English
consentglass · GDPR scanner for websites

www.heise.de

Checked on 9/24/2026 · https://www.heise.de/

F
38 / 100
Cookie banner: Sourcepoint · Privacy-policy link: yes · Legal-notice link: yes

Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.

Grade F: no clearly critical issues in the delivered HTML, but tracking services are embedded — whether they only load after consent needs checking — open items: 1.

Since the last scan (9/24/2026): no change.

How is the score calculated? (100 starting points)
Advertising/tracking service: Google Ads (DoubleClick)-22
Third-party CDN: Cloudimage (Bild-CDN)-5
Third-party CDN: Cloudimage (Bild-CDN) (additional)-2
Social plugin / pixel: Meta Pixel-20
Tag manager: Google Tag Manager-12
Tag manager loads further scripts unchecked-6
Cookie banner detected (Sourcepoint)+5
Result38 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. Because a cookie banner (Sourcepoint) is active, the actual trackers almost always load only afterwards and don't appear here. A tag manager is embedded — which services it loads is decided only in the browser. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.
Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Findings

To review

Cookie banner detected (Sourcepoint) — does it load before consent anyway?

A banner is embedded. Whether the services really load only after consent cannot be determined conclusively from the initial HTML.

What you should do: Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

OK

Detected services are named in the privacy policy

A text match of the linked privacy page found all detected providers. Whether the details are substantively complete is not checked by the match.

OK

Privacy-friendly services in use: YouTube (No-Cookie)

These services generally work without consent.

Next steps

  1. Cookie banner detected (Sourcepoint) — does it load before consent anyway?. Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

Third parties detected (6)

ServicePurposeVendorCountryLegal basis
Google Ads (DoubleClick)
doubleclick.net
Ad targeting and conversion tracking Google LLC US ⚠ Consent required
Cloudimage (Bild-CDN)
heise.cloudimg.io
Delivery of libraries or maps via third-party servers Scaleflex SAS FR Grey area — better to self-host; otherwise consent
Cloudimage (Bild-CDN)
cloudimg.io
Delivery of libraries or maps via third-party servers Scaleflex SAS FR Grey area — better to self-host; otherwise consent
YouTube (No-Cookie)
youtube-nocookie.com
data-minimising analytics without a personal profile Google LLC US ⚠ usually without consent
Meta Pixel
connect.facebook.net
Embedding of social networks, often with retargeting Meta Platforms Inc. US ⚠ Consent required
Google Tag Manager
www.googletagmanager.com
loads further scripts — content depends on the configuration Google LLC US ⚠ Consent required once it loads non-essential items

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/24/2026 we checked the HTML that www.heise.de delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website