How This Briefing Works
This report opens with key findings, then maps the gaps between what Google AdSense discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Pre-Consent Activity
Google AdSense was observed loading and executing before user consent was obtained on 6% of sites where it was detected.
Compliance Claim Mismatch
False certification claims
Claims vs. Observed Behavior
disclosure_gap
“Google-owned properties should only load Google services”
adsense.google.com loads non-Google third parties including Scrapemagic, Bytemine, Lavender, Scoreplex, Upcell
Third-party vendor detection on adsense.google.com
consent_gap
“GDPR and CCPA compliance with consent integration tools”
5.7% pre-consent rate observed across 264 detections
Runtime pre_consent=true on 5.7% of AdSense detections. Rate varies by publisher implementation.
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
If You Use Google AdSense
- →Verify your AdSense implementation uses Consent Mode v2 for EU/UK traffic — this eliminates most pre-consent compliance exposure
- →Implement Google Funding Choices or integrate AdSense with your CMP via Google's consent APIs
- →Review Google's Ad Technology Providers list to understand which third parties receive data through your AdSense deployment
- →Test your implementation with a runtime scan to verify 0% pre-consent rate on your property
- →Enable restricted data processing for California users under CCPA requirements
If You're Evaluating Google AdSense
- →AdSense is among the more compliant ad networks at 5.7% pre-consent versus industry averages exceeding 50%
- →Google explicitly does not sell personal information — a meaningful differentiator versus competitors like AdRoll or Criteo
- →Require implementation to use Consent Mode v2 from day one to avoid consent compliance gaps
- →Review Google's Data Processing Terms and Ad Technology Providers list before signing
- →Consider that Google's walled garden approach means less data leakage to external brokers but more dependency on Google's ecosystem
Negotiation Leverage
- →Consent Mode v2 implementation: Google provides Consent Mode v2 for EU/UK compliance. Require your implementation team to enable this before launch and verify 0% pre-consent rate with runtime testing.
- →Ad Technology Providers audit: Google operates an extensive network of ad technology providers that may receive data through AdSense. Request and review the complete Ad Technology Providers list to ensure compatibility with your privacy commitments.
- →Data retention terms: Review Google's Data Processing Terms for ad data retention periods and ensure alignment with your organization's data retention policies and GDPR Art 5(1)(e) requirements.
Runtime Detections
BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.
Evasion infrastructure, auditor bypass
Keystroke/mouse tracking
Full session replay
Identity stitching
Ignoring CMP signals
Device identification
Long-lived identifiers
PII deanonymization
Container/loader (neutral)
IOC Manifest
Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
22 detection signatures across scripts, domains, cookies, and network endpoints