The module seems like a good start and I've been searching for a module that helps me comply with the EU GDPR while serving Adsense ads on my site. From what I've been reading, to serve any Adsense ads, Google must use some cookies, and explicit consent is required to do so before any cookies can be set. Correct me if I'm wrong here (and I would love to be wrong) but to comply with the GDPR, we need a feature that suspends Adsense scripts altogether until an explicit "opt-in" action has been performed by the user.

Serving or not serving personalized ads to EU users can be done from within Adsense itself as a global setting. Giving users this choice is a nice feature, but not as important as suspending Adsense scripts and cookies until and "opt-in" state is achieved. Our Adsense serving Drupal sites are not going to be GDPR compliant until we do.

Comments

OMD created an issue. See original summary.

jamesoakley’s picture

I'm sure the module could be patched so that it only serves ads once a user has given their consent for them. I'll see what I can do, but if someone wants to beat me to it with a patch I'll gladly review it. The mechanism is already there, in the sense that it is already admin configurable as to whether personalisation is opt-in or opt-out, and this would simply be another option there.

In terms of why this module is the way it is: I am not a lawyer. I'm aware that there are many different interpretations out there of how GDPR affects things. What I did observe was consistency as I browsed the websites of, for example, well-known news outlets. They all seem to serve ads by default, but include a pop-up that links to where the visitor can tune the personalisation of those ads. Their privacy policies also now contain a list of all ad networks that are used (which is something AdSense now requires). I then shaped the module accordingly.

omd’s picture

I thought that initially too, but after more digging I discovered (on Adsense's own info pages) that even serving non-personalized ads requires consent. Here's the link and the relevant section:

"Non-personalized ads

Google will show all your users in the EEA only non-personalized ads.

Non-personalized ads are targeted using contextual information rather than the past behavior of a user. Although these ads don’t use cookies for ads personalization, they do use cookies to allow for frequency capping, aggregated ad reporting, and to combat fraud and abuse. Consent is therefore required to use cookies for those purposes from users in countries to which the EU ePrivacy Directive’s cookie provisions apply."

https://support.google.com/adsense/answer/7670013?hl=en

So if a user opts out of agreeing to the use of cookies, which logically we must request permission for before using cookies, then we are not able to serve ads at all in that instance and still comply with the GDPR.

Serving ads (using cookies) by default seems legal for locations outside the EU, but I don't see how this is possible for users inside the EU. Maybe those sites are employing some geolocation information that determines whether ads are served before permission or not.

jamesoakley’s picture

Status: Active » Postponed

I want to tackle this once #2991164: Move all visitor-specific logic to client-side to allow page-caching is fixed. That issue will move some of the logic from the back-end to the front-end. The change that this issue is asking for will add further complexity to the logic as to what exact JS gets called on the page to generate ads. It doesn't make sense to make these changes at the back-end, and then have to move the extra code from back-end to front-end. As this issue is all stuff that should happen on the front-end, let's do it once everything else is being done in the right place.

jamesoakley’s picture

Status: Postponed » Active

jamesoakley’s picture

Version: 7.x-1.0 » 7.x-1.x-dev
Status: Active » Needs review

https://cgit.drupalcode.org/adsense_consent/commit/?id=b2735c0 should do this. I'll leave it as Needs Review for a few days in case anyone spots any glaringly big bugs that means it would be a disaster if a site used this in production.

If anyone would like to suggest ways this could be better designed, please start a new issue.

  • JamesOakley committed 69d0a0b on 7.x-1.x
    Issue #2984882 by JamesOakley: Update README to explain new consent...
jamesoakley’s picture

Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.