A correct Google AdSense CMP setup is essential if your website serves personalized advertisements to visitors in the European Economic Area, the United Kingdom or Switzerland.
Google requires AdSense publishers serving personalized ads to users in these regions to use a Google-certified Consent Management Platform integrated with the IAB Europe Transparency and Consent Framework. This requirement has applied to the EEA and UK since January 16, 2024, and to Switzerland since July 31, 2024. 1
The requirement is based on the visitor’s location, not only the publisher’s country. Therefore, an Indian website can still need a suitable CMP when it receives visitors from the EEA, UK or Switzerland and serves Google advertisements to them. This is a direct practical consequence of Google’s region-specific publisher requirements. 1
This guide explains how to use Google’s CMP in AdSense, configure a European regulations message, test the banner and solve common deployment problems.
What Is a Consent Management Platform?
A Consent Management Platform, commonly called a CMP, is a system that presents privacy choices to website visitors and transmits their decisions to advertising and analytics technologies.
A CMP can help manage choices related to:
- Advertising cookies
- Local storage
- Personalized advertising
- Advertising user data
- Analytics storage
- Data sharing with vendors
- Consent withdrawal
- Legitimate-interest controls
Google’s CMP is available through the Privacy & messaging section of AdSense. It supports European regulations messages for the EEA, UK and Switzerland and privacy messages for applicable US state requirements. 3
Why Is Google AdSense CMP Setup Important?
Under Google’s EU User Consent Policy, publishers must make specific disclosures to eligible users and obtain consent for cookies or local storage where legally required. Publishers must also obtain consent for the collection, sharing and use of personal data for personalized advertising. 4
Without a properly certified CMP:
- Traffic may not be eligible for personalized ads.
- Some traffic may receive non-personalized or limited ads where supported.
- Advertising demand and revenue can be affected.
- The publisher may receive a regulatory issue.
- Google can conduct an EU User Consent Policy audit.
- Persistent non-compliance may lead to enforcement.
Google states that only traffic using a certified CMP is eligible for personalized ads under these regional requirements. Traffic from a non-certified CMP may be eligible only for non-personalized or limited ads where supported. 1
TCF v2.3 Requirements in 2026
The mandatory industry deadline for publishers and CMPs to implement IAB Europe TCF v2.3 was March 1, 2026. Google’s European regulations messages in AdSense now support the TCF v2.3 specification. 5
In a TCF implementation:
- The CMP collects the visitor’s privacy selections.
- It creates a Transparency and Consent string.
- The visitor’s choices are communicated through the TC string.
- AdSense consumes the signal supplied by the CMP.
- Google determines which advertising activities are permitted.
If Google does not have consent for TCF Purpose 1—storing or accessing information on a device—the publisher should not call the applicable Google ad tag in situations covered by the TCF implementation guidance. 5
For a new 2026 implementation, use a CMP that currently supports TCF v2.3 rather than following older tutorials designed only for TCF v2.1 or v2.2.
Google CMP vs Third-Party CMP
Publishers can choose between:
Google’s CMP
Google’s CMP is integrated into the AdSense Privacy & messaging section.
Benefits include:
- Direct AdSense integration
- Google certification
- TCF v2.3 support
- European regulations messages
- Vendor and consent controls
- Consent Mode options
- Consent-revocation functionality
- Engagement reporting
A Third-Party CMP
You can use a third-party CMP when it is included in Google’s current certified-CMP list and supports the required website environment.
A third-party platform may provide:
- Additional design controls
- Multi-platform consent management
- Cookie scanning
- More detailed reporting
- Support for several advertising networks
- Additional regional privacy frameworks
Google continuously updates its certified-CMP list and recommends that publishers select a platform based on their traffic locations and required functionality. Google certification does not mean that Google has confirmed the CMP’s full compliance with every applicable privacy law. 1
How to Complete Google AdSense CMP Setup
Before starting, confirm that:
- Your site has been added to AdSense.
- The correct AdSense account is being used.
- AdSense code is installed on the website.
- Your privacy policy is published.
- Your website works over HTTPS.
- You can test the website as a logged-out visitor.
Then follow these steps.
Step 1: Open Privacy & Messaging
- Sign in to Google AdSense.
- Open Privacy & messaging.
- Find the European regulations card.
- Click Create if you have not created a message.
- If a message already exists, click Manage and then Create message.
The Google CMP and all associated European regulations message controls are managed from this section. 6
Step 2: Select Your Websites
Click Select sites and choose every website where you want the European regulations message to appear.
Make sure that:
- You select the correct domain.
