Consent for embedded content: the iframe, video, and form embeds that bypass your banner
Your cookie banner is installed, your consent platform reports healthy opt-in rates, and your scan shows a tidy list of first-party cookies. Then someone drops a YouTube video, a Google Map, a review widget, and a lead-capture form into the homepage, and every one of them starts phoning home before the visitor clicks anything. Embedded content is the most common way trackers slip past an otherwise working consent setup.
An embed is a doorway into someone else's code. When the page loads an iframe from another service, that service runs its own scripts, sets its own cookies, and applies its own rules. Your banner never got a say, because the request was not yours. This is why scans that only look at cookies your own scripts set will miss the whole problem.
Which embeds cause the most trouble
Video embeds are the classic offender. A standard YouTube or Vimeo iframe loads the full player environment, which includes analytics and advertising infrastructure. Even if nobody presses play, the embed fires requests that fingerprint the visitor. Privacy-enhanced modes exist for both platforms, but they change the URL, which means every embed you already have needs to be edited, not just the new ones.
Maps and location widgets behave the same way. An embedded map loads location services, fonts, and telemetry from the provider. Forms and booking widgets are sneakier: a third-party form that powers your contact page or demo request may set tracking cookies and post visitor data to the provider's own analytics, entirely outside your data processing agreements.
Review widgets, chat bubbles, social feeds, and payment-adjacent buttons round out the list. A chat widget that loads on every page is a tracker on every page. An Instagram feed in the footer is a tracker in the footer. Each one was added for a good reason, and each one arrived with its own data collection.
How to find the embeds you already have
Start with the page source. Search your templates for iframe tags and for script tags whose src points at a third-party domain. That catches the obvious ones. Then open the network tab in your browser's developer tools, load the page in a fresh profile with no prior consent choice, and watch for requests to domains you do not recognize. Any request to an advertising or analytics domain that fires before you touch the banner is a finding.
Pay special attention to tag managers and page builders. A tag manager that injects an embed on certain pages will not show up in the template source. A page builder block that promises a nice video hero may load the vendor's full script bundle. Ask each one: what requests does this block make on first load, and where can I see the list?
The fix: block, replace, or gate
You have three options for each embed, and the right one depends on how much the embed matters. The simplest is replacement. Many services offer privacy-friendly embed modes: a video player that loads a static thumbnail until the visitor clicks, a map that only loads after consent for the relevant category, a social feed that renders as server-side images. These keep the functionality and drop the pre-consent tracking.
The second option is gating. Wrap the embed in your consent platform's blocking mechanism so it only loads after the visitor accepts the relevant category. A video that needs marketing consent should not load under an analytics-only choice. Test this the way a visitor experiences it: decline everything, then check whether the video placeholder appears without any background requests. A common failure is the gating wrapper hiding the iframe visually while the browser still prefetches it, so verify with the network tab, not your eyes.
The third option is removal. Some embeds are legacy decorations that nobody would miss. A social feed widget from three campaigns ago, a map on a page that also lists the address, a video nobody watches. Removing them is the fastest compliance fix and usually a performance win too.
Keep the embeds honest going forward
Embeds are a process problem, not a one-time cleanup. The marketing team will add new ones, and each will arrive with its own trackers. Three habits keep this under control. First, a short review step before any new embed goes live: what does it load, which consent category does it need, and who tested the gated version. Second, a recurring scan that includes iframe and third-party request inventory, not just cookie names. Third, documentation of every embed with its provider, purpose, and lawful basis, so the next audit does not start from zero.
The bottom line
A consent banner that ignores embedded content is a banner with a hole in it. The trackers that regulators and privacy tools find are increasingly the ones inside iframes and widgets, not the ones in your own scripts. Finding every embed, gating or replacing each one, and keeping a process for the next one turns the weakest part of most consent setups into the easiest part to defend.