Third-party scripts: the performance cost nobody owns
Every third-party tag runs on your main thread, in your users' browsers, with your performance budget. Almost none of them have an owner.
A typical website needs a lawful basis for processing personal data, a clear privacy notice, genuine consent before non-essential cookies and trackers, a way to honour access and deletion requests, defined retention periods, and processor agreements with the vendors handling your users' data. This is general guidance, not legal advice.
| Law | Applies to | Key requirement |
|---|---|---|
| GDPR (EU/UK) | Anyone processing EU/UK residents' data | Lawful basis, consent, data subject rights |
| DPDP Act (India) | Digital personal data of individuals in India | Notice, consent, purpose limitation |
| CCPA/CPRA (California) | Businesses over thresholds | Disclosure, opt-out of sale/sharing |
| ePrivacy (EU) | Cookies and similar technologies | Consent before non-essential storage |
Territorial scope follows the user, not the server. An Indian company with European visitors is generally within GDPR's reach. This article is engineering guidance — take actual legal advice for your circumstances.
Freely given, specific, informed and unambiguous — an affirmative action, with refusal as easy as acceptance.
Write this inventory down. You cannot answer a deletion request, complete a vendor assessment, or write an accurate privacy notice without knowing what you hold and where.
The practical engineering task is knowing every place a user's data lives: the database, the CRM, the email platform, the analytics tool, error tracking, backups and logs. Build the export and deletion path early; retrofitting it across eight systems is painful.
It has faced regulatory challenges in Europe over data transfers. Configure it carefully with consent gating and IP handling, or use a privacy-focused alternative that does not set cookies.
Most obligations apply regardless of size, though some record-keeping requirements scale. Enforcement priorities differ, but the requirements themselves largely do not.
ROVQIX Growth
SEO & growth team, ROVQIX
The ROVQIX growth team handles technical SEO, Core Web Vitals and AI-search visibility for the sites we build. Recommendations here are the ones we apply to client projects and to rovqix.in itself.
ROVQIXdesigns and builds production web platforms — Next.js front ends, Node.js APIs and the infrastructure behind them. Tell us what you're building and we'll scope it with you.
Every third-party tag runs on your main thread, in your users' browsers, with your performance budget. Almost none of them have an owner.
Not a compliance document. This is the list we actually work through before a client site handles its first real user.
The question is not whether a secret will leak. It is whether you will know, and how long it takes to make the leaked one useless.
No spam. Just the occasional case study and craft breakdown.