English
consentglass · GDPR scanner for websites

HomeGuides › Service

Embedding Vimeo videos in a privacy-compliant way

An embedded Vimeo video (player.vimeo.com) loads scripts and sets cookies for statistics and advertising on page view. Vimeo Inc. is based in the USA.

Many see Vimeo as the more privacy-friendly YouTube alternative — that is only partly true. A standard embed loads player.vimeo.com on page view, sets cookies such as vuid (Vimeo Analytics, lifetime around two years) and, depending on the account type, establishes connections to advertising and analytics partners. Without consent this is not permitted under § 25 (1) TDDDG.

The “Do Not Track” parameter dnt=1 (appended to the iframe URL) tells Vimeo not to perform visitor tracking or personal analytics. It significantly reduces the cookies set but does not prevent every connection: the player itself is still loaded from Vimeo servers in the USA, which transmits the IP address.

The cleanest solution remains the two-click embed: until the click, only a local preview image is shown; only afterwards does the player load. There are ready-made blocks or plugins for WordPress and the common site builders; it is important that the preview image is local and not itself loaded from Vimeo.

Is this a risk?

The standard embed sets non-necessary cookies (among others for Vimeo Analytics and partly advertising partners). This access to the device requires consent under § 25 (1) TDDDG. The parameter dnt=1 suppresses part of the tracking but does not switch off all connections.

What you can do

Häufige Fragen

Is Vimeo with dnt=1 allowed without a cookie banner?
Conservatively, no. dnt=1 stops visitor tracking, but the player is still loaded from Vimeo (USA) and transmits the IP address. This non-necessary access still requires consent.
What cookies does a normal Vimeo embed set?
Typically vuid (Vimeo Analytics) and, depending on the account, further statistics and advertising cookies. With dnt=1 most of them are dropped.
Is a link to Vimeo enough instead of an embed?
Yes. A plain text link or a linked local preview image triggers no connection to Vimeo while the page loads — only the click takes users to Vimeo.
Do Vimeo data go to the USA?
Yes. Vimeo Inc. is based in the USA. The transfer is generally covered by the EU-US Data Privacy Framework as long as Vimeo is certified, but it belongs in the privacy policy.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.