FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Google My Business
G

Google My Business

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Google Business Profile do?

Google Business Profile (formerly Google My Business) lets businesses appear in Google Search and Maps. When embedded maps or place widgets are added to a website, they load Google scripts that expose the visitor IP to Google and set Google cookies, requiring consent under GDPR and the ePrivacy Directive.

What is Google Business Profile?

Google Business Profile, previously called Google My Business, is the free listing that controls how a business appears in Google Search results and Google Maps. Business owners claim and verify their listing to display their address, opening hours, photos, reviews and contact details. On a website, the listing is integrated through embedded elements such as an interactive Google Map of the business location, an embedded reviews or place widget, or a find us on Google link. When these elements are present on a page, they load resources from Google domains, which means Google can observe the visitor's IP address and request metadata, and may set cookies on the visitor's device.

What Data and Cookies Does It Collect?

When an embedded Google Map or place widget loads, the visitor's IP address and HTTP request headers are sent to Google's servers. Google may set cookies including NID (a preferences and advertising identifier lasting 6 months), CONSENT (a 2 year cookie recording Google consent status) and SOCS (a Google Maps specific cookie). These cookies can identify the visitor across different Google services and sessions. Even without cookies, the IP address itself constitutes personal data under GDPR when combined with other information Google holds about the visitor.

GDPR and ePrivacy Implications

Embedding a Google Map creates two compliance obligations. First, under Article 5(3) of the ePrivacy Directive, loading the map scripts that store or access information on the visitor device requires prior informed consent, irrespective of the purpose of the cookies. Second, under GDPR, the disclosure of the visitor's IP address to Google in the United States constitutes a transfer of personal data to a third party in a third country, requiring a legal basis and appropriate safeguards. The website operator is the data controller responsible for these obligations and must not load the map without the visitor's consent.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements

Prior consent is required before the embedded map or widget loads. A common compliant approach is to display a static placeholder image with a button or checkbox labelled something like show map that triggers loading of the Google Map only after the user actively opts in. The consent must be freely given, specific, informed and unambiguous. Consent cannot be buried in general terms or pre ticked boxes. Users must be able to decline without losing access to the rest of the page content.

Data Transfers Outside the EU

Every time the Google Maps embed loads, visitor IP data is transmitted to Google LLC in the United States. This is an international data transfer under GDPR Chapter V. Google relies on the EU US Data Privacy Framework adequacy decision and standard contractual clauses as the transfer mechanism. Website operators must disclose this transfer in their privacy policy, reference the applicable safeguards and ensure that Google's Data Processing Terms are in place covering the Maps API or embedded maps usage.

Practical Compliance Steps

To implement Google Business Profile embedding in a GDPR compliant manner: (1) Replace live map iframes with a static placeholder that only loads the Google Map after the user clicks a consent button or grants map consent via your CMP. (2) Add Google Maps cookies (NID, CONSENT, SOCS) to your cookie policy with their purpose, provider and duration. (3) Disclose the IP transfer to Google US in your privacy policy and reference the EU US Data Privacy Framework. (4) Sign Google Maps Platform Terms of Service and Data Processing Amendment. (5) Consider whether a less privacy invasive alternative such as a static map image with a link to Google Maps would meet your needs without requiring consent. (6) If embedding is essential, audit all pages where maps appear and ensure the CMP blocks them by default.

GDPR consent category

Other

Websites using Google Business Profile must obtain user consent under GDPR regulations.

Legal basisConsent under Article 6(1)(a) GDPR for loading Google Maps and Google widgets that set cookies and disclose the IP address to Google in the United States
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (2002/58/EC)

DPIA considerations

A DPIA should be considered when Google Maps or place widgets are embedded on high traffic pages, given the systematic exposure of visitor IP addresses to Google in the United States. Key risk areas include: (1) IP address transmission to Google LLC as a third party controller on every page load that includes the map; (2) cookies set by Google that may be used for advertising; (3) international data transfer to the US under the EU US Data Privacy Framework. Organisations should assess whether the embedding is strictly necessary and whether less privacy invasive alternatives such as a static map image or a link to Google Maps would achieve the same purpose.

