Jul 22, 2026 · 7 min read
Google Will Use Your Gmail IP for Ads Starting Aug 3
A reversal of Google's own past position pulls IP addresses from Gmail, Search, and other sessions into cross service ad profiling, just as the UK's regulator is drafting stricter consent rules.
Starting August 3, 2026, Google will begin using the IP addresses it collects from UK, EEA, and Swiss users, logged during everyday activity across Gmail, Search, and other Google properties, to build advertising identifiers. The company has used IP addresses for years to route traffic and fight fraud. What changes is the purpose: those same addresses become an input for ad measurement and personalization, a use that triggers consent requirements under UK and EU law that traffic routing never did.
Key Takeaways
- Google will start using UK, EEA, and Swiss users' IP addresses for ad measurement and personalization on or shortly after August 3, 2026, according to BleepingComputer.
- Google is registering the change under IAB Europe's Transparency and Consent Framework as Feature 3, "identify devices based on information transmitted automatically," which governs cross service device identification for ads.
- The UK's Information Commissioner's Office called Google's related December 2024 decision to drop its fingerprinting ban for advertisers "irresponsible" within a day of the announcement.
- The rollout lands three months after the ICO published its own advice to the UK government on May 18, 2026, recommending that consent stay mandatory for any ad targeting that profiles a person's activity across services.
- Google frames the shift around privacy preserving techniques like on device processing and secure multi party computation, but user facing opt out controls for IP based personalization will not arrive until later in the rollout.
What Is Actually Changing on August 3?
Google already receives IP addresses through its Tag, its SDKs, direct HTTP calls, and advertiser data uploads. It has used those addresses for routing, fraud prevention, and basic ad delivery for years. Starting August 3, Google will start using the same addresses to identify devices for measurement and personalization purposes across the European Economic Area, the UK, and Switzerland.
That distinction matters because IP addresses count as personal data under both the UK GDPR and the EU GDPR. Routing a request to the correct server is a technical necessity that does not require consent. Using that same address to recognize a device across sessions and build an advertising profile is a different legal category entirely, one the ICO has spent years arguing needs explicit user permission. Google is registering the new use under IAB Europe's Transparency and Consent Framework as Feature 3, the mechanism advertisers use to declare that they identify devices from automatically transmitted data such as IP addresses.
Google has said the rollout will lean on privacy preserving infrastructure, including on device processing, trusted execution environments, and secure multi party computation. Some user facing controls for IP based personalization will not appear until later in 2026 or early 2027, leaving only the existing levers in the meantime: declining non essential cookies and adjusting settings at myadcenter.google.com.
How Did Google Get Here?
This is not Google's first reversal on device level tracking. In 2019, Chrome's then engineering director Justin Schuh wrote that browser fingerprinting "subverts user choice and is wrong, because users cannot clear it the way they can clear cookies." That position held, publicly, for five years.
In December 2024, Google quietly dropped its prohibition on fingerprinting for advertisers in its ad platform policies. The ICO responded within a day, calling the reversal "irresponsible" and noting that fingerprinting fails the same test Google itself once used to reject it: users have no simple way to see it, contest it, or clear it, the way they can delete a cookie. Gblock covered that reversal in detail in a prior analysis of Google's fingerprinting policy.
The August 2026 change reads as the next chapter of the same story rather than an isolated announcement. Both moves repurpose a device level signal, first fingerprinting, now IP addresses, for cross service ad personalization, and both arrive after the ICO had already opposed the underlying practice on record. Google appears willing to absorb a predictable regulatory rebuke in exchange for closing the measurement gap that cookie deprecation and Apple's App Tracking Transparency opened in its ad business.
Why Did the Timing Draw Criticism?
The criticism is sharper this time because of when the announcement landed. On May 18, 2026, the ICO published its own advice to the UK government on potential changes to online advertising consent rules. The regulator's preferred approach would let publishers run low risk, contextual advertising, ads based on the page being viewed, without asking for consent, while keeping consent mandatory for anything that tracks a person's activity across services to build an interest profile.
IP based device identification across Gmail, Search, YouTube, and third party sites that use Google's ad tags sits squarely on the consent required side of that line the ICO just drew. Google announcing the change roughly ten weeks later, while stressing that "nothing has changed yet" under existing rules, reads to privacy regulators as Google testing the boundary of a framework the ICO had not finished proposing. Google's own advertising technologies policy still describes IP addresses as one of several signals used to serve and measure ads, but it has not yet published the granular user controls for the new personalization use.
Why Email Users Should Care
It is worth being precise about the mechanism here, because it is easy to conflate this with email tracking pixels, and the two are not the same thing. This IP address change is an account and network level signal: Google logs the IP address associated with a session any time a signed in user opens Gmail, runs a search, or watches a YouTube video, and it plans to use that address to recognize the same device across those services for ad targeting. It has nothing to do with the content of a specific email or whether a marketer's message was opened.
Tracking pixels are a separate, narrower threat that Gblock does address directly: a sender embeds a hidden image in an email, and when the recipient opens it, that image loads from a remote server and reports back the open, the approximate location, and the device used, as covered in Gblock's guide to blocking spy pixels in Gmail. Gblock blocks that pixel request before it fires. It does not, and cannot, intercept Google's own IP based ad measurement, because that data never touches the tracking pixel mechanism Gblock is built to stop; it is collected at the network and account level by Google itself.
The practical takeaway is that these are two separate surveillance layers stacking on top of each other. A privacy conscious Gmail user who blocks tracking pixels has closed one door. Google's IP address change opens another, one that sits entirely outside the browser extension layer and inside Google's own infrastructure. Readers who want a fuller picture of what Google already does with account data should see Gblock's breakdown of how Google's real time ad auction settings work, since IP based personalization will likely feed the same auction pipeline.
What Can You Actually Do About It?
For individual users, the available protections are limited but not zero:
- Review Google's ad settings at myadcenter.google.com and turn off ad personalization, even though full IP based controls are not live yet.
- Decline non essential cookies in consent banners rather than accepting defaults, since cookie and consent signals still feed into how the new IP measurement is scoped.
- Use a VPN or privacy respecting DNS to mask or rotate your visible IP address for Google properties, which blunts device level correlation before Google's own controls arrive.
- Choose a browser with built in tracking protection, such as Firefox's Enhanced Tracking Protection or Brave's default shields, to limit the SDK and tag based collection this feature relies on.
- Watch for the promised opt out, expected later in 2026 or early 2027, rather than assuming the issue is resolved in the meantime.
For compliance teams, the near term obligation is narrower but concrete: any organization running Google Ads, Google Analytics, or Google tags on EEA, UK, or Swiss facing properties should confirm its consent management platform correctly maps Google's new IP based personalization use to a distinct, opt in consent purpose, rather than bundling it under an existing "analytics" or "measurement" category that predates this change.
Looking Ahead
Google has not published the interface UK and EEA users will get to opt out of IP based personalization, only that it is coming later in the rollout. Meanwhile the ICO's advice to government and Google's deployment are moving on separate, loosely coordinated tracks: one proposing tighter rules for cross service profiling, the other building the infrastructure to do more of it. Expect the ICO, and likely at least one EU data protection authority, to ask how Feature 3 registration squares with the consent standard the regulator just spent months drafting.