consentglass · GDPR scanner for websites

HomeGuides › Topic

Which services belong in the privacy policy?

Every embedded third-party service that processes personal data — analytics, advertising, fonts, maps, chat, CDN, hosting — must appear in the privacy policy.

Is this a risk?

Art. 13 GDPR requires details on purpose, legal basis, recipients, retention period and third-country transfer. An incomplete privacy policy is a separate infringement — regardless of whether the embedding itself is lawful.

What you can do

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.