Your marketing department has just uploaded 50,000 email addresses to Google Customer Match. All users accepted the privacy policy. They all subscribed to the newsletter. Is everything legal?
No – and on three levels at once.
Google Customer Match is an advertising tool that lets you upload a database of customer email addresses to Google Ads and target them with display, search, or YouTube ads. It sounds simple. The problem is that most e-commerce and SaaS companies base this operation on consents that do not cover it – acceptance of the privacy policy, a newsletter subscription, or clicking “I agree" on a cookie banner.
Since March 2024, Google has required advertisers in the European Economic Area to provide two separate consent signals: ad_user_data (sharing data with Google for advertising purposes) and ad_personalization (ad personalization). Without them, the data is not processed – campaigns simply do not work, and the budget is wasted.
But even if Google did not impose these requirements, the GDPR requires separate, documented consent to share email addresses with a third party for ad targeting purposes. Accepting a privacy policy does not meet this requirement. Neither does consent to receive a newsletter.
In this article, I explain why the three most common forms of “consent" are not enough, what risks are associated with uploading lists without a valid legal basis, and what you can do to put this area in order.
Key concepts before we go any further
Before moving on to the risk analysis, it is worth clarifying several terms that appear repeatedly throughout this article.
| Concept | What it means |
|---|---|
| Customer Match | A Google Ads feature that allows you to upload a list of customer email addresses and target them with ads across Google services |
| ad_user_data | A consent signal required by Google – it confirms that the user has consented to their data being shared with Google for advertising purposes |
| ad_personalization | A consent signal required by Google – it confirms that the user has consented to ad personalization |
| Consent Mode v2 | A Google mechanism that tells tags on a website whether they may process user data – it operates at browser level, not account level |
| Pseudonymization | Converting data into a form that makes identification more difficult (e.g. SHA-256 hashing), but the GDPR still applies because the purpose is to match the data to a specific person |
| CMP | Consent management platform (e.g. Cookiebot, OneTrust) – collects cookie consents and sends signals to tags on the website |
| PKE | Electronic Communications Law – the Polish act regulating, among other things, consent to marketing communications |
Three consent traps that affect most e-commerce companies
Trap No. 1: a privacy policy is not consent
Accepting a privacy policy is a way of fulfilling the information obligation under Article 13 of the GDPR. The controller must inform the user who processes the data, for what purposes, on what legal basis, and with whom it is shared. A privacy policy is an informational document – accepting it means that the user has read its contents. It does not mean that they have consented to a specific processing operation.
Recital 42 of the GDPR clarifies that if consent forms part of a broader declaration (e.g. acceptance of terms and conditions), safeguards must be in place to ensure that the person is aware that they are giving consent and understands its scope.
In Customer Match terms, a user who clicked “I accept the privacy policy" when registering with an online store did not consent to the store sharing their email address with Google so that display ads could be shown to them. This is an entirely different operation, involving a different recipient and a different purpose.
An additional problem: if your privacy policy identifies legitimate interests as the basis for sharing data with advertising partners, while a new version based on consent is still awaiting publication, the supervisory authority will see this inconsistency as the first red flag during an inspection.
Trap No. 2: newsletter consent does not cover Customer Match
Consent to receive a newsletter (Article 398 of the PKE) concerns sending marketing communications to the user’s address. Purpose: the store sends an email containing an offer. Recipient of the communication: the user.
Customer Match is an entirely different operation. Purpose: the store shares an email address with Google so that Google can match it to the user’s account and show them ads across its services. Data recipient: Google.
Recital 39 of the GDPR requires processing purposes to be explicit and specified at the time the data is collected. A user who agreed to receive emails from the store did not agree to the store sharing their address with a third party for ad targeting purposes.
| Parameter | Newsletter consent | Customer Match consent |
|---|---|---|
| Purpose | Sending marketing communications | Sharing data with Google for ad targeting |
| Data recipient | User (direct contact) | Google (third party) |
| Legal basis | Article 398 of the PKE + GDPR | Article 6(1)(a) of the GDPR + EU User Consent Policy |
| Channel | Email from the store | Google ads (display, YouTube, search) |
Trap No. 3: consent from a cookie banner is not linked to the user’s account
Consent given through a cookie banner (via a CMP) is stored per browser. A Customer Match email list is built from a database of user accounts – per user.
