English
consentglass · GDPR scanner for websites

www.heise.de

Checked on 9/24/2026 · https://www.heise.de/

F
32 / 100
Cookie banner: Sourcepoint · Privacy-policy link: yes · Legal-notice link: yes

Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.

Grade F: no clearly critical issues in the delivered HTML, but tracking services are embedded — whether they only load after consent needs checking — open items: 2.

Since the last scan (8/30/2026)Score -68 · new: Google Ads (DoubleClick), Cloudimage (Bild-CDN), YouTube (No-Cookie), Meta Pixel, Google Tag Manager
How is the score calculated? (100 starting points)
Advertising/tracking service: Google Ads (DoubleClick)-22
Third-party CDN: Cloudimage (Bild-CDN)-5
Third-party CDN: Cloudimage (Bild-CDN) (additional)-2
Social plugin / pixel: Meta Pixel-20
Tag manager: Google Tag Manager-12
Tag manager loads further scripts unchecked-6
Cookie banner detected (Sourcepoint)+5
5 detected services not found in the privacy policy-6
Result32 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. Because a cookie banner (Sourcepoint) is active, the actual trackers almost always load only afterwards and don't appear here. A tag manager is embedded — which services it loads is decided only in the browser. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.
Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Findings

To review

Cookie banner detected (Sourcepoint) — does it load before consent anyway?

A banner is embedded. Whether the services really load only after consent cannot be determined conclusively from the initial HTML.

What you should do: Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

To review

5 detected services not found in the privacy policy

On the linked privacy page no mention of Google Ads (DoubleClick), Cloudimage (Bild-CDN), Cloudimage (Bild-CDN), YouTube (No-Cookie), Google Tag Manager was found. Automated text match — they may be referred to differently there.

What you should do: Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.

Art. 13 (1) GDPR — duty to inform about recipients and purposes of processing.

OK

Privacy-friendly services in use: YouTube (No-Cookie)

These services generally work without consent.

Next steps

  1. Cookie banner detected (Sourcepoint) — does it load before consent anyway?. Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.
  2. 5 detected services not found in the privacy policy. Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.

Third parties detected (6)

ServicePurposeVendorCountryLegal basis
Google Ads (DoubleClick)
doubleclick.net
Ad targeting and conversion tracking Google LLC US ⚠ Consent required
Cloudimage (Bild-CDN)
heise.cloudimg.io
Delivery of libraries or maps via third-party servers Scaleflex SAS FR Grey area — better to self-host; otherwise consent
Cloudimage (Bild-CDN)
cloudimg.io
Delivery of libraries or maps via third-party servers Scaleflex SAS FR Grey area — better to self-host; otherwise consent
YouTube (No-Cookie)
youtube-nocookie.com
data-minimising analytics without a personal profile Google LLC US ⚠ usually without consent
Meta Pixel
connect.facebook.net
Embedding of social networks, often with retargeting Meta Platforms Inc. US ⚠ Consent required
Google Tag Manager
www.googletagmanager.com
loads further scripts — content depends on the configuration Google LLC US ⚠ Consent required once it loads non-essential items

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/24/2026 we checked the HTML that www.heise.de delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website