A fintech landing page does not get reviewed once. It gets reviewed four times, by four parties who do not talk to each other and do not share a definition of the word compliant.
Most advice about landing page compliance covers one of them. Search the term and you will find cookie banners, privacy policies and consent management. That is real work, and it is the first of the four, but it is the one that matters least if your ad account is what is at risk. The other three are the platform’s policy team, the regulator in the market you advertise into, and your own legal reviewer, the only one who can stop you before you lose anything.
For a regulated offer, landing page compliance means four things at once: consent collected before tracking loads, a form that takes permission in the form the law specifies, a destination that satisfies the ad platform, and a page that names whoever is legally responsible for it. This covers all four in the order they bite, and it is written so a growth lead can forward it to their reviewer without translating it first.
The short version
- Consent for non-essential cookies has to be collected before they are set, not after the page loads.
- A US form that feeds a dialer needs prior express written consent, and the one-to-one rule several ranking guides still describe is not in the current regulation.
- Google requires a physical business address and all associated fees on the destination, visible without a click or a hover.
- A UK promotion has to name the firm, and which rule says so depends on whether you sell credit or investments.
- Google’s UK verification matches your details against the FCA register exactly. A trading-name difference fails it while your authorisation is perfectly valid.
Table of Contents
Check one: consent has to happen before anything fires
Start here, because it is the check most likely to be half-done already.
In the UK the rule is PECR, and the ICO states it plainly: you cannot set non-essential cookies on a page before the user has consented. Consent must be “freely given, specific and informed” and needs “some form of unambiguous positive action, for example ticking a box or clicking a link”. Continuing to use the site is not consent.
There are two exemptions and only two: cookies whose sole purpose is carrying out the transmission of a communication, and cookies strictly necessary to provide a service the user asked for. Anything helpful or convenient but not essential still requires consent. A conversion pixel is neither. Nor is session replay.
The failure mode is structural rather than careless: the tag manager fires on page load and the cookie consent banner asks afterward. The page looks compliant; the network tab says otherwise, and the network tab is what an investigator opens first.
One thing this piece does not claim: the US position. State privacy laws differ from each other and from PECR, and we will not summarize them from memory on a page about getting compliance right. If your traffic is US-only, take the above as the UK rule and get counsel’s read on the US equivalent.
SOURCE · ICO · Cookies and similar technologies, PECR guidance
ico.org.uk/for-organisations/direct-marketing-and-privacy- — checked 20 September 2026.
Check two: the TCPA consent language underneath the form
If your page captures a phone number and anything downstream dials it, the sentence under that field is a legal instrument, not microcopy. Treat it accordingly.
The federal rule is 47 CFR 64.1200 and the standard is prior express written consent. The regulation defines it as “an agreement, in writing, bearing the signature of the person called that clearly authorizes the seller to deliver or cause to be delivered… advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice, and the telephone number to which the signatory authorizes such advertisements or telemarketing messages to be delivered.”
Three things that agreement has to carry:
- A clear and conspicuous disclosure that signing authorizes automated or prerecorded calls.
- A statement that the person is not required to sign, directly or indirectly, as a condition of purchasing any property, goods or services.
- The specific telephone number being authorized.
Workable TCPA consent language does all three inside the checkbox, not in the privacy policy the checkbox links to. A disclosure that needs a click to read is not conspicuous.
One correction, because several of the guides ranking for this term have it wrong: the one-to-one consent requirement is not in the current text of the regulation. It was not in 64.1200(f) on the eCFR when we checked it on 20 September 2026. If your consent language was rewritten to name a single seller, that is not wrong, but nothing in the section as it stands requires it.
SOURCE · eCFR · 47 CFR 64.1200
www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part- — checked 20 September 2026.
This is what an Acquisition Audit finds in week one. Not a strategy problem: a page that will be disapproved or returned by legal the moment someone looks closely. Two weeks, $2,500, fixed, credited in full to your first month. See what the Acquisition Audit covers.
Check three: the Google Ads landing page requirements that apply before finance adds its own
Google’s financial products and services policy is the one that bites soonest, because it is enforced by disapproval rather than by correspondence.
Start with what it asks of every destination, whatever the product. Disclosures “must be clearly and immediately visible without needing to click or hover over anything”, and the page has to carry a physical business address, all associated fees, and a link to the accreditation behind any affiliation you assert.
For personal loans it is more specific. You must prominently disclose all of the following on the destination:
- The minimum and maximum period for repayment.
- The maximum APR, stated separately from the example.
- A representative APR example of the total cost of the loan, including all applicable fees.
Two hard limits sit alongside those, and both are scoped to personal loans specifically. “Only personal loans that require repayment in full in 61 days or longer are allowed.” And in the United States, “Google doesn’t allow ads for personal loans with an APR of 36% and above.” Debt settlement, complex speculative products such as CFDs, forex and spread betting, and prediction markets each need separate certification first.
Then there are the Google Ads landing page requirements that have nothing to do with finance and disapprove ads anyway. The display URL’s domain has to match where the user actually lands. A destination mismatch introduced by a tracking template is a policy violation, not a technical inconvenience. The page has to be crawlable by AdsBot, or Google cannot verify it matches the ad’s claims, and reachable from every location you target, which catches teams who geo-fence their own site. It is the same policy surface we work in every day on fintech paid search accounts.
Clearing Google’s review is not the same as clearing the law. For a consumer financial product in the US, the CFPB judges a page by its overall net impression, and a disclosure in fine print may not be enough to correct a misleading claim. UDAAP for fintech marketers covers the three tests and who they reach.
SOURCE · Google Ads Help · Financial products and services, and Destination requirements
support.google.com/adspolicy/answer/2464998 — checked 20 September 2026.
Check four: whose name is on the page
The UK adds a requirement the other three do not: the page has to say who is responsible for it. Which rule says so depends on what you sell, and that is where this gets missed.
If you are in consumer credit, which covers lending, credit broking and buy-now-pay-later, the sourcebook is CONC. CONC 3.3.2R(3) requires a financial promotion to specify “the name of the person making the communication or communicating the financial promotion or the person on whose behalf the financial promotion is made”. If you broker rather than lend, CONC 3.3.2R(4) adds that you must also name the lender where you know it, a requirement a lot of comparison and marketplace pages simply do not meet.
If you are in designated investment business the sourcebook is COBS, and the rule is COBS 4.5.2R(1): the name of the firm, and where relevant the name of the firm that confirmed compliance. COBS 4.5.3G(3) adds that it should carry enough prominence for a retail client to easily identify who is responsible.
COBS then offers a concession for digital formats. COBS 4.5.2AR permits the firm name and approval details to sit on a webpage the promotion clearly links to, in the form “Approver FRN [firm reference number]”. That concession belongs to COBS. There is no equivalent in CONC. A lending page that moves its firm name behind a link because it read the COBS rule has satisfied the wrong sourcebook. Other regulated products have their own sourcebooks again, so check which one covers yours before copying a rule out of any blog post, this one included.
Behind it sits section 21 of FSMA. An unauthorised person may communicate a financial promotion only where it “has been approved by an authorised person, ie a s21 approver, who is lawfully able to approve that promotion”. Since the gateway introduced by PS23/13, a firm “can only approve a financial promotion if the FCA has granted the firm permission to do so, or the approval falls within the scope of an exemption”: appointed representatives, approvals within a corporate group, and a firm’s own promotions.
Over all of it sits one standard both sourcebooks open with, in nearly identical words. CONC 3.3.1R and the FCA’s own summary alike: every promotion must be fair, clear and not misleading, regardless of media type. That is why a risk warning below the fold, or a return figure set larger than the caveat beside it, is a finding rather than a design choice.
One trap sits between the regulator and the platform. Google’s UK verification requires that “the business information you provide during this verification process must exactly match with the business details available on the UK FCA registry or records”, and asks for the domains listed there plus any others you advertise from. A trading name differing from the FCA Financial Services Register entry fails verification while the authorisation itself is perfectly valid. We wrote that gate up in full in our piece on Google Ads financial services verification.
SOURCE · FCA Handbook CONC 3.3 and COBS 4.5, and Google Ads Help · Financial services verification (United Kingdom)
www.handbook.fca.org.uk/handbook/CONC/3/3.html — checked 20 September 2026.
The landing page compliance pass to run before legal sees the page
None of this needs a lawyer to spot. Run the pass yourself and you will clear most of what a reviewer would send back.
- Load the page in a clean profile with the network tab open. Note every request that fires before you touch the banner. Anything non-essential there is a finding.
- Read it at 390px. A disclosure visible on desktop but collapsed behind a tap on mobile is not visible without a click.
- Check the display URL’s domain against the real destination, including through the tracking template.
- If there is a phone field, confirm the consent text carries all three elements above.
- If you advertise into the UK, find the firm name on the page itself. If you cannot in ten seconds, it is not prominent enough, and check you are reading the right sourcebook.
- Confirm the page is not blocked to AdsBot in robots.txt.
That is the whole pass. It is short, and it moves the findings from your reviewer’s desk to yours, which is where they are cheap to fix. We are turning the same ground into a one-page US and UK checklist in mid-October.
FAQ: landing page compliance for fintech
What happens if Google disapproves the landing page rather than the ad?
The disapproval attaches to the ad, but the cause sits on the page, so editing ad copy will not clear it. Destination problems repeat across every ad pointing at that URL, which is why one page can look like an account-wide fault. If the account itself has been restricted, that is a different process, covered in our piece on recovering a disabled fintech ad account.
Do I need FCA authorisation to advertise a financial product in the UK?
There are two gates and they are independent. The regulatory one is authorisation, a section 21 approver, or an exemption. The platform one is Google’s verification. Clearing either does not clear the other, and they fail in opposite directions: firms with valid authorisation get stuck at verification over a name mismatch, and firms that pass verification can still be communicating an unapproved promotion.
We only email our leads. Does the TCPA consent language still apply?
That standard governs calls and texts delivered by automated systems or prerecorded voice, so if nothing dials or texts the number, it is not what binds you. The practical problem is that lead records outlive the campaign that collected them. A number captured without consent limits what sales can do with it six months later.
What to do next
Run the six-step pass on your highest-spend landing page this week. If it comes back clean, your other pages probably share the template and you have less exposure than you thought. If it comes back with findings, you have them before a reviewer or a policy team does.
Where landing page compliance goes wrong is rarely ignorance of the rules. It is four reviewers each assuming one of the other three already checked the thing they care about.
If you would rather someone else ran that pass across the whole account, it is the first week of an Acquisition Audit: a paid account and compliance-risk review, a keyword and demand map, a tracking and attribution gap analysis, and a prioritised 90-day plan. Start the Acquisition Audit, or read what we report on first.


