--- title: "Third-party scripts and privacy" category: privacy status: recommended url: https://webspecification.com/spec/privacy/third-party-scripts/ updated: "2026-07-09T00:00:00.000Z" sources: - title: "MDN — Content Security Policy (CSP)" url: "https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP" publisher: "MDN" - title: "EDPB Guidelines 2/2023 on Technical Scope of Art. 5(3) ePrivacy Directive" url: "https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en" publisher: "EDPB" - title: "MDN — Subresource Integrity" url: "https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Subresource_Integrity" publisher: "MDN" source_repo: undefined licence: CC-BY-4.0 --- # Third-party scripts and privacy > Every script loaded from another domain can read cookies, see the URL, and exfiltrate data from your page. Audit them, justify them, and lock them down. ## What it is A third-party script is any `