Introduction
At its core, the Global Privacy Platform GPP is a technical standard for consumer privacy communication. Developed by IAB Tech Lab (part of the Interactive Advertising Bureau), it gives websites and apps a standardized way to encode and transmit privacy and consent information across the digital advertising and martech ecosystem.
In early 2025, IAB Tech Lab formally renamed the initiative from “Global Privacy Platform” to “Global Privacy Protocol” to clarify that it is a specification, not a software product. The acronym GPP remains unchanged in documentation and vendor integrations, so you will see both names used interchangeably.
GPP acts as a transport layer for privacy signals. Instead of maintaining separate mechanisms for each law, CCPA/CPRA, VCDPA, CPA, CTDPA, and so on, GPP bundles them into one encoded GPP string. The framework encodes and transmits consumer privacy preferences across digital advertising, giving downstream technology vendors a single, consistent source of truth.
At a high level, a single GPP string can contain multiple regulatory sections:
- A US national string aligned with the Multi-State Privacy Agreement (MSPA)
- State-specific US state strings (California, Colorado, Virginia, etc.)
- An EU section carrying Transparency and Consent Framework data
- An IAB Canada Transparency and Consent Framework section
GPP is maintained under IAB Tech Lab’s Project Rearc. Implementation guidelines were finalized in February 2025 and will be updated through 2026 to reflect new US state privacy laws.
Why a Global Privacy Platform Is Needed
The United States has no unified federal privacy law. Instead, a growing number of comprehensive privacy laws create a patchwork of regulatory demands that complicates consent management and opt-out handling for every online business.
Here is a snapshot of key US data privacy laws and when they took or take effect:
State | Law | Effective |
|---|---|---|
California | CCPA / CPRA | 2020 / 2023 |
Virginia | VCDPA | Jan 2023 |
Colorado | CPA | Jul 2023 |
Connecticut | CTDPA | Jul 2023 |
Utah | UCPA | Dec 2023 |
Oregon, Texas, Florida, Montana | Various | 2024 |
Tennessee, Delaware, Iowa, Nebraska, New Hampshire, New Jersey | Various | 2024β2025 |
Minnesota, Maryland, Indiana, Kentucky, Rhode Island | Various | 2025β2026 |
Each law defines slightly different terminology, “sale,” “sharing,” “targeted advertising”, and grants different consumer rights. Some require explicit consent for sensitive data; others rely on opt-out models. Several now require recognition of universal opt-out mechanisms like Global Privacy Control.
US regulators are ramping up enforcement. Florida’s Attorney General received 596 consumer complaints under its Digital Bill of Rights in its first reporting period alone. California and Colorado have conducted enforcement sweeps targeting businesses that fail to honor browser-based opt-out signals.
GPP addresses fragmented US privacy regulations through a unified approach. Without it, brands would need fragmented, custom implementations and state-by-state logic, increasing the risk of non-compliance and inconsistent consumer privacy experiences.
How the GPP Works at a High Level
The basic flow is straightforward. A consent management platform collects user privacy and consent choices, then encodes them into a GPP string that ad tech providers, analytics tools, and marketing platforms can read and act on.
Here is the simplified sequence:
- A visitor lands on your site
- Your CMP detects the visitor’s region (geo-IP, Shopify market settings, browser signals)
- The CMP displays the appropriate UI-opt-out banners for US states, informed consent flows for GDPR in the EU/EEA, or other region-specific interfaces
- The user makes their selections (opt-out of sale, reject targeted advertising, customize sensitive data preferences)
- The CMP generates the GPP string and stores it in the browser
- Downstream vendors read the GPP string via the GPP API and adjust their behavior accordingly
GPP provides a common format for encoding consumer privacy choices. The string starts with a header section indicating which regulatory sections are present (e.g., US national string, California section, Colorado section), followed by separate encoded segments for each jurisdiction.
The GPP architecture enables seamless propagation of privacy preferences to vendors. It can represent both consent-based data models and opt-out logic, depending on the jurisdiction. For US states, this typically means opt-out signals for sale, sharing, and targeted advertising. For GDPR (General Data Protection Regulation), it requires explicit consent. GPP can also accommodate frameworks like APPI, Japan’s primary data protection law (amended in 2022).