Example: a user gives consent through a cookie banner on their laptop. They then log in to the store from their phone. The consent is stored in the laptop browser, while the Customer Match list is built from the account database – there is no connection between the two.
Without a mechanism linking consent status to the user’s account rather than their browser, there is no way to determine which addresses may be used in Customer Match.
Contact us – we will help you identify gaps in your consents and put the process in order before you upload a list.
Hashing email addresses does not exempt you from the GDPR
A common argument is: “we hash addresses using SHA-256 before uploading them to Google, so they are no longer personal data".
That is not true. Hashing is pseudonymization, not anonymization. The entire purpose of Customer Match is for Google to match the hashed address to a specific user’s account and show that person a personalized ad. Since the purpose is to identify an individual, the GDPR applies in full.
Pseudonymization is a technical measure that reduces risk, but it does not change the status of the data. In the context of Customer Match, a hashed email address still makes it possible to identify an individual – through Google, which has the data needed to reverse the matching process.
The false sense of security created by hashing leads companies to overlook the consent requirement, assuming that the “data has been anonymized". The supervisory authority will take a different view.
Consent Mode v2 and Customer Match – why they are two separate layers
Since March 2024, Google has required advertisers in the EEA to implement Consent Mode v2 – a mechanism that tells Google tags on a website whether they may process user data. Consent Mode v2 operates at the level of events generated by activity on the website – clicks, conversions, and remarketing events.
Customer Match operates on an entirely different layer. It is based on contact details (email addresses, phone numbers) submitted by the advertiser through the Google Ads API. The ConsentStatus fields (ad_user_data and ad_personalization) are set by the advertiser when creating a customer list – they are not automatically retrieved from Consent Mode.
| Layer | Consent Mode v2 | Customer Match ConsentStatus |
|---|---|---|
| Data source | User activity on the website (tags, SDKs) | Contact details from the advertiser’s CRM database |
| Consent mechanism | CMP (cookie banner) – per browser | Separate GDPR consent – per user account |
| Transmission of signals | Automatic (Google tags read the consent status) | Manual (the advertiser sets ConsentStatus in the API) |
| Consequence of no consent | Tags send anonymous “cookieless pings" | The Google Ads API returns an error and rejects the data |
Implementing Consent Mode v2 on your website does not replace the need to document separate consents for Customer Match. These are two independent systems. The controller must ensure consistency between them – it is not automatic.
If a value of DENIED is specified for either ConsentStatus field in a create request to the Google Ads API, the interface returns the following error: OfflineUserDataJobError.CUSTOMER_NOT_ACCEPTED_CUSTOMER_DATA_TERMS. Data relating to EEA users without both consents is not processed by Google.
Legal and operational risks – what the company may face
Risks under the GDPR and Polish law
-
Administrative fine from the UODO – up to EUR 20 million or 4% of annual global turnover for processing data without a valid legal basis (Article 83 of the GDPR). Uploading an email list to Customer Match without separate consent constitutes sharing data with a third party without a legal basis.
-
User complaint to the UODO – a user who learns that their email address has been shared with Google for ad targeting purposes may file a complaint. During an inspection, the authority will first check whether the published privacy policy is consistent with the actual data processing operation.
-
Discrepancy between the privacy policy and actual processing – if the policy identifies legitimate interests as the legal basis while the operation requires consent, the authority will view this as a breach of the principle of transparency (Article 5(1)(a) of the GDPR).
Risks on Google’s side
-
EEA data without consent signals is not processed – campaigns do not work and the budget is used inefficiently. You upload 50,000 addresses, but Google rejects data relating to users without
GRANTEDfor both ConsentStatus fields. The campaign reaches only a fraction of the intended audience. -
Revocation of access to Customer Match – Google may check at any time whether the company is complying with its policies and request information. Failure to respond within the specified deadline or the discovery of violations will result in access being revoked.
-
Suspension of the Google Ads account – in the event of serious or repeated violations, Google may immediately suspend the account without prior warning. This means losing an advertising channel.
Case law context
No European supervisory authority has yet issued a decision specifically concerning Customer Match. However, existing case law indicates the direction of travel. The binding decisions of the European Data Protection Board (EDPB) of 5 December 2022 in the cases concerning Meta Platforms Ireland Limited found that contractual necessity (Article 6(1)(b) of the GDPR) does not constitute an appropriate legal basis for behavioral advertising. The Irish supervisory authority imposed fines of EUR 210 million for Facebook and EUR 180 million for Instagram. The EDPB’s urgent binding decision of 27 October 2023 ordered a ban on Meta’s processing of data for behavioral advertising purposes throughout the EEA.
