English
consentglass · GDPR scanner for websites

www.spiegel.de

Checked on 9/3/2026 · https://www.spiegel.de/

D
59 / 100
Cookie banner: Sourcepoint · Privacy-policy link: yes · Legal-notice link: yes

No critical items in the delivered HTML · to review: 2.

Since the last scan (8/30/2026)Score -41 · new: Criteo, Adobe Experience Cloud (Launch)
How is the score calculated? (100 starting points)
Advertising/tracking service: Criteo-22
Tag manager: Adobe Experience Cloud (Launch)-12
Tag-Manager lädt ungeprüft weitere Skripte nach-6
Cookie banner detected (Sourcepoint)+5
1 detected services not found in the privacy policy-6
Result59 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. Because a cookie banner (Sourcepoint) is active, the actual trackers almost always load only afterwards and don't appear here. A tag manager is embedded — which services it loads is decided only in the browser. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.

Findings

To review

Cookie banner detected (Sourcepoint) — does it load before consent anyway?

A banner is embedded. Whether the services really load only after consent cannot be determined conclusively from the initial HTML.

What you should do: Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

To review

1 detected services not found in the privacy policy

On the linked privacy page no mention of Criteo was found. Automated text match — they may be referred to differently there.

What you should do: Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.

Art. 13 (1) GDPR — duty to inform about recipients and purposes of processing.

Next steps

  1. Cookie banner detected (Sourcepoint) — does it load before consent anyway?. Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.
  2. 1 detected services not found in the privacy policy. Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.

Third parties detected (2)

ServicePurposeVendorCountryLegal basis
Criteo
criteo.com
Ad targeting and conversion tracking Criteo S.A. FR Consent required
Adobe Experience Cloud (Launch)
assets.adobedtm.com
loads further scripts — content depends on the configuration Adobe Inc. US ⚠ Consent required once it loads non-essential items

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/3/2026 we checked the HTML that www.spiegel.de delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website