Critically, GPP accommodates universal opt-out mechanisms like Global Privacy Control. When a CMP detects a GPC signal in the browser, it encodes the corresponding opt-out choices into the appropriate US state sections of the GPP string. In US states where applicable laws allow it, GPP can enable automatic opt-out without requiring a separate cookie consent banner interaction.

GPP as a Foundation for US State Privacy Compliance
For US businesses and global merchants targeting US customers, GPP provides the only standardized framework that covers all active state privacy strings in one place. GPP simplifies compliance by allowing a single system to manage multiple state laws.
The MSPA US National Section
The MSPA (Multi-State Privacy Agreement), created by IAB Privacy for industry stakeholders, is an evolution of the LSPA (Limited Service Provider Agreement). The MSPA includes a US National section for unified compliance and provides a path for signatories to meet state privacy requirements through a “highest common denominator” approach. It facilitates compliance for digital advertising transactions by encoding privacy signals that align with-or exceed-many individual state law requirements. Member companies that sign the MSPA can use this US national string as a baseline.
- No coding required
- Works with all Shopify themes
- Blocks tracking before consent
- Google Consent Mode v2 ready
- Trusted by 180k+ stores
- 2,900+ 5-star reviews
- Google CMP Partner
State-Specific Coverage
GPP includes state-specific sections for 15 or more US states. By August 2026, finalized production sections are established in California, Virginia, Colorado, Utah, Connecticut, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Oregon, Montana, Texas, Maryland, Indiana, Kentucky, Florida, and Rhode Island.
GPP supports multiple state-specific privacy strings in the US, and GPP includes jurisdiction-specific privacy sections to address local laws. GPP supports consent signals for multiple US state laws, and is recommended for managing US state privacy signals-especially as more states enact comprehensive privacy laws.
While GPP is not mandated by any US statute, it is the IAB Tech Labβrecommended standard and is widely expected by ad exchanges, SSPs, DSPs, digital publishers, and major ad platforms. Compliance teams that adopt GPP can focus on practical outcomes, honoring “Do “ot Sell or Share” across states, standardizing targeted advertising opt-outs, rather than maintaining separate technical implementations for every jurisdiction.
The GPP String: What It Represents for Consent Data
The GPP string is a compact, Base64-like encoded representation of a useruser’svacy preferences across multiple jurisdictions. Think of it as a passport that carries all of a user’s consent strings and privacy choices in one place.
For US privacy specifications, the GPP string captures granular choices:
- Opt-out of sale or sharing of personal data
- Opt-out of targeted advertising
- Limits on sensitive data processing
- Consent for specific categories (where required by law)
- Known-child data flags
The same GPP string may also include European TCF v2.3 consent data, Canadian TCF preferences, or other frameworks, allowing global vendors to “read once, act everywhere.” GPP allows businesses to communicate privacy choices uniformly across platforms.
GPP standardizes privacy signals across jurisdictions and improves auditing and governance through consistent records. Technical details like Fibonacci encoding and tilde separators are handled entirely by CMPs and SDKs; compliance teams and marketing teams mainly need to understand that the string is auditable, standardized consent data. PIPL, China’s data privacy law with extraterritorial reach, is an example of a regime whose requirements future GPP sections could address as the protocol expands.
Developers who want to inspect strings can use public decoder tools or CMP-provided debugging utilities.
GPP vs. Other Consent and Privacy Mechanisms
Understanding how GPP fits alongside other privacy tools is essential for building a modern compliance strategy. Here is how GPP compares to the most common mechanisms.
GPP vs. IAB Europe TCF v2.3: The Transparency and Consent Framework sets the consent model for the EEA/UK, where GDPR governs personal data processing in the EU and EEA. GPP is the global transport layer that carries TCF sections, among others. TCF is the only framework for EU consent purposes, while GPP is the vehicle that delivers it alongside US and Canadian signals.
GPP vs. the deprecated US Privacy String: Before GPP, a simpler “US Privacy String” handled early CCPA opt-outs. It could only encode sale opt-outs-no state-level nuances, sensitive data, or child data flags. GPP is recommended over the deprecated US Privacy String because new state-specific strings after 2023 are available only via GPP.
