Every calculation runs in your browser — nothing is uploaded Editorial policy About Contact
Legal

AdSense Privacy Policy Requirements: The Three Clauses You Must Include

Google rejects AdSense applications over privacy policy gaps more often than over content. The exact disclosures required, and the EEA consent obligation.

Google AdSense requires a privacy policy as a condition of participation, and a missing or inadequate one is among the most common reasons applications are rejected. The requirements are specific and the fixes take minutes.

#Clause 1: third-party vendors use cookies

Your policy must state that third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to your website and other websites.

Standard wording:

Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our sites and/or other sites on the Internet.

The substance matters more than the exact phrasing, but this wording is widely accepted because it mirrors Google's own guidance.

#Clause 2: how users opt out

Your policy must explain how users can opt out of personalised advertising. Two routes should be given:

You may opt out of personalised advertising by visiting Google Ads Settings. Alternatively, you can opt out of a third-party vendor's use of cookies for personalised advertising by visiting aboutads.info.

Both links should be live. A policy stating that opt-out is possible without saying where fails the requirement.

For traffic from the European Economic Area, the United Kingdom and Switzerland, Google's EU user consent policy requires you to obtain consent for the use of cookies and for the collection, sharing and use of personal data for personalisation of ads.

Since 2024 this must be done through a Google-certified Consent Management Platform integrated with the IAB Transparency and Consent Framework. Using a home-built banner, however well designed, does not satisfy the contractual requirement, and non-compliance can result in ad serving being limited for those regions.

Your policy should disclose this:

For visitors in the European Economic Area, the United Kingdom and Switzerland, we obtain consent for advertising and measurement cookies through a certified Consent Management Platform, in line with the Google EU user consent policy.

#What else Google checks

Beyond the advertising clauses, AdSense reviewers look for a privacy policy that is complete and genuinely describes your site:

  • Accessible from every page, normally via a footer link
  • Not behind a login and not a PDF
  • Describes analytics if you run any
  • States what data is collected and why
  • Provides a contact method for privacy enquiries
  • Includes data subject rights where GDPR or CCPA apply

A generic template that mentions a mobile app you do not have, or payment processing you do not do, signals that nobody read it — and reviewers do notice.

#The other common rejection reasons

Privacy policy is one item on a longer list. Applications are also declined for:

Insufficient content. A handful of thin pages is not enough. Reviewers want substantial, original material that demonstrates the site serves a real purpose.

Missing required pages. An About page identifying who runs the site, and a Contact page with a working method, are effectively mandatory.

Navigation problems. Broken links, pages under construction, or a structure a reviewer cannot follow.

Duplicated or scraped content. Anything substantially copied from elsewhere.

Missing terms and disclaimer on sites offering financial, legal, health or similar information. This matters more than people expect in high-CPC verticals.

#Getting the policy right

Generate it from your actual practices rather than copying one. The privacy policy generator includes all three advertising clauses automatically when you tick advertising, along with the analytics, cookie and rights sections, and it omits sections that do not apply to you.

Then:

  1. Publish it at a stable URL such as /privacy-policy/
  2. Link it in the footer of every page
  3. Reference it from your cookie banner
  4. Add a Cookie Policy with a detailed category breakdown
  5. Add About, Contact, Terms and Disclaimer pages

#After approval

The requirements are ongoing, not one-time. If you add an analytics tool, a new ad partner, an email list or an AI feature, update the policy. Google periodically re-reviews sites, and the consent requirements in particular have tightened over time.

Also monitor Ad Serving Limits in your AdSense account. Limits applied to EEA traffic frequently trace back to a consent implementation that is not passing signals correctly, rather than to policy content — which is a technical fix, not a wording one.

Privacy Policy GeneratorGenerate a complete, customised privacy policy for your website or app in minutes. Covers GDPR, CCPA/CPRA, analytics, advertising and cookie disclosures.
Open the tool

Frequently asked questions

Will AdSense reject my site without a privacy policy?

Almost certainly. A published privacy policy is a stated requirement of the AdSense programme policies, and its absence is one of the most common rejection reasons.

Do I need a Consent Management Platform for AdSense?

If you have visitors from the EEA, UK or Switzerland, yes. Google's EU user consent policy requires consent through a Google-certified CMP integrated with the IAB Transparency and Consent Framework for those regions.

Can I use a free privacy policy generator for AdSense?

Yes, provided the resulting policy accurately describes your site and includes the required advertising disclosures. The failure mode is generic templates that mention services you do not use or omit the third-party cookie clause.