ConsentPixel – Privacy · Verified

AdSense · Publishers

Privacy policy for Google AdSense: what publishers actually have to disclose

Google won't let you run AdSense without a privacy policy — but "have a privacy policy" isn't the real requirement. Google is specific about what it must say, and for EU traffic there's a second requirement most publishers underestimate: your ad cookies have to actually wait for consent. Get both right and you protect your account and your ad revenue. Here's exactly what's required.

Quick answer

Google requires every AdSense publisher to display a privacy policy disclosing that third parties, including Google, use cookies and web beacons to serve ads based on users' prior visits. If you haven't opted out of third-party ad serving, you must also name the ad vendors on your site, link them, and tell users how to opt out (including via aboutads.info). For EEA/UK visitors, you additionally need consent before ad cookies fire — a policy alone doesn't cover that.

Most publishers meet the AdSense privacy-policy requirement by pasting in a generic template and moving on, assuming the box is checked. It usually isn't — not because the template is wrong, but because it's generic, and Google's requirement is specific. Google tells you, in its own program policies, roughly what your disclosure has to contain. And separately, for anyone with European traffic, there's a consent requirement that a privacy policy doesn't satisfy on its own — one that directly affects how much ad revenue you actually collect. This guide covers both, using Google's actual language.

Does AdSense require a privacy policy? (Yes — and here's the wording)

This one isn't optional or ambiguous. Google's AdSense program policies state it plainly:

"AdSense publishers must have and abide by a privacy policy that discloses that third parties may be placing and reading cookies on your users' browsers, or using web beacons to collect information as a result of ad serving on your website."

— Google AdSense Program Policies

So the requirement isn't just "have a privacy policy." It's "have one that specifically discloses the ad-serving cookies and web beacons." A privacy policy that talks about your contact form and newsletter but never mentions that third-party ad cookies are being placed doesn't actually meet Google's requirement — even though it's a real privacy policy.

Why this matters for AdSense approval — and staying approved

For a lot of publishers, this question comes up at the worst time: during the AdSense application. Google reviews your site before approving you, and a missing or inadequate privacy policy is one of the more common reasons applications get held up or rejected. So the privacy policy isn't just an ongoing obligation — it's often a gate to getting approved in the first place.

And it doesn't stop at approval. The AdSense terms require you to have and abide by a compliant privacy policy for as long as you run ads. Google can review your site at any time, and a policy that's missing the required ad-cookie disclosures — or that describes practices your site doesn't follow — puts your account at risk, not just your first approval. The practical takeaway: treat the privacy policy as something to get genuinely right before you apply, and to keep right afterward, not a formality you bolt on to pass review.

Exactly what your AdSense privacy policy must disclose

Pulling Google's requirements together, here's the concrete checklist. Your policy needs to cover each of these:

1

Third-party ad cookies. That third parties, including Google, may place and read cookies on your users' browsers, or use web beacons, as a result of ad serving on your site.

2

Cookies for personalised ads. Google's suggested framing: that third-party vendors, including Google, use cookies to serve ads based on a user's previous visits to your site or other sites.

3

The vendors on your site (if you haven't opted out of third-party ad serving) — notify visitors of the third-party vendors and ad networks serving ads, with links to them.

4

How to opt out. Tell users they can opt out of personalised advertising — via the vendors' own sites where offered, or collectively at aboutads.info.

5

How you handle data generally — the standard privacy-policy content (what you collect, why, rights), since AdSense sits on top of your normal obligations, it doesn't replace them.

⚠ A currency note that trips people up

A lot of older guides still tell you to specifically reference "DoubleClick cookies" by name in your policy. That specific requirement no longer applies — Google removed it. If you're copying an AdSense privacy-policy template from a few years ago, it may include outdated instructions. Follow Google's current AdSense help pages, not legacy blog posts, because this is exactly the kind of detail that quietly goes stale.

The part templates get wrong: your vendors

Here's where a generic AdSense privacy policy quietly falls short of Google's requirement. Point 3 above asks you to disclose the third-party vendors and ad networks actually serving ads on your site — and that list is specific to you. If you run AdSense alongside other ad networks, header bidding partners, or analytics that feed advertising, each is a third party your policy is supposed to name. A template can't know which networks you use; it describes a generic publisher.

