Scanned on 22 July 2026 at 01:40 UTC· 2 total scans
As of , dish.com has a GDPR compliance score of 0/100 with 189 pre-consent tracking violations detected.
Only Privacy Score 100 means full compliance. These violations mean that before you could even click the Cookie Consent banner, this website already collected your personal data and shared it with third parties. Learn why this matters (our blog) →
Who is responsible? The website owner is solely responsible for these violations and in general often benefits monetarily (directly or indirectly) from collecting and sharing your data without your consent.
Consent platform: Quantcast
Tracks your browsing behaviour to build a profile and serve targeted ads before you give consent.
A tag manager loading tracking scripts before the visitor has given consent.
Collects usage statistics (pages visited, clicks, session duration) without consent.
These are fonts, embeds, and other resources loaded from external servers. While they serve a legitimate purpose, they share your visitors' IP addresses with third parties before consent.
Tracking cookies are used to identify and follow users across websites. Under GDPR, these require explicit consent before being set, but on this website they are active immediately.
Low-severity concerns: external fonts, empty tag containers, WebSocket connections, and third-party storage.
Services and cookies that comply with GDPR requirements. No consent needed.
Pending classification by our team. No impact on your privacy score.
These items are pending classification. No impact on your privacy score.
Most findings on this page are configuration problems, not catastrophes. These plain-language guides explain what each one means and how to fix it, written for website owners rather than lawyers.
All guides live at gdprscanner.eu/guides.
dish.com has a GDPR compliance score of 0/100.
A score below 50 indicates serious GDPR compliance failures. Multiple high-severity trackers or advertising scripts load before consent, exposing the website to potential fines of up to €20 million or 4% of annual global turnover under GDPR Article 83.
172 trackers detected loading before user consent:
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CNIL Decision SAN-2022-023. Tag managers that actively load tracking scripts before consent enable personal data processing without a legal basis. The CNIL fined Google €150 million in 2022 partly because its tag manager loaded tracking before users could refuse cookies.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
This GDPR compliance scan of dish.com was performed by GDPR Scanner, a pre-consent privacy scanning tool. The scan captures all trackers, cookies, and third-party scripts that load before a user clicks any consent button.
Under GDPR (General Data Protection Regulation), websites must obtain explicit consent before processing personal data. Any tracker or cookie that fires before consent is a potential violation of EU privacy law.
A privacy score of 100/100 means the website loads zero trackers and zero tracking cookies before the user gives consent. This is the standard required by GDPR Article 5(1)(a) and Article 7.
Essential cookies (session management, security tokens) and first-party functional cookies do not incur penalties, as they are covered by the legitimate interest legal basis. See an example: playhth.com scores 100/100.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 44, Article 46, and LG München I (Case 3 O 17493/20). Exposing visitor IP addresses to third-party servers — especially outside the EU/EEA — without consent or adequate transfer safeguards violates GDPR's data transfer provisions. The Munich Regional Court confirmed that IP addresses constitute personal data and their transfer requires a legal basis.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and Austrian DSB Decision (DSB-D155.027, 2022). Analytics trackers process personal data such as IP addresses and browsing behaviour. The Austrian Data Protection Authority ruled in January 2022 that Google Analytics use without consent violates GDPR, as data is transferred to the US without adequate safeguards. The ePrivacy Directive requires prior consent for accessing information on a user's device unless strictly necessary.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and Austrian DSB Decision (DSB-D155.027, 2022). Analytics trackers process personal data such as IP addresses and browsing behaviour. The Austrian Data Protection Authority ruled in January 2022 that Google Analytics use without consent violates GDPR, as data is transferred to the US without adequate safeguards. The ePrivacy Directive requires prior consent for accessing information on a user's device unless strictly necessary.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CNIL Decision SAN-2022-023. Tag managers that actively load tracking scripts before consent enable personal data processing without a legal basis. The CNIL fined Google €150 million in 2022 partly because its tag manager loaded tracking before users could refuse cookies.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 44, Article 46, and LG München I (Case 3 O 17493/20). Exposing visitor IP addresses to third-party servers — especially outside the EU/EEA — without consent or adequate transfer safeguards violates GDPR's data transfer provisions. The Munich Regional Court confirmed that IP addresses constitute personal data and their transfer requires a legal basis.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and Austrian DSB Decision (DSB-D155.027, 2022). Analytics trackers process personal data such as IP addresses and browsing behaviour. The Austrian Data Protection Authority ruled in January 2022 that Google Analytics use without consent violates GDPR, as data is transferred to the US without adequate safeguards. The ePrivacy Directive requires prior consent for accessing information on a user's device unless strictly necessary.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and CJEU Planet49 (C-673/17). Advertising trackers profile visitors for targeted ads. The CJEU's Planet49 ruling (1 October 2019) confirmed that consent must be active and informed — pre-ticked boxes or implied consent are insufficient. This applies to all cookies and tracking mechanisms used for advertising purposes.
