Google Customer Match in Poland: Why Newsletter and Cookie Consent Are Not Enough
Your marketing team has uploaded 50,000 customer email addresses to Google Customer Match. Every customer accepted the privacy policy and subscribed to the newsletter. Can you use the list to run ads?
No-not on that basis. Privacy-policy acceptance, newsletter consent, and a click on a cookie banner each address something different from sharing customer data with Google for ad targeting.
Google Customer Match lets advertisers upload customer contact details to Google Ads to reach matched users through search, display, and YouTube ads. For e-commerce and SaaS businesses operating in Poland, the issue is both legal and operational: the General Data Protection Regulation (GDPR) requires a valid basis for the data-sharing operation, Polish marketing-communications rules may impose separate consent requirements, and Google requires specific consent signals for users in the European Economic Area (EEA).
Since March 2024, Google has required EEA advertisers to provide two signals: ad_user_data, concerning the use of data shared with Google for advertising, and ad_personalization, concerning personalized ads. The approved position discussed here is that Customer Match requires separate, documented consent covering both purposes. Without the required signals, EEA customer data is not processed for the campaign.
The terms that matter
| Term | Meaning in this article |
|---|---|
| Customer Match | A Google Ads feature that uses uploaded customer contact details, including email addresses, to match customers and target ads across Google services. |
ad_user_data |
Google’s consent signal for sharing user data with Google for advertising purposes. |
ad_personalization |
Google’s consent signal for personalized advertising. |
| Consent Mode v2 | Google’s mechanism for communicating consent status to website tags. It operates through website activity and browser-level signals, not automatically through a customer’s account record. |
| Pseudonymization | Processing that makes identification harder, such as SHA-256 hashing. It does not remove Customer Match data from the GDPR’s scope when the data is used to match an individual. |
| CMP | A consent management platform, such as Cookiebot or OneTrust, commonly used to collect cookie choices and pass signals to website tags. |
| PKE | Poland’s Electronic Communications Law (Prawo komunikacji elektronicznej), which regulates, among other matters, consent to marketing communications. |
| UODO | Poland’s data protection supervisory authority. |
Three consents that do not, by themselves, cover Customer Match
1. Accepting a privacy policy is not consent to ad targeting
Article 13 of the GDPR requires a controller to tell people who processes their data, for what purposes, on what legal basis, and with whom the data is shared. A privacy policy serves that information function. A customer’s acknowledgment that they have read it is not, by itself, consent to a particular processing operation.
Recital 42 of the GDPR adds that, where consent appears within a broader declaration-for example, alongside acceptance of terms-the person must be aware that they are consenting and understand its scope.
A customer who accepts an online store’s privacy policy during registration has not thereby agreed that the store may send their email address to Google to show them ads. Customer Match introduces a different purpose and a different data recipient.
Check the published policy as well as the consent flow. If it says that sharing data with advertising partners rests on legitimate interests, while the business has moved to a consent-based approach but has not published the revised policy, that inconsistency is an obvious issue for a supervisory authority reviewing the operation.
2. Newsletter consent concerns a different communication
Under Article 398 of the PKE, newsletter consent concerns sending marketing communications to the person’s address. A store emailing its own offer to a subscriber is not the same operation as supplying that subscriber’s address to Google for matching and advertising across Google services.
Recital 39 of the GDPR requires processing purposes to be explicit and specified when data is collected. Agreement to receive emails from a store does not also express agreement to third-party ad targeting.
| Question | Newsletter | Customer Match |
|---|---|---|
| What happens? | The business sends marketing communications to the subscriber. | The business shares contact data with Google for matching and ad targeting. |
| Who receives the relevant communication or data? | The subscriber receives the email directly. | Google receives the contact data. |
| Relevant requirements identified in the source | Article 398 PKE and the GDPR. | Consent under Article 6(1)(a) GDPR and Google’s EU User Consent Policy. |
| Channel | Email from the business. | Google search, display, or YouTube ads. |
3. Cookie-banner consent may not be linked to the customer record
A choice collected through a cookie banner and CMP is generally stored for a browser. A Customer Match list, however, is assembled from customer records-for example, accounts in a CRM.
Suppose a customer accepts cookies on a laptop, then signs in to the store on a phone. The laptop browser holds the cookie choice, but the email address selected for Customer Match comes from the account database. Unless your systems connect the relevant consent status to that account, the browser choice does not tell you whether that email address may be uploaded.
The practical requirement is a reliable, documented way to associate consent with the customer record used to build the list-not merely with a browser session.
Hashing the addresses does not take the upload outside the GDPR
“We hash email addresses with SHA-256 before uploading them” is not an answer to the legal-basis question.
Hashing in this setting is pseudonymization, not anonymization. Customer Match is designed to let Google match a hashed address to an individual account and show that person an ad. Google has the information needed to perform that match. The data therefore remains personal data in the context of this operation, and the GDPR continues to apply.
Hashing can reduce technical risk. It does not replace a valid legal basis or turn an otherwise impermissible list into an anonymized one.