- The domain uses the same AdSense account.
- The AdSense code exists on the selected website.
- You are not accidentally configuring a staging website.
Google does not support serving AdSense from multiple publisher accounts on one page. Consent-message behavior is also not guaranteed when a page contains AdSense tags from multiple accounts. 7
Step 3: Select the Message Languages
Choose:
- One default language
- Suitable additional languages
The default language is used when the visitor’s device language cannot be determined or does not adequately match an additional language.
Google determines the displayed message language based on the visitor’s device-language setting. English US and English UK are treated as separate languages in the message builder and need to be edited separately if both are selected. 6
Google’s current European regulations message language list does not include Gujarati. For an English-language AdSense website, English can be selected as the default. If your website is primarily in Gujarati, review whether the available message language provides sufficient clarity for your target visitors and obtain appropriate compliance advice. 8
Step 4: Configure the “Do Not Consent” Choice
You can enable the Do not consent option on the first page of the message.
When enabled, eligible visitors can decline consent to your selected advertising partners and purposes using a single first-layer choice. Google also allows the publisher to specify the countries where this button appears. 6
A clear starting configuration is:
- Consent: Displayed
- Do not consent: Displayed
- Manage options: Displayed
This provides visitors with visible choices, but you remain responsible for confirming that the implementation satisfies the requirements applicable to your website.
Step 5: Configure the Close Option
Google allows you to add a Close (do not consent) icon. When a visitor selects the close icon, the message is dismissed and consent is declined for the relevant ad partners and purposes. 6
Do not assume that a close icon means “ask me later.” In this message configuration, it operates as a do-not-consent action.
Step 6: Decide Whether to Use Consent Optimization
The Optimize my consent message option allows Google to determine which message experience is most likely to drive revenue based on previous performance and session information such as browser or location.
Google may show:
- A standard message requiring a decision before content access, or
- A limited, non-blocking message for users considered less likely to generate substantial personalized-ad revenue. 9
You can enable optimization for individual European regulations messages. If strict control over the first-layer presentation is important to your legal or editorial process, review this option with the person responsible for privacy compliance before enabling it.
Step 7: Name and Customize the Message
Add a descriptive internal name, such as:
AdSenseEarning-European-Consent-2026
The internal message name is visible only inside Privacy & messaging.
You can edit:
- Heading
- Body text
- Button labels
- Colours
- Logo
- Font styling
- Message layout
Review every selected language separately before publishing. Avoid misleading, pressuring or confusing language. Your message should clearly explain the use of data for advertising personalization and should not hide or misrepresent the visitor’s choices. 6
Step 8: Add Your Privacy Policy URL
Enter the URL of the website’s privacy policy.
Your privacy policy should accurately explain:
- The use of Google advertising
- Cookies and local storage
- Personalized and non-personalized advertisements
- Data sharing with Google and other vendors
- Analytics tools
- Consent choices
- How users can update or withdraw consent
Google’s audit guidance also expects publishers to explain data sharing with Google and provide access to information about how Google uses business data. 10
Do not use a copied privacy policy containing another company’s name, domain or contact details.
Step 9: Publish the Message
After reviewing your settings:
- Check desktop and mobile previews.
- Review every language.
- Confirm the privacy-policy URL.
- Confirm the selected sites.
- Click Publish.
You can use Save draft if the message is incomplete. A draft message will not display to website visitors. 6
Configure Your Ad Technology Partners
Google allows AdSense publishers to use:
- A commonly used set of ad technology partners, or
- A custom set of ad technology partners
The selected vendors should be identified to users through the consent flow or an accessible linked page. Publishers should also provide access to information describing each provider’s data activities. 4
Google updated its commonly used ad-technology-partner set on July 16, 2026. If automatic updates remain enabled, the commonly used set can be updated by Google. Publishers who do not want future automatic additions can choose not to automatically include commonly used partners, creating a custom list based on their current selections. 11
Do not remove vendors randomly only to shorten the consent message. Incorrect vendor selections can affect advertising demand and consent signaling.
Configure Legitimate-Interest Settings
AdSense lets publishers decide whether legitimate-interest controls appear and whether those choices are enabled by default.
If legitimate-interest controls are disabled, eligible advertising partners must rely on consent for applicable purposes. Google warns that partners relying only on legitimate interest may then be unable to operate for those purposes, potentially reducing revenue. 12
Because legitimate interest is a legal-basis decision, do not choose the setting based only on revenue. Review it with qualified privacy counsel.
If you make a significant change, AdSense can prompt you to decide whether previous visitors should be asked to make new selections.
