Privacy and consent become part of the publishing setup when advertising technologies collect or use information about visitors. A Privacy Policy, a cookie disclosure and a consent mechanism are related, but they are not interchangeable.
This guide explains the publisher-side concepts you need to understand before enabling AdSense. It deliberately avoids pretending that one website can use one universal privacy setup for every country and every technology.
Privacy policy, cookies and consent are different
| Term | Practical meaning |
|---|---|
| Privacy Policy | Explains how the site handles personal information and relevant technologies. |
| Cookie information | Explains cookies or similar storage/technologies used by the site and relevant services. |
| Consent | A user's choice where consent is required for a particular processing activity. |
| CMP | A consent-management platform used to present choices and communicate consent signals. |
| TCF | The IAB Europe Transparency and Consent Framework used by certified CMPs in the relevant Google publisher flow. |
Why this matters for AdSense
Google's EU User Consent Policy requires certain disclosures and consent for users in the European Economic Area, the UK and Switzerland. For publishers serving personalized ads in those regions, Google currently requires a CMP that is certified by Google and integrates with the IAB Transparency and Consent Framework.
These requirements are distinct from the general question of whether your website needs a Privacy Policy or what privacy law applies to a particular visitor. Google also states that CMP certification does not mean Google has determined that the CMP complies with all privacy laws; publishers remain responsible for the tools they use and their legal obligations.
What the Google CMP requirement means
For AdSense publishers serving personalized ads to users in the EEA, UK or Switzerland, Google currently requires a Google-certified CMP integrated with the IAB TCF. Google provides its own CMP option through Privacy & Messaging, and it also maintains a list of certified third-party CMPs.
Do not copy an old tutorial's consent code and assume it is still compliant. Check Google's current publisher documentation and the current certification status of the CMP you intend to use.
Do not confuse a cookie banner with a complete consent setup
A visual banner that says “We use cookies” is not automatically a complete consent solution. The implementation has to reflect the purposes, providers and choices that are actually relevant to the technologies on the site.
Google's Privacy & Messaging documentation explains that publishers identify the ad technology providers used and obtain the appropriate user choices through the consent flow. The exact configuration should be based on the services you actually deploy.
Think about the technologies you actually use
Before configuring consent, inventory the site. Advertising may not be the only technology that matters. Analytics, embedded media, third-party scripts, personalization systems and other services can have their own data or storage implications.
Make a simple list of:
- advertising services;
- analytics services;
- third-party embeds;
- cookies or local storage used by your own application;
- other external scripts that process or transmit visitor information.
Then make sure your privacy information and consent configuration describe the real implementation rather than a generic list copied from another website.
Personalized and non-personalized advertising
Do not assume that switching an ad setting automatically solves every privacy requirement. Google's consent requirements can depend on the ad personalization approach, the user's location and the products being used.
If you plan to serve ads internationally, design the implementation around the actual regional requirements rather than treating every visitor as if the same legal rules apply.
What TCF does—and does not—mean
The IAB Transparency and Consent Framework provides a standardized way for participating organizations to communicate consent information. Google's publisher requirement for relevant personalized advertising traffic is tied to a Google-certified CMP that integrates with TCF.
TCF participation is not a statement that every privacy-law obligation has been satisfied. Google explicitly notes that its CMP certification focuses on Google's certification criteria and TCF compliance; publishers remain responsible for applicable privacy obligations.
Prepare the Privacy Policy from the real site
Do not write the policy before you know what the site actually does. If the production implementation later adds AdSense, analytics or a CMP, revisit the policy so it describes those technologies accurately.
At minimum, the relevant privacy documentation should be consistent with the actual services, data uses, contact information and choices available to visitors. If the legal implications are significant, obtain advice appropriate to your business and jurisdictions rather than treating an online template as legal advice.
When should Tervilo enable consent management?
Tervilo does not currently have an AdSense account, so there is no reason to pretend that a production AdSense consent configuration is already active. The website can prepare its policy and technical architecture now, while the final Google Privacy & Messaging configuration is completed after the publisher account and actual advertising setup exist.
Until the advertising implementation is genuinely ready, keeping advertising disabled avoids creating a false impression that the site is already serving AdSense.
A practical pre-launch checklist
- □ Identify every advertising and analytics technology planned for production.
- □ Review the Privacy Policy against the real implementation.
- □ Review cookie/local-storage disclosures as appropriate.
- □ Determine which regions require specific consent handling.
- □ If serving personalized AdSense ads to EEA, UK or Swiss users, use the current Google-certified TCF CMP requirement as the implementation baseline.
- □ Check the current Google Privacy & Messaging documentation before launch.
- □ Re-test the site after adding the CMP and advertising scripts.
Quick answer
AdSense privacy preparation is more than adding a cookie banner. Your Privacy Policy should match the technologies you actually use, and consent should be collected where required. For personalized AdSense ads to users in the EEA, UK and Switzerland, Google currently requires a Google-certified CMP integrated with the IAB TCF. Because requirements and technologies can change, use Google's current publisher documentation as the source of truth and keep the production setup aligned with the actual services on the site.