GDPR Rules for Embedded YouTube videos
As per GDPR laws, if a website features embedded videos, it must not use cookies before the user has been prompted and has given explicit consent. So when a website uses an embed code for a video directly from YouTube(and since YouTube is part of Google) Google places tracking cookies and get the user’s information which is against the EU GDPR laws.
To get around this YouTube provides a “Privacy Enhance Mode”. The way for users to maintain compliance with this issue is straightforward. When you go to embed the video from YouTube, you can click on “Enable privacy-enhanced mode” toward the bottom of the screen.

When you check the box, the code automatically adds the “no cookie” code to the domain, removing the tracker and making the embed GDPR compliant. Below is an example of what the code might look like before and after.
- Before privacy mode is enabled: 
 <iframe width="1440" height="762" src="https://www.youtube.com/embed/7cjVj1ZyzyE" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
- After privacy mode is enabled: 
 <iframe width="1440" height="762" src="https://www.youtube-nocookie.com/embed/7cjVj1ZyzyE" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen></iframe>
