# Privacy & Consent Standards

> How GPP/TCF consent strings, DDRF deletion, Privacy Sandbox retirement, SKAdNetwork, AdAttributionKit, and ATT constrain advertising — validated September 2026.

- Canonical: https://nofluffadvisory.com/standards/privacy-consent-platform-apis/
- Standards last validated: 2026-09-08

---

*Standards & Protocols*

Reference

The consent strings, deletion frameworks, taxonomies, browser APIs, and OS-level constraints that govern what advertising systems can do.

Agentic advertising needs more than task protocols. It needs permission boundaries. Consent, regional privacy strings, deletion requests, platform APIs, browser controls, operating-system rules, and output policy all define what agents and platforms are allowed to execute.

*Figure: Seven permission inputs resolving through one permission-and-policy layer into six possible decisions — from targeting allowed to human approval required.*

If the protocol says the agent can act, privacy and platform rules decide whether it should.

## Fast read

- **What it is:** A guide to the privacy, consent, deletion, browser, OS, and platform rules that constrain what advertising systems — and agents — are allowed to do.
- **What it covers:** GPP, TCF, the Privacy Taxonomy, the Data Deletion Request Framework, the Accountability Platform, Privacy Sandbox status, SKAdNetwork, AdAttributionKit, and ATT.
- **What it is not:** It is not legal advice and not a full compliance manual. It is a map of the standards that make permission machine-readable.
- **Why it matters:** Agents can execute faster than governance can react. Permission boundaries have to be machine-readable before activation scales.
- **Best for:** AdTech, MarTech, media, data, AI, agency, publisher, and brand leaders designing activation and measurement under privacy constraints.
- **Best next read:** Core AdTech Standards, IAB Agentic Standards, and Enterprise Data Collaboration.

*Why it belongs here*

## Why privacy belongs in the standards stack.

Agentic advertising will still depend on the old rails. Agents need workflow protocols, runtime standards, transaction objects, privacy constraints, measurement trust, and research evidence. This page covers the constraint layer: the consent, deletion, browser, OS, and policy rules that decide whether a permitted action is also an allowed one.

- **01 · Protocols define the action** — AdCP and the agentic standards describe what an agent can request and execute.
- **02 · Consent defines the permission** — GPP and TC strings carry what a person allowed — purpose by purpose, jurisdiction by jurisdiction.
- **03 · Deletion defines the obligation** — Right-to-Delete requests must propagate to every system that holds the data.
- **04 · Platforms define the rails** — Browsers and operating systems decide what advertising code can observe and measure.
- **05 · Policy defines the output** — Output rules decide what leaves a system: person-level, cohort, or aggregate-only.
- **06 · Humans define the threshold** — Some actions should require a person, no matter what the protocol allows.

**The principle**

Permission boundaries must be machine-readable before agentic activation scales.

*IAB privacy frameworks*

## Five frameworks that make permission machine-readable.

Public documentation describes these five IAB Tech Lab frameworks as one interlocking privacy portfolio: GPP and TCF carry the consent signals, the Privacy Taxonomy labels the data, the Data Deletion Request Framework propagates deletion requests, and the Accountability Platform specifies how to audit whether signals were honored.

- **Signal transport · GPP — Global Privacy Protocol** — An IAB Tech Lab protocol for transmitting privacy, consent, and consumer-choice signals from sites and apps to ad tech providers — renamed from Global Privacy Platform to Global Privacy Protocol in February 2025, same acronym. Spec v1.0 was finalized September 28, 2022 (CMP API v1.1 followed in June 2023), and carries jurisdiction-specific sections — IAB Europe TCF, IAB Canada TCF, the MSPA US National string, and individual US state strings. The agentic question: which privacy signal applies to this person, in this jurisdiction, right now?
- **Consent and legal basis · TCF — Transparency and Consent Framework** — IAB Europe’s consent framework, with technical specifications stewarded by IAB Tech Lab. The operating version is TCF v2.3 — launched April 2025, released June 19, 2025, with the February 28, 2026 adoption deadline now passed; it makes the Disclosed Vendors segment mandatory in the TC String, and IAB Europe states that TC Strings created after that date without it are invalid. The CMP API stays at v2.2 (last updated February 2026 for disclosedVendors) and the Global Vendor List at format v3. A v2.4 technical update for TCF Policies v5.0.b — a standardTexts field in the GVL and removal of the Special Purpose–only vendor disclosure requirement — closed public comment June 29, 2026 and was merged into the specification repository July 20, 2026; IAB Europe’s TCF page still names v2.3 and its February 28, 2026 deadline as the current adoption milestone — validate current status. The agentic question: did the person grant a basis for this purpose and this vendor?
- **Common language · Privacy Taxonomy** — A classification language for data elements, data uses, and data subjects, so systems can label data the same way for rights handling and partner exchange. Released for public comment in September 2024, with implementation guidelines in comment through April 2025; IAB Tech Lab’s privacy-portfolio table lists it as v1.0 at public-comment status, with no finalization noted. The agentic question: can the agent describe what the data is, how it is used, and whose it is?
- **Deletion propagation · DDRF — Data Deletion Request Framework** — A standardized mechanism for transmitting Right-to-Delete signals through the ad supply chain — request packets, propagation sequence, signatures, response codes, and discovery. Version 1.0 was released May 2024 and announced final on June 5, 2024; version 2.0 was released August 2026 after a fall-2025 public-comment round. It addresses deletion rights under GDPR, US state privacy laws, and Quebec Law 25. The agentic question: when a person asks for deletion, does the request reach every system the agent touched?
- **Signal accountability · Accountability Platform** — A specification — not a live service — for open, auditable data structures that detect miscommunication of privacy preference signals such as GPP and TC strings across the supply chain. Version 1.0 of the spec was finalized November 5, 2024. The agentic question: can the ecosystem prove the consent signal was honored downstream?

