Privacy compliance in digital advertising is increasingly becoming a technical infrastructure problem rather than a policy exercise. IAB Tech Lab is addressing that challenge with proposed updates to its Global Privacy Protocol (GPP) and the finalized Data Deletion Request Framework (DDRF) Version 2.0, giving publishers, advertisers, ad-tech platforms and privacy vendors clearer mechanisms for handling consent and consumer data requests.
IAB Tech Lab Targets Privacy Complexity With GPP and DDRF Updates
The digital advertising industry is entering a period in which privacy compliance needs to work across more jurisdictions, platforms and technology layers without creating a different technical workflow for every regulation.
That is the problem IAB Tech Lab is attempting to address with updates to its Privacy Standards Portfolio.
The organization has released proposed enhancements to the Global Privacy Protocol (GPP) alongside the finalized Data Deletion Request Framework (DDRF) Version 2.0. Stakeholders can submit public comments on the proposed GPP changes through September 11, 2026.
The distinction between the two updates matters. GPP primarily provides a technical mechanism for communicating privacy and consent signals across the digital advertising supply chain, while DDRF addresses how organizations exchange and process consumer data deletion requests.
Together, they target two recurring challenges in advertising technology: communicating privacy preferences consistently and ensuring those preferences can translate into operational data controls.
GPP Changes Reflect a More Unified Privacy Environment
The proposed GPP changes are largely tied to the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA).
IAB Tech Lab says the proposed specification would remove MSPA coverage for the previous state-by-state approach. It would also eliminate Service Provider and Opt-Out Option Modes, remove secondary usage consents and simplify several notice and choice fields.
For ad-tech companies, the significance extends beyond the individual fields being changed.
Privacy signals sit at multiple points in the programmatic ecosystem. Consent management platforms, publishers, supply-side platforms (SSPs), demand-side platforms (DSPs), data providers and advertisers may all need to interpret privacy information before data is used for targeting, measurement, personalization or other advertising purposes.
When those signals are inconsistent, companies can end up maintaining complex combinations of jurisdiction-specific rules and integrations.
A standardized framework such as GPP is intended to reduce that fragmentation by creating a common technical language for privacy signals.
That puts IAB Tech Lab’s work in the same broader ecosystem as consent management and privacy infrastructure companies such as Didomi, which participated in the standards development process.
DDRF 2.0 Moves Data Deletion Toward Standardized Automation
The DDRF update addresses a different part of the privacy lifecycle.
Version 2.0 has now been finalized following a public comment period that began in 2025. IAB Tech Lab says the latest version incorporates implementation experience and questions raised by regulators.
Among the revisions are clearer definitions around identity and deletion-request JSON Web Tokens (JWTs), improved result feedback and troubleshooting, stronger framework-integrity mechanisms and support for implementation-specific extensions.
The objective is straightforward: make data deletion requests more predictable to process across organizations.
That is becoming increasingly important as advertisers and publishers rely on distributed technology stacks.
A consumer data record may not exist in one database. It can be distributed across customer data platforms, CRM systems, advertising platforms, analytics environments, identity systems and third-party vendors.
A deletion request therefore creates a chain of technical obligations. A standardized request format can help automate communication between systems rather than forcing organizations to develop bespoke integrations for every partner.
For enterprise advertising teams, that could reduce one of the less visible costs of privacy compliance: maintaining multiple technical pathways for similar requests.
Privacy Standards Are Becoming AdTech Infrastructure
The broader significance of the announcement is that privacy standards are increasingly becoming part of the infrastructure underlying programmatic advertising.
The advertising industry has already spent years adapting to changes involving third-party cookies, mobile identifiers, consent requirements and regional privacy legislation. The next challenge is interoperability: ensuring that privacy preferences and consumer rights can travel consistently across increasingly complex advertising supply chains.
That matters particularly as AI and automated decision-making become more embedded in advertising.
AI-powered targeting, audience modeling, creative optimization and measurement systems can process enormous volumes of data, but the underlying systems still need reliable rules governing what information can be collected, shared or used.
In that environment, privacy standards cannot remain isolated compliance documents. They need to function as machine-readable infrastructure.
This is where the GPP and DDRF updates could have their greatest impact.
Why Advertisers, Publishers and Platforms Should Pay Attention
For publishers, consistent privacy signaling can help reduce uncertainty around how user preferences are transmitted to downstream advertising partners.
For advertisers and agencies, standardized privacy infrastructure can make it easier to work across different media environments without creating entirely separate compliance workflows.
For SSPs, DSPs and data platforms, the benefits could be even more operational. Standardized signals and deletion requests can potentially reduce integration complexity while making privacy controls easier to audit.
The challenge, however, is adoption.
A standard only becomes useful when enough participants implement it consistently. That is why the current public comment period is important. IAB Tech Lab is seeking industry feedback before finalizing the proposed GPP specifications.
The work also highlights an increasingly important reality for ad-tech companies: privacy compliance is shifting from a legal requirement handled at the edges of a business into a technical capability embedded throughout the advertising stack.
The companies that can operationalize those requirements without slowing media buying, measurement and monetization will have an advantage as privacy regulation continues to evolve.
Market Landscape
The advertising industry is moving toward a more fragmented privacy environment while simultaneously demanding greater interoperability.
GPP is designed to standardize privacy and consent signaling, while DDRF provides a framework for communicating and managing consumer deletion requests. Together, they address different stages of the privacy lifecycle.
The competitive landscape extends beyond standards organizations. Google, Amazon, Microsoft, major SSPs and DSPs, consent management platforms, publishers and data providers all have a stake in how privacy signals are interpreted and acted upon.
For enterprise teams, the important issue is not simply whether a platform claims to be privacy compliant. The more useful questions are whether privacy signals are machine-readable, interoperable, auditable and consistently enforced across partners.
That is especially relevant as AI-driven advertising increases the volume and speed of automated data processing.
Top Insights
- IAB Tech Lab’s GPP proposal simplifies privacy signals while DDRF 2.0 standardizes deletion workflows, affecting publishers, advertisers, DSPs and SSPs.
- The updated privacy standards could reduce fragmented compliance integrations as programmatic advertising increasingly operates across multiple jurisdictions and technology platforms.
- DDRF 2.0 clarifies JWT definitions and troubleshooting, potentially making automated consumer deletion requests easier for enterprise ad-tech systems to process.
- GPP and DDRF updates reinforce privacy interoperability as critical advertising infrastructure for agencies, publishers, data platforms and technology providers.
Get in touch with our Adtech experts