This is the same accuracy problem that affects any privacy policy, but it bites harder for publishers because the whole point of the disclosure is naming the ad tech. A policy that says "we may use third-party ad vendors" without listing the ones actually on your pages is thinner than Google's requirement asks for — and it's the kind of gap that's trivial to spot, because anyone (including Google's reviewers) can load your site and see which ad networks fire.

◆ Why you have to know your real ad stack

You can't disclose vendors you don't know you're running. Ad tech has a way of multiplying — one network's tag can bring in others, and analytics or consent tools can add their own. The only reliable way to list the vendors actually serving on your site is to scan the live site and see what fires, then disclose that real list. Guessing from memory almost always misses something.

See your real ad vendors

Which ad networks actually fire on your site?

Run a free scan to see the ad and tracking vendors loading on your pages — the exact list your AdSense privacy policy is supposed to disclose. No account needed.

Scan my site free →

Free · about 10 seconds · no signup. Information, not legal advice.

For publishers with European traffic — and if you have any global audience, that's you — there's a second requirement that a privacy policy alone doesn't satisfy, and this one hits your wallet directly. In the EEA and UK, non-essential ad cookies generally can't fire until the visitor gives affirmative consent, collected through a Google-certified consent management platform. Disclosure in your policy is necessary but not sufficient: you also need a working consent banner that actually gates the cookies.

What makes this a revenue issue, not just a compliance one, is what happens when you get it wrong:

With valid consent
Personalised ads

Full programmatic value — the ads that actually pay, served on the strength of a valid consent signal Google recognises.

Without valid consent
Limited ads

Google falls back to limited (non-personalised) ads — and industry estimates put the revenue drop at 50% or more. Reject-all in the EEA can mean no AdSense ads at all.

So the consent setup isn't a compliance tax that eats your revenue — done right, it's what protects it. A valid consent signal is what keeps Google serving your high-value personalised ads. A broken or missing one silently downgrades your inventory to limited ads and quietly halves EEA earnings. This is why publishers who treat consent as an afterthought often can't figure out why their European RPMs cratered.

⚠ The TCF version detail

Google requires consent signals to come through the current version of the IAB Transparency & Consent Framework (TCF). Google stopped accepting older TCF v2.2 strings after 28 February 2026; consent strings without the required current-version data are treated as invalid, which defaults your ad requests to limited ads. If your consent platform hasn't been updated, your ad revenue may already be silently affected. Confirm your CMP supports the current TCF version.

Your options when a user declines consent

When an EEA visitor doesn't consent to ad cookies, you're not simply stuck with nothing — Google gives publishers a few ways to keep earning something while respecting the choice. It's worth knowing them, because the difference between them is real money:

  • Non-personalised ads (NPA). When no personalisation consent is given, AdSense can serve contextual ads only, without persistent tracking cookies. It earns less than personalised ads but more than nothing — and it keeps you serving to users who declined. Note it's not fully cookieless: AdSense still contacts Google's servers.
  • Google Consent Mode v2. A framework where AdSense adjusts its behaviour based on the consent signals your banner passes. With consent denied, Google can still model conversions from aggregated, anonymised data — recovering some measurement without setting tracking cookies.
  • Full blocking. The strictest approach: non-essential ad tech simply doesn't load until consent. Highest privacy footprint reduction; you serve personalised ads only to those who opt in.

None of these removes the need for the two fundamentals — an accurate disclosure and a real consent banner. They're just different ways of handling the "user said no" case. But they underline the same point: your consent setup isn't a single on/off switch, it's the machinery that decides how much of your EEA traffic you can still monetise, and how. Configuring it well is a revenue decision as much as a compliance one.

The honest picture: disclosure + real consent

Put the two halves together and the honest requirement for an AdSense publisher is clearer than "get a privacy policy." It's two things that have to both be true:

  • An accurate disclosure — a privacy policy that actually names the ad vendors serving on your site and covers Google's required points, not a generic template.
  • Real consent behaviour — for EEA/UK visitors, ad cookies that genuinely wait for consent, gated by a working banner, so the disclosure isn't describing something your site doesn't actually do.
The honest through-line

A privacy policy is a disclosure, not protection — and for publishers that cuts especially sharp. Your AdSense policy describing perfect consent practices means nothing if your ad cookies actually fire before anyone clicks "accept." The disclosure has to be true: the vendors listed have to be the ones really serving, and the consent it describes has to be consent your site really obtains. Getting that alignment right is what keeps both your AdSense account and your ad revenue intact — the document alone does neither.

