Lesson 5 of 5 · 9 min read · intermediate
Consent and privacy law: GDPR, TCF, GPP, CCPA and India's DPDP
How GDPR, the IAB TCF, GPP, CCPA/CPRA and India's DPDP Act shape what ad tech may collect, and how consent travels through a bid request.
Every cookie banner you click is the visible tip of a legal machine. Behind it, a consent string records what you agreed to, and that string rides along in every bid request so hundreds of companies can check whether they are allowed to use your data. Privacy law decides the rules; industry frameworks turn them into code.
Consent is like a permission slip for a school trip. The law says the school needs one. The framework is the standard form everybody uses, with tick boxes for bus ride, museum and photos. The consent string is the signed form photocopied and handed to every teacher on the trip, so each one knows what they are allowed to do.
The big laws, side by side
| Law | Where | Core idea for advertising |
|---|---|---|
| GDPR (in force May 2018) plus the ePrivacy Directive | EU and EEA; UK has its own version | You need a lawful basis to process personal data; for cookies and similar tracking, the ePrivacy rules generally require prior opt-in consent |
| CCPA / CPRA / CPRA (in force 2020, expanded 2023) | California, US | Opt-out model: people can say do not sell or share my personal information, including for cross-context behavioral advertising |
| Other US state laws | Virginia, Colorado, Texas and many more | Mostly opt-out rights for targeted advertising, with different details per state |
| India DPDP Act 2023 plus DPDP Rules 2025 | India | Consent-centred: processing needs free, specific, informed consent or a listed legitimate use, with a consent manager framework |
| LGPD | Brazil | GDPR-inspired, with several lawful bases including consent and legitimate interest |
| APPI | Japan | Rules on personal information and on sharing personally referable information with third parties |
| PIPA | South Korea | Strict consent requirements and strong enforcement by the privacy commission |
India's DPDP Act and Rules
India passed the Digital Personal Data Protection Act in August 2023. The government notified the DPDP Rules on 13 November 2025 with a phased rollout: the Data Protection Board provisions came first, the consent manager framework follows about a year later, and most substantive obligations apply after 18 months, around May 2027. Penalties can reach ₹250 crore per breach. For ad tech, the big shifts are clear notice and consent, the right to withdraw consent as easily as giving it, and extra care for children's data, which restricts tracking and targeted advertising aimed at under-18s.
How consent travels through ad tech
- A banner appearsA CMP (consent management platform) on the site or app shows the choices.
- Choices become a stringThe CMP encodes your answers, per purpose and per vendor, into a compact consent string.
- The string joins the auctionThe publisher's ad stack puts the string into every bid request, following OpenRTB conventions.
- Each vendor checks itselfDSPs, SSPs and data partners read the string and must not use personal data for purposes you refused.
- Changes flow throughIf you change your mind later, the CMP updates the string and future requests carry the new choice.
TCF and GPP: the frameworks
In Europe the dominant standard is the IAB Europe IAB TCF. Version 2.2, rolled out in 2023, removed legitimate interest as a basis for personalised advertising purposes, tightened wording shown to users, and required CMPs to show how many vendors are asked for consent. The TCF has faced legal scrutiny: in 2022 Belgium's data protection authority found problems with how it worked, and in 2024 the EU Court of Justice ruled that a TC string can be personal data.
The US patchwork of state laws needed a different container. The IAB Tech Lab's IAB Global Privacy Platform (Global Privacy Platform), launched in late 2022, is one string that can carry several regional signals at once: TCF for Europe, the US national and state-specific sections, and more. Browsers can also send a Global Privacy Control signal, which California and several other states treat as a valid opt-out of sale or sharing.
Opt-in (EU, India)
- No tracking until the person agrees
- Silence or pre-ticked boxes do not count
- Withdrawal must be as easy as consent
- Lower addressable scale, clearer legal footing
Opt-out (most US states)
- Processing allowed until the person objects
- Do not sell or share links and GPC signals
- Sensitive data and minors often need opt-in
- Higher scale, but a moving patchwork of rules
Special cases
- Children: COPPA in the US, GDPR's child provisions and India's DPDP Act all restrict tracking of minors.
- Big platforms: the EU's Digital Markets Act requires designated gatekeepers to get consent before combining personal data across their services, and the Digital Services Act bans targeted ads to minors and ads based on sensitive data on online platforms.
- Apple's App Tracking Transparency: not a law, but a platform rule that works like one for iOS apps.
- Data minimization: most laws say collect only what you need, which cuts against sending full user data to every bidder.
Key takeaways
- Privacy laws set the rules; frameworks like IAB TCF and GPP encode user choices into consent strings.
- Europe and India are broadly opt-in for tracking; most US state laws, including CCPA/CPRA, are opt-out.
- TCF v2.2 (2023) removed legitimate interest as a basis for personalised ads.
- India's DPDP Rules were notified on 13 November 2025, with most obligations phased in over 18 months.
- Consent strings travel in bid requests and can be faked, so verify that consent was genuinely collected.
Questions people ask
What is the IAB TCF?
The Transparency and Consent Framework is IAB Europe's standard for collecting and passing user consent in digital advertising. A consent management platform shows a banner, records choices per purpose and per vendor, and encodes them into a TC string sent with ad requests. Vendors must read the string and respect the choices. Version 2.2 launched in 2023.
When do India's DPDP Rules take effect?
The DPDP Rules, 2025 were notified on 13 November 2025 with phased timelines. Provisions setting up the Data Protection Board applied first, the consent manager framework follows after about a year, and most remaining obligations, including notice and consent requirements for businesses, apply after 18 months, around May 2027. Companies should check the official text for exact dates.
What is the difference between GDPR and CCPA for advertisers?
GDPR, together with EU ePrivacy rules, generally requires opt-in consent before tracking people with cookies for advertising. CCPA as amended by CPRA mostly uses an opt-out model: businesses can process data but must let Californians opt out of the sale or sharing of personal information for cross-context behavioral advertising, including via Global Privacy Control signals.