The conclusion: extensive marketing profiling based on user data requires consent. Attempting to rely on another legal basis carries a high level of risk.
Is legitimate interest sufficient instead of consent?
Recital 47 of the GDPR explicitly states that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. Does this mean that Customer Match can be based on Article 6(1)(f) of the GDPR instead of consent?
In theory – partly yes. Legitimate interests could provide a legal basis for certain stages of the process (e.g. creating a customer segment in the CRM). However, this approach encounters limitations under Polish law:
-
Article 172 of the Telecommunications Law prohibits the use of terminal equipment for direct marketing purposes without prior consent. Legitimate interests under the GDPR do not remove this requirement.
-
The Act on the Provision of Electronic Services prohibits sending unsolicited commercial communications without consent.
-
EDPB Guidelines 8/2020 on the targeting of social media users indicate that consent may be more appropriate than legitimate interests for forms of targeting that significantly intrude on privacy.
-
Market practice confirms this direction – for example, Tchibo bases Customer Match on consent under Article 6 of the GDPR in its privacy policy, rather than on legitimate interests.
Recommendation: use consent as the legal basis for Customer Match. Relying on legitimate interests carries the risk of being challenged by the supervisory authority and does not eliminate the telecommunications consent requirement.
What to do – a specific remediation path
Immediate action (priority: you must do this)
-
Stop uploading email lists to Customer Match until you have implemented a mechanism for collecting and documenting valid GDPR consent with the
ad_user_dataandad_personalizationsignals. -
Publish an updated privacy policy that identifies consent (Article 6(1)(a) of the GDPR) as the legal basis for sharing data with advertising partners, including Google. As long as the document refers to legitimate interests while the operation relies on consent, there is an inconsistency that the authority will see as the first sign of a problem.
-
Conduct an audit of your email database. Check which addresses have valid GDPR consent covering the sharing of data with advertising partners, which only have newsletter consent (which is insufficient), and which belong to guests (without an account).
-
Build a mechanism linking consent status to the user’s account – not to their browser. Two options:
- Target solution: separate consent to share data with advertising partners, collected during registration and accessible in the account settings.
- Interim solution: mapping CMP signals to the logged-in user’s account (requires back-end integration).
Additional action (priority: you should do this)
-
Review the Google Ads terms accepted by the company – whether the Data Processing Terms or the terms for independent controllers apply, and who accepted them and when.
-
Implement a process for automatically removing users from the Customer Match list after they withdraw consent or object to processing. Recital 70 of the GDPR guarantees an absolute right to object to direct marketing – it must be presented clearly and separately from any other information. Define how often the list will be refreshed.
-
Train the performance marketing team on the differences between accepting a privacy policy, GDPR consent, newsletter consent, and Customer Match consent. Without this training, the same false assumption will continue to be repeated.
-
Document the Customer Match operation in the record of processing activities (Article 30 of the GDPR) as a separate activity, specifying its legal basis, data categories, recipient (Google), and retention period.
-
Remember exclusion lists. Uploading an exclusion list to Customer Match also involves sharing data with Google – it is subject to the same consent requirements.
Comparison of requirements across advertising platforms
Customer Match is not the only tool of this kind. Meta Custom Audiences and LinkedIn Matched Audiences work in a similar way – and are subject to analogous requirements.
| Criterion | Google Customer Match | Meta Custom Audiences | LinkedIn Matched Audiences |
|---|---|---|---|
| Required consent signals | ad_user_data + ad_personalization (both GRANTED) |
Consent to share data with Meta for advertising purposes | Consent to share data with LinkedIn for targeting purposes |
| Requirement effective since | March 2024 (EEA) | In force (EU User Consent Policy) | In force |
| Consequence of no consent | Data is not processed and the API returns an error | Limited reach, risk of suspension | Limited reach |
| GDPR requirement | Separate consent under Article 6(1)(a) | Separate consent under Article 6(1)(a) | Separate consent under Article 6(1)(a) |
| PKE requirement (Polish law) | Yes – separate consent to marketing communications | Yes | Yes |
The CJEU judgment of 2 December 2025 in Case C-492/23 (Russmedia Digital) confirmed that the operator of an online platform is responsible for personal data contained in advertisements and must verify whether the advertiser has obtained explicit consent. This direction in case law applies to all advertising platforms, not just Google.
