There is a lot of confusion when it comes to the changes by CIG about two months ago, which created issues for data sensitive participicants from the European Union (EU) with embedded videos in Spectrum discussion threads. I think most of you already have seen the result: Most often, discussions about that topic are being dismissed or dwarved with the remark: "It is the fault of GDPR". This, however, isn't the whole story. TL;DR: It is absolutely the fault of CIG that this is happening. There is no entity except CIG itself which prevents Spectrum to show embedded 3rd party material. Please let me share what is going on here and why CIG is to be hold accountable for what is happening here. While the claim, that the image above is a result of the GDPR for EU participants is true, it is plainly wrong to BLAME the GDPR for it. But before going into details, we have to understand what GDPR is. General Data Protection Regulation (GDPR) is a European law which was finalized in 2016 and became enforcable on May, 25th 2018 (Source: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation). This regulation is for keeping private data protected and hence, collecting data requires the collector to state Wich data will be collected What will happen to the data How long will the data be stored The foundation of GDPR is transparency (both parties can review which data was collected for which purpose and how long it will be stored), and protection. Failing to comply to GDPR can result in fines up to $10M or 2% of annual global revenue, whichever is higher. And here we have the first "strange" thing: GDPR is enforced since FOUR years now, however, CIG shows that image above since about two months. Doesn't fit... Now let's take a look into the data requirement: GDPR requires all data to be opt-in. What exactly does that mean? When looking at private data, there is data which is mandatory. For example, when you purchase something online, you require to identify a shipping address as well as bank account information such the seller can process the order and getting paid for it. This data is required, or mandatory, for the process of the purchase including shipping. Example for CIG mandatory item in regard to Spectrum is your login, which consists of your email address and a couple of additional data like (legal) name. GDPR had no real change on that data except that the collector (called "controller") must be transparent on the data. Data confidentiality was already required before GDPR. Opt-in means that the data subject (you) is actively consenting in the collection and storage of the data. However, there is a lot of data which isn't required, but companies are interested in it: Your location, your preferences, your shopping or browsing behavior, ... And this is where GDPR has its most impact: Controller mustn't simply collect that data. They have to transparently communicate a) what data is being collected for b) which purpose and c) how long that data is being stored. Because of that, all web hosting companies had to implement changes in their web page, mainly regarding cookies, to actively REACH OUT FOR CONSENT from the data subject (you). So lets sum up what we just learned: GDPR is requiring the data controller to inform the data subject about the data being collected and what will happen with those. This is configered with the cookie settings in the offending case, the embedded videos. As result, CIG created and maintains this web page: https://robertsspaceindustries.com/cookies Every user of CIG hosted web pages can make an educated decision on which cookies they will allow or if they don't want to use CIG services at all (rejecting the necessary cookies). Given that aspect, CIG is absolutely compliant to GDPR when blocking embedded Youtube videos unless you consent to those cookies, right? Before answering that question, let us see which cookies are used referencing Youtube: This is part of the cookies liste as necessary: Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies. These two cookies do verify, if the user is consenting to other cookies in the marketing category. If the user is not, CIG is displaying the initial interface shown above. Looking into the marketing category, we see multiple cookies, which are indeed fropm 3rd party. Mainly Youtube and Twitch. Marketing cookies are defined as: Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers. These so called "tracking cookies" are used to track user interaction and collect data about your behavior and interests. These cookies are indeed from other companies and are not owned by CIG. The golden question now is "Is CIG forced to provide 3rd party cookies by GDPR"? And the answer is - NO. GDPR simply forces CIG to transparently communicate what data is being collected for which purpose and has to reach out for the users consent. But GDPR doesn't enforce CIG to embed 3rd party tracking cookies. So if GDPR isn't the requirement for these cookies.... it is Youtube and Twitch for sure who force CIG to use these cookies, right? And again, the answer is - NO. Youtube is NOT forcing to comply to tracking cookies, even if the video is embedded in other company web pages: Source: https://www.youtube.com/t/terms In fact, there are many tutorials out there which show how to embed Youtube videos without the need for any cookies. Conclusion: We have seen that GDPR is part of the issue that EU customers do see that interface instead of the video. However, it is 100% up to CIG that this is happening as neither GDPR nor Youtube enforces CIG to require consent to tracking cookies for those videos. UPDATE: After doing some more intense research (triggered by J3pt), it becomes obvious to me that the offender is Google/Youtube. See more details in my response below.