Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View

Updates to Data Control Between Google Analytics and Google Ads

Author

Usman Tariq

Senior Global Compliance Analyst at Securiti

CIPP/US

Published May 17, 2026

Listen to the content

Introduction

Google is introducing major changes to the way data is managed between Google Analytics and Google Ads. These updates are aimed at simplifying privacy controls, streamlining consent management, and ensuring that user preferences are applied consistently across both platforms. Currently, when a Google Analytics property is linked to a Google Ads account, data flows from Analytics into Ads and becomes subject to Google Ads terms and conditions. However, some settings within Google Analytics still influence how that data is used in Ads. Google now plans to centralize these controls based on where the data is ultimately used.

Current System of Data Sharing

At present, linking a Google Analytics property to a Google Ads account enables Analytics data to flow into Google Ads. Once transferred, the data is controlled under Google Ads policies and terms. Despite this, several settings within Google Analytics continue to regulate how the data is handled in Google Ads.

For example:

  • Google Signals settings manage Google Ads cookies and identifiers.
  • Ads personalization settings within Google Analytics determine how audiences are used for advertising purposes.

This overlap has created multiple layers of controls, which can complicate consent management and data governance.

Purpose of the Upcoming Changes

Google aims to simplify and consolidate data controls by assigning authority based on the platform where the data is used.

Under the new system:

  • Google Ads settings will exclusively control all advertising-related data, including data shared from Google Analytics.
  • Google Analytics settings will only govern data used inside Analytics for reporting and behavioral analysis.

According to Google, this change will:

  • reduce redundant settings,
  • simplify privacy management,
  • improve consistency in enforcing user consent preferences,
  • and streamline compliance processes.

Importantly, users and advertisers will still maintain control over whether and how data is collected and used.

Changes to Google Signals

Current Role of Google Signals

At present, Google Signals and Consent Mode Ads settings jointly control the collection of:

  • Google Ads cookies,
  • advertising identifiers,
  • and related user data collected through the Google Analytics tag and SDK.

Upcoming Update

Starting from June 15, 2026, Google will shift to a simplified model in which:

  • Consent Mode within Google Ads becomes the single control mechanism for advertising-related data collection.

This means users’ privacy choices managed through Ads Consent Mode settings will exclusively determine how such data is collected and used.

New Role of Google Signals

After June 15, 2026:

  • Google Signals settings in Analytics,
  • and the Google Signals API,

will only control the association of Google Analytics data with signed-in user information for behavioral reporting purposes.

Thus, Google Signals will no longer determine advertising data collection for Ads.

Changes to Ads Personalization

Existing System

Currently, ads personalization is controlled through multiple layers within Google Analytics, including:

  • account-level settings,
  • property-level settings,
  • Ads link settings,
  • and event-level settings.

This creates a complex governance structure for advertisers.

Planned Simplification

Later in 2026, Google plans to simplify this process by transferring exclusive control of ads personalization to Google Ads settings.

Once a Google Analytics property is linked to Google Ads:

  • the Consent Mode ad_personalization setting will solely determine whether data can be used for personalized advertising.

This means Google Ads will become the central authority for all ad personalization decisions.

Changes Regarding IP Addresses

Google also announced updates concerning IP address handling.

Encryption of IP Addresses

IP addresses automatically collected through:

  • Google Tag,
  • and Google SDK systems.

will be encrypted before being transferred to linked Google Ads accounts.

Control Under Google Ads

Once transferred:

  • encrypted IP addresses will fall under Google Ads controls,
  • and their usage will follow Google Ads settings, configurations, and terms of service.

Google has indicated that additional details regarding the use of IP addresses outside:

  • the European Economic Area (EEA),
  • the United Kingdom,
  • and Switzerland.

will be shared through its Help Center resources.

Significance of These Changes

These updates reflect Google’s broader strategy to:

  • centralize privacy governance,
  • simplify consent frameworks,
  • and eliminate overlapping controls between Analytics and Ads.

The changes are expected to:

  • improve transparency,
  • reduce administrative complexity,
  • strengthen consistency in consent enforcement,
  • and make data management easier for businesses.

For advertisers and organizations, this means a clearer distinction between:

  • reporting functions handled by Google Analytics,
  • and advertising functions controlled by Google Ads.

What CMPs need to do to stay compliant

To remain compliant and properly integrated with Google Consent Mode, Consent Management Platforms (CMPs) should focus on the following key requirements:

  • Implement Google Consent Mode v2 correctly.
  • Support consent signals such as:
    • ad_storage
    • analytics_storage
    • ad_user_data
    • Ad_personalization
    • functionality_storage, personalization_storage,
    • security_storage.
  • Ensure user consent choices are passed to:
    • Google Analytics
    • Google Ads
      in real time.
  • Allow granular consent choices (analytics, ads, personalization, etc.).
  • Dynamically adjust Google tags and SDKs based on consent status.
  • Maintain secure consent logs for compliance with:
    • GDPR,
    • CCPA,
    • and other privacy laws.
  • Support easy withdrawal or modification of consent by users.
  • Ensure transparency by clearly explaining:
    • what data is collected,
    • why it is used,
    • and who receives it.
  • Prepare for Google’s 2026 changes, where Google Ads Consent Mode settings will become the primary control for advertising-related data.
  • Integrate with industry standards such as Google-certified CMP frameworks and IAB TCF v2.2.

Conclusion

Google’s upcoming changes to Google Analytics and Google Ads represent a major shift in digital advertising and privacy management. By consolidating advertising-related controls within Google Ads and limiting Google Analytics to reporting functions, Google aims to create a simpler and more consistent consent system. The updates to Google Signals, ads personalization, and IP address management are designed to reduce redundant settings while ensuring that user privacy preferences are respected across platforms. As these changes roll out through 2026, businesses and advertisers will need to review and adapt their consent and data governance practices accordingly. Meanwhile, CMPs need to ensure that they are implementing the Google Consent Mode V 2.0 accurately.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer View More
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
DSPM in 2026: Why It Matters More Than Ever View More
DSPM in 2026: Why It Matters More Than Ever
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
An Overview of Bangladesh’s Personal Data Protection Act, 2026
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
EU AI Act: What Changes Now vs What Starts in 2026 View More
EU AI Act: What Changes Now vs What Starts in 2026
Understand the EU AI Act rollout—what obligations apply now, what phases in by 2026, and how providers and deployers should prepare for risk tiers,...
AI Governance Fails When Privacy Controls Stay Disconnected View More
AI Governance Fails When Privacy Controls Stay Disconnected
Access the whitepaper and learn how to operationalize core privacy controls across the AI lifecycle to ensure compliance, accountability, and defensible AI use.
You Can’t Protect What You Can’t See View More
You Can’t Protect What You Can’t See
Discover why disconnected security findings create hidden breach paths, why 57% of organizations can't prove data flows, and how to identify toxic risk combinations...
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New