Approvalens

AdSense Privacy Policy Requirements, With Sample Wording

Approvalens · Updated October 4, 2026 · 6 min read

A privacy policy is one of the few hard requirements for AdSense. It must tell visitors that third parties, including Google, use cookies (or web beacons and IP addresses) to serve ads based on their visits to your site and other sites, and it must tell them how to opt out of personalised advertising. If you run other ad networks or analytics, name them too. Generic privacy templates often miss the ad-specific parts, which is why a site can "have a privacy policy" and still fall short.

This guide explains what Google asks for. It is not legal advice, and local law (GDPR, the UK GDPR, KVKK in Turkey, CPRA in California) may require more.

What Google requires

Two official pages set the rules.

The Google Publisher Policies require that you "have and abide by a privacy policy" and state: "The privacy policy must disclose to users that third parties may be placing and reading cookies on your users' browsers, or using web beacons or IP addresses to collect information as a result of ad serving on your website."

The AdSense required content page lists what to include:

  • "Third party vendors, including Google, use cookies to serve ads based on a user's prior visits to your website or other websites."
  • "Google's use of advertising cookies enables it and its partners to serve ads to your users based on their visit to your sites and/or other sites on the Internet."
  • "Users may opt out of personalized advertising by visiting Ads Settings." (Alternatively, you can point users to www.aboutads.info.)
  • For other networks: "Notify your site visitors of the third-party vendors and ad networks serving ads on your site."

Instead of explaining Google's data use in your own words, Google also lets you "display a prominent link to How Google uses data when you use our partners' sites or apps".

The required elements as a checklist

Element Required? Example of a passing line
Third-party vendors, including Google, use cookies Yes "Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this site or other websites."
Google's advertising cookies explained Yes "Google's use of advertising cookies enables it and its partners to serve ads based on your visits to this and other sites."
Opt-out of personalised ads Yes "You can opt out of personalised advertising in Google's Ads Settings."
Other ad networks named Yes, if you use any "We also work with Ezoic and Media.net, which may use cookies..."
Web beacons / IP addresses mentioned Yes, as part of the disclosure "...or use web beacons and IP addresses to collect information..."
Link to Google's partner-sites page Optional, recommended Link text: "How Google uses data when you use our partners' sites or apps"
How users can manage or withdraw consent Required where consent applies (EEA/UK/CH) "You can change your cookie choices at any time via Privacy settings in the footer."
Contact details for privacy requests Required by most privacy laws "Email privacy@example.com"

Sample wording you can adapt

Put this inside your own policy, under a heading such as "Advertising and cookies". Replace the bracketed parts and remove networks you do not use.

We use Google AdSense to show ads on [example.com]. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the Internet.

These vendors may place and read cookies in your browser, or use web beacons and IP addresses, to collect information as a result of ad serving on this site.

You may opt out of personalised advertising by visiting Google Ads Settings. You can also opt out of some third-party vendors' use of cookies for personalised advertising at www.aboutads.info.

For more information, see How Google uses data when you use our partners' sites or apps.

Then add a list of any other ad networks and analytics tools you run, with a link to each provider's privacy policy.

Other ad networks. If you also run Ezoic, Media.net, Amazon affiliate links with tracking, or a native ads widget, name each one. Google's wording is to notify visitors "of the third-party vendors and ad networks serving ads on your site".

Analytics. Google Analytics has its own requirement to disclose its use and how it collects data. Mention it, and any other analytics or heatmap tools.

EEA, UK and Switzerland. A privacy policy alone is not consent. If you have visitors from those regions and want personalised ads for them, you need a Google-certified CMP integrated with the IAB TCF (CMP requirement), and consent strings created from 1 March 2026 must be TCF v2.3. Google's EU user consent policy also asks you to "provide end users with clear instructions for revocation of consent", so add a persistent "Privacy settings" link and explain it in the policy.

US states. Google recommends complying with laws such as the CPRA. If you use AdSense's US states message, mention the "Do Not Sell or Share" option.

  • Publish it as a normal HTML page at a stable URL such as /privacy-policy or /privacy. Not a PDF, not a pop-up only.
  • Link it from the footer on every page. Reviewers and crawlers look there first.
  • Write it in the same language as your site. A Turkish site with an English-only policy confuses visitors.
  • Make it reachable without login and allow crawling. Do not add noindex if you want automated checkers to find it.
  • Keep it current. When you add a new network, update the policy the same day.

Common mistakes

Mistake Why it fails
A generic template with no mention of Google or advertising cookies Misses the required third-party cookie disclosure
Opt-out link missing or broken The opt-out is part of the required content
Policy only in a cookie banner Banners are not a full policy and are often hidden after the first click
Policy page returns 404 or is behind login Reviewers and crawlers cannot read it
Other networks you run are not named Google asks you to notify visitors of all vendors serving ads
Copied from another site, with their domain name still in it Looks careless and may misstate what you do

The approval checklist covers the other trust pages (About, Contact), and the EEA consent guide explains CMP setup step by step. Our checklist shows the privacy items next to the rest.

Check your privacy page for free

A free scan finds your privacy policy, checks it for the Google, cookie, third-party and opt-out wording, and reports what is missing. Run a free scan.

FAQ

Can I use a privacy policy generator?

Yes, as a starting point. Check that the output names Google, describes advertising cookies and includes an opt-out link. Many generators leave those out unless you select an advertising option.

Does the privacy policy need to be in English?

No. Write it in your site's language. Google's required statements are about content, not language.

No. The policy is required on its own. In the EEA, UK and Switzerland you need both a policy and a certified consent platform.

Google does not require a separate page. Many sites keep cookies in a section of the privacy policy, which is fine as long as the required statements are there.

Check your own site

Free scan: readiness score and every issue, usually in a few minutes.

Free scan · score and top 3 issues · no sign-up

More guides