Resources · 45

Third-party scripts and tags: govern access, cost and removal

Connect each script to a purpose, owner, visible data and a tested shutdown path.

· 3 min

Method diagram: Purpose → Observed script → Data / cost → Decision → Tested removal Method diagram · steps explained in the text

What this guide helps achieve

  • Find indirectly loaded scripts
  • Reduce unnecessary data and dependencies
  • Measure cost by journey
  • Remove a tag without breaking an essential action

Quick check

  • Who approved each tag?
  • What further scripts does it load?
  • Which document data can it read?
  • Does loading follow the user’s collection choices?
  • Has removal been tested?

Step-by-step method

  1. 01

    Observe actual loading

    Check representative pages, mobile and desktop, signed-in and anonymous users, and different collection choices. Record initiator, domain, size, frequency, downstream calls and transmitted parameters. The tag-manager configuration does not always reveal the full chain.

    Deliverable: request and dependency inventory.

  2. 02

    Assign purpose and ownership

    For each script, record function, provider, business owner, publishing access, affected pages and usefulness criterion. Remove tags without an active purpose after checking dependencies. Separate preparation and publishing permissions.

    Deliverable: tag, purpose, owner and approval register.

  3. 03

    Examine data exposure

    Inspect URLs, parameters, form data, identifiers and accessible content. A script running in the page may have broader capabilities than its sales description implies. Define permitted fields, exclusions and loading conditions actually enforced.

    Deliverable: observed data flows and fixes.

  4. 04

    Test suitable protections

    Consider local hosting when allowed, pinned versions, SRI for compatible resources and loading policies. An SRI hash checks expected bytes; it does not judge whether code is safe or cover secondary scripts. Changing resources need an update process.

    Deliverable: protections, limitations and change procedure.

  5. 05

    Measure cost and failure

    Compare the same journey with and without the tag: requests, processor time, interaction and task completion. Simulate provider unavailability or slow responses. Avoid conclusions based on a single laboratory score.

    Deliverable: documented comparison and journey budget.

  6. 06

    Exercise removal

    Disable in testing, check forms, cart, messages and measurement, then prepare rollback. Confirm that the script does not return through another container or plugin. Recheck after provider changes or a new campaign.

    Deliverable: removal evidence and review plan.

Worked example

Illustrative situation

Illustrative situation: an old campaign still loads a script on the contact form.

Decision and expected evidence

The team finds no active objective, tests the form without the script and confirms its absence from requests.

Distinguish the mechanisms

MechanismPurposeCheck or limitation
In-page scriptIntegrated functionalityPotential access to the document
Isolated iframeSeparated content depending on configurationCheck messaging and permissions
Server-side collectionProcess some events outside the browserStill requires data minimisation

Management indicators

IndicatorWhat it measuresFirst action
Justified tagsTags with a purpose and ownerReview orphaned entries
Interaction costTag-related time on an actual actionRestrict or move loading
Verified removalsDeletions confirmed in requestsFind indirect loading

Common pitfalls

  • Inventorying only the first script
  • Confusing asynchronous with cost-free
  • Publishing tags without review
  • Assuming server-side collection excludes personal data

Frequently asked questions

Does SRI work on every tag?

No. It depends on resource type, browser, origin rules and content compatible with an expected hash.

Is a tag manager a security control?

It centralises publishing, but security depends on permissions, reviews, versions, accessible data and loaded scripts.

Which tag should be removed first?

One with no active purpose or whose cost and exposure exceed demonstrated value, after dependency testing.

Official references