Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Google Sign-In lets visitors authenticate with their Google account through the Identity Services library, the sign in button and the One Tap prompt. It simplifies login but loads Google code that can set cookies and share data with Google in the United States.
Google Sign-In, also presented as Sign in with Google, lets people authenticate on your site using their existing Google account. It is built on the Google Identity Services library and supports a branded button, a pop up flow and the One Tap prompt that can appear automatically. After the user authorises access, Google returns an identity token with profile details such as name, email and avatar.
Loading the Identity script contacts Google domains and exposes the visitor IP address and user agent. The One Tap flow uses a first party g_state cookie to remember dismissal, while authenticated sessions rely on Google account cookies such as SID, HSID, SSID and NID set in the google.com context. The profile data returned after sign in is personal data that you become responsible for once received.
Authentication that a user deliberately starts can rely on contract as its legal basis, and the session cookies needed to keep them logged in are strictly necessary. However, automatically loading the Identity script and showing One Tap before any user action processes data for Google purposes and falls under Article 5(3) of the ePrivacy Directive, so it needs consent. The two situations must be treated separately.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Do not auto display One Tap or load the Identity script before the visitor has had a chance to choose. Trigger the script only when the user clicks a clearly labelled login control, or gate automatic prompts behind consent for functional or marketing features. Make sure the prompt does not pressure users into accepting, since consent that is not freely given is invalid.
Authentication and profile data are processed by Google in the United States under the EU US Data Privacy Framework and standard contractual clauses. Disclose this transfer in your privacy notice, request only the scopes you genuinely need, and store the returned profile data securely with a defined retention period. Treat Google as a separate controller for the data it holds about the account.
Load the Google Identity script on user action or after consent, disable automatic One Tap on first visit, request minimal scopes, and describe the login feature, the cookies and the US transfer in your privacy and cookie policies. Offer an alternative login method so visitors are not forced to use a Google account, and review requested permissions periodically.
Websites using Google Sign-In must obtain user consent under GDPR regulations.
DPIA considerations
Distinguish the strictly necessary authentication a user starts from the One Tap prompt and Identity script that load automatically and expose data to Google. Assess the IP disclosure on script load, the profile fields requested, the lawfulness of US transfers, and whether One Tap nudges users in a way that undermines free consent.
Sample consent text
We offer sign in with your Google account. Loading Google login features shares data such as your IP address with Google, including in the United States, and may set Google cookies. We enable these features with your consent.
Third-party domains contacted
accounts.google.comapis.google.comwww.gstatic.comssl.gstatic.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| g_state | Functional | Until cleared or login | First party cookie set by the One Tap prompt to remember that the visitor dismissed or interacted with the sign in prompt. |
| SID / HSID / SSID | Functional | Up to 2 years | Google account cookies that authenticate the user and protect against unauthorised access to account data in the google.com context. |
| APISID / SAPISID | Functional | Up to 2 years | Google cookies used to enable Google account features and APIs, including the identity exchange used during sign in. |
| NID | Marketing | 6 months | Google cookie storing preferences and identifiers that Google can also use for personalisation and advertising. |
Google Sign-In is an essential service, but transparency matters. Manage all your consent with FlowConsent.
The One Tap flow uses a first party g_state cookie to remember dismissal. Authenticated sessions rely on Google account cookies such as SID, HSID, SSID, APISID and NID set in the google.com context, which can persist for months. Your own session cookie keeps the user logged in to your site.
The authentication a user actively starts and the session cookie that keeps them logged in are strictly necessary and exempt. Loading the Identity script or showing One Tap automatically before any action requires prior consent, because it shares data with Google for its own purposes.
Contract under Article 6(1)(b) GDPR covers the login a user requests. The automatic loading of Google code and the One Tap prompt rely on consent under Article 6(1)(a), since they are not necessary to deliver the page.
Yes. Google processes authentication and profile data in the United States under the EU US Data Privacy Framework and standard contractual clauses. Loading the script also exposes the visitor IP address to Google before any login occurs.
A full DPIA is not always required for simple login, but you should document the processing. A DPIA becomes appropriate if you enable automatic One Tap, request broad scopes, or combine the profile data with profiling or marketing.
Load the Identity script only on user action or after consent, disable automatic One Tap on first visit, request the minimum scopes, and store profile data securely with a retention limit. Always offer an alternative login that does not require a Google account.
You can offer email and password login, magic links, or other identity providers, and self hosted options such as Keycloak keep authentication within the European Union. Offering a choice avoids forcing visitors into the Google ecosystem.
Describe the g_state One Tap cookie and the Google account cookies, explain that the Identity script shares the IP address with Google, and disclose the US transfer. Note which elements are strictly necessary and which depend on consent.