Consent Rules for EEA, UK and Swiss Traffic in Ad Manager

Published · 8 min read

If any of your visitors come from Europe, consent is part of your ad setup, not an optional extra. Google requires publishers using AdSense, Ad Manager or AdMob to use a google certified cmp (consent management platform) that integrates with the IAB Transparency and Consent Framework (TCF) when serving personalized ads to users in the European Economic Area, the UK and Switzerland. This guide explains the policy, the dates, what happens to traffic without a certified CMP, how to carry your setup over from AdSense to Ad Manager, and how Multiple Customer Management (MCM) changes who configures messages.

Please note: this guide describes Google's requirements for its ad products. It is not legal advice. Privacy and consent law varies by country and changes over time, so check your own obligations with a qualified adviser.

The EU User Consent Policy in one paragraph

Google's EU User Consent Policy applies to partners using Google products for end users in the EEA, the UK and Switzerland. In short, it asks you to obtain legally valid consent for the use of cookies or other local storage where legally required, and for the collection, sharing and use of personal data for ads personalization. You must keep records of the consent users give and give them clear instructions for withdrawing it. You must also clearly identify each party that may collect, receive or use users' personal data, and give prominent, easily accessible information about how they use it. The Google Publisher Policies make compliance with the EU User Consent Policy a requirement for anyone using Google ad code.

Certified CMP plus TCF: the requirement and its dates

On top of the consent policy, Google has set a technical requirement for how consent is collected and passed on. To comply, publishers must use a CMP that has been certified by Google and integrates with the IAB's TCF when serving personalized ads in these regions:

  • EEA and UK: required since 16 January 2024.
  • Switzerland: required since 31 July 2024.

Google assesses CMPs against certification criteria focused on TCF compliance, and publishes a list of certified CMPs that it says is updated weekly. For each CMP the list shows its name, its TCF CMP ID (the identifier assigned by the IAB) and the platforms it is certified for: web, app, CTV or a combination. Make sure the CMP you use is certified for the platform you monetize; a CMP certified only for apps does not cover your website.

Two details are easy to miss:

  • Google says it does not check CMPs for full compliance with the TCF or with privacy laws. Certification means the CMP meets Google's criteria; it does not mean your consent setup is legally complete.
  • If you work with ad technology vendors that are not registered with the TCF, Google supports them through its Additional Consent specification, and its CMP assessments check that CMPs supporting it do so correctly.

Google also advises publishers to choose a CMP based on where their traffic comes from and the features each CMP offers. If your current CMP is not on the list, Google suggests asking the provider whether it intends to be certified.

What happens to traffic without a certified CMP

Google's rule is about eligibility for ad types, and it is stated clearly:

  • Traffic from a certified CMP remains eligible for personalized ads, non-personalized ads and limited ads (including programmatic limited ads) where supported.
  • Traffic from a non-certified CMP may be eligible only for non-personalized ads or limited ads (including programmatic limited ads) where supported.

In other words, only traffic that comes through a certified CMP can receive personalized ads. A missing or non-certified CMP therefore limits the ad types available for your European visitors. We cannot put a figure on the effect for your site, and you should be wary of anyone who does without looking at your data.

Separate from the CMP question, Google notes that it will not serve personalized ads, regardless of consent signals, if a publisher has indicated that a child is present or labeled content as child-directed.

Moving your consent setup from AdSense to Ad Manager

If you already use a consent message in AdSense, you are not starting from scratch, but you should check the setup deliberately when you move to Ad Manager.

If you use Google's own message. Google says the European regulations message available in the Privacy & messaging section of Ad Manager, AdSense and AdMob is certified under the TCF requirement. Google's help pages do not describe messages carrying over from one product to the other, so before you switch, check in Ad Manager's Privacy & messaging section that a European regulations message is set up and published for your site, with the wording, languages and design choices you rely on today.

Ad Manager uses its site list for this. Under Inventory > Sites, Google notes that if you are not using MCM you do not need to add your owned sites unless you want to use Google's consent management platform; if you do, add them. You can target messages to any site you have added, but Google says published messages only appear live once eligible ads begin serving on the site. Our Ad Manager account setup guide covers adding sites.

If you use a third-party CMP. Confirm it is on Google's certified list for your platform, then ask your CMP provider how it should be loaded alongside Google Publisher Tag so the TCF signal reaches your ad requests. If you add other demand partners in Ad Manager, make sure your CMP's vendor list covers them.

