Google Ads GDPR Settings: Complete Configuration Guide for 2026
Google Ads has more built-in GDPR tooling than most ad platforms — but that tooling only works if it's actually configured, and Google's EU User Consent Policy makes correct configuration a platform requirement, not just good practice. Here's what to check in your account.
1. Google's EU User Consent Policy
Google requires advertisers serving ads to users in the EEA and UK to obtain legally valid consent for the use of cookies (or other local storage) and for the collection, sharing, and use of personal data for ad personalization, where required by GDPR. Google enforces this policy on advertiser accounts — non-compliance can affect ad delivery, not just create legal exposure. The policy requires that a Google-certified Consent Management Platform (CMP), typically operating on the IAB Europe Transparency & Consent Framework (TCF), is used if you rely on Google's ad personalization tools with EEA/UK traffic.
2. Consent Mode v2 — required, not optional, in the EEA
Google Consent Mode adjusts how Google's tags (Google Ads, Analytics, Floodlight) behave based on a visitor's consent status, communicated by your CMP. Since March 2024, Consent Mode v2 has been required for advertisers using Google Ads personalization or remarketing features with EEA/UK traffic. There are two implementation levels:
- Basic Consent Mode — tags don't fire at all until consent is given; simplest to implement but loses more measurement signal from users who decline.
- Advanced Consent Mode — tags fire in a "cookieless ping" mode even without consent, allowing Google to model conversions statistically rather than losing that traffic entirely; requires more careful implementation but preserves more usable data.
Check which mode your current tag setup uses — many sites that added a cookie banner without revisiting their Google tag configuration are technically still sending unconsented signals, which is exactly what the policy is meant to prevent.
3. Restricted Data Processing (RDP)
Google Ads offers a Restricted Data Processing setting that limits how Google uses the data it receives from your account — similar in spirit to a data processing addendum applied at the account level. This is a narrower tool than Consent Mode and doesn't replace it, but it's worth reviewing as an additional control, particularly for accounts handling data from users who've declined ad personalization.
4. Conversion tracking and first-party data
Google's shift toward privacy-focused measurement (following third-party cookie deprecation in Chrome) means conversion tracking increasingly relies on first-party signals — Enhanced Conversions, Customer Match using hashed first-party data, and server-side tagging via Google Tag Manager's server container. Each of these still needs a lawful basis and, where cookies or similar technology are used, valid consent under the same rules as any other tracker. Enhanced Conversions in particular processes hashed customer data (email, phone, address) for matching — treat this the same as any other customer data upload: confirm your original collection of that data covers this use, and disclose it in your privacy policy.
5. Remarketing lists and audience data
Remarketing lists built from your website visitors depend on the same consent-gated tags discussed above — a remarketing list built before proper Consent Mode implementation may include improperly collected data. Customer Match lists (uploaded customer data for targeting) carry the same requirement as Meta's Custom Audiences or LinkedIn's Matched Audiences: the original data collection needs a lawful basis that extends to advertising use, disclosed to the people on the list.
6. Data processing terms and transfers
Google Ads Data Processing Terms (Google's DPA for advertisers) govern how Google processes account and campaign data on your behalf, including cross-border transfer mechanisms. As with any US-headquartered platform, Google's specific transfer safeguards (Standard Contractual Clauses, EU-US Data Privacy Framework certification where applicable) are documented in materials that are updated periodically — review the current version rather than relying on a general understanding from a prior year.
Step-by-step configuration checklist
- Confirm a Google-certified CMP (IAB TCF-compliant) is installed and actually gating tag firing, not just displaying a banner.
- Verify Consent Mode v2 is implemented (Basic or Advanced) and test that Google Ads/Analytics tags respond correctly to both consent and non-consent states.
- Review Restricted Data Processing settings for accounts that need it.
- Check Enhanced Conversions and Customer Match data sources trace back to a lawful basis that covers ad use, disclosed in your privacy policy.
- Audit existing remarketing lists for data collected before Consent Mode was correctly configured.
- Review Google Ads' current Data Processing Terms for the transfer mechanism currently in effect.
This guide is general information, not legal advice, and Google's specific policy requirements and product names change over time — verify current requirements directly in Google Ads' help documentation for your account before relying on this as a final checklist.
Adverizeo's Google Ads integration includes a direct API connection for publishing, and every generated ad passes through the same GDPR compliance check used across all platforms — helpful for catching creative-level issues, but account-level Consent Mode and CMP configuration is a separate setup step that has to happen in Google Ads and your CMP directly.