Effective June 15, 2026, Google made structural changes to how it collects and manages website visitor data. If your business operates in Texas or serves Texas residents and uses Google Analytics or Google Ads, those changes are now in effect, and they create real compliance obligations under the Texas Data Privacy and Security Act (TDPSA) (see Ch. 541, Tex. Bus. & Comm. Code) that require your attention now.
In this post, we describe what has changed, why it matters under Texas law, and what you should do about it.
What Google Changed
Before June 15th, your website’s visitor data flowed through two separate gates before reaching Google’s advertising and analytics tools:
- Gate 1 — Google Signals, operating through Google Analytics
- Gate 2 — Consent Mode, operating through Google Ads, controlled by your website’s Cookie Management Platform (CMP)
When a visitor opted out of tracking on your website, your CMP sent a signal to Consent Mode blocking that visitor’s data from flowing into Google Ads. If something went wrong with that signal such as a misconfiguration, a CMP error, or a timing issue, Google Signals acted as a backstop, catching the mistake and preventing data from passing through anyway.
As of June 15th, Google Signals is now gone. Thus, Gate 1 has been removed, and Consent Mode is now the sole mechanism controlling data flow between your CMP and Google’s systems. If your CMP sends the wrong signal, or no signal at all, that visitor’s data now flows through to Google Ads unchecked.
Why This Matters for Texas Businesses
Does the TDPSA Apply to You?
The TDPSA applies if your business conducts operations in Texas or produces products or services consumed by Texas residents; processes or engages in the sale of personal data; and is not a nonprofit corporation or small business as defined by the U.S. Small Business Administration. Unlike other states’ consumer data privacy laws, TDPSA does not use a revenue threshold; instead, it is based on what you do with data, not how large your company is. If you run a website with Google Analytics, there is a good chance your organization is covered.
Your Opt-Out Mechanism Must Actually Work
Under the TDPSA, if you process personal data for targeted advertising, you must give Texas consumers a clear, functional way to opt out. A cookie banner that appears to work, but does not actually suppress data flows, is not compliant.
With Google Signals removed, your CMP is now the only mechanism standing between a visitor’s opt-out choice and Google’s advertising infrastructure. A misconfigured CMP is no longer caught by any backstop. It simply fails, and data that should be blocked passes through.
The Universal Opt-Out Signal Requirement
Since January 1, 2025, the TDPSA has required businesses to recognize universal opt-out mechanisms, such Global Privacy Control (GPC) signals, which are browser-level settings that automatically communicate a user’s opt-out preference for data sales and targeted advertising. When a visitor arrives at your site with GPC enabled, your website must immediately suppress advertising and targeting scripts, without requiring any banner interaction.
If your CMP is not reliably passing GPC signals through Consent Mode—now the only available channel to operate as the opt-out stopgap—you may be failing this requirement continuously across your entire Texas audience without realizing it.
The Enforcement Risk
The Texas Office of Attorney General (OAG) has exclusive enforcement authority under the TDPSA and can seek civil penalties of up to $7,500 per violation. There is no private right of action in Texas, but OAG enforcement is real. $7,500 per violation scales quickly across a website’s traffic profile.
5 Practical Steps to Take Now
1. Audit Your CMP Configuration
This is the most urgent action item. Your CMP is now the only gate between your visitors and Google’s data systems. Log into your CMP platform and verify that:
- It is properly integrated with Google’s Consent Mode;
- It is sending and updating accurate consent signals on an ongoing basis;
- When a visitor selects “reject non-essential cookies” or opts out, the correct denial signals are being sent to Consent Mode; and
- GPC browser signals are being recognized and honored automatically, before any banner interaction.
If your team is not certain how to verify this, your web developer or CMP vendor should be able to run a consent signal audit. Do not assume your CMP is working properly just because it was working before June 15th. The removal of Google Signals means errors that were previously caught silently are now invisible.
2. Review Your Google Analytics and Google Ads Setup
Now that the architecture has changed, take stock of how your accounts are configured:
- Review your data sharing settings within Google Analytics and confirm they reflect your current intent; and
- Confirm your Google Analytics and Google Ads accounts are properly linked under the Consent Mode-only structure.
3. Update Your Privacy Policy
If your privacy policy describes how data is collected and shared on your website, it likely needs to be updated to reflect the post-June 15 reality. Specifically:
- Remove or update any language that implies Google Signals functions as a secondary control or backstop, as it no longer exists;
- Confirm that your policy accurately describes consumers’ right to opt out of targeted advertising and explains how to exercise that right; and
- Under the TDPSA, your policy must identify categories of personal data you collect, the purposes for which it is processed, and the categories of third parties with whom it is shared, so verify those disclosures remain accurate under the new structure.
4. Test Your Cookie Banner
Walk through your own website as a visitor would and verify the following:
- Does your cookie banner load before any Google Analytics or Google Ads scripts fire?
- When you click “reject non-essential cookies,” do those scripts actually stop, or do they load regardless?
- Is there a clear, accessible opt-out option for returning visitors who did not interact with the banner on a prior visit?
- Does your site immediately suppress tracking scripts when a visitor arrives with GPC enabled?
5. Consult With a Web Developer or Your CMP Vendor
Ensuring alignment of the CMP with Consent Mode typically requires the knowledge of someone familiar with Google Tag Manager and the specific CMP in use. Do not assume your CMP vendor has already handled the June 15th Google transition on your behalf. Reach out to your vendor and ask:
- Has the platform been updated to fully support Google Consent Mode following the June 15th changes to Google Analytics and Google Ads?
- Is there a verification report or consent signal log we can review to confirm signals are being transmitted correctly?
The Bottom Line
Google’s changes are here. For Texas businesses covered by the TDPSA, the question is no longer whether to prepare, it’s whether your current setup is actually functioning as required under the law. The removal of Google Signals means there is no longer a safety net catching CMP errors before they become data management failures.
The good news: if you act now, any gap can still be corrected.
Audit your CMP. Test your opt-out flows. Update your privacy policy. And contact your CMP vendor.