Privacy · 28 Apr 2026
GPP, TCF, and US state strings in the bid request
A consent string is not a banner. It is the note that says whether this person agreed to be identified, and under which law.

Before an ad auction, a website or app often asks the visitor to accept or refuse certain uses of their data. That choice has to reach every company in the bid, not only the publisher. If it does not, a DSP in Europe or a US state with a privacy law may be bidding on an impression it is not allowed to use.
The industry packed those choices into short strings. The one buyers should expect in 2026 is the Global Privacy Platform string, GPP. Older European traffic still carries the Transparency and Consent Framework string, TCF. US state opt-outs often travel inside GPP as well.
What the person actually decided
Consent and opt-out are different ideas, and the string should not blur them.
- Consent means the person said yes to a stated use, such as personalized ads or measurement. This is the usual European pattern under the TCF.
- Opt-out means ads can run until the person says no to “sale” or “sharing.” Several US state laws work this way. The string records the no.
- A missing string is not a yes. On traffic where a law applies, buyers should assume they lack permission until the signal says otherwise.
GPP in one paragraph
GPP is a container. One string can hold a European TCF section, a US national section, and sections for individual US states. A companion list, the GPP section ID, tells the reader which sections are present so nobody decodes the wrong law. IAB Tech Lab’s GPP is the string DSPs look for when the same request might be subject to more than one rule.
Where it sits in OpenRTB
Privacy signals belong with the request, not buried in an unstructured note. In current OpenRTB practice you will see:
regs.gppandregs.gpp_sidfor the GPP string and its section IDsuser.ext.consentor the TCF field your integration still documents, for a legacy European consent stringregs.ext.us_privacyfor the older US Privacy String, still present on some integrations that have not moved fully to GPPregs.coppawhen the inventory is directed at children under 13 in the United States. That flag is not a substitute for a consent string
Pass the string you received. Do not invent one, and do not copy yesterday’s string onto today’s user.
What a DSP should do with it
- Read which GPP sections apply.
- If the person refused personalized ads or opted out of sale or sharing, bid without using excluded identifiers. Contextual and first-party placements the law still allows are a different bid.
- If the string is required and absent, no-bid. A cheap win on an unlawful impression is not a bargain.
- Log the string with the impression so a later audit can show what you relied on.
What publishers and SSPs should do
- Fire the auction only after the consent dialog has answered, unless the law lets you request a non-personalized ad with no identifier.
- Put the same string on OpenRTB, Prebid, and any server-side stitcher. A CTV stitcher that drops GPP has dropped the only proof you had.
- Match the string to the region. A European TCF “yes” does not answer a California opt-out.
India’s DPDP Act is a separate statute with its own consent duties. Do not assume a GPP string satisfies it. This note is about the strings exchanges already pass in OpenRTB.
FAQ
Is GPP a replacement for a consent banner?
No. The banner, or the app’s privacy screen, collects the choice. GPP only carries it.
Can I send both TCF and GPP?
Yes during a transition. They must describe the same choice. Two strings that disagree are a bug, and buyers will trust neither.
Does a contextual ad still need the string?
If the request includes cookies, device IDs, or other personal data, yes. Dropping those fields is what makes the ad contextual. The string is how you prove you dropped them for the right reason.
← All posts · What is OpenRTB? · Privacy policy · Demand partners