Approvalens

AdSense CMP Rules for EEA, UK and Swiss Visitors (TCF v2.3)

Approvalens · Updated October 4, 2026 · 7 min read

If any of your visitors come from the European Economic Area, the UK or Switzerland, AdSense needs a Google-certified consent management platform (CMP) that integrates with the IAB Transparency and Consent Framework before it can serve personalized ads to them. Since 1 March 2026, every consent string that CMP creates must use TCF v2.3. A missing or uncertified CMP doesn't stop your site from existing in AdSense, but that traffic drops to non-personalized or limited ads, and those usually earn less.

This guide covers what the rule actually says, which setups work, and how to check your own banner in about ten minutes.

There are three separate layers, and people often mix them up.

  1. The EU user consent policy. Google's EU user consent policy says you "must obtain end users' legally valid consent to: the use of cookies or other local storage where legally required; and the collection, sharing, and use of personal data for personalization of ads." It covers the EEA, the UK and Switzerland. It also requires you to keep records of consent, explain how to revoke it, and name each party that receives personal data.
  2. The certified CMP requirement. According to AdSense Help, publishers serving ads to these users are "required to use a consent management platform (CMP) that has been certified by Google and integrates with the IAB's Transparency and Consent Framework (TCF)." It has applied to the EEA and UK since 16 January 2024 and to Switzerland since 31 July 2024.
  3. The TCF version. Google's TCF integration page says: "TCF v2.3 is mandatory for all TC strings generated on or after March 1, 2026." A CMP that still writes v2.2 strings is out of date.

What happens if you skip the certified CMP? Google says traffic from a non-certified CMP "may be eligible for non-personalized ads or limited ads (including programmatic limited ads) where supported." So you aren't banned. You're just leaving most of your European demand unsold.

Does a CMP affect AdSense approval?

Google doesn't publish anything that makes a CMP an approval condition. Approval depends on content, policy compliance and whether the site can be crawled. The privacy policy is a different matter: it's mandatory everywhere. Still, set up the CMP before you apply if you have European traffic, for two reasons:

  • The day your site moves to "Ready", ads begin serving to every visitor. Without consent in place, your first weeks of European traffic earn limited-ads rates.
  • A banner that hides content, can't be closed, or traps people on mobile is a user-experience problem on its own. Reviewers see your pages the way a visitor does.

A Turkish site with 3% German readers and a UK cooking blog with 60% UK readers are very different cases. Check your analytics. If EEA, UK or Swiss traffic is more than a rounding error, set up a CMP.

Your options: Google's CMP or a third-party one

Google's own CMP (Privacy & messaging)

AdSense includes a free consent message under Privacy & messaging → European regulations. Google lists it as "Google LLC CMP" with TCF CMP ID 300, and its help page says the messages in that tab "are certified in accordance with the new TCF requirement." For most small publishers this is the easiest route:

  • You don't need a plugin or another script. The message loads through your existing AdSense code.
  • It appears only to visitors in the regulated regions.
  • It handles the TC string and the Google vendor setup for you.

The trade-off is control. You get fewer design options, and if you also run analytics or other ad tags you still have to make them respect consent yourself.

A certified third-party CMP

If you already use a cookie banner, check that it's on Google's certified list on the CMP requirement page and that TCF mode is switched on. Examples of certified CMPs with their TCF IDs: Cookiebot (134), OneTrust (28), CookieYes (401), Complianz (332) and InMobi/Quantcast Choice (10). A banner that only shows "Accept / Reject" without generating a TCF string doesn't count, even if it looks professional.

Setup Certified for AdSense? Typical result for EEA traffic
Google Privacy & messaging, EU message on Yes (ID 300) Personalized ads where consent is given
Cookiebot, CookieYes, Complianz etc. with TCF enabled and current version Yes, if on the list Personalized ads where consent is given
Same plugin, TCF mode off (simple banner) No Non-personalized or limited ads
Home-made JavaScript banner No Non-personalized or limited ads
No banner at all No Limited ads at best, plus legal risk

Purpose 1 and when your ad tag may load

TCF splits consent into purposes. Purpose 1 is "Store and/or access information on a device." Google's guidance is direct: "If you do not have consent for Google for Purpose 1 (Store and/or access information on a device), you should not call Google's ad tag."

