Proposed Privacy Protocol Overhaul Goes to the Public
The IAB Tech Lab, the global technical standards body for digital advertising, has released a significant update to its Privacy Standards Portfolio. The proposed revisions, open for public comment until September 11, 2026, target two key frameworks: the Global Privacy Protocol (GPP) and the newly finalized Data Deletion Request Framework (DDRF) Version 2.0. The changes are designed to reduce complexity for companies navigating a patchwork of U.S. state privacy laws.
Central to the overhaul is a wholesale streamlining of how the Multi-State Privacy Agreement (MSPA) is implemented. The proposal removes the previous state-by-state approach, which required advertisers to manage distinct settings for California, Colorado and other jurisdictions. It eliminates Service Provider Mode and Opt-Out Option Mode entirely, along with secondary usage consents, and simplifies the notice and choice fields embedded in Consent Management Platforms (CMPs).
Meanwhile, DDRF 2.0 brings clarifications drawn from real-world implementation experience and regulator inquiries. The framework now defines identity and deletion requests more precisely using JSON Web Tokens (JWT), an open standard for secure data transmission. Improvements also cover feedback mechanisms, troubleshooting and support for implementation-specific extensions. The aim, according to the Tech Lab, is to make data deletion requests easier to execute while maintaining strong privacy safeguards.
The working groups that produced the updates — the Global Privacy Working Group and the Privacy Rearc Commit Group — included input from companies actively deploying these standards. Jeff Wheeler, Vice President of Product at consent management firm Didomi, emphasized that shared technical standards are essential because “privacy requirements don’t stop at organizational boundaries.”
Why the GPP and DDRF 2.0 Updates Reshape Ad Tech Compliance
Moving from a State Patchwork to a Unified MSPA
The decision to scrap Service Provider Mode and Opt-Out Option Mode marks a fundamental shift. Previously, websites and ad networks had to parse separate privacy signals for each U.S. state, a fragmentation that increased technical overhead and compliance risk. By collapsing the rules into a single, simplified MSPA framework, IAB Tech Lab is betting that uniformity will boost adoption across the advertising ecosystem. The removal of secondary usage consents further shrinks the granular controls, focusing on a cleaner consent model. This directly responds to industry frustration with maintaining divergent implementations for California, Colorado and others, and aligns with calls from major CMP providers for a more practical operational standard.
What DDRF 2.0 Fixes Under the Hood
The Data Deletion Request Framework version 2.0 addresses pain points that have surfaced since the original rollout. Defining JWT structures for identity verification and deletion requests reduces ambiguity for engineers implementing privacy dashboards. The improved feedback and troubleshooting capabilities mean that when a data subject’s deletion request fails or gets stuck across multiple ad-tech intermediaries, both the initiator and the recipient can trace the problem. For companies that handle large volumes of deletion requests, these clarifications translate directly into lower operational costs and fewer disputes with regulators who increasingly scrutinize how promptly and completely data is erased.
Industry Implications and What Comes Next
These updates, while technical, carry genuine commercial weight. If adopted after the comment period, they will set the de facto plumbing for how online consent and data subject rights travel between publishers, advertisers, CMPs and tech platforms. Early adopters may gain an efficiency edge, but the more pressing issue is that firms which ignore the shift risk being left with non-compliant configurations as state privacy enforcement intensifies. The Tech Lab’s emphasis on “interoperability” signals that the challenge is no longer just about legal compliance—it is about ensuring privacy signals actually function across the dozens of ad-tech vendors that participate in a single programmatic ad transaction.
What Ad Tech Companies Should Do Before the Deadline
The following steps are directly tied to the specific proposals and deadlines in this story:
- Submit comments by September 11, 2026. Companies that currently use MSPA’s state-specific Service Provider Mode or Opt-Out Option Mode should explain to IAB Tech Lab how their removal will affect existing integrations. Concrete feedback now can shape the final technical specification.
- Audit your CMP configuration. Consent management platforms will need to shed the granular state-by-state signals. Map your current setup against the proposed simplified notice and choice fields so you are not caught off guard when vendors update their libraries post-comment period.
- Review data deletion workflows. Compare your internal right-to-delete processes against the DDRF 2.0 JWT definitions. If your system built its own interpretation of identity tokens, you may need to adjust to ensure interoperability with the new standardized payloads.
- Brief engineering and legal teams on the timeline. Although final adoption could take months, the removal of two core operating modes means that when the update goes live, ad networks and publishers will have no fallback. Early internal briefings prevent rushed re-architecture later.
- Check cross-jurisdictional impact. For organizations running ad campaigns that span the U.S. and other regions, confirm that the streamlined MSPA fields do not conflict with GDPR or other local consent mechanisms in your tech stack.
Risk & Opportunity Assessment
| Commercial Risk | Low | Standards updates are evolutionary and include a comment period; no immediate revenue impact, though non-compliance could eventually lead to partner requirements or operational friction. |
| Competitive Risk | Medium | Firms that rapidly adopt the unified MSPA approach may lower their implementation overhead and gain smoother consent collection, potentially disadvantaging slower competitors still maintaining fragmented state modes. |
| Regulatory Risk | Medium | MSPA and state privacy law enforcement are tightening. Continued reliance on deprecated modes after final adoption could be seen as a failure to keep up with industry standards, drawing regulator attention in investigations. |
| Reputation Risk | Low | Privacy missteps can erode consumer trust, but this update is unlikely to trigger immediate public blowback; it mainly affects internal plumbing. |
| Technology Disruption | Low | The changes are incremental clarifications and simplifications, not a replacement of core infrastructure, so disruption is minimal for most ad-tech stacks. |
| Commercial Opportunity | Medium | Simplified consent fields and clearer deletion standards can cut the cost and complexity of maintaining privacy compliance, freeing resources for other ad-tech investments. |
Comments 0