
Identity & Addressability
AdTech privacy and permission signals
An advertising permission signal records or conveys a person's choice for a defined purpose.
An advertising permission signal records or conveys a person’s choice for a defined purpose. Its presence in an ad transaction does not prove that the choice was validly obtained, correctly interpreted or honoured by every vendor. Treat it as one part of a governed data path, alongside the notice, collection, processing and deletion rules.
Distinguish the permission signal from the separate operational question of how it travels through the ad supply chain. This article covers the signal and its governance; a separate article in this cluster maps how signals travel through the supply chain.
IAB Tech Lab’s Global Privacy Protocol transmits privacy, consent and choice signals; IAB Europe’s TCF has its own specifications. They are not interchangeable: assess each against the relevant market’s requirements.
Check which markets a protocol covers
The Global Privacy Protocol (GPP) supports distinct privacy strings: IAB Europe’s TCF, IAB Canada’s TCF, the MSPA US National string and a number of US State strings. It is a container for signals designed for different regulatory settings, not a single globally uniform permission value.
GPP is intended to expand to more jurisdictions as privacy requirements evolve. Check supported strings and implementation guidance for each market where an advertising service operates; support for one string does not establish that another market’s requirements are addressed.
Specifications can change. GPP’s implementation guidelines were finalised in February 2025; its published string history records version 1.0 published on 28 September 2022 and a clarification update on 3 November 2023. Track the applicable specification version when maintaining an integration.
Global Privacy Protocol (GPP) vs. IAB Europe’s TCF: Key Differences
- ScopeGPP is a container for multiple privacy strings across different jurisdictions; not a single global standard.
- Jurisdictions SupportedIAB Europe’s TCF, IAB Canada’s TCF, MSPA US National string, and several US State strings.
- PurposeTo transmit privacy, consent, and choice signals in digital advertising supply chains.
- InterchangeabilityNot interchangeable—each market requires assessment against its own regulatory requirements.
Use the framework’s technical reference points
IAB Europe’s TCF resources list the Transparency and Consent string with Global Vendor List format, the Consent Management Platform API and implementation guidelines as technical references. These give teams concrete artefacts to consult when building or reviewing a TCF implementation, rather than relying on a banner description alone.
The TCF resources also list vendor registration, CMP registration and a CMP Validator. These can help establish whether a chosen implementation uses the framework’s published operational resources; they do not establish how an organisation handles choices in practice.
Keep framework policy and technical specifications distinct in internal documentation. IAB Europe lists TCF v2.3 implementation resources and TCF v5.0 policies, updated in May 2026, alongside terms and technical materials. Record which policy and technical references an implementation is intended to follow.
Test the default and the change
Use test profiles for permission granted and declined states, and for a later changed state. Check network calls and vendor behaviour, not just the banner text. Record each test outcome against the organisation’s documented signal governance.
For Australian organisations, the Privacy Act sets obligations for covered entities handling personal information. Ask privacy specialists to map the actual technologies and jurisdiction; do not claim one universal toggle resolves every obligation.
Record the permission signals your organisation uses, including purpose and signal format, so internal governance can be reviewed.
Key Steps for Validating Permission Signal Implementation
- Test permission granted state using valid profiles
- Test permission declined state with proper tracking
- Verify changed states (e.g., user updates choice post-initial selection)
- Document signal governance outcomes for internal review
Place signals in the Australian privacy context
The Privacy Act 1988 applies to Australian organisations with annual turnover of more than $3 million and to some other organisations. It includes 13 Australian Privacy Principles (APPs), which apply to some private sector organisations and most Australian Government agencies; those covered organisations and agencies are known as APP entities.
A signal format is an operational mechanism; the Privacy Act sets obligations for covered entities handling personal information. Assess the signal as part of the organisation’s practices under its applicable privacy obligations.
Pros and Cons of Relying on a Single Consent Toggle in Australia
- Pro: Simplifies user experienceOne toggle can improve transparency and reduce friction for users.
- Con: May not satisfy all APP obligationsThe Privacy Act 1988 requires more than a single toggle—context, purpose, and processing rules matter.
- Pro: Aligns with industry trends toward centralised consentMany organisations are adopting unified consent mechanisms.
- Con: Risk of non-compliance if not mapped to actual technologiesA universal toggle does not guarantee compliance with Australian privacy laws.
- Pro: Easier for internal governance and auditsCentralised tracking supports accountability under the Privacy Act.
- Con: Over-simplification may misrepresent legal standingSignals must be validated against jurisdiction-specific frameworks like GPP or TCF.
Use industry trends as context, not permission
IAB Australia’s Data State of the Nation Report 2025 found that 92% of surveyed industry decision-makers viewed data usage as critical or very important to commercial success. It also found that 44% rated their understanding of Australia’s Tranche 1 Privacy Act reforms at 6 or above on a 10-point scale; 67% said they were at least somewhat prepared for the changes.
Those figures describe industry views and reported preparedness; they do not establish that a particular permission signal is valid or that an organisation meets its obligations. Use them as context for clear governance, and decide on signals against the organisation’s actual technologies, markets and applicable rules.
Australian Industry Preparedness for Privacy Reforms (2025)
- 92%% viewing data as critical to success
- 1% rating understanding of Tranche reforms at 6+ (10-point scale) — 44%
- 67%% at least somewhat prepared for changes
- 1988Applicable legislation
In this guide
- Mapping permission signals through the ad supply chainA permission signal can change meaning as it passes from a site to an advertising platform and downstream partners.
- Checking how vendors handle missing consent signalsA missing permission signal is not a blank cheque.
- Documenting responsibility for advertising data requestsAn advertising data request may reach the advertiser, publisher, consent provider or technology vendor.



