Skip to main content
Promotional banner for the pentest readiness checklist
Category: TCF and Vendors

Third-Party Vendor

Also known as: Third-Party Provider, Third Party, External Vendor, Service Provider
Simply put

A third-party vendor is an external organization or person that provides goods or services to a company, rather than being part of that company itself. In the cookie consent context, these vendors often include the analytics, advertising, and other service providers whose scripts or technologies place cookies or collect data through a website. Because these vendors may access or process data from a website's visitors, organizations generally need to account for them when managing consent and disclosures.

Formal definition

A third-party vendor is an external entity, distinct from the organization operating a service, that supplies goods or services and may include suppliers, integrators, service providers, telecommunications, and infrastructure support. In the cookie and tracking context, third-party vendors frequently supply technologies (cookies, pixels, tags, SDKs, or scripts) embedded on a first party's website that place or read information on the user's device and may process personal data. Their presence has distinct implications under the ePrivacy regime, which governs the placing of and access to information on the user's device, and under the GDPR, which governs any resulting processing of personal data; a vendor's role may be that of a processor or an independent or joint controller depending on the facts, which affects the contractual and disclosure obligations that apply. Note that the term is used broadly across sources and its precise legal characterization is fact-dependent; this definition does not resolve the controller/processor classification for any specific vendor relationship, which requires separate legal analysis.

Why it matters

Third-party vendors are central to how modern websites function, but they are also one of the most significant sources of compliance risk in cookie consent management. When an organization embeds an analytics, advertising, or other vendor's script, pixel, tag, or SDK on its site, that vendor may place or read information on the visitor's device and may process personal data. Under the EU ePrivacy regime, the placing of and access to information on a user's device generally requires prior consent unless an exemption applies, and where the resulting activity involves personal data, the GDPR governs that processing separately. This means that the first party operating the website typically cannot address only its own cookies while ignoring the technologies its vendors bring in.

The difficulty is that these vendors are often only partly visible to the organization deploying them. Some vendors load additional third parties of their own, and the technologies used are not always literally cookies; pixels, local storage, SDKs, and similar mechanisms can fall within the same rules. A vendor's legal role also matters and is fact-dependent: depending on the arrangement, a vendor may act as a processor or as an independent or joint controller, and this classification affects the contractual terms, disclosures, and consent handling that apply. Because this characterization is not resolved by the label "vendor" alone, organizations generally need separate legal analysis for each significant relationship.

For these reasons, accounting for third-party vendors is usually a prerequisite to giving visitors the specific and informed consent that EU law expects, and to producing accurate disclosures. Requirements differ across jurisdictions, however: EU and UK regimes generally rely on prior consent for non-essential technologies, while several US state frameworks lean toward opt-out mechanisms. The scope of a vendor's obligations therefore depends both on the facts of the relationship and on the applicable legal regime.

Who it's relevant to

Privacy and data protection officers
They generally maintain the inventory of third-party vendors operating on the organization's websites and assess each vendor's role and the data it may access or process. This informs consent categorization, disclosures, and record-keeping, and often requires coordination with legal counsel where a vendor's controller or processor status is unclear.
Legal and compliance counsel
Counsel assess the fact-dependent legal characterization of each vendor relationship, which may be that of a processor or an independent or joint controller, and determine the resulting contractual and disclosure obligations. They also advise on how requirements differ across the EU, UK, and US state regimes, since the applicable consent standard varies.
Web developers and engineers
They implement and control the vendor scripts, pixels, tags, and SDKs embedded on a site, including how and when these load relative to a user's consent. Their work is essential to ensuring that non-essential third-party technologies do not fire before valid consent is obtained where that is required.
Marketing and advertising compliance teams
These teams often introduce analytics and advertising vendors whose technologies place or read information on users' devices. They need to understand which vendors they are deploying and coordinate with privacy and legal functions so that these vendors are properly disclosed and governed by consent.

Inside Third-Party Vendor

Definition of a Third-Party Vendor
An external organization other than the first-party website operator whose technologies (cookies, pixels, SDKs, tags, or scripts) are loaded on or accessed through a site or app, often to deliver analytics, advertising, content, or other functionality.
Technologies Deployed
Third-party vendors may set cookies but also rely on similar technologies such as tracking pixels, local storage, software development kits (SDKs), and device fingerprinting. In most EU jurisdictions these are treated under the same rules governing the placing of or access to information on a user's device, even though they are not literally cookies.
Roles Under Data Protection Law
A third-party vendor may act as a processor acting on the operator's instructions or as an independent or joint controller, depending on how it determines the purposes and means of processing. The characterization affects contractual and accountability obligations under the GDPR and is fact-dependent.
Distinct Legal Layers
Deployment typically engages two separate regimes in the EU: the ePrivacy Directive (and its national implementations) governing the placing of and access to information on the user's device, and the GDPR governing any subsequent processing of personal data. Consent obtained for one does not automatically satisfy the requirements of the other.
Consent and Category Dependence
Whether prior consent is required generally depends on the purpose the vendor's technology serves. Strictly necessary functions are often exempt, while analytics and advertising functions typically require prior consent under EU law. Requirements differ under other frameworks, such as US state privacy laws that often rely on opt-out mechanisms.
Consent Management and Signaling
Third-party vendors are commonly integrated through consent management platforms (CMPs), and some participate in frameworks such as the IAB Transparency and Consent Framework (TCF) or respond to signals like Global Privacy Control, alongside consent logging and record-keeping obligations.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Vendor.

