Privacy compliance in digital advertising has stopped being a project with an end date. It is now a maintenance cycle, and the latest release from IAB Tech Lab proves it: on August 11, the standards body opened public comment on updates to its Privacy Standards Portfolio, revising the Global Privacy Protocol (GPP) and finalizing version 2.0 of its Data Deletion Request Framework (DDRF). Neither change introduces a new rule. Both exist because the old ones could not keep pace with how many state privacy laws now touch a single ad transaction.

What actually changed

The GPP update, open for comment through September 11, aligns the protocol with the Fifth Amended and Restated Multi-State Privacy Agreement. In practice that means removing the state-by-state coverage fields GPP previously required, eliminating the separate Service Provider and Opt-Out Option Modes, dropping secondary usage consent strings, and simplifying the notice and choice fields that publishers and ad platforms pass along the bidstream. Each of those pieces was added at some point to handle a specific state’s language. Stripped out together, they are an admission that signal-by-signal patching does not scale.

DDRF 2.0, finalized after a fall 2025 comment period, is narrower but more concrete. It clarifies how deletion requests are authenticated (the JWT definitions), gives companies clearer feedback when a deletion request succeeds or fails, tightens the integrity checks on the framework itself, and opens the door to implementation-specific extensions vendors can build on top of the base spec. DDRF exists because “delete my data” is one instruction that has to move correctly through dozens of downstream systems, not just get logged at the point of collection.

Advertisement

MarTech Your brand belongs here. Reach the decision-makers who read MarTech every day. Premium placements across the site and newsletter. Advertise with us

Why the industry needed a rewrite, not a patch

IAB Tech Lab CEO Anthony Katsur framed the release as a response to what companies are actually running into. “Privacy requirements continue to change, but that doesn’t mean implementation has to become more complicated,” Katsur said, adding that the updates “reflect what we’ve heard from companies putting these standards into practice and help make compliance more consistent, transparent, and practical across the ecosystem.”

That framing matters because it concedes the real problem is not any single state law. It is that ad tech’s privacy plumbing was built to accumulate rules rather than replace them, and accumulation eventually breaks. Rowena Lam, IAB Tech Lab’s senior director of product, put the goal in more operational terms: the updates are “intended to make implementation more predictable while helping companies meet growing privacy expectations.” Predictability, not just compliance, is the pitch. That is a tell about how much engineering time these frameworks have already cost the ecosystem.

An outside implementer backed that up. Jeff Wheeler, VP of product at consent management vendor Didomi, said the changes “reflect real implementation experience” and “give organizations clearer guidance.” Vendors who build directly against GPP and DDRF are the ones who feel every ambiguous field and every edge case a state legislature didn’t anticipate, so their read on whether a revision actually reduces friction is a useful check on the standards body’s own framing.

What it means for the marketing leader

The direct impact lands on whoever owns consent management and data governance vendor relationships, but it is a marketing leadership problem because it is a launch-timeline problem. Campaigns that touch first-party data activation, retargeting, or any cross-platform identity resolution run through GPP strings somewhere in the stack. A protocol change that simplifies those fields is good news operationally, but only after every vendor in the chain, from the CDP to the DSP to the tag manager, ships support for the new version. Marketing leaders should ask their martech and adtech vendors now, not after the September 11 comment period closes, whether GPP 2.0 support is already on their roadmap, and whether their deletion-request workflows are being rebuilt against DDRF 2.0 or just patched again.

The deletion framework specifically deserves a second look from anyone who has fielded a consumer data-deletion request in the last year and struggled to confirm it actually propagated. DDRF 2.0’s improved result feedback is meant to close exactly that gap: instead of a request disappearing into a vendor’s system with no confirmation, companies are supposed to get a clear signal that deletion succeeded, failed, or is still processing. That is a real, measurable trust signal marketing and legal teams can point to the next time a regulator or a customer asks whether a deletion request was honored.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

The pattern underneath the update

This is the second time in roughly a year that IAB Tech Lab has had to revise GPP to keep up with state legislation, following an earlier expansion of the same privacy portfolio. That cadence is the actual story. Standards bodies exist to give the industry one thing to build against instead of fifty, but when the underlying law keeps moving, “one thing to build against” turns into a subscription. Marketers who treat privacy compliance as a box checked once, at the last major state law’s deadline, are already behind. The companies represented in this release, from a consent platform vendor to the standards body itself, are effectively telling the market that privacy infrastructure is now a recurring line item, not a one-time build.

Related coverage on this site has already tracked that pressure building from the regulatory side, including New Jersey’s data broker law, which took effect with obligations most ad tech companies had not yet mapped to their existing consent infrastructure, and the FTC’s warning that health-adjacent data cannot simply be repurposed as ad fuel, covered in our reporting on the FTC’s ad tech guidance. Each of those actions adds another input the standards portfolio eventually has to absorb.

What to do next

The public comment period runs to September 11. Marketing and legal teams with a stake in how GPP 2.0 handles consent strings, or how DDRF 2.0’s extensions get implemented, have a genuine window to weigh in before the spec locks. For everyone else, the more useful step is auditing which vendors in the current stack are already committed to supporting the new versions and setting an internal deadline that does not wait for a state attorney general to set one instead.

Source: IAB Tech Lab via PR Newswire