Consent Mode v2 does not supply Customer Match consent automatically
These Google mechanisms address different data flows.
Consent Mode v2 communicates consent information to Google tags in connection with activity on a website, such as clicks, conversions, and remarketing events. Customer Match uses contact details drawn from the advertiser’s database and submitted to Google Ads, including through the Google Ads API. When creating a customer list, the advertiser sets the relevant ConsentStatus fields-ad_user_data and ad_personalization. Those fields are not automatically populated from Consent Mode.
| Consent Mode v2 | Customer Match ConsentStatus | |
|---|---|---|
| Data source | Website activity collected through tags or SDKs. | Contact details from the advertiser’s CRM or other customer database. |
| Where consent is typically recorded | Through a CMP at browser level. | Against the customer record or user account used for the list. |
| How the signal reaches Google | Website tags read the consent state. | The advertiser sets ConsentStatus when submitting the customer data. |
| Consequence described for missing consent | Tags may send cookieless pings. | Customer data is rejected or not processed. |
Implementing Consent Mode v2 is therefore not a substitute for collecting and documenting Customer Match consent. The controller must make the systems consistent.
The approved source also identifies a specific API consequence: if either ConsentStatus field is set to DENIED in a create request, the Google Ads API returns OfflineUserDataJobError.CUSTOMER_NOT_ACCEPTED_CUSTOMER_DATA_TERMS. It states that Google does not process EEA user data without both required consents.
What the business risks
GDPR and Polish-law exposure
- An administrative fine. Processing without a valid legal basis can fall within the GDPR’s highest fine tier: up to EUR 20 million or 4% of annual worldwide turnover under Article 83. The source treats an upload to Customer Match without the required separate consent as sharing data with a third party without a legal basis.
- A complaint to UODO. A customer who discovers that their email address was sent to Google for ad targeting can complain to Poland’s supervisory authority. The published privacy policy and the business’s actual processing are likely to be compared.
- A transparency problem. If the policy names legitimate interests while the operation requires and purportedly relies on consent, the mismatch raises an issue under the transparency principle in Article 5(1)(a) GDPR.
Google Ads exposure
- An ineffective audience. Uploading 50,000 addresses does not mean Google will use all 50,000. If the required EEA consent signals are missing, the intended audience may be substantially reduced or the data rejected.
- Loss of Customer Match access. Google can seek information about compliance with its policies. A failure to respond within the specified period, or a policy violation, may result in access being revoked.
- Account suspension. Serious or repeated violations may lead Google to suspend a Google Ads account without advance warning, putting an advertising channel at risk.
The wider enforcement context-and its limit
The approved source notes that no European supervisory authority had issued a decision specifically about Customer Match. It points instead to decisions concerning behavioral advertising by Meta Platforms Ireland Limited.
In binding decisions dated December 5, 2022, the European Data Protection Board (EDPB) found that contractual necessity under Article 6(1)(b) GDPR was not an appropriate legal basis for that behavioral advertising. The Irish supervisory authority imposed fines of EUR 210 million concerning Facebook and EUR 180 million concerning Instagram. An urgent binding EDPB decision dated October 27, 2023, called for a ban on Meta’s processing for behavioral advertising throughout the EEA.
Those matters are not Customer Match rulings. The practical conclusion drawn in the approved source is that extensive marketing profiling based on user data calls for consent, while reliance on another basis carries substantial challenge risk.
Can legitimate interests replace consent?
Recital 47 of the GDPR says that processing personal data for direct marketing may be regarded as carried out for a legitimate interest. That does not settle the legal basis for every stage of a Customer Match campaign.
The approved source allows that legitimate interests under Article 6(1)(f) GDPR could, in theory, support some preparatory steps-such as creating a customer segment within a CRM. It recommends consent for Customer Match itself, pointing to these constraints:
- Polish telecommunications consent: the source cites Article 172 of Poland’s Telecommunications Law as requiring prior consent for using terminal equipment for direct marketing. A GDPR legitimate-interest assessment does not remove that separate requirement.
- Unsolicited commercial communications: the source also cites Poland’s Act on the Provision of Electronic Services as prohibiting unsolicited commercial information without consent.
- Intrusive targeting: EDPB Guidelines 8/2020 on targeting social media users indicate that consent may be more appropriate than legitimate interests where targeting significantly interferes with privacy.
- Market practice: the source notes that Tchibo’s privacy policy bases Customer Match on consent under Article 6 GDPR rather than legitimate interests.
For a business dealing with Poland, the recommendation is to use consent as the Customer Match legal basis rather than assume that a legitimate-interest assessment also satisfies Polish marketing rules or Google’s requirements.
A practical remediation plan
Do before another upload
-
Pause Customer Match email-list uploads until you have a way to collect and document valid GDPR consent covering
ad_user_dataandad_personalization. -
Make the published privacy policy match the operation. The recommended approach identifies consent under Article 6(1)(a) GDPR as the basis for sharing data with advertising partners, including Google. Do not leave a policy describing legitimate interests in place while operating a consent-based process.