If AdSense keeps running as backfill. If you set up AdSense inside Ad Manager to compete for your inventory, your consent setup still has to be in place on every page those ads appear on. See AdSense backfill in Ad Manager for how that setup works.

MCM and user messages: who configures what (MA vs MI)

MCM adds a question that AdSense publishers have never had to answer: which account's message appears on your site? Google's answer depends on the delegation type. The how MCM works guide explains the two types in full.

Manage Account (MA). The parent publisher should configure all messaging inside the child publisher's account. The messages then serve through the child's own ad tag. There is one account and one message, which keeps things simple.

Manage Inventory (MI). A site with MI parents carries ad tags for the child's own ad units plus those of up to 15 MI parents. If more than one of those accounts publishes user messages to the same domain, Google's Privacy & messaging by default picks one account arbitrarily and shows only that account's messages, of every type. Google's example: if the selected parent has published only a European regulations message, none of the other accounts' messages (GDPR, US states, ad blocking recovery and so on) will show. The selection stays the same for a given set of accounts but can change when a new MI parent starts publishing messages to the domain.

Google gives children two ways to choose the account explicitly:

  1. Deploy the ad blocking recovery tag from the account you want; the account that generated that tag always manages messaging. Google does not support deploying recovery tags from several accounts on the same site.
  2. Append ?network-code=<account_network_code> to the GPT script tag in your page header (on every gpt.js tag if you have several).

Google's own advice is that MI children agree with their parents on who manages messaging, so that only one account publishes messages to the domain. Settle this in writing before you go live.

Checking it works before you switch

A short test before you move traffic to Ad Manager saves surprises later:

  1. Confirm certification. Find your CMP on Google's certified list and check the platform column covers web (and app or CTV if you use them).
  2. Test from the right regions. Load your pages as a visitor from the EEA, the UK and Switzerland (a VPN works) in a fresh browser profile. The consent message should appear before ads load.
  3. Test each choice. Accept, reject and customize, and check that the site still works and that users can later change their choice, which the consent policy requires.
  4. Check the privacy policy. The Publisher Policies require a privacy policy that discloses data collection and use from Google products, including that third parties may place and read cookies.
  5. Under MCM, confirm one owner. For MA, the parent should configure messaging in your account. For MI, agree in writing which single account publishes messages, and use the network code parameter or recovery tag if you need to lock it in.
  6. Recheck after changes. Any new parent, new CMP version or template change is a reason to run the test again.

Keep screenshots and notes of the test. They are useful if your partner, or Google, asks how consent is collected on your site.

Next step

A certified CMP and clear ownership of user messages are part of a clean move to Ad Manager. Once consent, policy and traffic quality are in order, eligible publishers may receive an MCM invitation, subject to Google's policies. Check the requirements, then Get AdX access to request a review.

Frequently asked questions

Google's requirement applies whenever you serve personalized ads to users in the EEA, the UK or Switzerland, so even a small share of visitors from those regions is covered. Without a certified CMP, that traffic may only be eligible for non-personalized or limited ads. Whether other laws apply to your US traffic is a separate question for your own legal adviser.

Yes. Google states that the European regulations message in the Privacy & messaging tab of Ad Manager, AdSense and AdMob is certified under the TCF requirement. Google also encourages publishers to consider which CMP solution suits them best, so you can use either Google's message or another CMP from the certified list.

If the child and one or more Manage Inventory parents all publish user messages to the same domain, Google's Privacy & messaging picks one account arbitrarily by default and shows only that account's messages. Google recommends that children agree with their parents which single account manages messaging, and explains how to choose it explicitly in the tag.

For Google's requirement, what matters is that the CMP appears on Google's certified list and integrates with the IAB TCF, not what it costs. Note that Google says it does not check CMPs for full compliance with the TCF or privacy laws. Whether a given setup meets your legal obligations is a question for a qualified adviser.

Sources

  1. https://support.google.com/admanager/answer/13554116?hl=en
  2. https://www.google.com/about/company/user-consent-policy/
  3. https://support.google.com/admanager/answer/14112208?hl=en
  4. https://support.google.com/admanager/answer/10130765?hl=en
  5. https://support.google.com/adsense/answer/10502938?hl=en

Related guides

Ready for AdX? Get access

Coming from AdSense? Set up your Ad Manager network, then apply with its code. Eligible publishers may receive an invitation from our MCM partner network, subject to Google's policies.

Get AdX access