---------------------------
Title: Google EU User Consent Policy Audit Checklist
URL: https://www.cookiebot.com/en/google-eu-user-consent-policy-audit-checklist/
---------------------------

# Google EU User Consent Policy Audit Checklist

## At A Glance

- Google audits cite one or more of eight specific issue categories, each with its own responsible team and fix.
- Assign an owner and start logging the audit right away. You don't need every issue fixed before you begin.
- Most repeat flags come from partial fixes, such as an updated banner with an unchanged Google Consent Mode default.
- Closing the loop with Google, and keeping your own evidence, protects you if the issue resurfaces.

A step-by-step guide to responding to a Google EU User Consent Policy audit, covering all eight issue categories, how to fix them, and how to close the loop with Google.

Google periodically runs a Google EU User Consent Policy audit on websites and apps that use its advertising services. A reviewer visits your site or app as a real user would and checks the consent notice and the consents it actually collects. If Google finds gaps, it contacts you directly and asks for fixes within a reasonable timeframe.

The process starts as a cooperative one. Silence causes the deadline pressure. If you don't respond or make a good-faith effort to fix the issues, Google can suspend ad personalization, remarketing, and conversion measurement for advertisers. Publishers can be restricted to Limited Ads only.

Work through the steps below to identify each issue, fix it, and close the loop with Google.

## Step 1: On Receipt Of The Audit Letter

Before you touch your consent banner, take five quick actions.

- Confirm the email is genuine and came from Google's policy or compliance channel. Check the sender domain and cross-reference it with notifications in your Google Ads or Ad Manager account.
- Identify exactly which of the eight issue categories the audit cites. Audits often flag more than one at a time.
- Note any stated deadline or review window.
- Assign an internal owner right away. Don't wait until every issue is fixed before you start working on the first one.
- Log the audit in your privacy compliance tracker: date received, issues cited, owner assigned, fix status, and re-audit request date.

## Step 2: Diagnose And Fix Your Google EU User Consent Policy Audit, By Issue Category

Google's audit findings map to eight categories. Each one has a specific fix and a team that's typically responsible for it.

### 1. Missing Consent Mechanism Or Banner

Google checks for a banner on all European Economic Area (EEA), UK, and Switzerland traffic, an affirmative action button, "ads personalization" named on the first layer, and a link to Google's Business Data Responsibility Site.

**Responsible:** Your content and consent management teams

**Fix:** Deploy a banner covering all EEA, UK, and Switzerland traffic, with a clear affirmative action button, "ads personalization" named on the first layer, and a link to Google's Business Data Responsibility Site.

### 2. Missing Or Incomplete Personal Data Use Disclosure

Google checks that your first layer explicitly names cookies or personal data use for personalized advertising.

**Responsible:** Your content and consent management teams

**Fix:** Update your first-layer banner copy to explicitly name cookies or personal data use for personalized advertising.

### 3. User Affirmative Action Not Set Up Correctly

Google looks for a clear "OK" or "I Agree" action, not implied consent.

**Responsible:** Your consent management platform administrator

**Fix:** Replace implied consent with a clear "OK" or "I Agree" button as the affirmative action.

### 4. Missing Or Incomplete Data Sharing Disclosure

Google checks that third parties, including Google itself, are named as recipients of user data, with a link to the Business Data Responsibility Site.

**Responsible:** Your legal or privacy team

**Fix:** Update your consent disclosure and privacy policy to explicitly list Google and other third parties as data recipients.

### 5. Missing Link To Google's Business Data Responsibility Site

Google wants a direct link, or one reachable from your banner through your privacy policy, to business.safety.google/privacy/.

**Responsible:** Your consent management platform administrator

**Fix:** Publish a working link to business.safety.google/privacy/ in your banner, or make it reachable in one click from your privacy policy.

### 6. Consent Signal Not Set Up Correctly

Google checks for validated consent signals that reflect real user choices, sent through the latest version of [Google Consent Mode](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/) or the Transparency and Consent Framework (TCF).

**Responsible:** Your web development or tag management team

**Fix:** Confirm consent signals reflect real user choices and are sent through the latest version of Google Consent Mode or TCF.

### 7. Cookies Set Before Consent

Google checks that no cookies fire before consent, and that ad_storage defaults to denied for EEA and UK users under Advanced Consent Mode.

**Responsible:** Your web development or tag management team

**Fix:** Configure ad_storage to default to denied for EEA and UK users under Advanced Consent Mode, so no cookies fire before consent.

### 8. Consent Management Platform Not Set Up Correctly

Google checks that you have a Google-certified consent management platform in place. If you use the Transparency and Consent Framework (TCF), which applies mainly to publishers, Google also checks for correct consent string generation and granular choices for IAB Purposes 1, 3, and 4.

**Responsible:** Your consent management platform administrator

**Fix:** Confirm you're using a Google-certified CMP. If you're a publisher using TCF, also confirm correct consent string generation and granular choices for IAB Purposes 1, 3, and 4.

## Step 3: Close The Loop With Google

Once your fix is live, don't just move on. Close the loop formally.

- Submit a re-audit request through the [EU User Consent Policy contact form](https://support.google.com/adspolicy/contact/euucp).
- If you're an app advertiser, email a screenshot of your live first-layer consent management platform, as it appears in your current Google Play Store build, to <euucp-escalations@google.com>.
- Record the re-audit request date and expected turnaround in your privacy compliance tracker.
- Keep a dated screenshot or archive of the fixed implementation as your own evidence, separate from Google's review.

## Step 4: If You're Flagged Again Or Escalation Occurs

Repeat flags almost always trace back to one thing.

- Re-check the specific implementation detail, not just whether the feature is present. Most repeat flags come from partial fixes, such as an updated banner with an unchanged Google Consent Mode default.
- Engage your consent management platform or tag management support if the issue involves Consent Mode signals or TCF strings.
- Escalate internally right away if account-level restrictions are imminent. This can affect ad personalization, remarketing, and conversion measurement all at once.

## Staying Ahead Of The Next Audit

A Google EU User Consent Policy audit checks whether your consent setup matches what a real visitor sees, and what Google's reviewers see when they check it. Work through the eight issue categories and assign clear owners. Close the loop with documented evidence, and you'll be well positioned to clear the audit and reduce the odds of a repeat flag.

A correctly configured consent management platform is designed to support your privacy compliance efforts across every one of these eight categories, from the first-layer banner language to the Google Consent Mode signals validated behind the scenes.

Legal disclaimer: Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.

## See Where Your Consent Setup Stands

Run a free scan to check your current banner, disclosures, and consent signals against what Google's auditors look for.

[RUN COMPLIANCE TEST](https://www.cookiebot.com/en/google-consent-audit-fixes/)

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/en/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/en/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)
- [View all regulations](https://www.cookiebot.com/en/regulations-and-frameworks/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Customer stories](https://www.cookiebot.com/en/customer-stories/)
- [Customer directory](https://www.cookiebot.com/en/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)