Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: TCF and Vendors

Global Privacy Platform

Also known as: GPP, Global Privacy Protocol, IAB Tech Lab GPP
Simply put

The Global Privacy Platform (GPP) is a framework developed by IAB Tech Lab that provides a standardized way to carry a user's privacy, consent, and choice signals from websites and apps to advertising technology providers. It is designed to package different regional privacy signals into a single transportable format, which can simplify how consent information is passed along the advertising supply chain. GPP is a technical signaling mechanism and does not by itself determine whether consent is valid under any particular law.

Formal definition

GPP is an IAB Tech Lab framework that standardizes the encoding and transmission of privacy, consent, and consumer choice signals from publisher sites and apps to downstream ad tech vendors. It packages multiple regional privacy signals into a single transportable string (a consent string), intended to accommodate differing jurisdictional signaling requirements within one interoperable structure and to support participants in reflecting user choice across the advertising ecosystem. As a signaling protocol, GPP standardizes the format and transport of consent data rather than the collection of consent itself; the legal sufficiency of any signal it carries depends on the applicable regime (for example, opt-in requirements under EU/UK rules versus opt-out approaches under certain US state laws) and remains a matter of separate legal assessment. The evidence provided describes GPP's general purpose but does not detail its full technical specification, supported regional signals, or governance, which are out of scope for this definition.

Why it matters

As privacy laws have proliferated across jurisdictions, the advertising supply chain has faced a growing challenge: user consent and choice signals must travel accurately from the publisher's site or app to the many downstream ad tech vendors that process data, and each region may impose different signaling requirements. The Global Privacy Platform matters because it offers a standardized, interoperable way to carry these varied signals in a single transportable format, reducing the fragmentation that arises when multiple regional frameworks must be handled separately. For organizations operating across borders, this can simplify the technical burden of communicating user choices consistently along the chain.

At the same time, it is important to keep GPP's role in perspective. GPP standardizes the format and transport of consent data; it does not collect consent, nor does it determine whether a given signal reflects valid consent under any particular law. Whether an opt-in signal satisfies EU or UK requirements, or whether an opt-out signal aligns with a particular US state law, remains a matter of separate legal assessment that depends on how consent was obtained and on the applicable regime. Adopting GPP does not, by itself, establish compliance.

For compliance and privacy teams, the practical significance is that GPP can support consistent transmission of user choice across the ecosystem, but it must be paired with a compliant consent-collection mechanism and sound legal judgment. Treating a signaling protocol as a substitute for a proper consent process, or assuming that a signal carried by GPP is automatically lawful in every jurisdiction, would be a misreading of what the framework does.

Who it's relevant to

Publishers and app operators
Organizations that place cookies or similar technologies on user devices and pass user choices to ad tech partners may use GPP to transmit consent and choice signals in a standardized format. They should remember that GPP handles transmission, not collection, and that a compliant consent-gathering mechanism and appropriate legal basis remain their responsibility.
Ad tech vendors and supply-chain participants
Vendors receiving consent and choice signals downstream may rely on GPP to interpret user choices consistently across regions. Because the framework carries signals reflecting different jurisdictional approaches (for example, opt-in in the EU and UK versus opt-out under certain US state laws), vendors still need to assess how to act on each signal under the relevant regime.
Privacy officers and legal counsel
Those responsible for cross-border compliance may find GPP useful for reducing the technical fragmentation of handling multiple regional signals. They should treat it as a supporting tool rather than a compliance guarantee, since the validity of any carried signal depends on separate legal assessment against the applicable law.
Web and mobile developers
Engineering teams implementing consent signaling may work with GPP to encode and transport user choices in a standardized string. The full technical specification and supported regional signals sit outside this definition and should be confirmed against IAB Tech Lab's documentation before implementation.

Inside GPP

Cross-jurisdiction signal framework
The Global Privacy Platform (GPP) is an IAB Tech Lab specification designed to transmit consent, opt-out, and privacy preference signals across multiple jurisdictions through a single, standardized technical container, rather than requiring separate mechanisms for each legal regime.
Encoded consent string
The GPP conveys user choices through an encoded string that can carry section-specific data for different frameworks, including EU/UK signals derived from the IAB Transparency and Consent Framework (TCF) and US state signals. The presence of a string reflects captured preferences but does not by itself establish that the underlying consent or opt-out was validly obtained under any given law.
Section-based structure
The specification is organized into sections that correspond to particular jurisdictions or frameworks (for example, EU/UK TCF sections and US state-level sections), allowing a single payload to represent choices relevant to multiple regimes at once.
Signal transmission layer, not a consent-collection UI
The GPP is a transport and encoding standard for communicating preferences between parties in the advertising and data supply chain. It is distinct from the consent management platform (CMP) interface that actually collects a user's choices and from the legal analysis of whether those choices meet applicable standards.
Relationship to opt-in and opt-out models
Because the GPP spans jurisdictions, it can carry both opt-in-style signals typical of EU/UK ePrivacy and GDPR contexts and opt-out-style signals typical of certain US state privacy laws. The framework itself does not determine which model applies; that depends on the governing law and the facts of processing.

Common questions

Answers to the questions practitioners most commonly ask about GPP.

