Drücke „Enter”, um zum Inhalt zu springen.
Hinweis zu diesem Datenschutz-Blog:
Anscheinend verwenden Sie einen Werbeblocker wie uBlock Origin oder Ghostery, oder einen Browser, der bestimmte Dienste blockiert.
Leider wird dadurch auch der Dienst von VG Wort blockiert. Online-Autoren haben einen gesetzlichen Anspruch auf eine Vergütung, wenn ihre Beiträge oft genug aufgerufen wurden. Um dies zu messen, muss vom Autor ein Dienst der VG Wort eingebunden werden. Ohne diesen Dienst geht der gesetzliche Anspruch für den Autor verloren.

Ich wäre Ihnen sehr verbunden, wenn Sie sich bei der VG Wort darüber beschweren, dass deren Dienst anscheinend so ausgeprägt ist, dass er von manchen als blockierungswürdig eingestuft wird. Dies führt ggf. dazu, dass ich Beiträge kostenpflichtig gestalten muss.

Durch Klick auf folgenden Button wird eine Mailvorlage geladen, die Sie inhaltlich gerne anpassen und an die VG Wort abschicken können.

Nachricht an VG WortMailtext anzeigen

Betreff: Datenschutzprobleme mit dem VG Wort Dienst(METIS)
Guten Tag,

als Besucher des Datenschutz-Blogs Dr. DSGVO ist mir aufgefallen, dass der VG Wort Dienst durch datenschutzfreundliche Browser (Brave, Mullvad...) sowie Werbeblocker (uBlock, Ghostery...) blockiert wird.
Damit gehen dem Autor der Online-Texte Einnahmen verloren, die ihm aber gesetzlich zustehen.

Bitte beheben Sie dieses Problem!

Diese Nachricht wurde von mir persönlich abgeschickt und lediglich aus einer Vorlage generiert.
Wenn der Klick auf den Button keine Mail öffnet, schreiben Sie bitte eine Mail an info@vgwort.de und weisen darauf hin, dass der VG Wort Dienst von datenschutzfreundlichen Browser blockiert wird und dass Online Autoren daher die gesetzlich garantierten Einnahmen verloren gehen.
Vielen Dank,

Ihr Klaus Meffert - Dr. DSGVO Datenschutz-Blog.

PS: Wenn Sie meine Beiträge oder meinen Online Website-Check gut finden, freue ich mich auch über Ihre Spende.
Ausprobieren Online Webseiten-Check sofort das Ergebnis sehen

Bullshit Basics: Google Tag Manager is not a cookie-free domain (w/ proof)

0
Dr. DSGVO Newsletter detected: Extended functionality available
More articles · Website-Checks · Live Offline-AI
📄 Article as PDF (only for newsletter subscribers)
🔒 Premium-Funktion
Der aktuelle Beitrag kann in PDF-Form angesehen und heruntergeladen werden

📊 Download freischalten
Der Download ist nur für Abonnenten des Dr. DSGVO-Newsletters möglich

Many privacy policies claim that Google Tag Manager is a cookie-free domain. Others suggest that no consent is required to use the Tag Manager. Both are untenable. Even Google itself provides arguments against this claim.

The Google Tag Manager is a tool with which the deployment of other tools can be controlled. Instead of deploying, one could also speak of reloading other tools. Often the abbreviation GTM for the Google Tag Manager is used.

Is the Google Tag Manager a cookieless domain?

The Google Tag Manager is not a domain. If it were a domain, it would not be cookie-free. It is correct that cookies can be set and loaded via the googletagmanager.com domain.

