FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Google Sign-in
G

Google Sign-in

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Google Sign-In do?

Google Sign-In lets visitors authenticate with their Google account through the Identity Services library, the sign in button and the One Tap prompt. It simplifies login but loads Google code that can set cookies and share data with Google in the United States.

What Google Sign-In is

Google Sign-In, also presented as Sign in with Google, lets people authenticate on your site using their existing Google account. It is built on the Google Identity Services library and supports a branded button, a pop up flow and the One Tap prompt that can appear automatically. After the user authorises access, Google returns an identity token with profile details such as name, email and avatar.

What data and cookies it involves

Loading the Identity script contacts Google domains and exposes the visitor IP address and user agent. The One Tap flow uses a first party g_state cookie to remember dismissal, while authenticated sessions rely on Google account cookies such as SID, HSID, SSID and NID set in the google.com context. The profile data returned after sign in is personal data that you become responsible for once received.

GDPR and ePrivacy implications

Authentication that a user deliberately starts can rely on contract as its legal basis, and the session cookies needed to keep them logged in are strictly necessary. However, automatically loading the Identity script and showing One Tap before any user action processes data for Google purposes and falls under Article 5(3) of the ePrivacy Directive, so it needs consent. The two situations must be treated separately.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and the One Tap prompt

Do not auto display One Tap or load the Identity script before the visitor has had a chance to choose. Trigger the script only when the user clicks a clearly labelled login control, or gate automatic prompts behind consent for functional or marketing features. Make sure the prompt does not pressure users into accepting, since consent that is not freely given is invalid.

Data transfers to the United States

Authentication and profile data are processed by Google in the United States under the EU US Data Privacy Framework and standard contractual clauses. Disclose this transfer in your privacy notice, request only the scopes you genuinely need, and store the returned profile data securely with a defined retention period. Treat Google as a separate controller for the data it holds about the account.

Practical compliance steps

Load the Google Identity script on user action or after consent, disable automatic One Tap on first visit, request minimal scopes, and describe the login feature, the cookies and the US transfer in your privacy and cookie policies. Offer an alternative login method so visitors are not forced to use a Google account, and review requested permissions periodically.

GDPR consent category

Essential

Websites using Google Sign-In must obtain user consent under GDPR regulations.

Legal basisContract under Article 6(1)(b) GDPR for the authentication a user actively starts, and consent under Article 6(1)(a) for the Google Identity script and the One Tap prompt that load before any user action
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (2002/58/EC)

DPIA considerations

Distinguish the strictly necessary authentication a user starts from the One Tap prompt and Identity script that load automatically and expose data to Google. Assess the IP disclosure on script load, the profile fields requested, the lawfulness of US transfers, and whether One Tap nudges users in a way that undermines free consent.

Sample consent text

We offer sign in with your Google account. Loading Google login features shares data such as your IP address with Google, including in the United States, and may set Google cookies. We enable these features with your consent.

Technical details

Tracking methodGoogle Identity Services library implementing OAuth 2.0 and OpenID Connect, offering a sign in button and the One Tap prompt that exchange tokens with Google accounts
Server locationUnited States
Data transferred outside the EUAuthentication requests, account identifiers and profile data are processed by Google LLC in the United States. Transfers rely on the EU US Data Privacy Framework and standard contractual clauses. Loading the Identity script also exposes the visitor IP address to Google.

Third-party domains contacted

accounts.google.comapis.google.comwww.gstatic.comssl.gstatic.com

Cookies placed

NameTypeDurationPurpose
g_stateFunctionalUntil cleared or loginFirst party cookie set by the One Tap prompt to remember that the visitor dismissed or interacted with the sign in prompt.
SID / HSID / SSIDFunctionalUp to 2 yearsGoogle account cookies that authenticate the user and protect against unauthorised access to account data in the google.com context.
APISID / SAPISIDFunctionalUp to 2 yearsGoogle cookies used to enable Google account features and APIs, including the identity exchange used during sign in.
NIDMarketing6 monthsGoogle cookie storing preferences and identifiers that Google can also use for personalisation and advertising.

Google Sign-In is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Google Sign-In set?

The One Tap flow uses a first party g_state cookie to remember dismissal. Authenticated sessions rely on Google account cookies such as SID, HSID, SSID, APISID and NID set in the google.com context, which can persist for months. Your own session cookie keeps the user logged in to your site.

Is consent required?

The authentication a user actively starts and the session cookie that keeps them logged in are strictly necessary and exempt. Loading the Identity script or showing One Tap automatically before any action requires prior consent, because it shares data with Google for its own purposes.

What is the legal basis?

Contract under Article 6(1)(b) GDPR covers the login a user requests. The automatic loading of Google code and the One Tap prompt rely on consent under Article 6(1)(a), since they are not necessary to deliver the page.

Does it transfer data to the United States?

Yes. Google processes authentication and profile data in the United States under the EU US Data Privacy Framework and standard contractual clauses. Loading the script also exposes the visitor IP address to Google before any login occurs.

Do I need a DPIA?

A full DPIA is not always required for simple login, but you should document the processing. A DPIA becomes appropriate if you enable automatic One Tap, request broad scopes, or combine the profile data with profiling or marketing.

How do I implement it compliantly?

Load the Identity script only on user action or after consent, disable automatic One Tap on first visit, request the minimum scopes, and store profile data securely with a retention limit. Always offer an alternative login that does not require a Google account.

Are there alternatives?

You can offer email and password login, magic links, or other identity providers, and self hosted options such as Keycloak keep authentication within the European Union. Offering a choice avoids forcing visitors into the Google ecosystem.

How do I update my cookie policy?

Describe the g_state One Tap cookie and the Google account cookies, explain that the Identity script shares the IP address with Google, and disclose the US transfer. Note which elements are strictly necessary and which depend on consent.