Sitelet https://brocode.at/modules/brocode-consent-embed/

WordPress GDPR Embeds Plugin: Click to Load Maps & Video

WordPress GDPR embeds plugin: Google Maps, YouTube, Vimeo and any other block load only after a click. Per-service consent, WP Consent API support.

A Google Map or a YouTube video on a WordPress page sends every visitor’s IP address to Google the moment the page loads, before anyone has agreed to anything. BroCode Consent Embed is a small WordPress GDPR embeds plugin that puts a click-to-load placeholder in front of maps, calendars and videos, and in front of any other blocks you wrap in a consent section, so nothing reaches the third party until the visitor clicks. It fits sites that need the classic two-click solution without a full consent-management platform, and sites that already run a consent banner and want their embeds to follow it.

Typical impact: zero requests to Google, YouTube or Vimeo before consent, one click to load, and existing YouTube and Vimeo embeds covered without editing a single post.

A Google Map behind the click-to-load placeholder, with the privacy notice, the Load button and the always-load option

Who For

  • Associations, clubs and small businesses with a contact page map and a few videos, who need the embeds to wait for consent but not a full cookie-banner suite.
  • Agencies building block themes that want one consent pattern for maps, calendars, videos and custom widgets across client sites.
  • Sites with a consent banner that implements the WP Consent API, where embeds should open as soon as the visitor accepts marketing.
  • Editors who paste embed codes: a whole Google Maps <iframe> snippet goes into the block as it is.

Who Skip

  • Sites that already block embeds through their consent platform’s own content blocker. Two blockers in a row mean two clicks.
  • Sites built with the classic editor or a page builder. The two blocks need the block editor; only the automatic YouTube and Vimeo gate works in classic content.
  • Sites that need a preview image of the video before consent. The placeholder shows no thumbnail, because loading one from YouTube would itself send the visitor’s IP to Google.

How the WordPress GDPR embeds work

The plugin adds two blocks and one automatic gate. In every case the page contains only a placeholder, and the browser creates the real content after the click.

  • Consent Embed block. Paste a Google Maps or Google Calendar embed link, any YouTube or Vimeo link, or an OpenStreetMap embed link. YouTube is rewritten to youtube-nocookie.com, Vimeo gets dnt=1. Any other URL renders nothing, so the block cannot embed arbitrary pages.
  • Consent Section block. Wrap any blocks in it, such as a Custom HTML widget, a booking form, a social feed or several embeds, and name the service and the company that receives the data. The section renders its blocks into an inert <template> element, where no image, iframe or script loads, and inserts them only after consent.
  • Existing embeds. YouTube and Vimeo videos from the core Embed block, and bare video URLs in classic content, get the same placeholder automatically.
A Consent Section around a newsletter sign-up form in the editor: the inner blocks stay editable, and the sidebar names the service, the company and the consent category

Consent can come from three places. A click loads that one embed. Ticking Always load YouTube on this site first remembers the choice for that service, in the visitor’s own browser storage, with no cookie and nothing stored on the server. A consent banner that implements the WP Consent API opens every embed in a category as soon as the visitor accepts it. All three run in the browser, so page caching keeps working.

Sections and embeds nest the way consent works. A YouTube video inside a YouTube section loads together with it. A YouTube video inside an Instagram section keeps its own placeholder, because agreeing to Instagram is not agreeing to Google.

Before and after

Before

  • The contact page map loads Google Maps for every visitor, consent or not.
  • Every YouTube video in old posts loads from youtube.com on page view.
  • A booking or newsletter widget pasted as Custom HTML runs its third-party script on every page load.

After

  • The map, the videos and the widget show a short notice with the service name, the receiving company and a link to the privacy policy.
  • One click loads the content; a ticked always load box keeps it loading on every page for that service.
  • Nothing from the third party loads before the click, which shows up as zero requests to its domain in the browser’s network panel.
A YouTube video from the core Embed block, gated automatically on a phone

Installation

Download brocode-consent-embed.zip from the GitHub release and upload it under Plugins → Add New → Upload Plugin, or install it with WP-CLI:

wp plugin install https://github.com/brosenberger/brocode-consent-embed/releases/download/1.0.0/brocode-consent-embed.zip --activate

Then add the Consent Embed or Consent Section block. Existing YouTube and Vimeo embeds need nothing. The plugin is in review for the WordPress.org plugin directory; once it is listed there, updates arrive through the normal plugin updates.

Developers can register further services through the brocode_consent_embed_providers filter:

add_filter( 'brocode_consent_embed_providers', function ( array $providers ): array {
    $providers['example'] = [
        'label'     => 'Example Video',
        'company'   => 'Example Inc.',
        'category'  => 'marketing',
        'embed_url' => fn ( array $parts, string $url ): ?string =>
            $parts['host'] === 'video.example.com' ? $url : null,
    ];
    return $providers;
} );

Compatibility

  • WordPress 6.5 or later, tested on 7.1
  • PHP 8.1 or later
  • Block themes and classic themes with the block editor
  • English, with German (de_DE, de_AT) included
  • A Content Security Policy needs frame-src entries for the services you embed, for example https://www.youtube-nocookie.com and https://www.google.com

FAQ

Do Google Maps and YouTube embeds need consent under the GDPR?

Loading them leads to a transfer of the visitor’s IP address to Google, and the embeds can set cookies. EU data protection guidance treats that as needing the visitor’s consent first. In 2022 the Munich Regional Court (LG München I, 3 O 17493/20) awarded damages against a site that passed visitors’ IP addresses to Google through Google Fonts without consent. This plugin is a technical measure, not legal advice.

Does this replace my cookie banner?

No. It makes sure embeds wait for consent. Visitors can give that consent per embed, or your banner can give it through the WP Consent API.

What can go inside a Consent Section?

Any blocks. Images, iframes and inline scripts inside the section load only after consent. Scripts that a plugin loads globally, outside the section’s own markup, are not held back, so keep the third party’s code inside the section, for example in a Custom HTML block.

Can visitors withdraw an "always load" choice?

The choice lives in the visitor’s own browser storage for your site. Clearing the site data in the browser resets it.

Does it work with page caching?

Yes. Every consent decision happens in the browser, so the cached page is the same for everyone and still correct.

Related reading

Related Topics

Ask a module question or suggest improvements

Tell us your use case and the module context. Spam protection is handled by ALTCHA.




More Projects