Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Google Consent Mode

Google Ad Tech Providers List

Also known as: ATP List, Google Ad Technology Providers (ATP) list, Additional Consent (AC) vendor list, Associated ad technology providers list
Simply put

The Google Ad Tech Providers List is a directory maintained by Google of the third-party advertising companies (such as measurement, delivery, and related service providers) that can operate through Google's advertising products like Google Ad Manager and AdSense. Publishers and site owners use this list to identify and manage which of these partners they work with, which can affect how user consent is handled for advertising on their sites. It is a tool that supports consent and vendor management but does not by itself determine whether any given data practice is lawful.

Formal definition

The Google Ad Tech Providers (ATP) list is Google's enumeration of approved third-party ad technology vendors that publishers can permit to receive data or serve functions within Google's ad serving stack, primarily configured through the "Associated ad technology providers" controls in Google Ad Manager and equivalent settings in AdSense. In the EU/EEA and UK context, this list underpins Google's Additional Consent (AC) mode, which sits alongside the IAB Transparency and Consent Framework (TCF) to capture consent signals for vendors not registered on the IAB Global Vendor List; the AC string is passed together with the TC string to communicate user choices for these Google-approved partners. Practitioners should note that inclusion of a vendor on the ATP list, and the collection of an AC signal, addresses consent signalling and vendor declaration but does not, on its own, establish a valid legal basis or satisfy the ePrivacy consent requirements for placing or accessing information on a user's device, nor the GDPR requirements for any subsequent processing of personal data. The precise scope, categories of partners listed, and interaction with TCF versions may change over time as Google updates its documentation and as data protection authority guidance evolves; jurisdiction-specific obligations (for example under US state privacy laws, which often rely on opt-out mechanisms) fall outside what this list determines and require separate assessment.

Why it matters

For publishers and site owners running Google advertising products in the EU, EEA, or UK, the Google Ad Tech Providers List sits at the intersection of vendor governance and consent signalling. Many advertising partners that a publisher relies on for measurement, delivery, and related functions are not registered on the IAB Global Vendor List used by the Transparency and Consent Framework (TCF). Google's Additional Consent (AC) mode was designed to capture user choices for these Google-approved partners, and the AC string is passed alongside the TCF's TC string. Understanding which vendors appear on the ATP list, and how the AC signal operates, is therefore central to knowing what consent your ad setup is actually communicating to downstream partners.

The practical risk is treating inclusion on the list, or the presence of an AC signal, as evidence that a data practice is lawful. It is not. The ATP list and AC mode address vendor declaration and consent signalling; they do not, on their own, establish a valid legal basis for placing or accessing information on a user's device under ePrivacy rules, nor do they satisfy GDPR requirements for any subsequent processing of personal data. A publisher can be signalling consent correctly and still be non-compliant if the underlying consent was not freely given, specific, informed, and unambiguous.

Because the scope of the list, the categories of partners included, and the interaction with TCF versions can change as Google updates its documentation and as data protection authority guidance evolves, publishers should treat the ATP list as a component to monitor rather than a fixed compliance checkbox. Obligations under US state privacy laws, which often rely on opt-out mechanisms rather than opt-in consent, are outside what this list governs and require separate assessment.

Who it's relevant to

Publishers and site owners using Google ad products
Those running Google Ad Manager or AdSense in the EU, EEA, or UK use the ATP list to identify and manage which advertising partners can operate through their inventory, and to configure the "Associated ad technology providers" settings that drive Additional Consent signalling. They should treat the list as a vendor governance tool rather than a guarantee of lawful processing.
Privacy officers and data protection professionals
These practitioners need to understand that inclusion of a vendor on the ATP list and the collection of an AC signal address consent signalling and vendor declaration, but do not on their own establish a valid legal basis under ePrivacy rules or satisfy GDPR requirements for subsequent processing. They should assess whether the underlying consent is freely given, specific, informed, and unambiguous.
Consent management platform (CMP) implementers and web developers
Those integrating consent solutions need to know how AC mode sits alongside the IAB TCF and how the AC string is passed together with the TC string. Because the interaction with TCF versions may change as Google updates its documentation, they should monitor for changes rather than assume a static configuration.
Legal counsel and compliance teams
Advisers assessing advertising data flows should recognise that the ATP list and AC mode do not resolve jurisdiction-specific obligations. US state privacy laws, which often rely on opt-out mechanisms, fall outside what this list determines and require separate analysis, as do evolving data protection authority positions in the EU and UK.

Inside ATP List

Ad Technology Providers (ATP)
The Google Ad Tech Providers List is a curated set of third-party ad technology vendors that Google's advertising products may work with. Publishers using Google's consent management or advertising tools can reference this list to identify which providers might place cookies or similar technologies, or process personal data, in connection with serving and measuring ads.
Provider identity and purpose information
For each listed provider, the list is intended to convey information such as the vendor's identity and links to its policies, supporting the transparency element that is generally required before consent can be considered informed under EU and UK rules. The precise fields presented may vary and should be verified against Google's current documentation.
Relationship to the IAB TCF vendor list
The Ad Tech Providers List is distinct from the vendor list maintained under the IAB Transparency and Consent Framework (TCF), although the two may overlap. Some Google-related providers may not participate in the TCF, so publishers relying on a TCF-based consent management platform (CMP) may need to account for both to cover the vendors relevant to their setup.
Role within a consent flow
The list functions as an input to a publisher's consent and disclosure process rather than as a consent mechanism itself. It helps a publisher and its CMP determine which vendors to disclose and, where required, obtain prior consent for, but the collection and logging of that consent occurs through separate tools and processes.

Common questions

Answers to the questions practitioners most commonly ask about ATP List.

