Overview
edX is a massive open online course (MOOC) platform co-founded by MIT and Harvard, now operated by 2U, Inc. Publishers and educational institutions embed edX course players, enrollment widgets, and promotional iframes on their own web properties to surface course offerings to visitors. The platform's scripts manage content delivery, learner authentication, and engagement tracking across both the edX domain and partner-embedded contexts.
What This Script Does
When edX components are embedded on external sites, browser scripts handle several functions. Course enrollment widgets load from edx.org or partner-specific subdomains and set authentication cookies including edxloggedin and session tokens (session-duration cookies) to detect whether the visiting user has an existing edX account. Video players served via the edX CDN use playback state cookies to resume progress. Analytics tracking via Segment or similar intermediaries may set persistent identifiers to measure engagement metrics such as video completion rates, quiz attempts, and enrollment conversions. Scripts communicate with api.edx.org endpoints to fetch course metadata and enrollment status. Form submissions for course registration transmit name and email data to edX servers. For partner sites using edX's white-label programs, scripts may load from custom subdomains but follow the same functional patterns.
Consent & Compliance
edX scripts combine functional elements (authentication, content delivery) with analytics tracking (engagement measurement). Under GDPR, functional cookies enabling content the user has specifically requested may rely on legitimate interest or contract performance. Analytics cookies tracking engagement across sessions require consent under ePrivacy. edX (via 2U, Inc.) is a US company; personal data transferred to edX infrastructure from EU visitors requires standard contractual clauses. The EU-US Data Privacy Framework may apply if 2U is certified. Under CCPA/CPRA, edX may share learner interaction data with third-party analytics vendors; California residents have opt-out rights if data constitutes a sale or cross-context behavioral advertising. Consent category: functional/analytics.
Should You Block This Without Consent?
Conditional. Functional scripts required to display course content and manage authentication may proceed without explicit consent if they qualify as technically necessary. Analytics scripts tracking learner behavior across sessions should be gated behind consent. Configure your consent platform to load edX content widgets immediately while delaying analytics-oriented tracking until opt-in is received.
Is edX GDPR compliant?
edX typically loads functional and analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So edX can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads edX, not on edX itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
edx.orgFunctionaledx.org is a functional domain operated by edX, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for edX
ConsentStack automatically detects and manages edX trackers so your site stays compliant with global privacy regulations.