When we talk about first-party data with a client, the first reaction is nearly always one of two: "weren’t cookies supposed to disappear?" or "we uploaded a list years ago". The first question has been overtaken by events; the second, more often than not, describes a list that is doing nothing today. In this article we set out what has changed, what you need to use Customer Match in Europe in 2026, and which lists are actually worth building.
Customer Match in two lines
Customer Match is the Google Ads feature that lets you upload your customers’ contact details — email, phone number, name and address — and match them to Google accounts. The data is hashed before matching. The result is an audience you can use on Search, Shopping, YouTube, Gmail, Display and in Performance Max and Demand Gen campaigns: to reach those people, to exclude them or, increasingly, to tell the algorithms who your customers are.
Third-party cookies have not gone. It matters anyway.
For years first-party data was sold as preparation for the end of third-party cookies in Chrome. That end never came. In April 2025 Google announced it would keep its current approach, leaving the choice to users in Chrome’s settings, and would not introduce the standalone prompt it had floated. On 17 October 2025 it went on to announce the retirement of most Privacy Sandbox technologies, including Topics, Protected Audience and Attribution Reporting.
So why keep talking about it? For three very practical reasons:
- Cookies were never the main problem in Europe. A significant share of users reject advertising cookies in the banner, and other browsers already block them. The audience you can observe on your site is partial regardless.
- First-party data does not depend on the browser. A customer who gave you their email and their consent stays recognisable on any device where they are signed in to Google.
- Automated campaigns run on signals. Performance Max, Demand Gen and customer lifecycle goals use lists to understand who is already a customer and who is worth more. Without lists, those features work blind or not at all.
- March 2024 Customer Match requires consent signals on every upload for EEA users.
- 7 April 2025 Maximum list membership set at 540 days, applied to existing lists too.
- April 2025 Google confirms Chrome will keep third-party cookies with users’ current choices.
- 17 October 2025 Retirement of most Privacy Sandbox technologies announced.
- December 2025 Data Manager API launched; the minimum audience size drops to 100 users across all networks.
- 1 April 2026 Customer Match uploads via the Google Ads API blocked for inactive developer tokens.
Who can use it: account requirements
The Customer Match policy requires the account to have a good history of policy compliance and a good payment history. At the time of writing, the policy page then distinguishes two tiers: all policy-compliant advertisers can use lists in observation and as exclusions; full targeting and manual bid adjustments are listed for accounts with at least 90 days of history and more than USD 50,000 in lifetime spend. In practice, check what your account actually lets you do: that is what counts.
Since January 2025 Google has also made clear it can withdraw Customer Match access from accounts whose ads may harm users or create a poor experience, taking into account user feedback, severity and repeated violations. A warning is issued at least seven days before any suspension. The policy also restates two basics: the data must have been collected by you, with the necessary consent, and it must not be used to reach people under 18.
Consent in Europe: where lists stop working
Under the Digital Markets Act, Google updated its EU user consent policy. Since March 2024, to use a Customer Match list with EEA users, every upload must carry two consent signals: ad_user_data (sending data to Google for advertising purposes) and ad_personalization (ad personalisation). Both must be granted.
The box many people leave unticked. When you upload a list through the Google Ads interface, there is a checkbox confirming you have obtained consent. Leave it empty and the consent status is sent as unspecified, and Google ignores the data of EEA and UK users. The upload looks successful, the list has a name and a date, but for a business selling in Europe the usable part can be close to nothing. Ticking it, of course, only makes sense if you genuinely hold that consent.
It is the same principle that governs tags on your site, which we covered in our article on Consent Mode v2 and the DMA: there consent travels with every event, here with every uploaded contact. If your CRM does not know who gave which consent, the problem is not Google Ads: it is the CRM.
How to upload: interface, Data Manager, API
There are three routes, and in 2026 the choice is no longer neutral.
| Method | Who it suits | Notes |
|---|---|---|
| File upload in the interface | Getting started, small lists | Simple but manual: lists start ageing the moment you stop re-uploading |
| Data Manager (interface) | Most SMEs | Direct connections to sources such as HubSpot, Salesforce, BigQuery and Google Sheets; the same connection can feed conversions too |
| Data Manager API | Custom integrations, CDPs, developers | The route Google points to for new programmatic integrations |
The biggest change affects anyone uploading through an API. Since 1 April 2026, developer tokens that had not uploaded Customer Match data via the Google Ads API in the previous 180 days can no longer do so: their requests are rejected. The rest of the Google Ads API — campaign management, bidding, reporting — carries on as before. The way forward is the Data Manager API, launched at the end of 2025 as a single entry point for data into Google Ads, Google Analytics and Display & Video 360. Offline conversions have taken the same path, as we explain in our article on enhanced conversions for leads and the Data Manager API: it makes sense to design one pipeline from your CRM to Google, not two.
