
Today, IAB Tech Lab released new versions of its privacy standards. The move comes in response to evolving state privacy laws and the operational challenges of handling consumer data-deletion requests.
The standards body released proposed changes to its Global Privacy Protocol (GPP) and finalized Version 2.0 of its Data Deletion Request Framework (DDRF). The GPP changes are open for public comment through Sept. 11, 2026.
For marketers and adtech teams, the changes are intended to make it easier to communicate privacy choices consistently across the companies that collect, process, and share advertising data.
GPP changes reflect a new approach to state privacy laws
The proposed GPP updates support the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA), which provides a contractual framework for complying with U.S. state privacy laws.
The changes would remove MSPA support for the previous state-by-state approach, eliminate Service Provider and Opt-Out Option Modes, remove secondary usage consents, and simplify notice and choice fields.
The goal is to reduce the number of variations companies must accommodate when transmitting privacy information across the advertising ecosystem.
Because customer and advertising data can flow among publishers, advertisers, agencies, platforms, and technology providers, each participant must understand the permissions and restrictions associated with it.
Common technical signals reduce the need for each company to create its own way of communicating those requirements.
Data deletion gets an update
IAB Tech Lab also finalized DDRF Version 2.0 following a public comment period that began in fall 2025.
The framework provides a standardized way for companies to send data deletion requests to one another. That’s essential when fulfilling a consumer request requires an organization to notify vendors and other partners that also hold the person’s data.
Version 2.0 clarifies definitions for identity and deletion-request JSON Web Tokens, improves feedback and troubleshooting for deletion results, strengthens framework integrity, and allows implementation-specific extensions.
The world’s most powerful SEO platform, purpose-built for Enterprise.
The revisions are based in part on feedback from companies implementing the framework and on questions from regulators, according to IAB Tech Lab.
The practical objective is to make deletion requests easier to process across multiple systems while providing companies with better information on whether those requests were successfully completed.
Why marketers should care
Standards such as GPP and DDRF are designed to provide those systems with a common way to communicate privacy information, rather than relying on custom integrations among all participants.
For organizations using GPP, the immediate task is to determine how the proposed changes affect existing implementations, particularly those built around state-specific MSPA signals or fields slated for removal. Companies using DDRF should review Version 2.0 against their deletion workflows, including how requests are authenticated, passed to downstream vendors, monitored, and confirmed.
Companies using DDRF should review Version 2.0 against their current deletion workflows, including how requests are authenticated, passed to downstream vendors, monitored, and confirmed.
The GPP proposals were developed through IAB Tech Lab’s Global Privacy Working Group and Privacy Rearc Commit Group. Companies affected by the changes can submit comments here before the Sept. 11 deadline, after which IAB Tech Lab can incorporate industry feedback into the final specification.
The post IAB Tech Lab releases new privacy standards appeared first on MarTech.