In practice, Google's own tag reads the TC string and adjusts its behaviour. Problems usually come from custom setups: a hand-coded banner that loads adsbygoogle.js before the visitor has chosen anything, or a script that rejects Google as a vendor by default. If you use a third-party CMP, make sure Google (vendor ID 755 in the IAB Global Vendor List) appears in its vendor list. If it doesn't, every "Accept all" still means "no consent for Google".

How to check your CMP from the outside

You can test this yourself in a browser. Use a VPN with an EEA exit or ask a friend in Germany or the Netherlands, then open a private window:

  1. Load your home page. The consent message should appear before any ads.
  2. Open the developer console and run __tcfapi('getTCData', 2, (d, ok) => console.log(d.cmpId, d.tcfPolicyVersion, ok)).
  3. Check the result. cmpId should be a certified ID (300 for Google's CMP). tcfPolicyVersion should reflect v2.3 for strings created after 1 March 2026. If __tcfapi is undefined, there is no TCF CMP on the page.
  4. Click "Manage options" and confirm that Google appears among the vendors.
  5. Scroll to the footer. You need a persistent link such as "Privacy settings" or "Manage consent" so visitors can change their decision later. The consent policy requires clear instructions for revocation.

Approvalens runs the static part of these checks on every scan. It looks for known CMP scripts, Google's fundingchoicesmessages.google.com loader and a consent re-open link. Our methodology page lists exactly which signals we read and which ones need a real browser in the EEA.

Common mistakes we see

  • Two banners at once. A WordPress cookie plugin plus Google's EU message, both active. Visitors get asked twice and the strings can conflict. Pick one.
  • Outdated plugin version. The CMP vendor supports v2.3, but the site still runs a 2024 plugin build. Update it, and check the version again in the console.
  • Banner covers the whole screen on mobile with no visible close or reject. Besides annoying people, this can hide the content a reviewer is trying to evaluate.
  • Privacy policy doesn't mention the CMP or the vendors. Your policy should name Google as a third-party vendor that uses cookies for ads and explain how to opt out. See our privacy policy guide.
  • Forgetting the US. The CMP rule is about Europe, but Google's account setup page also asks you to comply with laws like the CPRA. Privacy & messaging has a separate US states message for that.
  • Thinking User-agent rules or Cloudflare settings fix consent. They don't. Consent happens in the visitor's browser, not at the crawler level. If you're working on crawler access, the robots.txt guide is the right place.

A short setup checklist

  • Check the share of EEA, UK and Swiss visitors in analytics
  • Choose one CMP: Google Privacy & messaging or a certified third-party CMP with TCF on
  • Confirm __tcfapi exists and returns a certified cmpId
  • Confirm consent strings are v2.3 (strings created since 1 March 2026)
  • Google appears in the vendor list
  • A "Privacy settings" link is visible in the footer on every page
  • The privacy policy names Google and other ad vendors, plus the opt-out links
  • Only one consent banner loads

You'll find the rest of the pre-application items in the AdSense approval checklist.

Check your site

A free Approvalens scan at /#scan shows whether a known CMP and a consent re-open link are present, along with the other readiness checks.

FAQ

Do I need a CMP if my site is in Turkey or the US?

The rule is about where your visitors are, not where you are. If people from the EEA, UK or Switzerland read your site, the certified CMP requirement applies to that traffic.

Is Google's free CMP good enough?

Yes. Google lists its own CMP (ID 300) as certified. It's the simplest choice for most blogs that only run AdSense.

What happens if my CMP still produces TCF v2.2 strings?

Google made v2.3 mandatory for strings created on or after 1 March 2026. Older strings risk being treated as invalid consent, which pushes that traffic toward limited ads. Update the CMP.

Will a CMP get my site approved faster?

No. Approval depends on content, policy and access. A CMP affects which ads can serve to European visitors once you're approved.

You can, but it won't be a Google-certified TCF CMP. European traffic would then only be eligible for non-personalized or limited ads.

Check your own site

Free scan: readiness score and every issue, usually in a few minutes.

Free scan · score and top 3 issues · no sign-up

More guides