If a third-party vendor sets cookies on our site, is it their responsibility rather than ours to obtain consent?
This is a common misconception. In most EU jurisdictions, the website operator (the party controlling the site the user visits) generally bears primary responsibility for ensuring that consent is obtained before third-party cookies or similar technologies are placed on or read from a user's device, because the operator determines which vendors run on the site. The ePrivacy rules govern the placing of and access to information on the device, and both the operator and the vendor may have obligations depending on the facts. Under the GDPR, the parties may be joint controllers or act as controller and processor, which affects how responsibility is allocated. Responsibility is typically shared and fact-dependent rather than resting solely with the vendor, so contractual arrangements and a clear allocation of roles are important.
Does using a well-known third-party vendor mean their tags are automatically compliant?
No. The reputation or size of a vendor does not, on its own, establish compliance for how their technology is deployed on your site. Whether the vendor's cookies, pixels, SDKs, or fingerprinting techniques are lawful depends on how consent is obtained, what categories of cookies are involved, the geographic scope of your users, and the applicable legal regime. Strictly necessary cookies may be exempt from consent in the EU, while analytics and advertising technologies typically require prior consent there. Vendor tools can support compliance but do not replace your own legal judgment or your obligation to configure consent gating and disclosures appropriately.
How can we identify all the third-party vendors operating on our website?
A practical starting point is a cookie and tracking audit that inventories the cookies, pixels, local storage entries, SDKs, and network requests generated when users load and interact with your site, including those triggered indirectly by one vendor loading another. Consent management platforms and scanning tools can assist with discovery, but automated scans may miss technologies that fire only under certain conditions or through chained third parties. Combining automated scanning with a review of tag manager configurations and vendor contracts generally produces a more complete picture. Note that vendor lists can change over time, so periodic re-scanning is advisable; this answer does not address any specific tool's coverage.
Should we block third-party vendor tags until the user has given consent?
In most EU jurisdictions, non-exempt third-party cookies and similar technologies should generally not be placed or read until valid prior consent has been obtained, which typically means preventing the relevant tags from firing before the user takes a clear affirmative action. Prior blocking is one common technical approach and is often implemented through a consent management platform integrated with a tag manager. Requirements differ under other frameworks, such as certain US state privacy laws that rely on an opt-out model rather than prior consent, so the appropriate default may depend on where your users are located. The specific technical implementation and whether a given technology qualifies as strictly necessary depend on facts outside this definition.
What should we include in our contracts with third-party vendors?
Contractual terms commonly address the allocation of data protection roles (for example whether the vendor acts as a processor, controller, or joint controller), the purposes and scope of data processing, security and confidentiality obligations, arrangements for any international data transfers, and cooperation with responding to individual rights requests and regulatory inquiries. Where the GDPR applies, controller-to-processor relationships generally require a written agreement covering specified matters. The precise terms depend on the relationship and applicable law, and legal advice is typically needed to draft or review these arrangements; this definition does not specify required clauses for any particular jurisdiction.
How do we keep records of the third-party vendors and the consent that applies to them?
Consent record-keeping generally involves logging when and how consent was obtained, the categories of cookies or vendors it covered, and the version of the notice or configuration presented, so that you can demonstrate that consent met the applicable standard. Maintaining an up-to-date vendor inventory alongside these consent records helps show which technologies were active and under what basis. Consent management platforms often provide logging features, but you should verify that the records captured are sufficient for your accountability needs. The extent and retention of such records depend on the applicable legal regime and are not fixed by this definition.

Common misconceptions

Only cookies set directly by third-party vendors are regulated, so pixels, SDKs, and fingerprinting fall outside consent rules.
In most EU jurisdictions, similar technologies such as pixels, local storage, SDKs, and fingerprinting are treated under the same rules that govern the placing of and access to information on a user's device, even though they are not literally cookies.
The website operator's consent covers all third-party vendor activity, so vendors carry no separate obligations.
A third-party vendor may act as a processor or as an independent or joint controller depending on how it determines purposes and means. This characterization is fact-dependent and affects the vendor's own contractual and accountability obligations, and it separately engages both ePrivacy consent for device access and GDPR obligations for subsequent processing.
The same third-party vendor rules apply identically everywhere.
Cookie and tracking obligations vary between the EU, the UK, and individual US states such as California under the CCPA and CPRA. EU frameworks generally rely on prior opt-in consent for non-essential purposes, while several US state laws rely on opt-out mechanisms, so the applicable rules depend on jurisdiction.

Best practices

Maintain an inventory of all third-party vendors and the technologies they deploy (cookies, pixels, local storage, SDKs, fingerprinting), and map each to the purpose it serves so consent requirements can be assessed per category.
Determine and document each vendor's role as processor, independent controller, or joint controller, since this is fact-dependent and drives contractual and accountability obligations under the GDPR.
Address both legal layers separately: ensure any consent required under the ePrivacy Directive for placing or accessing information on the device is obtained, and confirm a lawful basis and safeguards under the GDPR for the resulting processing.
Where prior consent is required in EU jurisdictions, block or defer loading of non-essential vendor technologies until valid consent is obtained through a CMP, and honor applicable signals such as Global Privacy Control where relevant.
Configure vendor integration to match the applicable jurisdiction, recognizing that EU and UK rules generally rely on opt-in for non-essential purposes while several US state laws rely on opt-out, so a single global configuration may not suffice.
Keep records of consent and vendor configurations, and treat CMPs and frameworks such as the TCF as tools that support compliance rather than substitutes for legal judgment, revisiting arrangements as regulatory guidance evolves.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps