Summary
The purpose of confidential computing, or Trusted Execution Environments, in Google Ads Data Manager is to process first-party data securely and protect user privacy. Identifiers are hashed before they leave your systems and matched inside an encrypted enclave that nobody can read into. This is what gives privacy and legal teams the confidence to approve first-party data connections for Customer Match and enhanced conversions.
Nitin Batra is a Google Ads Search certified professional who configures first-party data connections in Google Ads Data Manager, including Customer Match and enhanced conversions setups, for live advertiser accounts.
Last updated: August 22, 2026
Confidential computing, or Trusted Execution Environments, is used in Google Ads Data Manager to process first-party data securely and protect user privacy, keeping customer data encrypted and isolated even while it is being matched.
- To allow Google to access unhashed personally identifiable information.
- To process first-party data securely and protect user privacy.
- To automatically increase daily spend for the advertiser.
- To replace the need for the Google tag.
The correct answer is: To process first-party data securely and protect user privacy.
Key Takeaways
- – Confidential computing, or Trusted Execution Environments, exists in Google Ads Data Manager to process first-party data securely and protect user privacy.
- – Identifiers such as email and phone number are hashed with SHA-256 before they leave your systems, and the match runs inside an encrypted, isolated enclave that no one can inspect.
- – It protects data in use, which is the gap that ordinary encryption at rest and in transit does not cover, and this is what makes secure customer data matching possible.
- – It does not remove your own obligations. You still need proper consent, a valid privacy policy and lawful basis for the customer data you connect, and it does nothing to change bidding, budgets or the need for the Google tag.
What is a Trusted Execution Environment in simple terms?
It is a hardware protected, isolated area of a processor where code and data are encrypted while they are being processed. Even the operator of the machine cannot read what is inside. In Google Ads Data Manager, this is where your hashed first-party identifiers are matched against Google accounts, so the underlying data is never exposed.
Does Google Ads Data Manager see my customers' raw email addresses?
No. Data Manager hashes identifiers using SHA-256 before they are sent, so Google receives the hash and not the plain text email or phone number. The comparison then happens inside the Trusted Execution Environment. Any answer suggesting the purpose is to give Google access to unhashed personally identifiable information is wrong.
Where do I actually connect my first-party data in Google Ads Data Manager?
In the Google Ads interface, go to Tools, then Data manager. From there you add a connection and pick your source, which can be BigQuery, Google Cloud Storage, Salesforce, Snowflake, HTTPS or a file upload. You then map your columns to the accepted fields such as email, phone number, first name, last name, country and postal code, and choose the destination, for example a Customer Match list or enhanced conversions for leads.
Does confidential computing replace the Google tag or the need for consent mode?
It does not. The Google tag still handles site side measurement and the passing of conversion data, and consent mode still governs how user consent signals are respected. Confidential computing only concerns how first-party data is protected during processing inside Data Manager. Treat them as separate layers that all need to be set up correctly.