In recent years, US data privacy regulations have been multiplying. While they share a common foundation, each state brings its own set of nuances, making compliance a logistical headache for companies operating across state lines.
To tackle this fragmented landscape, the US media and publishers ecosystem is steadily adopting the Global Privacy Platform (GPP), a standardized protocol designed to broadcast user preferences across the entire advertising supply chain. In this latest edition of Compliance Check-Up, we break down how the GPP works, when you actually need it, and how to easily enable it straight from your Axeptio back-office.

The GPP: Why Was This Standard Created?
Unlike Europe, where the GDPR provides a unified framework across all member states, the US lacks a single, overarching federal privacy law governing personal data and tracking technologies.
Ever since the California Consumer Privacy Act (CCPA) came into effect, a growing number of states have rolled out their own legislation. Furthermore, this regulatory landscape is in a constant state of flux, with new local laws surfacing on a regular basis.
However, a fragmented landscape doesn't necessarily mean each state operates on a completely different wavelength. At their core, these regulations all pivot on the same underlying mechanism: the opt-out model. Unlike the GDPR, which requires explicit prior consent (opt-in) before dropping cookies or trackers, US laws allow tracking by default, provided users are given a clear way to opt out. (If you want to dive deeper into the contrast between the EU and US models, check out our previous Compliance Check-Up: Privacy Made in USA: Navigating a Fragmented and Evolving Regulatory Landscape).
For companies operating across multiple US states or on an international scale, this patchwork of state-specific rules turns broadcasting user privacy preferences to downstream partners into a highly complex ordeal.
The Global Privacy Platform (GPP) was born precisely to solve this bottleneck. Spearheaded by the IAB Tech Lab, this standard establishes a common language to encode and signal user privacy choices across the board, regardless of the specific jurisdiction in play.
When Should You Use the GPP?
The GPP isn’t a one-size-fits-all requirement for every organization. Its relevance ultimately boils down to your target market and the partners with whom you share privacy-related data.
For a website catering exclusively to a European audience, the GDPR naturally remains the gold standard. Publishers serving ads on their own sites via Google solutions already rely on the Transparency & Consent Framework (TCF), which is tailor-made for the European ad ecosystem.
The GPP, on the other hand, was engineered to streamline compliance with US privacy laws by providing a standardized communication format for players across the digital supply chain. Keep in mind: it is a technical standard, not a legal regulation. As such, it proves particularly invaluable for publishers (such as news organizations and media platforms) that target a US audience and work with AdTech partners who need to instantly parse user choices against a myriad of US laws.
How Does the GPP Work?
At its core, the Global Privacy Platform condenses a user’s privacy preferences into a single alphanumeric string, aptly named the GPP_String.
This string encodes the user's choices according to applicable regulations into a unified structure. It is broken down into distinct sections, where each section maps to a specific regulatory framework and can be parsed exclusively by the relevant partners.
Operationally, the GPP can rely on the Multi-State Privacy Agreement (MSPA), a sweeping industry contract designed to bring order to the execution of fragmented US privacy laws. In this sense, the standard provides a common baseline that facilitates seamless data sharing among signatories. It is this approach to GPP management that Axeptio has chosen to offer you through its back-office system.
Activating the GPP in the Axeptio Back-Office
To help companies looking to leverage this standard, Axeptio now offers native support for the Global Privacy Platform directly within its back-office.
Setting up a GPP banner is straightforward: simply select the United States as your target broadcasting region and choose "Global Privacy Platform (GPP)" as your regulatory framework. Axeptio does the heavy lifting, automatically applying the appropriate parameters for this standard.

Enabling the GPP also triggers a new option in the back-office: Enable MSPA opt-out mode. As previously mentioned, this document serves as the contractual bedrock for the GPP. By signing this agreement, the various players within the ecosystem pledge to abide by the same rules when interpreting user privacy signals. For this reason, Axeptio requires administrators to review and explicitly accept the MSPA terms before deploying a GPP banner.
From the end-user’s perspective, the front-end experience looks remarkably similar to a standard CCPA banner.
The three existing display modes remain fully available:
- Hide the banner and collect data by default (provided you offer a clear opt-out mechanism for users and support Global Privacy Control (GPC) signals, which Axeptio handles natively).
- Display an informational banner while collecting data by default (again, contingent upon providing an opt-out mechanism and supporting GPC).
- Display a banner and delay tracking until the user makes a choice (mirroring the strict European approach).
The standout difference lies within the advanced choices. Unlike a traditional CCPA banner, the GPP does not support granular, purpose-by-purpose customization. Consequently, the familiar "Let me choose" button is replaced by "See partners", allowing users to review exactly which vendors are involved in processing their data, strictly in line with the standard's design.