Third-Party Vendor
A third-party vendor is an external organization or person that provides goods or services to a company, rather than being part of that company itself. In the cookie consent context, these vendors often include the analytics, advertising, and other service providers whose scripts or technologies place cookies or collect data through a website. Because these vendors may access or process data from a website's visitors, organizations generally need to account for them when managing consent and disclosures.
A third-party vendor is an external entity, distinct from the organization operating a service, that supplies goods or services and may include suppliers, integrators, service providers, telecommunications, and infrastructure support. In the cookie and tracking context, third-party vendors frequently supply technologies (cookies, pixels, tags, SDKs, or scripts) embedded on a first party's website that place or read information on the user's device and may process personal data. Their presence has distinct implications under the ePrivacy regime, which governs the placing of and access to information on the user's device, and under the GDPR, which governs any resulting processing of personal data; a vendor's role may be that of a processor or an independent or joint controller depending on the facts, which affects the contractual and disclosure obligations that apply. Note that the term is used broadly across sources and its precise legal characterization is fact-dependent; this definition does not resolve the controller/processor classification for any specific vendor relationship, which requires separate legal analysis.
Why it matters
Third-party vendors are central to how modern websites function, but they are also one of the most significant sources of compliance risk in cookie consent management. When an organization embeds an analytics, advertising, or other vendor's script, pixel, tag, or SDK on its site, that vendor may place or read information on the visitor's device and may process personal data. Under the EU ePrivacy regime, the placing of and access to information on a user's device generally requires prior consent unless an exemption applies, and where the resulting activity involves personal data, the GDPR governs that processing separately. This means that the first party operating the website typically cannot address only its own cookies while ignoring the technologies its vendors bring in.
The difficulty is that these vendors are often only partly visible to the organization deploying them. Some vendors load additional third parties of their own, and the technologies used are not always literally cookies; pixels, local storage, SDKs, and similar mechanisms can fall within the same rules. A vendor's legal role also matters and is fact-dependent: depending on the arrangement, a vendor may act as a processor or as an independent or joint controller, and this classification affects the contractual terms, disclosures, and consent handling that apply. Because this characterization is not resolved by the label "vendor" alone, organizations generally need separate legal analysis for each significant relationship.
For these reasons, accounting for third-party vendors is usually a prerequisite to giving visitors the specific and informed consent that EU law expects, and to producing accurate disclosures. Requirements differ across jurisdictions, however: EU and UK regimes generally rely on prior consent for non-essential technologies, while several US state frameworks lean toward opt-out mechanisms. The scope of a vendor's obligations therefore depends both on the facts of the relationship and on the applicable legal regime.
Who it's relevant to
Inside Third-Party Vendor
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Vendor.