Version and status details above reflect official sources as of September 2026. Public-comment drafts are not operating versions; validate current status before implementation.

*Browser privacy APIs*

## Browser privacy APIs: check the status before the architecture.

This is the part of the stack where assumptions age fastest. In April 2025, Google announced that Chrome would keep third-party cookies under the existing user-choice settings, with no standalone prompt. In October 2025, it announced the retirement of most Privacy Sandbox ad APIs — including Topics, Protected Audience, and Attribution Reporting — citing ecosystem feedback and low adoption. The November 2025 Intent-to-Deprecate threads then deprecated all three in Chrome 144 (January 2026) with removal planned for Chrome 150; Chrome Platform Status listed the removal milestone as Chrome 153 (September 2026) as of this validation. Google's feature-status page (updated August 14, 2026) still lists CHIPS, FedCM, and Private State Tokens as continuing.

- **Interest signals — retiring · Topics API** — Designed to support interest-based advertising without sharing the specific sites a person visited. Google announced retirement of the API in October 2025, citing ecosystem feedback and low adoption. The November 2025 Intent to Deprecate and Remove deprecated it in Chrome 144 (stable January 13, 2026) with removal planned for Chrome 150; Chrome Platform Status now lists the removal milestone as Chrome 153 (stable September 8, 2026), with the entry still marked Proposed. Validate the current milestone before any dependency.
- **On-device auctions — retiring · Protected Audience API** — Designed to run on-device ad auctions in the browser for remarketing and custom audiences without cross-site tracking. The same October 2025 retirement announcement applies. Deprecated in Chrome 144 under the November 2025 Intent to Deprecate and Remove, with removal planned for Chrome 150 and the removal milestone now listed as Chrome 153 on Chrome Platform Status — validate the current milestone.
- **Conversion reports — retiring · Attribution Reporting API** — Designed to connect ad interactions to conversions through browser-generated reports rather than cross-site tracking. Also covered by the October 2025 retirement announcement: deprecated in Chrome 144 with removal planned for Chrome 150 and the removal milestone now listed as Chrome 153 on Chrome Platform Status; server-side summary-report computation was scheduled to stop by late December 2025. Google intends to carry the work into an interoperable attribution standard at the W3C. Validate the current milestone.

**The framing**

Privacy Sandbox APIs should be treated as browser-platform constraints and capabilities with retirement announced — not replacements for cookies.

*Figure: Browser APIs with retirement announced and Apple’s OS attribution frameworks feed one shared constraint: platforms set what advertising systems may observe, target, and measure.*

*Apple and mobile attribution*

## Apple and mobile attribution.

On mobile, the operating system is the permission layer. Apple’s attribution and tracking frameworks define what app advertising can measure, at what granularity, and with whose authorization.

- **Install attribution · SKAdNetwork** — Apple’s privacy-preserving install-validation API for ad networks and apps. The current documented version is version 4: up to three conversion windows starting iOS 16.1, up to three postbacks, and a winning postback plus up to five runner-up postbacks. Two older methods are deprecated — the framework itself remains documented and interoperable with AdAttributionKit.
- **Newer framework · AdAttributionKit** — Apple’s newer attribution framework, available from iOS, iPadOS, and Mac Catalyst 17.4. It supports install and re-engagement attribution, works in the App Store and alternative app marketplaces, requires no App Tracking Transparency authorization, and sends cryptographically signed postbacks with no user- or device-specific data. Apple documents formal interoperability with SKAdNetwork and recommends AdAttributionKit for new ad campaigns.
- **Tracking authorization · ATT — App Tracking Transparency** — The framework that gates tracking across apps and websites: apps must declare a usage description and request user authorization before accessing app-related data for tracking. Available from iOS and iPadOS 14.0, with equivalents on macOS, tvOS, and visionOS. Public documentation shows no deprecation notes — ATT remains in force.

