
Thank you!
Please check your email to view the guide.

After Google’s privacy control change on June 15th, users should expect more personalized ads when they opt out.
On June 15, 2026, Google removed the Google Analytics setting that limits cross-device remarketing, leaving Google Consent Mode as the only privacy control for Google Ads.
Without this backstop, any website with a Google Consent Mode misconfiguration will now be further out of compliance with CCPA, GDPR, and other privacy laws because the full signal will be sent to Google Ads for cross-device remarketing
To understand how many companies are now more at risk of enforcement, Privado AI scanned the top 250 websites by traffic across the US and Europe and published a new report, The State of Google Consent Mode, to share what the team found.
The Privado AI research finds that 48% of the websites it tested have a misconfigured Google Consent Mode, sending personal data to Google Ads, even when visitors opt out.
This means a lot more cross-device remarketing against users’ consent.
Consent management platforms (CMPs) record a visitor’s choice, but they were not built to verify if it is enforced across the tags and third parties that fire on a page. As marketing teams change third-party data flows week to week, new gaps open that the banner cannot catch.
In 2024, Privado AI launched Web Auditor in 2024 to help privacy teams flag any compliance gaps and continuously verify consent is properly honored in each jurisdiction. In 2025, a new website privacy auditing category was created as CMP companies attempted to fill this gap by launching similar products.
With most websites out of compliance and many privacy teams unaware, the data shows that CMP companies cannot be trusted to identify issues with their own CMP. Privado AI, on the other hand, offers the most robust auditing solution — with no conflict of interest from also selling a CMP.
By using Web Auditor continuously verify Google Consent Mode and all other personal data flows, Privado AI customers like Chipotle and Forbes can ensure visitors do not see personalized ads against their consent.
Daniel Goldberg, Chair of Data Strategy & Privacy at Frankfurt Kurnit Klein + Selz, said, “GDPR, CCPA, and CIPA (California Invasion of Privacy Act) operate differently, yet many companies implement cookie-based approaches designed for GDPR. As a result, they miss key state law requirements, helping explain why California implementation lags. This increases regulatory and litigation risk, including exposure to dark patterns and misleading claims.”
The findings arrive as enforcement accelerates. Fines and lawsuits tied to website data sharing are rising under the CCPA, CIPA, the Video Privacy Protection Act (VPPA), and the EU’s General Data Protection Regulation (GDPR). Regulators in the UK and EU have announced enforcement sweeps. Under the CCPA, penalties are assessed per violation and rise when violations are intentional or involve minors, so a single misconfiguration repeated across millions of sessions can carry material exposure.
Vaibhav Antil, Co-Founder and CEO of Privado AI, said, “Collecting consent and enforcing it are two different things. The banner records the choice, and the data reaches Google Ads anyway. What our research shows is that surface-level compliance and manual checks are no longer enough. The controls change overnight and the websites change every week, so a setup that passed last month can be failing today, and no one would see it. Privacy is fast becoming critical infrastructure within businesses, too important and too complex to fail, and as such requires intelligent real-time monitoring.”
Download The State of Google Consent Mode now