US Privacy String
The US Privacy String was a standardized code, developed by the IAB Tech Lab, used to record and pass along a person's privacy choices, such as whether they opted out of the sale of their personal information. It was created to support compliance with early US state privacy laws, particularly the California Consumer Privacy Act (CCPA). It has since been deprecated and is now considered a legacy signal format.
The US Privacy String (USP String) is a compact, encoded data format defined by the IAB Tech Lab to communicate consumer privacy disclosures and opt-out choices across the digital advertising supply chain, developed specifically to support CCPA compliance. It captured elements such as whether notice was provided and whether the consumer had exercised opt-out rights (for example, opt-out of sale), reflecting the opt-out-oriented model of US state privacy laws rather than the opt-in consent model prevalent under EU frameworks. According to the evidence, the specification was deprecated as of January 31, 2024 and was not updated, and it is generally treated as a legacy signal, with the IAB's successor Global Privacy Platform intended to address broader US state requirements; practitioners should confirm current signal handling and the applicable legal requirements independently, as this definition does not address the full scope of US state privacy obligations or the technical details of any replacement framework.
Why it matters
The US Privacy String represented an early attempt to standardize how consumer privacy choices, most notably opt-outs of the sale of personal information, could be communicated across the digital advertising supply chain in the United States. Because US state privacy laws such as the California Consumer Privacy Act (CCPA) generally rely on an opt-out model rather than the opt-in consent model prevalent under EU frameworks, the advertising ecosystem needed a compact, machine-readable way to signal whether notice had been given and whether a consumer had exercised their rights. The USP String was developed by the IAB Tech Lab to fill that role, and understanding it remains relevant for anyone maintaining or auditing existing implementations.
For practitioners, the significance today is largely transitional. According to the evidence, the specification was deprecated as of January 31, 2024 and was not updated, and it is generally treated as a legacy signal format. Organizations that built CCPA compliance workflows around the USP String need to be aware that continued reliance on a deprecated standard carries operational and compliance risk, as vendor and platform support for legacy signals may diminish over time. The IAB's Global Privacy Platform is intended to address broader US state requirements going forward.
The practical takeaway is that recognizing the USP String helps teams identify where migration may be needed and avoid conflating a legacy signal with a current, actively maintained framework. This entry does not address the full scope of US state privacy obligations or the technical details of any replacement framework, and it makes no claim that using or having used the USP String satisfies any particular legal requirement. Signal handling supports compliance but does not replace independent legal judgment about the applicable state laws.
Who it's relevant to
Inside USP String
Common questions
Answers to the questions practitioners most commonly ask about USP String.

