Two dates worth knowing if you run a website with EEA/UK traffic, Google Ads, or Indian users — and honestly, most sites we look at have neither wired correctly.
1. Google folds Google Signals into Consent Mode on 15 June 2026
Since 6 March 2024, Google has required four Consent Mode v2 signals — ad_storage, analytics_storage, ad_user_data, ad_personalization — before it will use EEA/UK visitor data for remarketing, enhanced conversions or conversion modelling.
What's changing: right now, Google Analytics gates ad-related data behind two separate controls — its own Google Signals toggle and your Consent Mode ad_personalization setting. From 15 June 2026, Google Analytics stops using the Signals toggle for that purpose entirely and relies solely on Consent Mode. Per Google's own help center:
"starting June 15, 2026, Google Analytics will transition to using Consent Mode (within Google Ads) as the single control for data"
After that date, the Google Signals setting in GA admin will only govern linking your GA data to signed-in user info for behavioural reporting — nothing about ad data. If your Consent Mode wiring has a bug, that bug is what decides what happens to EEA visitor data on 15 June 2026 — the Signals toggle won't save you anymore, even if it's switched on.
Source: support.google.com/analytics/answer/17016975
We wire Consent Mode v2 into GTM properly (all four signals, advanced mode, proved in Tag Assistant) for a fixed ₹1,799: zoopcoder.com/services/cookie-consent-consent-mode-v2
2. India's DPDP Rules are notified law, not a draft
A lot of Indian sites still treat the DPDP Act as something "coming eventually." It isn't — the DPDP Rules 2025 were notified on 14 November 2025, officially giving full effect to the Digital Personal Data Protection Act, 2023. That started an 18-month phased compliance window (per the government's own release):
"The Rules introduce an eighteen-month period for phased compliance... Every Data Fiduciary must issue a separate consent notice that is clear and easy to understand."
Two details that don't get repeated enough:
- The Rules require a separate, plain-language consent notice — distinct from your general privacy policy page — stating what's collected, why, and how to withdraw consent.
- A Data Fiduciary has a 90-day window to act on a data principal's access, correction, update or erasure request.
- Penalties run up to ₹250 crore for failing to maintain reasonable security safeguards.
Source: PIB press release, MeitY, 17 Nov 2025
We audit what your site actually collects and draft both documents (privacy policy + the separate consent notice the Rules require) for a fixed ₹5,999: zoopcoder.com/services/dpdp-privacy-policy-consent-notice
Disclosure: I'm with ZoopCoder — the pricing and service links above are ours. The two facts and dates are sourced directly from Google's and the Indian government's own primary documents, linked above.
Top comments (0)