Skip to content
Brief

Global Privacy Platform (GPP)

Privacy & Consent Management StandardsProduct· part of IAB Tech Lab

GPP consolidates consent and privacy signals from all major global regulations into a single standardized string, dramatically reducing integration complexity for publishers, CMPs, and ad tech vendors operating across multiple jurisdictions.

Last updated Sep 26, 2026 by ATDb automated enrichment · Connections updated Sep 28, 2026

Founded
2022
HQ
New York, NY, United States
Connections
12

AI-drafted from public sources2 sources cited

At a glance

11integrations1corporate family

About

The dominant open industry standard for multi-jurisdictional privacy signal transmission in programmatic advertising, maintained by IAB Tech Lab

The Global Privacy Platform (GPP) is an open technical standard developed and maintained by IAB Tech Lab designed to streamline the communication of user privacy preferences and consent signals across the programmatic advertising ecosystem. Rather than requiring separate integrations for each regional privacy regulation, GPP provides a unified container string that can carry consent and opt-out signals for multiple jurisdictions simultaneously — including GDPR (via TCF), CCPA/CPRA (via the US Privacy String and US National Privacy Technical Specification), and other regional frameworks. GPP was introduced to address the growing complexity of global privacy compliance as regulations proliferated across the US states and internationally. Publishers, CMPs (Consent Management Platforms), DSPs, SSPs, and ad servers can implement a single GPP integration and receive structured, machine-readable privacy signals regardless of the user's jurisdiction. The framework uses a modular architecture where each regulatory section is encoded as a discrete 'section' within the GPP string, allowing new regulations to be added without breaking existing integrations. As a technical standard rather than a commercial product, GPP is freely available and open-source, governed by IAB Tech Lab's working groups with input from major industry stakeholders including publishers, ad tech vendors, and privacy advocates. Its adoption is considered critical infrastructure for privacy-compliant programmatic advertising, and it is increasingly required by major DSPs and SSPs as a condition of doing business. GPP effectively supersedes and extends earlier frameworks like the IAB US Privacy String and works alongside TCF 2.x for European consent.

Business model

Open-source industry standard / Non-profit trade body initiative

Target market

Enterprise

What they offer

  • GPP String

    A standardized, encoded container string that carries privacy and consent signals from multiple regulatory frameworks in a single payload, transmitted via the ad request or JavaScript API

  • GPP JavaScript API

    A standardized browser-side API (similar to __tcfapi and __uspapi) that CMPs implement to expose GPP signals to ad tech vendors on the page

  • US National Privacy Technical Specification

    A GPP section covering US state-level privacy laws (CPRA, VCDPA, CPA, CTDPA, etc.) with a unified opt-out signal structure for US multi-state compliance

  • TCF Section Integration

    Native support for embedding IAB Europe's Transparency and Consent Framework (TCF 2.x) signals as a discrete section within the GPP string for GDPR compliance

  • GPP Header Field

    A standardized field for passing GPP strings in OpenRTB bid requests, enabling downstream buyers to parse and honor privacy signals programmatically

Key features

Modular section-based architecture supporting multiple regulatory frameworks simultaneouslySingle unified string replacing multiple separate privacy strings (USP, TCF, etc.)Standardized JavaScript API for CMP-to-vendor signal communication on the pageOpenRTB integration for server-to-server signal passing in bid requestsExtensible design allowing new regulatory sections to be added as laws evolveOpen-source specification with publicly available documentation and reference implementationsBackward compatibility with existing TCF 2.x and US Privacy String implementations

Use cases

Publishers passing user consent and opt-out signals to all demand partners via a single stringCMPs encoding multi-jurisdictional privacy preferences into one GPP string for transmissionDSPs and SSPs parsing a single field to determine bid eligibility across all regulatory contextsAd servers enforcing privacy-compliant ad delivery based on standardized GPP signalsUS state privacy law compliance for publishers serving users across multiple statesGDPR consent signal transmission alongside US privacy signals in the same bid request

Customer segments

Consent Management Platforms (CMPs)Publishers and media companiesDemand-Side Platforms (DSPs)Supply-Side Platforms (SSPs)Ad servers and ad networksData Management Platforms (DMPs)Identity and data vendors

Tech & specs

Technology stack

JavaScript (browser-side API specification)Base64url encoding (string encoding format)OpenRTB protocol integrationJSON schema for specification documentationGitHub for open-source specification hosting

Security & compliance

GDPRCCPACPRAUS State Privacy Laws (VCDPA, CPA, CTDPA, UCPA, etc.)IAB Tech Lab compliance program

Deployment

Cloud

API

Yes

Explore further

2 views