Why did Google disapprove my ad for data collection?
Direct answerGoogle disapproves the ad when the destination collects card, bank, or government ID numbers on a page that is not HTTPS, or when a remarketing tag receives someone’s email address or similar identifier in the URL. Customer Match, Enhanced Conversions, and Store sales are named exceptions. An ad that says “Hello John Smith” or “You’re buried in debt” is a separate misuse. A warning comes at least 7 days before suspension.
Which of the five rules fired
Google’s Data collection and use policy, reviewed on September 27, 2026, is five bans. Personalized-advertising limits, such as which products can use remarketing, are a different page.
| Section | What fails |
|---|---|
| Inadequate security | Card, bank, wire, national ID, tax, pension, health, license, or Social Security numbers on a page that is not SSL, with no valid certificate |
| Unacceptable sharing | Personally identifiable information sent to Google in a remarketing tag, a conversion tag, or a product feed. An email address in the URL is the example |
| Misuse | Reselling contacts, using someone’s image without consent, addressing them by name or job, or implying you know their finances or politics |
| European consent | Remarketing or conversion tracking for EEA or UK users without the consent the policy describes |
| Cookies on Google domains | Anyone other than Google setting a cookie on doubleclick.net or googlesyndication.com |
The URL is the usual leak
Google says the sharing ban does not apply to Enhanced Conversions, Customer Match, or Store sales, including direct upload, when those products are under the Google Ads Data Processing Terms. Everywhere else, an email in a tagged URL is the published example. Google’s own fix is to submit forms with POST so the fields do not become the query string, and to replace an email in a profile or campaign URL with an identifier that is not the address. The page’s illustration is /my_settings/sample@email.com changed to a numeric ID.
Use the URL list in Google’s notice, then the response form on that policy. Google says it checks again and writes back within two weeks. Remarketing lists that still include the data are disabled. You can test on a site tagged with the same customer ID before you ship the change. For the HTTPS failure, either collect those numbers on a page whose URL starts with https:// and has a valid certificate, or stop asking. Then edit the ad. Google says most of those reviews finish within one business day.
The ad cannot pretend it knows the person
Google’s misuse examples are reselling contact details, using a person’s image without consent, “Hello John Smith — buy flowers here,” and “You’re buried in debt. Get help today.” A loan product still has to meet credit and loan rules. On Meta, “are you in debt?” can also fail personal attributes. For the EEA and the UK, the policy requires legally valid consent for cookies or local storage where the law requires it, and for using personal data to personalize ads. The consent message has to include a prominent link to Google’s page on how it processes personal data. Violations of these rules warn at least 7 days before suspension.
Setup workflow
- If the page collects a card, bank, tax, health, license, or Social Security number, serve that page over HTTPS with a valid certificate, or stop collecting it.
- If a remarketing or conversion tag is on a URL that contains an email address, switch the form to POST, or replace the address with an ID that is not the email.
- Do not put the person’s name, job, debt, or politics into the ad. Customer Match stays on its own terms. It is not a license to write “Hello John.”
- For visitors in the EEA or the UK, get the consent Google describes before remarketing or conversion tags, and link how Google processes personal data from the consent message.
- Do not set a cookie on doubleclick.net or googlesyndication.com. This policy warns at least 7 days before suspension.
Frequently asked questions
Is Customer Match banned because it uses email addresses?
No. Google says the ban on sharing personally identifiable information through remarketing tags and product feeds does not apply to Enhanced Conversions, Customer Match, or Store sales, including direct upload, when those services are under the Google Ads Data Processing Terms.
Can the ad say the customer’s name?
Google’s example of misuse is an ad that addresses the person by name, such as “Hello John Smith.” Ads that imply you know their financial status or political affiliation are also listed. “You’re buried in debt” is the example on the page.
Sources
This reading is as of September 27, 2026. It is not a privacy-law opinion for a specific country.
Check the form, not only the headline
LaunchGuarding reads the destination, including a checkout that still collects a card number on an unsecured page.