3.5 Treat third parties the same as first parties
Minimize and carefully manage third-party services by using lightweight, user-controlled integrations that are loaded only when needed.
Success Criteria
- Assess and reduce:
Review third-party content and/or services early in the design or ideation process, including plugins, widgets, feeds, maps, carousels, tracking scripts, and similar components. Use as few as possible, preferring lightweight options to reduce overall environmental impact, including GHG Protocol Scope 3 emissions. Ensure third-party providers enforce the same compliance, security, privacy, data retention limits, data deletion policies, and mandatory security update standards as the first party. Account for long-term dependency risks when selecting third-party services, including data portability and transition options. - Third-party implementation:
Load third-party content only when the user interacts with it. Offer simple alternatives, such as linking to a form instead of embedding a widget. - Self-hosting:
Serve assets such as content, icons, fonts, scripts, and widgets from infrastructure you control where practical, rather than embedding or depending on third-party services for their storage or delivery. This reduces dependency on external systems, improves reliability, and can reduce unnecessary network requests. - Third-party preferences:
Respect user preferences around third-party content and services. Provide clear controls to disable or opt out of non-essential third-party features.