The agreement prohibits users from uploading to GTM any data that personally identifies an individual, including names, email addresses, and billing information, as well as data that Google can reasonably link to such identifying information.
This analysis describes what Google's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a direct contractual obligation on GTM users to configure tags and data layer implementations so that no personally identifiable or reasonably linkable data is transmitted through the GTM platform. Breach of this restriction constitutes a terms violation and may also implicate applicable data protection law depending on jurisdiction.
Under this clause, users are contractually required to ensure that no PII, including names, email addresses, or billing data, passes through the GTM service, and this obligation extends to preventing third parties from doing so as well through the user's account.
Cross-platform context
See how other platforms handle Prohibition on Uploading Personally Identifiable Information and similar clauses.
Compare across platforms →"You agree not to, and not to allow third parties to use the Service or interfaces provided with the Service: to upload any data to Google Tag Manager that personally identifies an individual (such as a name, email address or billing information), or other data which can be reasonably linked to such information by GoogleExcerpt from Google's Tag Manager Terms of Service
(1) REGULATORY LANDSCAPE: This provision interacts with GDPR Article 5 data minimization and purpose limitation principles, as well as Article 25 data protection by design obligations for EU/EEA deployments.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a direct contractual obligation on GTM users to configure tags and data layer implementations so that no personally identifiable or reasonably linkable data is transmitted through the GTM platform. Breach of this restriction constitutes a terms violation and may also implicate applicable data protection law depending on jurisdiction.
Under this clause, users are contractually required to ensure that no PII, including names, email addresses, or billing data, passes through the GTM service, and this obligation extends to preventing third parties from doing so as well through the user's account.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google.