IAB Tech Lab, the global digital advertising standards body from the Interactive Advertising Bureau, announced Tuesday updates to its Privacy Standards Portfolio.
Enhancements to the
Global Privacy Protocol (GPP) and the Data Deletion Request Framework (DDRF) Version 2.0. which has been finalized, will help to mitigate privacy risk and support consistency across the advertising
industry. Public comments are accepted until September 11, 2026.
DDRF introduces updates based on implementation experience and regulator questions. The proposed revisions clarify
identity and deletion request JSON Web Tokens (JWT) definitions, an open standard that defines a URL-safe method for securely transmitting information between
parties.
This also improves feedback and troubleshooting, strengthens framework integrity, and supports implementation-specific extensions. These updates are also intended to make
data deletion requests easier to implement.
advertisement
advertisement
Anthony Katsur, CEO, IAB Tech Lab, believes privacy requirements continue to change, but that doesn't mean implementation has to
become more complicated.
The proposed GPP updates incorporate feedback from companies using set standards. They aim to make compliance more consistent, transparent, and practical across the
ecosystem.
They focus on changes needed to support the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA).
Part of the plan is to remove MSPA coverage for the
previous state-by-state approach, eliminating Service Provider and Opt-Out Option Modes, removing secondary usage consents, and simplifying notice and choice fields.
This means getting rid of the old, fragmented rules
that treated every U.S. state differently, such as California and Colorado.
Service Provider Mode and Opt-Out Option Mode are core settings used by websites and advertisers to comply with U.S. state privacy laws under the Interactive
Advertising Bureau (IAB) Multi-State Privacy Agreement (MSPA).
Embedded into a website's code or Consent Management Platform (CMP), the settings tell ad networks exactly how they
are allowed to handle user data.
"Privacy requirements don't stop at organizational boundaries, so having common technical standards makes implementation more
consistent across the ecosystem," stated Jeff Wheeler, vice president of Product, Didomi.
The updates were developed through IAB Tech Lab's Global Privacy Working Group and Privacy
Rearc Commit Group (PRCG), which oversees standards and guidelines for the areas of global privacy, identity, and addressability.