Request Consent for Your Own Use of Data
European regulations messages can also request permission for data processing performed by your own website.
Examples may include:
- Personalized article recommendations
- User-profile functionality
- Audience measurement
- Content-performance analysis
- Customized website features
For each supported purpose, AdSense can let you select:
- None
- Consent
- Legitimate interest
Your selections must reflect what your website actually does and comply with applicable requirements. Do not request consent for purposes that your website does not use. 13
Configure Consent Mode
If you use products such as Google Analytics or Google Ads, Google’s CMP can interpret existing EEA, UK and Swiss privacy decisions for Consent Mode.
Available settings include:
- Consent Mode for advertising purposes
- Consent Mode for analytics purposes
Advertising purposes can include signals for ad storage, ad personalization and advertising user data. The analytics option appears when advertising Consent Mode has been enabled. Changes apply across the sites and apps where your European regulations messages are configured. 14
Consent Mode does not replace the consent message. It helps compatible Google tags adjust their behavior based on the collected choices.
Add a Consent-Revocation Link
Users must be able to return to their privacy settings and change their previous choices.
AdSense automatically adds the required European regulations revocation link to approved websites displaying these messages and containing the AdSense code. Publishers can also place their own privacy-settings link on a privacy or cookie-policy page. 15
Google documents this JavaScript function for opening the revocation flow:
<a href="javascript:googlefc.callbackQueue.push(googlefc.showRevocationMessage)">
Privacy and cookie settings
</a>
Use a clear label such as:
Privacy and cookie settings
Test the link after publishing the message.
How to Test an AdSense GDPR Consent Message
You do not need to travel to Europe or use a VPN simply to display a published test message.
Open an eligible page and add:
?fc=alwaysshow&fctype=gdpr
Example:
https://example.com/article/?fc=alwaysshow&fctype=gdpr
This parameter displays the currently published European regulations message and ignores the visitor’s normal regional eligibility for testing purposes. 8
Test:
- Consent
- Do not consent
- Manage options
- Vendor preferences
- Privacy-policy link
- Consent revocation
- Desktop layout
- Mobile layout
- All selected languages
Use a private browsing window or clear your existing consent state before repeating the test.
Why Is the AdSense CMP Message Not Showing?
1. The Message Is Still a Draft
Only a published message can appear on the live website.
2. AdSense Code Is Missing
The site needs an up-to-date AdSense tag associated with the account where the message was configured. 7
3. The Publisher IDs Do Not Match
The publisher ID in the website code must match the account containing the consent-message configuration.
4. Multiple AdSense Accounts Are Used
AdSense does not support serving from multiple accounts on one page, and Google CMP behavior is not guaranteed in that configuration. 7
5. The Referrer Policy Blocks the Message
The site’s referrer policy must allow the referrer header to be included in cross-origin requests. Google gives strict-origin and strict-origin-when-cross-origin as examples of compatible policies. 6
A possible header is:
Referrer-Policy: strict-origin-when-cross-origin
Ask your developer to review the setting before changing a production security policy.
6. The Test Parameter Is Incorrect
Use:
?fc=alwaysshow&fctype=gdpr
If the page already has a query parameter, additional parameters may need to begin with & instead of another ?.
7. The Page Uses AMP
Google’s current AdSense documentation states that European regulations messages created through this AdSense flow do not support AMP pages. 6
8. Caching Is Serving an Older Page
Clear:
- WordPress cache
- CDN cache
- Server cache
- Browser cache
Then test in a private browser window.
TCF v2.3 Troubleshooting
AdSense provides reporting for detected TCF implementation errors.
Common problems can include:
- An invalid CMP ID
- An invalid Global Vendor List ID
- Google missing as a vendor
- Missing consent for required purposes
- An outdated or invalid TC string
- Delayed CMP callbacks
- Incorrect consent-state transmission
- Problems with Additional Consent signals
Google’s vendor ID under the TCF is 755. Google recommends investigating errors that affect significant traffic volume and ensuring that the CMP responds promptly to registered addEventListener calls. Delayed responses can cause ad requests to remain unmonetized. 16
If you use a third-party CMP, send the detected error codes to its technical-support team.
How to Measure Consent Performance
Privacy & messaging provides engagement metrics that can include:
- Messages shown
- Consent rate
Google defines consent rate as the percentage of European regulations messages with an outcome where the user consented to all applicable purposes and vendors. Messages closed without a measurable outcome are excluded from the denominator. 17
Do not judge the message only by consent rate. Also monitor:
- EEA, UK and Swiss ad revenue
- Ad coverage
- Personalized versus non-personalized demand
- Page RPM
- Website engagement
- Returning visitors
- Privacy complaints
- TCF error reports
Avoid misleading design changes intended only to pressure more users into accepting.
