IAB Tech Lab Opens Privacy Updates For Public Comment

IAB Tech Lab, the global digital advertising standards body from the Interactive Advertising Bureau, announced Tuesday updates to its Privacy Standards Portfolio.

Enhancements to the Global Privacy Protocol (GPP) and the Data Deletion Request Framework (DDRF) Version 2.0. which has been finalized, will help to mitigate privacy risk and support consistency across the advertising industry. Public comments are accepted until September 11, 2026. 

DDRF introduces updates based on implementation experience and regulator questions. The proposed revisions clarify identity and deletion request JSON Web Tokens (JWT) definitions, an open standard that defines a URL-safe method for securely transmitting information between parties. 

This also improves feedback and troubleshooting, strengthens framework integrity, and supports implementation-specific extensions. These updates are also intended to make data deletion requests easier to implement. 

advertisement

advertisement

Anthony Katsur, CEO, IAB Tech Lab, believes privacy requirements continue to change, but that doesn't mean implementation has to become more complicated.

The proposed GPP updates incorporate feedback from companies using set standards. They aim to make compliance more consistent, transparent, and practical across the ecosystem.

They focus on changes needed to support the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA).

Part of the plan is to remove MSPA coverage for the previous state-by-state approach, eliminating Service Provider and Opt-Out Option Modes, removing secondary usage consents, and simplifying notice and choice fields. 

This means getting rid of the old, fragmented rules that treated every U.S. state differently, such as California and Colorado.

Service Provider Mode and Opt-Out Option Mode are core settings used by websites and advertisers to comply with U.S. state privacy laws under the Interactive Advertising Bureau (IAB) Multi-State Privacy Agreement (MSPA).

Embedded into a website's code or Consent Management Platform (CMP), the settings tell ad networks exactly how they are allowed to handle user data.  

"Privacy requirements don't stop at organizational boundaries, so having common technical standards makes implementation more consistent across the ecosystem," stated Jeff Wheeler, vice president of Product, Didomi.

The updates were developed through IAB Tech Lab's Global Privacy Working Group and Privacy Rearc Commit Group (PRCG), which oversees standards and guidelines for the areas of global privacy, identity, and addressability.
 

Next story loading loading..