The Google Tag Manager is embedded via a Script and an alternative for systems with disabled JavaScript. Often, code like this can be found:

<script>
(function(w, d, s, l, i) {
w[l] = w[l] || [];
w[l].push({ 'gtm.start': new Date().getTime(), event: 'gtm.js' });
var f = d.getElementsByTagName(s)[0],j = d.createElement(s),
dl = l != 'dataLayer' ? '&l=' + l : '';
j.async = true;
The JavaScript code is setting a variable named src to a string that includes a URL from Google Tag Manager, with an ID appended to it. The ID appears to be a placeholder for some value (i) and a delimiter (dl);
f.parentNode.insertBefore(j, f);
})(window, document, 'script', 'dataLayer', 'GTM-XXXXXXXX');
An iframe element with a source URL, set to zero height and width, and styled to be invisible;

The script part is the logic to load the gtm.js script named Tag Manager. Some parameters are set here. Below follows in a IFRAME-tag a logic to fire the Tag Manager, if JavaScript is disabled in the user's browser.

Before the misunderstandings are clarified, here is the very first misunderstanding. Many think that Google does not receive any personal data via GTM at all. That's wrong. Correctly: For Google, your and my IP address is potentially always personal. The GTM receives your and my IP address every time we visit websites that integrate the GTM. Unfortunately, Google's explanations are formulated in such a way that Google almost admits that it uses data received for its own purposes. So, the GTM would already be consent-obligatory on this account alone.

Common misconceptions about the Tag Manager

As can be seen, the Tag Manager is loaded from the domain googletagmanager.com. A domain can theoretically be cookieless. Labelling a tool as a domain is inherently wrong.

Declaring a domain as cookieless is a very bold statement. This statement can only be true if it's interpreted in a benevolent manner. A domain itself is not a cookie manager. Rather, all web pages hosted on this domain and external files loaded from third-party websites are potential cookie managers. Whoever dares to claim knowledge of all these web pages and files must be extremely well-informed.

A domain itself cannot manage cookies. Only files located on this domain can do that. Leaving aside server-side configurations, only files that execute program logic can manage cookies. By managing we mean here creating, reading, modifying and deleting cookies.

The Google Tag Manager is not a cookieless domain. To say it correctly:

Cookies are being loaded from the domain googletagmanager.com!

Investigation of Google Tag Manager on websites that use it (source: dr-dsgvo.de) and statement from Google (July 2021).

The Google Tag Manager loads cookies directly

Yes, you've read it correctly. Don't believe what others claim! This section shows why cookies are loaded when the Google Tag Manager is embedded on a website.

Cookies exist within a domain (depending on configuration also in subdomains). In order for Google Tag Manager cookies to be transferred when retrieving them, a cookie must first exist in the domain googletagmanager.com or be newly generated by Google Tag Manager.

It is therefore sufficient if a single website exists worldwide in the domain or subdomain in question and sets a cookie. We are only talking about persistent cookies here. Session cookies are rather uncritical (but can still cause problems under certain conditions).

Here's the proof that cookies are loaded when integrating the Google Tag Manager:

Proof that a cookie is transferred when the Google Tag Manager is loaded.

The video shows how the "naked" Tag Manager is loaded, without further tools being reloaded by the Tag Manager (which would otherwise be responsible for subsequent data processing). Nevertheless, a cookie is transferred when the Tag Manager is accessed. Because the cookie was already sent with the loading of the GTM, it is actually irrelevant whether the GTM loads additional tools or not, since the cookie was already there when the GTM was accessed!

Noted, all of this was shown in the video without consent. There isn't even a consent query on the shown website. The shown website was randomly selected. There are numerous other websites that use Tag Manager where the same behavior is verifiable.

To reproduce the behavior shown in the video, do the following in Mozilla Firefox:

  1. Visit a website on the domain googletagmanager.com or one of its subdomains and create a cookie
  2. To track network traffic in the browser press the F12 key to open the developer console. There click on the Network Analysis folder.

    Read full article now via free Dr. GDPR newsletter.
    More extras for subscribers:
    Offline-AI · Free contingent+ for Website-Checks
    Already a subscriber? Click on the link in the newsletter & refresh this page.
    Subscribe to Newsletter
About the author on dr-dsgvo.de
My name is Klaus Meffert. I have a doctorate in computer science and have been working professionally and practically with information technology for over 30 years. I also work as an expert in IT & data protection. I achieve my results by looking at technology and law. This seems absolutely essential to me when it comes to digital data protection. My company, IT Logic GmbH, also offers consulting and development of optimized and secure AI solutions.