Does implementing the Global Privacy Platform (GPP) make my consent management compliant?
No. The GPP is a technical framework developed by the IAB to standardize how consent and privacy signals are encoded, stored, and transmitted between parties in the advertising ecosystem. It supports interoperability across jurisdictions but does not, by itself, guarantee compliance with the GDPR, the ePrivacy Directive, US state privacy laws, or any other regime. Compliance depends on the underlying legal basis you rely on, the quality of the consent or opt-out you actually obtain, and how signals are honored downstream. The GPP is a tool that can facilitate compliance workflows, but it does not replace legal judgment or the substantive requirements of applicable law.
Is the Global Privacy Platform the same thing as the IAB Transparency and Consent Framework (TCF)?
Not exactly. The GPP is a broader technical framework designed to carry multiple privacy signals across different jurisdictions within a single standardized structure. The TCF, which is oriented toward EU and UK consent under the GDPR and ePrivacy rules, can be one of the sections carried within the GPP alongside signals designed for US state privacy laws. In other words, the GPP acts as a container that can transport TCF strings and other jurisdiction-specific strings, rather than being a replacement for or a synonym of the TCF. The two operate at different levels of scope.
How does the Global Privacy Platform relate to a consent management platform (CMP)?
A CMP is typically the software component that collects user choices, presents consent or opt-out interfaces, and generates the encoded signals. The GPP defines the standardized format those signals can take and how they are shared with downstream vendors. In practice, a CMP that supports the GPP encodes the user's choices into a GPP string, which can then be read by ad tech partners and other parties. Selecting a CMP that supports the GPP does not remove the organization's responsibility to configure it correctly and to ensure the signals reflect legally valid consent or opt-out choices for each relevant jurisdiction.
Which jurisdictions can the Global Privacy Platform's signals cover?
The GPP is designed to accommodate signals for multiple jurisdictions within one framework, including sections aligned with EU and UK consent requirements and sections aligned with various US state privacy laws that generally rely on opt-out mechanisms. Because obligations differ between the EU, the UK, and individual US states such as California, the appropriate section and signal type varies by the user's location and the applicable legal regime. Organizations should confirm which jurisdiction-specific sections are supported and correctly configured, and should not assume that a signal valid for one regime satisfies the substantive requirements of another.
How should signals from the Global Privacy Platform be honored by downstream vendors?
For the GPP to be effective, the encoded signals must be read and acted upon by the vendors and partners receiving them, so that a user's consent, refusal, or opt-out is respected throughout the chain. Transmitting a GPP string is not sufficient on its own; organizations generally need to confirm that their ad tech partners can parse the relevant sections and that processing actually stops or proceeds in line with the user's expressed choice. Where partners do not support or honor the signal, gaps in compliance can arise regardless of what the string encodes. Contractual arrangements and testing may be needed to verify this in practice.
What record-keeping and configuration considerations apply when using the Global Privacy Platform?
Because consent and opt-out choices may need to be demonstrated to regulators, organizations typically maintain records of the choices collected and the signals generated. Using the GPP does not remove consent logging or record-keeping obligations that may apply under frameworks such as the GDPR. Configuration considerations include mapping each applicable jurisdiction to the correct GPP section, ensuring the CMP encodes signals accurately, and periodically reviewing that the setup reflects current guidance, since enforcement positions and technical specifications may evolve. The precise records required will depend on the applicable legal regime and are outside the scope of the technical framework itself.

Common misconceptions

Adopting the Global Privacy Platform makes an organization compliant with cookie and privacy laws.
The GPP is a technical standard for encoding and transmitting signals; it supports interoperability but does not by itself guarantee compliance. Whether consent is freely given, specific, informed, and unambiguous under the GDPR and ePrivacy rules in EU/UK jurisdictions, or whether opt-out obligations under US state laws are met, still requires appropriate collection mechanisms, legal judgment, and record-keeping. Tools do not replace that assessment.
The GPP replaces the IAB Transparency and Consent Framework (TCF).
The GPP is designed to carry TCF signals as one of its sections alongside signals for other jurisdictions, rather than to abolish the TCF. It acts as a broader container so that EU/UK TCF data and US state signals can travel together, but the substantive requirements and criticisms associated with each underlying framework continue to apply.
A single GPP signal means the same consent status applies everywhere in the world.
Cookie and privacy obligations differ across the EU, the UK, and individual US states such as California under the CCPA and CPRA, as well as other regimes. The GPP encodes jurisdiction-specific sections precisely because the underlying legal standards diverge. A choice valid for one jurisdiction's requirements does not automatically satisfy another's.

Best practices

Treat the GPP as a signaling and interoperability layer, and pair it with a legal analysis of whether the consent or opt-out captured actually meets the standards of each applicable jurisdiction (for example, opt-in consent in most EU/UK contexts versus opt-out mechanisms under certain US state laws).
Ensure your consent management platform collects choices through a compliant interface, since the GPP transmits preferences but does not itself gather them; avoid relying on it to cure defects such as pre-ticked boxes or implied consent, which are widely regarded as non-compliant in the EU.
Map which GPP sections you are populating to the specific jurisdictions and frameworks you operate under, and verify that the correct section (EU/UK, US state, or others) is applied based on the user's applicable law rather than a single global default.
Maintain records of the consent or opt-out decisions underlying the signals you transmit, so that consent-logging and record-keeping expectations can be evidenced independently of the encoded string.
Confirm that downstream vendors and partners in your supply chain correctly interpret and honor the GPP signals you send, and document these arrangements, since transmitting a signal does not guarantee that recipients act on it.
Monitor evolving guidance from data protection authorities and updates to the specification and its constituent frameworks, and revisit your implementation periodically, as enforcement positions and technical requirements may change over time.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps