An embedded Vimeo video (player.vimeo.com) loads scripts and sets cookies for statistics and advertising on page view. Vimeo Inc. is based in the USA.
Many see Vimeo as the more privacy-friendly YouTube alternative — that is only partly true. A standard embed loads player.vimeo.com on page view, sets cookies such as vuid (Vimeo Analytics, lifetime around two years) and, depending on the account type, establishes connections to advertising and analytics partners. Without consent this is not permitted under § 25 (1) TDDDG.
The “Do Not Track” parameter dnt=1 (appended to the iframe URL) tells Vimeo not to perform visitor tracking or personal analytics. It significantly reduces the cookies set but does not prevent every connection: the player itself is still loaded from Vimeo servers in the USA, which transmits the IP address.
The cleanest solution remains the two-click embed: until the click, only a local preview image is shown; only afterwards does the player load. There are ready-made blocks or plugins for WordPress and the common site builders; it is important that the preview image is local and not itself loaded from Vimeo.
The standard embed sets non-necessary cookies (among others for Vimeo Analytics and partly advertising partners). This access to the device requires consent under § 25 (1) TDDDG. The parameter dnt=1 suppresses part of the tracking but does not switch off all connections.
The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.
This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.