BusinessCybersecurityDigital MarketingNewswireTechnology

IAB Tech Lab unveils new privacy standards

Originally published on: August 11, 2026
▼ Summary

– IAB Tech Lab released proposed updates to the Global Privacy Protocol (GPP) and finalized Version 2.0 of the Data Deletion Request Framework (DDRF) to address evolving state privacy laws and data-deletion challenges.
– The GPP changes support the Fifth Amended and Restated Multi-State Privacy Agreement, removing state-by-state approaches, Service Provider and Opt-Out Option Modes, and secondary usage consents to simplify privacy signals.
– The GPP proposals are open for public comment until Sept. 11, 2026, and were developed by IAB Tech Lab’s Global Privacy Working Group and Privacy Rearc Commit Group.
– DDRF Version 2.0 standardizes how companies send data deletion requests, clarifying identity and deletion-request JSON Web Tokens, improving feedback on deletion results, and allowing implementation-specific extensions.
– Marketers using GPP or DDRF must review their current implementations and deletion workflows to adapt to the changes, including how requests are authenticated, passed to vendors, and monitored.

The adtech industry is getting a significant update to its privacy infrastructure. IAB Tech Lab has officially released new versions of its key privacy standards, a move designed to address the growing complexity of state-level regulations and the logistical headaches surrounding consumer data deletion requests.

The organization has put forward proposed updates to its Global Privacy Protocol (GPP) and has simultaneously finalized Version 2.0 of its Data Deletion Request Framework (DDRF). Industry stakeholders have until September 11, 2026, to submit feedback on the GPP changes before they are finalized.

For marketing and advertising technology teams, the core goal of these revisions is to streamline how privacy preferences are communicated across the web of companies responsible for collecting, processing, and sharing advertising data.

A Shift in How State Privacy Laws Are Handled

The proposed GPP modifications are built to support the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA). This agreement serves as the contractual backbone for compliance with various U. S. state privacy laws.

Under the new proposal, the GPP would scrap the previous approach that required specific configurations for each state. Specifically, the updates call for the elimination of Service Provider and Opt-Out Option Modes, the removal of secondary usage consents, and a simplification of the notice and choice fields.

This consolidation is intended to drastically cut down the number of variations that companies must program for when transmitting privacy information. Given that customer data frequently flows between publishers, advertisers, agencies, platforms, and tech vendors, a unified set of technical signals reduces the need for bespoke communication methods between each party.

Finalized Framework for Data Deletion

On the deletion front, DDRF Version 2.0 has been finalized after a public comment period that kicked off in the fall of 2025. This framework standardizes the process for companies to send deletion requests to one another, a critical function when fulfilling a consumer’s request necessitates notifying every vendor and partner that holds their personal data.

The new version brings clarified definitions for identity and deletion-request JSON Web Tokens, enhanced feedback mechanisms for troubleshooting deletion outcomes, stronger framework integrity, and support for implementation-specific extensions. According to IAB Tech Lab, these revisions were shaped by real-world feedback from companies already using the framework and by inquiries from regulators.

The practical benefit here is a smoother deletion process across disparate systems, paired with better visibility into whether those requests were actually completed successfully.

What This Means for Marketers

These standards exist to give the industry a common language for privacy, moving away from the fragile network of custom integrations between individual partners.

For organizations currently operating with GPP, the immediate priority is auditing how these proposed changes will impact existing setups, particularly those that were built around state-specific MSPA signals or fields that are now slated for removal. Similarly, companies using DDRF should map Version 2.0 against their current deletion workflows, paying close attention to how requests are authenticated, passed downstream, monitored, and ultimately confirmed.

The GPP proposals were crafted by IAB Tech Lab’s Global Privacy Working Group and the Privacy Rearc Commit Group. Companies that will be affected by these shifts are encouraged to review the documentation and submit their comments before the September 11 deadline, after which the organization will integrate industry feedback into the final specification.

(Source: MarTech)

Topics

privacy standards 98% global privacy protocol 95% data deletion requests 92% state privacy laws 90% advertising ecosystem 88% technical standards 85% Regulatory Compliance 82% consumer privacy 80% implementation challenges 78% public comment period 75%