Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Google Business Profile (formerly Google My Business) lets businesses appear in Google Search and Maps. When embedded maps or place widgets are added to a website, they load Google scripts that expose the visitor IP to Google and set Google cookies, requiring consent under GDPR and the ePrivacy Directive.
Google Business Profile, previously called Google My Business, is the free listing that controls how a business appears in Google Search results and Google Maps. Business owners claim and verify their listing to display their address, opening hours, photos, reviews and contact details. On a website, the listing is integrated through embedded elements such as an interactive Google Map of the business location, an embedded reviews or place widget, or a find us on Google link. When these elements are present on a page, they load resources from Google domains, which means Google can observe the visitor's IP address and request metadata, and may set cookies on the visitor's device.
When an embedded Google Map or place widget loads, the visitor's IP address and HTTP request headers are sent to Google's servers. Google may set cookies including NID (a preferences and advertising identifier lasting 6 months), CONSENT (a 2 year cookie recording Google consent status) and SOCS (a Google Maps specific cookie). These cookies can identify the visitor across different Google services and sessions. Even without cookies, the IP address itself constitutes personal data under GDPR when combined with other information Google holds about the visitor.
Embedding a Google Map creates two compliance obligations. First, under Article 5(3) of the ePrivacy Directive, loading the map scripts that store or access information on the visitor device requires prior informed consent, irrespective of the purpose of the cookies. Second, under GDPR, the disclosure of the visitor's IP address to Google in the United States constitutes a transfer of personal data to a third party in a third country, requiring a legal basis and appropriate safeguards. The website operator is the data controller responsible for these obligations and must not load the map without the visitor's consent.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Prior consent is required before the embedded map or widget loads. A common compliant approach is to display a static placeholder image with a button or checkbox labelled something like show map that triggers loading of the Google Map only after the user actively opts in. The consent must be freely given, specific, informed and unambiguous. Consent cannot be buried in general terms or pre ticked boxes. Users must be able to decline without losing access to the rest of the page content.
Every time the Google Maps embed loads, visitor IP data is transmitted to Google LLC in the United States. This is an international data transfer under GDPR Chapter V. Google relies on the EU US Data Privacy Framework adequacy decision and standard contractual clauses as the transfer mechanism. Website operators must disclose this transfer in their privacy policy, reference the applicable safeguards and ensure that Google's Data Processing Terms are in place covering the Maps API or embedded maps usage.
To implement Google Business Profile embedding in a GDPR compliant manner: (1) Replace live map iframes with a static placeholder that only loads the Google Map after the user clicks a consent button or grants map consent via your CMP. (2) Add Google Maps cookies (NID, CONSENT, SOCS) to your cookie policy with their purpose, provider and duration. (3) Disclose the IP transfer to Google US in your privacy policy and reference the EU US Data Privacy Framework. (4) Sign Google Maps Platform Terms of Service and Data Processing Amendment. (5) Consider whether a less privacy invasive alternative such as a static map image with a link to Google Maps would meet your needs without requiring consent. (6) If embedding is essential, audit all pages where maps appear and ensure the CMP blocks them by default.
Websites using Google Business Profile must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered when Google Maps or place widgets are embedded on high traffic pages, given the systematic exposure of visitor IP addresses to Google in the United States. Key risk areas include: (1) IP address transmission to Google LLC as a third party controller on every page load that includes the map; (2) cookies set by Google that may be used for advertising; (3) international data transfer to the US under the EU US Data Privacy Framework. Organisations should assess whether the embedding is strictly necessary and whether less privacy invasive alternatives such as a static map image or a link to Google Maps would achieve the same purpose.
Sample consent text
We would like to embed an interactive Google Map on this page. Loading this map allows Google to see your IP address and may set cookies on your device. Do you agree to load the Google Map? [Show Map] [No thanks]
Third-party domains contacted
maps.googleapis.commaps.gstatic.comwww.google.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| NID | Advertising / Preferences | 6 months | Google identifier storing user preferences and used for advertising personalisation across Google properties |
| CONSENT | Preference | 2 years | Records the visitor Google consent choices across Google domains |
| SOCS | Functional | Session | Google Maps operational state cookie managing map session data |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
Embedding a Google Map or Business Profile widget on your website causes Google to set several cookies on the visitor device. The main cookies are NID (a Google preferences and advertising identifier lasting 6 months), CONSENT (a 2 year cookie recording the visitor's Google consent choices) and SOCS (a Google Maps operational cookie). These are set under the google.com domain and can persist across sessions and other Google services.
Yes. Under Article 5(3) of the ePrivacy Directive, any script that stores or accesses information on the visitor's device requires prior consent, regardless of purpose. Additionally, the IP address transfer to Google in the US requires a legal basis under GDPR. The most common approach is to block the map iframe until the visitor actively opts in via your consent management platform or a dedicated show map button on the page.
The appropriate legal basis is consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive. Legitimate interest is generally not sufficient for loading third party map iframes that set advertising cookies and transfer visitor IP to a third country, given the significant data processing impact on the visitor. Consent must be specific, informed, freely given and revocable. Some authorities have found legitimate interest acceptable only for strictly functional maps without advertising cookies, but this remains legally uncertain.
Yes. Every time the embedded Google Map or widget loads, the visitor IP address and request metadata are transmitted to Google LLC servers in the United States. This is an international data transfer under GDPR Chapter V. Google relies on the EU US Data Privacy Framework and standard contractual clauses. You must disclose this transfer in your privacy policy, including the transfer mechanism and Google's identity as recipient, and ensure Google Maps Platform Data Processing Terms are accepted.
A DPIA may be required depending on the scale and sensitivity of the pages where the map appears. Factors pointing toward a DPIA include: systematic collection of visitor IPs on high traffic pages, transfer to a US third party controller (Google), use of advertising cookies, and embedding on pages where sensitive topics might be inferred from the visit. Consult your Data Protection Officer and your supervisory authority's DPIA trigger list to determine whether a formal assessment is mandatory.
Best practices for compliant embedding: (1) Replace live iframes with a static placeholder showing the location address and a show map button. (2) Only load the Google Map script after the user clicks the show map button or grants map consent in your CMP. (3) Add Google Maps cookies to your cookie policy with name, purpose, duration and provider. (4) Disclose the IP transfer to Google US in your privacy policy and reference EU US Data Privacy Framework. (5) Sign the Google Maps Platform Data Processing Amendment. (6) Explore whether a static map image with a link to Google Maps could serve the purpose without triggering consent requirements.
If you want to show your business location without triggering Google consent requirements, consider: (1) A static map image generated via a serverside call to the Maps Static API (the visitor does not load Google resources directly). (2) OpenStreetMap based embeds via Leaflet.js or OpenLayers, which can be self hosted and do not transfer data to US third party controllers. (3) A text address with a link to external Google Maps that the user can choose to open. (4) A simple map screenshot with a caption. Each alternative avoids the ePrivacy cookie consent requirement and limits international data transfer.
Your cookie policy must list cookies set by the Google Maps or Business Profile embedding. Add entries for: NID (google.com, 6 months, preferences and advertising), CONSENT (google.com, 2 years, Google consent state), SOCS (google.com, session or short term, Google Maps operational state). For each cookie include name, provider, purpose, duration and cookie category. Classify NID and CONSENT as advertising or analytics cookies. Link your cookie policy from the consent banner and update it whenever you change your map provider or add new Google integrations.