GPP
3 chaptersThe Global Privacy Platform (GPP) is the container: the whole string is Header ~ Section ~ Section, with the Header declaring which sections travel in this bid. This chapter expands into three sub-pages: string structure, section registry and gpp_sid.
Enter chapter→TCF EU (GPP §2 payload)
5 chaptersTransparency & Consent Framework (TCF) EU is the payload of Global Privacy Platform (GPP) §2 and also coexists with GPP as the standalone TC string (leading C). The current baseline is Final v.2.2 with rolling 2.3 / 2.4 revisions; 2.4 has no released version and must not be cited as one.
Enter chapter→Canadian TCF (GPP §5)
0 chaptersThe Canadian edition of the Transparency & Consent Framework (TCF) published by the Interactive Advertising Bureau (IAB) Canada, carried as Global Privacy Platform (GPP) §5 with apiPrefix tcfcav1. This site's decoder only reads the leading Version field for this section; the field-level layout is not integrated.
Enter chapter→MSPA US National + states
21 chaptersThe Multi-State Privacy Agreement (MSPA) family: US National §7 is the baseline, and each state's §8–§27 is a subset with per-state N-Bitfield parameters. The technical-spec publisher and the MSPA contracting entity are two distinct parties (detailed below) and must not be conflated.
Enter chapter→USPrivacy String (GPP §6, legacy)
0 chaptersFour plaintext characters (version · explicitNotice · optOutSale · lspaCoveredTransaction), not base64-encoded — a ready-made counter-example to the assumption that section payloads must be bit-encoded. Support ended 2023-09-30, superseded by Global Privacy Platform (GPP) §6 in 2024-01; legacy traffic and some platform parameters still pass it directly, so it is honestly kept for debugging.
Enter chapter→Google Additional Consent
0 chaptersGoogle Additional Consent's addtl_consent (AC) string travels in the TCData returned by __tcfapi and is not a Global Privacy Platform (GPP) section. It works only alongside Interactive Advertising Bureau (IAB) Europe's Transparency & Consent Framework (TCF) v2, may only be created by a registered Consent Management Platform (CMP), and conveys transparency/consent to vendors not on the Global Vendor List (GVL) but on Google's Ad Tech Provider (ATP) list; whether it sunsets must come from Google's own documentation — this site asserts nothing.
Enter chapter→Global Privacy Control
0 chaptersGlobal Privacy Control (GPC) has a dual identity: natively the Sec-GPC request header (value 1, or the header omitted entirely; the official spec defines no 0) and navigator.globalPrivacyControl (true/false), expressible without the Global Privacy Platform (GPP) container; within GPP it is the first officially listed Reusable Subsection (SubsectionType Int(2)=1, payload a single Boolean), attachable to any section. It carries legal effect in California and elsewhere.
Enter chapter→CMP JS API
0 chaptersThe three browser-side entry points: __gpp() (the Global Privacy Platform (GPP) Consent Management Platform (CMP) API v1.1, 2023-06) / __tcfapi() (the pre-Transparency & Consent Framework (TCF) 2.2 entry, still coexisting) / __uspapi() (USPrivacy legacy). The queue-callback model, the generic command set, and the PingReturn / TCData return-body structures (the getGPPData command and GPPData object were deprecated in v1.1).
Enter chapter→