If you rely on a third-party connector or a CDP, ask the vendor two things explicitly: whether it has moved to the Data Manager API, and how it passes consent signals for each contact.
Size, match rate and duration
Three numbers worth knowing:
- 100 active users. The minimum for a list to be usable. In May 2025 Google lowered it from 1,000 to 100 for Search campaigns, and in December 2025 extended it to all networks and audience types. What counts is matched users, not rows in the file: upload 300 contacts and you will not necessarily reach 100.
- 540 days. Since 7 April 2025 list membership lasts at most 540 days, and the limit was applied retroactively to lists with no expiry. A customer uploaded once and never refreshed drops out. If you do not re-upload, the list shrinks on its own until it can no longer serve.
- Match rate. There is no guaranteed figure. It depends on how many of your customers use a Google account with those details. We see it often in B2B: work email addresses match worse than personal ones, and adding phone and address helps.
How lists are used today
How lists are used has changed more than the requirements. Email-style remarketing — "show an ad to people who are already customers" — has become the least interesting use. The ones that matter:
Audience signals in Performance Max and Demand Gen
In Performance Max a list added as an audience signal does not restrict reach: it tells the system where to start. In Demand Gen, customer lists are the best seed for lookalike segments, as we explain in our Demand Gen guide: the quality of the seed decides the quality of the audience.
Observation or targeting
On Search the distinction is clear-cut. In observation ads still reach everyone, but you can read the segment’s results — how existing customers convert compared with new ones — and bidding gets one more piece of information. In targeting you restrict the campaign to people on the list: that only makes sense for dedicated campaigns, for instance a brand campaign for existing customers with different messaging.
Exclusions and new customer acquisition
If your goal is acquisition, paying for clicks from existing customers is often waste. On Search and other campaigns you can exclude the customer list. In Performance Max and Search the most complete lever is the new customer acquisition goal, which can bid only for new customers or bid more for them; the high-value new customer version needs a list of your best customers. Lists are the main signal Google uses to tell a new customer from an existing one: without up-to-date lists, that goal works poorly.
Retention
Google has also introduced a retention goal in Performance Max, with a re-engagement mode that lets you bid more for customers who have not bought for a while. Here too the prerequisite is a list that defines who counts as "lapsed", and that is kept up to date.
Which lists to build
You do not need a list for every CRM segment. A few, well maintained, are enough:
| List | How to define it | Main use |
|---|---|---|
| All customers | Anyone who has bought or signed at least once, within a sensible window | Exclusions, new customer goal |
| High-value customers | For example the top 20% by revenue or margin, or repeat buyers | PMax signal, lookalike seed, high-value new customers |
| Lapsed customers | No purchase for longer than your typical repurchase cycle | Retention, re-engagement campaigns |
| Leads that did not close | Qualified contacts who never became customers | Re-engagement or exclusion, depending on why |
Leads that did not close deserve some thought. If they did not buy because of price or timing, a dedicated campaign may make sense. If they were never a fit, using them as a seed teaches the algorithm to look for more of the wrong people: better to exclude them.
CRM hygiene beats optimisation
The quality of a list is decided before the upload. The rules we apply:
- Normalise the data. Emails in lower case with no spaces, phone numbers with the international prefix, separate name and address fields.
- Record consent in the CRM, per contact, with date and source. That is the information that has to travel with the upload.
- Handle objections. Anyone who asks not to be contacted or objects to processing must also leave the lists at the next refresh.
- Automate the refresh. With Data Manager or an API integration, lists update themselves. As a rule of thumb: at least monthly for signals, more often for exclusions, because a customer acquired yesterday should not see a "first order discount" ad today.
- Check the diagnostics. Matched size, upload errors, date of the last refresh: if a list is not growing or is shrinking, something has broken.
GDPR basics, without replacing your adviser
This is not legal advice, but there are a few points every business should check with whoever handles data protection before uploading a list:
- Lawful basis. On what basis can you use this data for advertising? The answer must be documented, and Google’s consent requirements sit on top of the GDPR’s, not in place of them.
- Privacy notice. People who give you their details should know they may be shared with advertising platforms such as Google to show or exclude ads.
- Minimisation and retention. Upload only the fields you need and only the contacts for whom it makes sense. Google’s 540-day limit does not replace your own retention periods.
- Data subject rights. Objection and erasure must take effect on uploaded lists too.
Checklist
- Check what your account allows: observation and exclusion, or targeting as well.
- Check that uploads carry consent and that the confirmation checkbox is handled deliberately.
- If you upload via API, make sure you are on the Data Manager API or on a connector that uses it.
- Build the four core lists and check they clear 100 matched users.
- Automate the refresh and schedule it like any other process.
- Use lists as signals, exclusions and goals, not just as a remarketing audience.
If you want to know what your first-party data is worth inside Google Ads today, our free audit starts right here: which lists exist, how fresh they are and whether consent is actually getting through. You can see our services, our process and the answers to the most common questions in the FAQ.