Sample consent text

We would like to embed an interactive Google Map on this page. Loading this map allows Google to see your IP address and may set cookies on your device. Do you agree to load the Google Map? [Show Map] [No thanks]

Technical details

Tracking methodEmbedded Google Maps and Google place or review widgets loaded from Google domains that expose the visitor IP and can set Google cookies
Server locationUnited States
Data transferred outside the EUWhen the embedded map or widget loads, the visitor IP address and request data go to Google LLC in the United States under the EU US Data Privacy Framework and standard contractual clauses

Third-party domains contacted

maps.googleapis.commaps.gstatic.comwww.google.com

Cookies placed

NameTypeDurationPurpose
NIDAdvertising / Preferences6 monthsGoogle identifier storing user preferences and used for advertising personalisation across Google properties
CONSENTPreference2 yearsRecords the visitor Google consent choices across Google domains
SOCSFunctionalSessionGoogle Maps operational state cookie managing map session data

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Google Business Profile embedding set?

Embedding a Google Map or Business Profile widget on your website causes Google to set several cookies on the visitor device. The main cookies are NID (a Google preferences and advertising identifier lasting 6 months), CONSENT (a 2 year cookie recording the visitor's Google consent choices) and SOCS (a Google Maps operational cookie). These are set under the google.com domain and can persist across sessions and other Google services.

Is consent required before loading an embedded Google Map?

Yes. Under Article 5(3) of the ePrivacy Directive, any script that stores or accesses information on the visitor's device requires prior consent, regardless of purpose. Additionally, the IP address transfer to Google in the US requires a legal basis under GDPR. The most common approach is to block the map iframe until the visitor actively opts in via your consent management platform or a dedicated show map button on the page.

What is the legal basis for embedding Google Maps on a website?

The appropriate legal basis is consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive. Legitimate interest is generally not sufficient for loading third party map iframes that set advertising cookies and transfer visitor IP to a third country, given the significant data processing impact on the visitor. Consent must be specific, informed, freely given and revocable. Some authorities have found legitimate interest acceptable only for strictly functional maps without advertising cookies, but this remains legally uncertain.

Does embedding Google Maps transfer data to the United States?

Yes. Every time the embedded Google Map or widget loads, the visitor IP address and request metadata are transmitted to Google LLC servers in the United States. This is an international data transfer under GDPR Chapter V. Google relies on the EU US Data Privacy Framework and standard contractual clauses. You must disclose this transfer in your privacy policy, including the transfer mechanism and Google's identity as recipient, and ensure Google Maps Platform Data Processing Terms are accepted.

Is a DPIA required for embedding Google Maps?

A DPIA may be required depending on the scale and sensitivity of the pages where the map appears. Factors pointing toward a DPIA include: systematic collection of visitor IPs on high traffic pages, transfer to a US third party controller (Google), use of advertising cookies, and embedding on pages where sensitive topics might be inferred from the visit. Consult your Data Protection Officer and your supervisory authority's DPIA trigger list to determine whether a formal assessment is mandatory.

How do I embed Google Maps in a GDPR compliant way?

Best practices for compliant embedding: (1) Replace live iframes with a static placeholder showing the location address and a show map button. (2) Only load the Google Map script after the user clicks the show map button or grants map consent in your CMP. (3) Add Google Maps cookies to your cookie policy with name, purpose, duration and provider. (4) Disclose the IP transfer to Google US in your privacy policy and reference EU US Data Privacy Framework. (5) Sign the Google Maps Platform Data Processing Amendment. (6) Explore whether a static map image with a link to Google Maps could serve the purpose without triggering consent requirements.

What are the privacy friendly alternatives to embedding Google Maps?

If you want to show your business location without triggering Google consent requirements, consider: (1) A static map image generated via a serverside call to the Maps Static API (the visitor does not load Google resources directly). (2) OpenStreetMap based embeds via Leaflet.js or OpenLayers, which can be self hosted and do not transfer data to US third party controllers. (3) A text address with a link to external Google Maps that the user can choose to open. (4) A simple map screenshot with a caption. Each alternative avoids the ePrivacy cookie consent requirement and limits international data transfer.

How do I update my cookie policy to cover the Google Maps embedding?

Your cookie policy must list cookies set by the Google Maps or Business Profile embedding. Add entries for: NID (google.com, 6 months, preferences and advertising), CONSENT (google.com, 2 years, Google consent state), SOCS (google.com, session or short term, Google Maps operational state). For each cookie include name, provider, purpose, duration and cookie category. Classify NID and CONSENT as advertising or analytics cookies. Link your cookie policy from the consent banner and update it whenever you change your map provider or add new Google integrations.