preloader

· digital-privacy gdpr europe google compliance advertising data-protection consent-management

Google Started Using IP Addresses for Ad Targeting Across Europe This Week. Your Consent Banner May Not Cover It

Source: BleepingComputer

Google has collected IP addresses for years without much controversy, because collecting one to route a request or measure basic traffic does not by itself require consent under GDPR. What changed on 3 August is the purpose. Google now uses those same IP addresses to identify devices for ad measurement and personalisation across the EEA, UK and Switzerland, and identifying a device for targeted advertising is exactly the kind of processing that does require a valid legal basis, in this case, user consent.

Google has registered the new use under IAB Europe’s Transparency and Consent Framework as Feature 3, “identify devices based on information transmitted automatically.” TCF is the industry-standard mechanism most European publishers and ad tech vendors already use to capture and pass consent signals between platforms, which means the infrastructure to handle this correctly already exists on most sites. The problem is that existing does not mean configured. A consent management platform that was set up before Feature 3 existed, or that was never explicitly reviewed against Google’s updated requirements, will not be capturing consent for this specific use case even if it is functioning normally for everything else.

Google put the compliance burden on you, not on itself

Google has been explicit that advertisers and publishers, not Google, are responsible for ensuring valid consent is obtained under its EU User Consent Policy. That is a familiar pattern for anyone who has watched platform-level ad tech changes roll out before, the platform ships the capability and registers the framework entry, and the legal exposure for getting consent wrong sits with the site operator running the banner. The UK’s ICO has already flagged this rollout and warned publishers to check their consent flows rather than assume existing setups cover it. Sites that have not touched their CMP configuration since before this announcement are the ones most likely to be either quietly excluded from Google’s expanded targeting or, more seriously, processing personal data without a consent record that would hold up if a regulator asked to see one.

What this means beyond ad revenue

For most organisations reading this, the immediate business impact is ad targeting effectiveness, but the underlying issue is broader: this is a live example of how quickly a legal basis for processing personal data can shift underneath a system that looks unchanged from the outside. The banner still displays, the site still functions, and nothing about the user experience signals that the purposes behind the data being collected just expanded. That is precisely the kind of change GDPR’s accountability principle expects organisations to actively monitor for, rather than discover during an audit or a complaint.

If your organisation runs a website with a consent management platform and you want a check on whether it correctly captures Feature 3 consent for Google’s updated IP address use, or a broader review of whether your CMP configuration still matches what you are actually collecting, contact Excello Digital. We help European organisations keep consent infrastructure aligned with what platforms actually do, not just what they did when it was configured.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!