How we can help you put this area in order
Uploading email lists to advertising platforms is an operation that combines three legal regimes: the GDPR, electronic communications law, and the platform’s terms. An error in one creates risks under the others.
We help e-commerce and SaaS companies put this process in order:
-
Audit of the email database and consents – we check which addresses have valid GDPR consent, which only have newsletter consent, and which have no legal basis for Customer Match.
-
Privacy policy review – we verify that the published document is consistent with the actual data processing operations. We identify discrepancies and prepare an updated version.
-
Designing a consent collection mechanism – we help build a process in which consent to share data with advertising partners is collected separately, linked to the user’s account, and documented.
-
GDPR documentation – we add the Customer Match operation to the record of processing activities, prepare a data protection impact assessment (if required), and put data processing agreements in order.
-
Training for the marketing team – we explain the differences between the various types of consent and show how to filter the database before uploading a list.
We work with marketing teams, e-commerce managers, and legal departments at companies that want to use Customer Match without risking a UODO fine or losing their Google Ads account.
Put your consents in order before uploading another list
Accepting a privacy policy, consenting to a newsletter, and clicking a cookie banner – none of these actions provides a legal basis for uploading an email address to Google Customer Match. Separate, informed consent is required, covering both the sharing of data with Google for advertising purposes and ad personalization.
Since March 2024, Google has enforced this technically – data without the ad_user_data and ad_personalization signals is not processed. But even if Google did not require this, the GDPR and Polish electronic communications law impose the same obligations.
If your company uses Customer Match or plans to implement it, start with an audit of your consents and privacy policy. Contact us – we will help you put the process in order and implement a mechanism that allows you to run campaigns without legal risk.
Frequently asked questions
Can I upload my customer email database to Google Customer Match if the customers have accepted the privacy policy?
No. Accepting a privacy policy is a way of fulfilling the information obligation under Article 13 of the GDPR – the user confirms that they have read the information about data processing. It is not a declaration of intent expressing consent to a specific operation. Customer Match requires separate consent to share data with Google for advertising purposes (ad_user_data) and to personalize ads (ad_personalization). Without these two consents – documented and linked to the user’s account – there is no legal basis for uploading the email address to Customer Match.
How does newsletter consent differ from the consent required for Customer Match?
Consent to receive a newsletter (Article 398 of the PKE) concerns sending marketing communications to the user’s address – the store sends an email containing an offer directly to the recipient. Customer Match consent covers an entirely different operation: sharing the email address with a third party (Google) so that it can match the address to the user’s account and show them ads across its services. A different purpose and a different data recipient require a separate legal basis.
Does hashing email addresses before uploading them to Google mean that the GDPR does not apply?
No. SHA-256 hashing is pseudonymization, not anonymization. The entire purpose of Customer Match is for Google to match the hashed address to a specific user’s account and show that person a personalized ad. Since the purpose is to identify an individual, the GDPR applies in full, including the requirement to have a valid legal basis.
Does implementing Consent Mode v2 on the website satisfy the consent requirements for Customer Match?
No. Consent Mode v2 and the ConsentStatus fields for Customer Match operate on two separate layers. Consent Mode v2 operates at the level of tags on the website and tells them whether they may process data (per browser). Customer Match relies on contact details sent from the CRM to the Google Ads API – the advertiser must set the ConsentStatus fields when creating the list (per user account). Implementing Consent Mode v2 does not replace the need to collect and document separate consents for Customer Match.
Does an exclusion list in Customer Match also require user consent?
Yes. Uploading an exclusion list to Customer Match also involves sharing personal data with Google – it is subject to the same consent requirements as a targeting list. The fact that the purpose is to exclude the user from a campaign rather than target them with ads does not change the fact that data is being shared with a third party.
What GDPR legal basis can I use for Customer Match – is the controller’s legitimate interest sufficient?
Legitimate interests (Article 6(1)(f) of the GDPR) could theoretically provide a legal basis for certain stages of the process, but this approach encounters limitations under Polish law. Article 172 of the Telecommunications Law requires separate consent for direct marketing involving the use of terminal equipment – legitimate interests under the GDPR do not remove this requirement. EDPB Guidelines 8/2020 indicate that consent is more appropriate for forms of targeting that significantly intrude on privacy. Recommendation: use consent as the legal basis for Customer Match.