| Cookie Name | Domain | Type | Service | Duration |
|---|---|---|---|---|
| _fbp | .dish.com | 1st party | Facebook - Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers | Session |
| _gcl_au | .dish.com | 1st party | Google Ads - Google Ads first-party conversion attribution | Session |
| _ga_01HM7F38JG | .dish.com | 1st party | Google Analytics - ID used to identify users | Session |
| s_ppv | .dish.com | 1st party | Adobe Analytics - Stores information on the percentage of the page displayed | Session |
| QuantumMetricSessionID | .dish.com | 1st party | Quantum Metric - Quantum Metric session recording | Session |
| nmstat | .www.dish.com | 1st party | Siteimprove - This cookie is used to help record the visitor's use of the website. It is used to collect statistics about site usage such as when the visitor last visited the site. This information is then used to improve the user experience on the website. This Siteimprove Analytics cookie contains a randomly generated ID used to recognize the browser when a visitor reads a page. The cookie contains no personal information and is used only for web analytics. It is also used to track the sequence of pages a visitor looks at during a visit to the site. This information can be used to reduce user journeys, and enable visitors to find relevant information quicker. | Session |
| s_tp | .dish.com | 1st party | Adobe Analytics - This lets us know how much of the page you viewed. | Session |
| s_ips | .dish.com | 1st party | Adobe Analytics - Adobe scroll tracking | Session |
| AMCV_9425401053CD40810A490D4C%40AdobeOrg | .dish.com | 1st party | Adobe Audience Manager - Adobe Experience Cloud uses a cookie to store a unique visitor ID that is used across Experience Cloud Solutions. | Session |
| _ga | .dish.com | 1st party | Google Analytics - ID used to identify users | Session |
| _pin_unauth | .dish.com | 1st party | Pinterest - Registers a unique ID that identifies and recognizes the user. Is used for targeted advertising. | Session |
dish.com has serious GDPR compliance deficiencies with a score of 0/100 and 189 violations detected. Multiple trackers and cookies are loading before user consent, which constitutes a clear breach of the ePrivacy Directive Article 5(3).
This level of non-compliance exposes the website operator to significant regulatory risk. Under GDPR Article 83(5), infringements of the basic principles for processing — including conditions for consent — are subject to administrative fines of up to €20 million or 4% of annual global turnover. Recent enforcement trends show increasing DPA activity across the EU.
Immediate action is recommended: audit all third-party scripts, implement a Consent Management Platform (CMP) that blocks non-essential trackers before consent, and verify compliance through re-scanning.
dish.com scores 0/100 with 189 violation(s) detected. Trackers or cookies were found loading before user consent.
Our scan detected 198 tracker(s) loading before consent, including Adobe Launch (active - loading: Aggregate Knowledge, The Trade Desk, Pinterest +20 more), hcaptcha.com, Ketch Kloud.
Yes, 35 cookie(s) were detected before the user interacted with any consent banner.
dish.com has a GDPR compliance score of 0/100 as of 22 July 2026. A score of 100 means no trackers or cookies load before consent. dish.com currently has 189 violation(s) affecting its score.
dish.com should implement a Consent Management Platform (CMP) that blocks all non-essential trackers and cookies until the visitor gives explicit consent. This includes configuring tag managers like Google Tag Manager to use consent-aware triggers, self-hosting external fonts, and auditing all third-party scripts. After making changes, re-scan with GDPR Scanner to verify compliance.