The Global Privacy Protocol (GPP) carries privacy, consent and consumer choice signals from sites and apps to ad tech providers. IAB Tech Lab’s GPP page says it currently supports the IAB Europe TCF, the IAB Canada TCF, the MSPA US National string and a number of US state strings. Each of those signals has its own section ID in the Section Information file.

What does GPP actually carry?

GPP does not decide what a law requires. It carries a signal that a site, app or consent platform has already produced, so every party downstream reads the same format. The specification repository calls it a transport layer for consent and preference signals, and its disclaimer says the specifications are not legal advice and do not by themselves make anyone compliant.

The Section Information file assigns these IDs:

  • Section 2: the IAB Europe TCF v2 section.
  • Section 3: the GPP header, which the file marks as required.
  • Section 5: the Canadian TCF section.
  • Section 7: the MSPA US National section.
  • Sections 8 to 27: individual US state sections, from California (8) to Rhode Island (27).

The same file defines reusable subsections. The one it lists is Global Privacy Control: a party building a GPP string may check the Sec-GPC header or the globalPrivacyControl JavaScript API and pass the value along. It also notes that a GPP string starts with the letter D, while an IAB Europe TCF v2 string starts with C.

On versions, the GPP page lists the string format at version 1.0, clarified on November 3, 2023, and the consent management API at version 1.1, dated June 2023. A vendor that says it supports GPP should be able to name the section IDs it reads and writes.

Why was it renamed from Platform to Protocol?

In February 2025, IAB Tech Lab renamed the Global Privacy Platform to the Global Privacy Protocol. The word platform led some readers to assume it was software that Tech Lab licenses and maintains. A protocol is something every party can adopt and run inside its own processes. The acronym stayed GPP.

The same post names the GitHub repository as the source of truth for protocol details, version history and public comment records. That repository’s address still says Global-Privacy-Platform, so expect to see both names for a while. The GPP page adds that implementation guidelines were finalized in February 2025.

What changed in the 2025 and 2026 state-string updates?

The GPP page reports that the Maryland, Indiana, Kentucky and Rhode Island sections were in public comment until December 1, 2025 and are now final. It lists Minnesota’s section as final too. The page gives no finalization date for either update.

The next change is still a draft. In August 2026, the GPP page pointed to pull request 160 as the public-comment draft that updates the US sections for the Fifth Amended and Restated MSPA. Comment ran to September 11, 2026. As of October 2, 2026, that pull request was still open and unmerged, and the GPP page reports no final release.

As proposed, the draft would:

  • Move the National section (ID 7) to the newer string layout first used by the Maryland, Indiana, Kentucky and Rhode Island sections.
  • Cut that section’s core subsection to four fields: MspaVersion, MspaNotice, MspaOptOut and MspaId.
  • Fix several MSPA-related fields in the state sections to constant values, for example MspaVersion always 0.

A comment on the pull request, dated September 9, 2026, asks whether folding the separate sale, sharing and targeted advertising flags into one opt-out field is wise. The layout may still change, so do not build on it yet.

What should a buyer do with a GPP string?

  • Read the section IDs present in a string instead of assuming one jurisdiction.
  • Expect new sections. Tech Lab says the protocol will keep expanding to more jurisdictions, and the list already runs to ID 27.
  • Wait for a final release before relying on any draft field layout.
  • Treat GPP as a carrier. Questions about what a law permits belong with counsel.

How does Vectravia handle this?

Audience Lab reads GPP and TCF consent strings before data is used. That puts the signal ahead of the data use, not after it. Reading a string does not make any campaign compliant, and this article does not claim it does.