Vendor
A vendor is a party in a supply chain that provides goods or services to a company or to consumers. In the cookie consent context, the term is commonly used to refer to the external companies whose cookies, pixels, or tracking technologies a website relies on, though the evidence provided here describes the general commercial meaning rather than a consent-specific one.
In its general commercial and accounting sense, a vendor (also called a supplier, provider, or seller) is a person or enterprise that contributes goods or services within a supply chain, whether by manufacturing, distributing, or reselling to businesses or consumers. The evidence supplied supports only this general definition and does not establish a specialized meaning within cookie consent or data protection frameworks; readers should note that in consent management practice the word is often applied to third parties whose tracking technologies require handling under applicable law, but that usage is out of scope of the sources cited here and would require additional authoritative evidence to define precisely.
Why it matters
The term vendor appears constantly in cookie consent and data protection discussions, where it is frequently used to describe the external companies whose cookies, pixels, SDKs, or other tracking technologies a website loads. However, the evidence available here supports only the general commercial and accounting meaning of the word: a party in a supply chain that supplies goods or services to businesses or consumers. Readers should be aware that the widely used consent-management sense of vendor is not established by the sources cited and would require additional authoritative material to define precisely.
This distinction matters because precision about roles and parties is central to sound compliance decisions. When practitioners refer to third-party vendors in a cookie context, they are typically pointing to entities whose technologies may place or access information on a user's device and may process personal data as a result, which can engage both the ePrivacy rules on device access and the GDPR rules on personal data processing in EU jurisdictions. Conflating the general commercial vendor with a specifically defined consent-management role risks papering over questions that actually depend on the technical behavior of each third party and the applicable legal framework.
Because the specialized usage is out of scope of the evidence provided, this entry does not attempt to assign vendors specific obligations, roles such as controller or processor, or consent-handling duties. Those determinations vary between the EU, the UK, and individual US state regimes and depend on facts not covered here. Treat the term as a general label unless a more specific, evidence-backed definition is supplied.
Who it's relevant to
Inside Vendor
Common questions
Answers to the questions practitioners most commonly ask about Vendor.

