Harnessing the Power of the Global Privacy Platform (GPP) with SecurePrivacy
The Global Privacy Platform (GPP) is a standardized framework created by the IAB to unify user consent signals across multiple privacy frameworks and jurisdictions. This guide explains what GPP is and how to enable it on your website through SecurePrivacy.
What Is the Global Privacy Platform?
- A protocol that consolidates different consent frameworks into a single standardized string known as the GPP String.
- Supports frameworks including:
- IAB Europe’s Transparency and Consent Framework (TCF)
- IAB Canada TCF
- MSPA US National string
- US state privacy laws for California, Virginia, Utah, Colorado, and Connecticut
How GPP Works
- Reads and merges consent signals from regional frameworks into the GPP String.
- The GPP String contains:
- Header: Describes included jurisdictional frameworks.
- Sections: Holds jurisdiction-specific privacy and consent details.
Benefits of Implementing GPP
- Simplifies privacy compliance globally.
- Improves communication efficiency between websites, advertisers, and vendors.
- Built to adapt to evolving privacy regulations.
- Reduces compliance costs across multiple jurisdictions.
GPP and Compliance with Data Privacy Laws
- Supports EU GDPR via IAB's TCF v2.2 framework.
- Supports US state privacy laws, including:
- California (CCPA/CPRA)
- Virginia (VCDPA)
- Utah (UCPA)
- Colorado (CPA)
- Connecticut (CTDPA)
- SecurePrivacy supports US privacy strings:
- usca (California)
- usva (Virginia)
- usco (Colorado)
- usut (Utah)
- usct (Connecticut)
How to Enable GPP in SecurePrivacy: Step-by-Step
- Log in to your SecurePrivacy account.
- Navigate to your domain’s settings.
- Find the dropdown labeled Framework and select IAB GPP.
- Select the TCF Vendors you want to support.
- Choose relevant notices and opt-out categories to comply with US Privacy Strings and provide user control over their data.
Note: The US Privacy notices are not provided by SecurePrivacy. Customers must create and maintain these notices on their own domains.
Who Should Use This Guide?
- Compliance officers managing consent requirements across jurisdictions.
- Developers implementing privacy protocols.
- Marketing teams operating in global markets.
Common Issues & Fixes
Unsure which TCF vendors to include?
Consult the vendor list relevant to your jurisdiction.
Notices not applying correctly?
Ensure correct selection within SecurePrivacy settings.