Does including a provider on the Google Ad Tech Providers List mean I have valid consent to work with them?
No. The list identifies ad technology vendors that Google recognizes for use within its advertising products, but appearing on it does not, by itself, establish that you have obtained valid consent for any given user. Under EU and UK rules, consent must generally be freely given, specific, informed, and unambiguous, and must be collected and recorded through your own consent mechanism (often a CMP). The list is an operational reference for which vendors Google supports, not evidence that consent obligations have been met. You remain responsible for the legal basis for placing cookies or similar technologies and for any subsequent processing of personal data.
Does using the Google Ad Tech Providers List make my cookie setup compliant?
No tool or vendor list guarantees compliance; they support compliance efforts but do not replace legal judgment. The list helps you manage which ad tech vendors are permitted within Google's ecosystem, but compliance depends on factors it does not address, such as how you present consent notices, whether you rely on prior opt-in (as is typically required in the EU and UK) or opt-out (as often applies under certain US state laws), how you log consent, and how vendors actually process data. Whether your overall setup is lawful is a fact-specific assessment that varies by jurisdiction and should be evaluated against applicable requirements.
How does the Google Ad Tech Providers List relate to a consent management platform (CMP)?
The list and a CMP serve different functions. A CMP is the technical component that presents consent choices to users, captures their decisions, and typically records those decisions for accountability purposes. The Ad Tech Providers List is a reference set of vendors that may be involved in delivering Google's advertising services. In practice, you would configure your CMP to reflect the vendors you actually use and to gate the loading of their cookies, pixels, SDKs, or similar technologies until an appropriate legal basis exists. The list informs which vendors are in scope; the CMP operationalizes user choices about them.
How does this list interact with the IAB Transparency and Consent Framework (TCF)?
Google's Ad Tech Providers List and the IAB TCF are separate mechanisms that some organizations use together. The TCF is an industry framework with its own registered vendor list and standardized consent signal (the TC string), whereas Google's list reflects vendors recognized within Google's own products. Google has provided ways for these to operate alongside one another, but the specifics of that integration are configuration-dependent and subject to change. Because implementation details and the relationship between the two frameworks evolve, you should confirm current configuration requirements against the applicable up-to-date documentation rather than assuming a fixed mapping.
Do I need to keep the list of vendors I use aligned with my consent notice?
Generally, yes. In most EU and UK contexts, consent is expected to be informed and specific, which typically means users should be able to understand which categories of technologies and, where relevant, which vendors may process their data. If you rely on a set of ad tech vendors, aligning your consent notice, vendor disclosures, and CMP configuration with the vendors actually in use supports the informed and specific standard. The precise level of vendor-specific disclosure expected can vary by jurisdiction and by guidance from data protection authorities, so treat this as an area requiring ongoing review rather than a one-time setup.
How should I handle vendors on the list when users opt out or send a Global Privacy Control signal?
How you respond depends on the applicable legal regime. In the EU and UK, where prior opt-in is generally required, vendors' cookies and similar technologies should typically not be loaded until valid consent is obtained, and withdrawal of consent should be as easy to exercise as granting it. Under certain US state laws, opt-out mechanisms, including recognized signals such as Global Privacy Control, may need to be honored for activities like sale or sharing of personal data. In practice, this means configuring your consent tooling so that user choices and any applicable opt-out signals are propagated to the relevant vendors. Whether and how a specific signal must be respected is jurisdiction-dependent and should be assessed against current requirements.

Common misconceptions

Using Google's Ad Tech Providers List means my site is compliant with cookie consent rules.
The list is a reference resource that supports transparency and disclosure; it does not by itself establish compliance. In most EU and UK jurisdictions, prior consent that is freely given, specific, informed, and unambiguous is generally required before non-essential cookies or similar technologies used for advertising are placed, and that consent must be obtained and recorded through appropriate mechanisms. Legal judgment about your specific configuration remains necessary. Requirements also differ under US state laws, which often rely on opt-out rather than opt-in.
The Ad Tech Providers List and the IAB TCF vendor list are the same thing.
They are separate lists that may overlap but are not identical. Some providers relevant to Google's advertising products may fall outside the TCF, so relying solely on a TCF vendor list within a CMP may not cover every provider your setup involves. Practitioners should confirm which providers apply to their implementation.
If a provider appears on the list, I have all the disclosure information I need for consent.
The list supports the informed element of consent by identifying providers, but the fields it presents may vary and it does not replace a publisher's own obligation to give clear, accurate notice about the specific cookies and technologies used, their purposes, and how users can exercise their rights. Scope of disclosure obligations varies by jurisdiction.

Best practices

Treat the Ad Tech Providers List as an input to your disclosure and consent process, not as evidence of compliance in itself, and confirm which providers actually apply to your specific advertising configuration.
Where you use a TCF-based CMP, check whether relevant Google-related providers fall outside the TCF, and ensure your disclosures and consent flows account for both TCF and non-TCF vendors.
For users in the EU and UK, obtain prior consent that is freely given, specific, informed, and unambiguous before placing non-essential advertising cookies or similar technologies, and avoid pre-ticked boxes, implied consent, or cookie walls, which are widely regarded as non-compliant.
For users covered by US state privacy laws such as those in California, implement the applicable opt-out mechanisms (including honoring recognized signals such as Global Privacy Control where required) rather than assuming an opt-in model applies.
Maintain records of the consent or preference choices you rely on, using your CMP's logging capabilities, so you can demonstrate the basis on which providers were engaged.
Verify provider details and list contents against Google's current documentation before relying on them, and involve legal or data protection advisors to assess your specific setup, since regulatory guidance and enforcement positions continue to evolve.
Promotional banner for the Penetration Report Template Kit