Recommended Google AdSense CMP Settings
The following is a practical starting point—not legal advice or a universal compliance formula:
| Setting | Suggested starting point |
|---|---|
| CMP | Google CMP or certified third-party CMP |
| TCF version | TCF v2.3 |
| Do not consent | Display |
| Manage options | Display |
| Close option | Review before enabling |
| Consent optimization | Test and review |
| Privacy policy | Accurate and publicly accessible |
| Ad partners | Commonly used set or reviewed custom list |
| Legitimate interest | Obtain legal advice |
| Consent Mode | Enable if required for your Google tags |
| Revocation link | Confirm it appears and works |
| Testing parameter | ?fc=alwaysshow&fctype=gdpr |
| Message languages | Match supported site languages |
| Performance review | Monthly |
| TCF errors | Investigate regularly |
Google AdSense CMP Setup Checklist
- The website is added to the correct AdSense account.
- The current AdSense code is installed.
- A Google-certified CMP is being used.
- The implementation supports TCF v2.3.
- The correct sites are selected.
- Default and additional languages are reviewed.
- The Do not consent choice is configured.
- Manage options is available.
- The privacy-policy URL is correct.
- Advertising partners have been reviewed.
- Legitimate-interest settings have been reviewed.
- Purposes for the website’s own data use are accurate.
- Consent Mode has been configured where appropriate.
- The message is published rather than saved as a draft.
- The test parameter displays the message.
- Consent withdrawal works.
- The mobile message is readable.
- The referrer policy permits message deployment.
- The website does not use multiple AdSense accounts on one page.
- TCF errors are monitored.
- Consent and advertising performance are reviewed regularly.
Frequently Asked Questions
Is a CMP required for an Indian AdSense website?
It can be required when the website serves personalized Google ads to users located in the EEA, UK or Switzerland. The requirements are based on the eligible visitor traffic, not only the publisher’s location. 1
Is Google’s CMP free?
Google’s CMP is available within the AdSense Privacy & messaging interface. Publishers should compare its functionality with certified third-party CMPs before selecting a solution.
Is Google’s CMP certified?
Yes. European regulations messages provided through AdSense Privacy & messaging are certified for Google’s TCF-related CMP requirements. 18
Does Google CMP guarantee GDPR compliance?
No. Google says its CMP assessments focus on certification criteria related to TCF compliance. Google does not validate full compliance with the TCF or every applicable privacy law. 1
Is TCF v2.3 mandatory in 2026?
The IAB transition deadline was March 1, 2026, and Google’s CMP now supports TCF v2.3. New implementations should use the current supported framework. 5
Can I use a third-party cookie banner?
Yes, but when serving personalized ads to eligible users in the EEA, UK and Switzerland, the CMP must satisfy Google’s certification and TCF-integration requirements. 1
Why does my consent message not appear in India?
A standard European regulations message is displayed according to factors including the visitor’s region and prior consent status. Use the official ?fc=alwaysshow&fctype=gdpr test parameter to preview the published message outside the eligible region. 8
Can users change their consent later?
Yes. Publishers must provide consent revocation. AdSense automatically adds a revocation link to eligible approved websites using European regulations messages, and publishers can add an additional privacy-settings link. 15
Does a “Do not consent” selection stop all ads?
Not necessarily. Depending on the available signals and eligibility, Google may attempt to serve non-personalized or limited advertisements where supported. 1
Does Google CMP support Gujarati?
Gujarati is not currently listed among the supported languages for AdSense European regulations messages. English and several European languages are supported. 8
Can I use the Google CMP on AMP pages?
Google’s current AdSense setup documentation says European regulations messages in AdSense do not support AMP pages. 6
Conclusion
A correct Google AdSense CMP setup requires more than displaying a basic cookie banner. Publishers serving personalized ads to EEA, UK and Swiss users need a Google-certified CMP integrated with the current TCF framework.
Use Google’s Privacy & messaging section or select a certified third-party provider. Configure visible consent choices, review your advertising partners, connect an accurate privacy policy and provide a working method for visitors to change their preferences.
Finally, test the message with the official GDPR testing parameter, monitor TCF v2.3 errors and review both consent metrics and advertising performance. CMP implementation can support your compliance process, but the publisher remains responsible for meeting applicable policy and legal requirements.

