area — better to self-host; otherwise consent |
| Cloudimage (Bild-CDN) cloudimg.io |
Delivery of libraries or maps via third-party servers | Scaleflex SAS | FR | Grey area — better to self-host; otherwise consent |
| YouTube (No-Cookie) youtube-nocookie.com |
data-minimising analytics without a personal profile | Google LLC | US ⚠ | usually without consent |
| Meta Pixel connect.facebook.net |
Embedding of social networks, often with retargeting | Meta Platforms Inc. | US ⚠ | Consent required |
| Google Tag Manager www.googletagmanager.com |
loads further scripts — content depends on the configuration | Google LLC | US ⚠ | Consent required once it loads non-essential items |
⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).
Weekly re-scan, email as soon as a new tracker appears — coming soon.
On 9/24/2026 we checked the HTML that www.heise.de delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.
Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.