How to put it together

The practical sequence for an AdSense publisher, in order:

  • Find your real ad vendors. Scan your live site to see which ad networks and trackers actually fire, so your disclosure lists the real ones.
  • Build the policy from that — covering Google's required points plus your standard privacy-policy content, with the actual vendor list and opt-out routes. A policy built from a real scan gets the vendor list right by construction.
  • Add a proper consent banner for EEA/UK visitors, on a Google-certified CMP using the current TCF version, that actually blocks non-essential ad cookies until consent — so your personalised ads keep serving and your disclosure stays true.
  • Keep it current. Add or drop an ad partner and both your disclosure and your consent setup need to keep pace — ad stacks change often.

The bottom line

Google's AdSense privacy-policy requirement is specific, not generic: your policy has to disclose that third-party vendors including Google use cookies and web beacons to serve ads, name the ad networks actually on your site, and tell users how to opt out (including via aboutads.info). Skip the specifics — or list vendors you don't actually run — and you fall short of Google's own requirement. And you no longer need to name DoubleClick cookies specifically; that requirement is gone.

Then there's the half most publishers underrate: for EU traffic, your ad cookies have to actually wait for consent, through a current-TCF consent banner — and that's not just compliance, it's what keeps Google serving your full-value personalised ads instead of downgrading you to limited ads and halving your EEA revenue. Disclose accurately, obtain consent for real, keep both current as your ad stack changes. That's the whole job — and the privacy policy is only one piece of it.

Frequently asked questions

Does Google AdSense require a privacy policy?

Yes. Google's AdSense program policies require every publisher to have and display a privacy policy that discloses that third parties, including Google, may place and read cookies on your visitors' browsers or use web beacons to collect information as a result of ad serving. Without one, you're in breach of the AdSense terms. This is information, not legal advice.

What must an AdSense privacy policy disclose?

At minimum: that third-party vendors including Google use cookies to serve ads based on users' prior visits; that third parties may place and read cookies or use web beacons through ad serving; and — if you haven't opted out of third-party ad serving — the vendors and ad networks on your site, with links and how users can opt out of personalised advertising, including via aboutads.info. You no longer need to name DoubleClick cookies specifically.

Do I need cookie consent for AdSense in the EU?

Yes. For visitors in the EEA and UK, non-essential ad cookies generally require affirmative consent before they fire, collected through a Google-certified consent management platform using the current IAB TCF version. If a user rejects, AdSense serves limited (non-personalised) ads or none. A privacy-policy disclosure alone doesn't satisfy the consent requirement — you also need a working consent banner.

Does a privacy policy alone make my AdSense setup compliant?

No. The privacy policy is a required disclosure, but it's only one piece. It has to accurately list the ad vendors actually serving on your site, and — for EEA/UK visitors — your ad cookies have to actually wait for consent, handled by a consent banner, not just described in the policy. Disclosure plus real consent behaviour is what's required; the document by itself isn't enough.

Why did my European AdSense revenue drop?

A common cause is a consent problem. If EEA/UK visitors aren't giving valid consent — or your consent platform sends outdated TCF strings Google now rejects — AdSense falls back to limited (non-personalised) ads, which industry estimates suggest can cut revenue by 50% or more. Confirm your consent management platform supports the current TCF version and that valid consent signals are actually reaching Google.

Disclaimer: This article is general information, not legal advice, and does not create an attorney–client relationship. Google's AdSense requirements and program policies change over time; verify current requirements in Google's official AdSense Help Center. ConsentPixel — Privacy · Verified is not a law firm and is independent of and not affiliated with Google ("Google," "AdSense" and "DoubleClick" are trademarks of their respective owner). Generating a privacy policy or configuring consent does not by itself make your site compliant with any law or program policy. Consult qualified counsel for your specific situation.

Scroll to Top