AdSense rejected: missing privacy policy or required pages
This is the least excusable rejection on the list, because it costs an afternoon to fix and reviewers check for it first. AdSense requires a privacy policy that discloses third-party advertising and cookie use; in practice reviewers also expect reachable about and contact pages, linked from somewhere visible on every page.
How to fix it
- Write a privacy policy that names what you actually do. It must disclose that third parties, including Google, use cookies to serve ads based on prior visits, and how a visitor opts out. A generic template that never mentions advertising does not satisfy this.
- Publish an about page that identifies who is behind the site. A real name or organisation, what the site covers, and why you are worth reading on it. Anonymous sites are approved, but they clear a higher bar on everything else.
- Publish a contact page that actually works. An email address or a working form. A contact page whose form is broken is worse than none, because it fails visibly.
- Link all three from the footer. Every page, not just the homepage. Reviewers land on interior pages and look for these links where every site puts them.
- Check each page loads logged out. A privacy policy behind a broken permalink, or an about page still in draft, counts as missing.
Why this rejection is worth being annoyed about
Everything else in the rejection list involves a judgement you can argue with.
This one does not. A reviewer looked for a privacy policy, did not find one, and
stopped. The fix takes an afternoon, and the cost of not doing it beforehand is a
full review cycle.
It is also the rejection most likely to be hiding behind another one. A site
declined for "low value content" that also has no privacy policy has two
problems, and only one of them was named.
What the privacy policy has to cover
The AdSense requirement is narrower than most publishers assume, and most
templates miss exactly the part that matters. The policy must disclose:
- That third parties, Google included, use cookies to serve ads based on a
visitor's prior visits to your site or other sites - That visitors can opt out of personalised advertising through Google's Ads
Settings - How to opt out of third-party vendors' use of cookies
A privacy policy that discusses your newsletter and your analytics but never
mentions advertising does not meet this, however professional it looks.
Separately from AdSense's requirement, if you have visitors in the EU or
California you have legal obligations that a generated template will not
discharge on its own. Those are not the same problem, and clearing one does not
clear the other.
The two pages that are not required but keep appearing
Neither an about page nor a contact page is a formal AdSense requirement. Both
show up constantly in rejection post-mortems anyway, and the reason is
straightforward: reviewers use them to decide whether they are looking at a
publication or at a site assembled to carry ads.
An about page should identify who is behind the site and why they are worth
reading on the subject. That is the same first-hand credibility that keeps a site
clear of "low value content", so the work is not wasted on a formality.
A contact page needs a route that actually reaches you. A form that silently
fails is worse than no form, because it fails in front of the reviewer.
Link them where reviewers look
Footer, on every page. Not only on the homepage, and not only in a menu that
collapses on mobile. Reviewers frequently land on an interior page from a search
result, and they look for these links where every publication puts them.
Then open each one in a private window. A privacy policy behind a broken
permalink, an about page still saved as a draft, or a contact page gated behind a
login all count as missing — and all three are invisible to the logged-in owner.
Frequently asked
- What must an AdSense privacy policy actually say?
- At minimum: that third-party vendors including Google use cookies to serve ads based on a user's prior visits to your site and other sites, that users can opt out of personalised advertising through Google's Ads Settings, and how to opt out of third-party vendors' cookies. If you are in scope for GDPR or CCPA, considerably more is required, and a generic template will not cover it.
- Is a generated privacy policy good enough?
- For the AdSense requirement specifically, a generated policy that includes the advertising and cookie disclosures usually is. For your actual legal obligations it may not be, because it describes a generic site rather than yours — what you collect, what analytics you run, what forms you have. Treat the generator's output as a starting draft.
- Does AdSense require a terms of service page?
- No. Terms and a disclaimer are good practice and cheap to add, but the hard requirement is the privacy policy. About and contact pages are not formally required either, yet their absence is a recurring factor in rejections because reviewers use them to judge whether a site is a real publication.
- How fast can I re-apply after fixing this?
- As soon as the pages are live and linked. This is the fastest rejection on the list to clear, because it is a checklist rather than a judgement.
Check whether this is still blocking you
The free Monetific checker tests your site against this and every other mechanical requirement, and tells you what is still outstanding before you re-apply.
Run the free check