-
Audit the email database. Separate records with documented consent covering advertising-partner data sharing from records with only newsletter consent. Identify guest customers without accounts as well; an account-based solution will not automatically resolve their status.
-
Link consent status to the record used for Customer Match. The preferred solution is a separate advertising-partner consent collected at registration and available in account settings. As an interim approach, CMP signals could be mapped to a signed-in customer’s account, but that requires back-end integration. A browser-only record is not enough to determine which CRM addresses belong on the list.
Put ongoing controls in place
-
Review the Google Ads terms your business accepted. Establish whether Data Processing Terms or terms for independent controllers apply, and record who accepted them and when.
-
Remove people from Customer Match lists after withdrawal or objection. Set a list-refresh frequency and an automatic removal process. Recital 70 GDPR addresses the right to object to direct marketing and requires that right to be brought clearly and separately to the individual’s attention.
-
Train the performance marketing team. Privacy-policy acknowledgment, GDPR consent, newsletter consent, cookie choices, and Customer Match consent should not be treated as interchangeable.
-
Record Customer Match as a processing activity. Under Article 30 GDPR, document the operation in the record of processing activities, including its legal basis, categories of data, recipient-Google-and retention period.
-
Include exclusion lists in the review. Uploading addresses to exclude people from a campaign still involves sharing those addresses with Google. The source applies the same consent requirements to those lists.
If you are preparing an upload and cannot establish which records meet these conditions, contact us before sending the list.
Do the same checks for other matched-audience tools
Meta Custom Audiences and LinkedIn Matched Audiences also use advertiser-supplied data for matching and targeting. The approved source treats them as subject to analogous consent concerns, although Google’s named ConsentStatus fields are specific to Google.
| Google Customer Match | Meta Custom Audiences | LinkedIn Matched Audiences | |
|---|---|---|---|
| Consent described in the source | ad_user_data and ad_personalization, both GRANTED. |
Consent to share data with Meta for advertising. | Consent to share data with LinkedIn for targeting. |
| Timing identified in the source | EEA requirements from March 2024. | Requirement described as in force. | Requirement described as in force. |
| Stated consequence of missing consent | Data is not processed; an API error may be returned. | Reduced reach and suspension risk. | Reduced reach. |
| GDPR approach recommended in the source | Separate consent under Article 6(1)(a). | Separate consent under Article 6(1)(a). | Separate consent under Article 6(1)(a). |
| Polish PKE consideration identified in the source | Separate marketing-communications consent. | The source identifies a PKE consent requirement. | The source identifies a PKE consent requirement. |
The approved source also cites the Court of Justice of the European Union judgment of December 2, 2025, in **Case C-492/23, *Russmedia Digital***. It describes that ruling as confirming an online platform operator’s responsibility for personal data in advertisements and a duty to verify whether the advertiser has explicit consent. The source presents it as part of a wider direction in platform-advertising case law, not as a Customer Match-specific decision.
How we can help
For a company operating in Poland, a matched-audience upload sits at the intersection of the GDPR, Polish electronic-communications requirements, and platform terms. We help e-commerce and SaaS teams:
- Audit customer records and consents to distinguish valid Customer Match permissions from newsletter-only records or records without an identified basis.
- Review the privacy policy against the data flows actually used and prepare an updated version where needed.
- Design a documented consent process that is separate from other choices and connected to the customer record.
- Update GDPR documentation, including the record of processing activities, a data protection impact assessment if required, and relevant data processing arrangements.
- Train marketing teams to filter lists correctly before upload.
Start with the consent records and the published policy before building-or refreshing-the next audience. Contact us to review the process.
Frequently asked questions
Can we upload customers who accepted our privacy policy?
Not on that basis alone. A privacy policy provides information required under Article 13 GDPR; acknowledging it is not consent to send an email address to Google for advertising. The source calls for separate, documented consent covering data sharing and ad personalization, linked to the customer record used for the list.
Does newsletter consent cover Customer Match?
No. Article 398 PKE newsletter consent concerns marketing communications sent to the subscriber. Customer Match sends contact data to Google for matching and advertising through Google services-a different operation, purpose, and data recipient.
What if we hash the email addresses first?
SHA-256 hashing does not anonymize them for Customer Match. Google is meant to match the hashed value to an individual account, so the GDPR and its legal-basis requirement still apply.
Does implementing Consent Mode v2 solve this?
No. Consent Mode v2 communicates choices to website tags. The advertiser must separately establish the consent status for contact details submitted through Customer Match and set the relevant ConsentStatus fields. The two systems do not synchronize automatically.
Does an exclusion list need the same review?
Yes. An exclusion list still sends customer data to Google. The approved source applies the same consent requirements even though the intended outcome is to avoid showing those people an ad.
Could we rely on legitimate interests instead?
Possibly for certain preparatory processing, such as segmenting customers in a CRM, but the source recommends consent for Customer Match. It identifies challenge risk under the GDPR, separate Polish marketing-consent requirements, and Google’s consent-signal requirements.