GPP vs. Global Privacy Control (GPC): GPC is a browser-level signal that expresses a user’s preference to opt-out of sale or sharing. GPP does not replace GPC; it encodes and transmits that preference downstream through the digital ad supply chain so ad tech vendors can honor it programmatically.
GPP vs. Google Consent Mode: Google Consent Mode v2 controls how Google’s services behave based on user consent. GPP provides the encoded consent data that CMPs expose to Google Consent Mode to drive its behavior. They work in tandem.
For US state compliance, a modern strategy combines a CMP, GPP support, Google Consent Mode v2, and GPC handling to cover both explicit choices and browser-based opt-out signals. GPP does not replace a consent management platform; CMPs are still needed to show banners, collect choices, and map legal requirements into privacy signals that GPP can transport. GPP is not the only framework you need, but it is the only framework that unifies preference signaling across multiple frameworks.

Role of Consent Management Platforms (CMPs) in GPP Implementation
CMPs are the operational layer that makes GPP practical. They interface with visitors through banners and preference centers and with back-end vendors through APIs and tag management.
A Google-certified consent management platform handles the following in a GPP implementation:
- Jurisdiction detection: Determines the visitor’s jurisdiction via geo-IP, store settings, or Shopify market configuration and loads the appropriate UI-explicit consent banners for GDPR/UK GDPR, or opt-outβcentric interfaces for US states
- GPP string generation: Once a user acts (accepts, rejects, customizes), the CMP generates or updates the GPP string, storing it in the browser and exposing it via the GPP API
- Managing user consent: Centralizes consent management, logging consent data for audit and ensuring that ad tech and analytics tools correctly interpret and honor the GPP string
- Vendor coordination: Ensures that downstream partners, ad networks, measurement pixels, and analytics platforms receive consistent GPP signals
GPP integrates with CMPs to manage consent signals and to manage user consent preferences effectively. GPP helps manage consent and opt-out preferences efficiently by giving CMPs a standardized output format, rather than forcing them to produce multiple proprietary signals for each vendor.
For Shopify merchants, using a CMP integrated with Google Consent Mode and IAB GPP simplifies aligning cookie banners, tracking tags, and ad pixels with US and global privacy regulations.
How Pandectes Uses GPP to Support US Privacy Compliance
Pandectes is a Google-certified consent management platform for Shopify that supports IAB Tech Lab’s standards as part of its global privacy compliance capabilities. With over 180,000 Shopify store installs and processing more than 15 million consents per day, it is built for scale.
Pandectes helps Shopify stores comply simultaneously with GDPR, CCPA/CPRA, LGPD (which regulates personal data processing in Brazil), and other privacy laws. GPP supports GDPR, CCPA, LGPD, and other laws as the standardized layer for encoding US and other jurisdictional signals.
The Pandectes flow works like this:
- The app scans your Shopify store for tracking technologies (cookies, pixels, scripts)
- It categorizes each technology and maps it to legal consent categories
- Region-specific banners and consent flows are configured automatically
- When a visitor interacts with the banner, Pandectes generates a compliant GPP string
- That string is aligned with Google Consent Mode v2, Google Ad Manager, Google Analytics, and other major ad platforms that read GPP or related privacy signals
For multi-market Shopify merchants, Pandectes GDPR Compliance app unifies consent data, including GPP sections, TCF where applicable, and local consent requirements, into a single, auditable privacy platform. This simplifies ongoing legal compliance, reporting, and lawful processing of user preferences across internal systems and external vendors.
Conclusion
The Global Privacy Platform (GPP) is a vital tool for businesses navigating the complex landscape of US state laws and global privacy regulations. By providing a unified, standardized framework for encoding and transmitting consumer privacy preferences, GPP simplifies compliance across multiple jurisdictions, including the fragmented US privacy landscape and international laws like GDPR and LGPD. Its integration with consent management platforms and support for consumer choice signals such as Global Privacy Control ensures efficient management of opt-out requirements and targeted advertising restrictions.
As privacy laws continue to evolve, the flexible GPP framework and its contractual framework, the Multi-State Privacy Agreement (MSPA), offer a scalable, future-proof solution that helps businesses maintain compliance while minimizing operational complexity in the digital advertising supply chain. Adopting GPP is a strategic step for any organization committed to robust privacy management and responsible data practices in today’s market.