For app-growth teams, DSPs, and MMPs, the practical point is that postback windows, conversion granularity, and re-engagement support are implementation-sensitive and version-dependent. Validate current platform behavior before committing a measurement design to it.

- [Mobile identifiers, SKAN, AdAttributionKit, Android Advertising ID → Video & Mobile Ad Delivery Standards](https://nofluffadvisory.com/standards/video-mobile-ad-delivery/)
- [Mobile App Growth playbook](https://nofluffadvisory.com/services/playbooks/mobile-app-growth/)

*Agentic implications*

## What this means for agents.

An agent that can transact is not an agent that may transact. Each constraint below is a runtime question the system should be able to answer before it acts — and a failure mode if it cannot.

| Constraint | Agentic question | Risk if ignored |
| --- | --- | --- |
| Consent string | Does the GPP or TC string permit this purpose, this vendor, this jurisdiction? | Activation without a legal basis, executed at machine speed. |
| Deletion request | Has the deletion request propagated to every system the agent touches? | Deleted data resurfacing in targeting, enrichment, or training. |
| Browser API | Is the capability the workflow relies on still supported by the browser? | Pipelines built on retiring APIs that quietly stop returning data. |
| OS attribution | Does the measurement design respect SKAdNetwork and AdAttributionKit constraints? | Attribution claims the platform cannot actually support. |
| Output policy | Is the output aggregate-only where required, with no person-level leakage? | Person-level data leaving a system that promised aggregates. |
| Human approval | Does this action cross a threshold where a person must approve? | Privacy-sensitive actions executed without accountability. |

*Figure: Every agentic action passes a consent check and a policy check before it is allowed, escalated to a human, or blocked.*

*No Fluff POV*

## No Fluff POV.

Privacy cannot be bolted onto agentic advertising later. The permission layer has to be designed in from the start — consent checked before action, deletion propagated by default, outputs constrained by policy, and people in the loop where the stakes are high. And the layer earns its keep twice: the same permissions that keep a system away from what it must not touch also tell it which signal matters — consent, provenance, and scope are a relevance input, not only a brake. The operator case: [permissions are a relevance signal](https://nofluffadvisory.com/writing/the-context-economy/#permissions-are-a-relevance-signal).

- Treat consent and policy as runtime inputs, not legal paperwork.
- Encode permission boundaries where the agent executes — not only in a contract.
- Design deletion propagation before the first record is collected.
- Assume browser and OS rails keep moving; validate current status before building on them.
- Default to aggregate-only outputs and escalate exceptions to humans.
- Log which signal allowed each action, so the decision can be audited later.

**The point**

An agent that cannot show it was allowed to act should not act.

*Where this connects*

## Related materials.

### Standards

- [Core AdTech Standards](https://nofluffadvisory.com/standards/core-adtech-standards/)
- [IAB Agentic Standards](https://nofluffadvisory.com/standards/iab-agentic-standards/)
- [Video & Mobile Ad Delivery Standards](https://nofluffadvisory.com/standards/video-mobile-ad-delivery/)

### Standards deep dives

- [DOOH location signals and place-based privacy → DOOH & Place-Based Media Standards](https://nofluffadvisory.com/standards/dooh-place-based-media/)
- [Audio and podcast attribution caveats — downloads are not listens → Audio & Podcast Advertising Standards](https://nofluffadvisory.com/standards/audio-podcast-advertising/)
- [Consent, identity modules, and first-party data sharing become operational inside publisher auction workflows → Prebid & Header Bidding Infrastructure](https://nofluffadvisory.com/standards/prebid-header-bidding/)
- [PETs, PAIR activation, ADMaP attribution, and output policy — collaboration without sharing raw data → Data Clean Rooms, PETs & PAIR](https://nofluffadvisory.com/standards/data-clean-rooms-pets-interoperability/)
- [Server-to-server outcome events carry GPP consent metadata — gpp_string, gpp_sid, and a measurement-only flag → Event & Conversion APIs and Outcome Signals](https://nofluffadvisory.com/standards/event-conversion-apis-outcome-signals/)
- [First-party commerce data, closed-loop attribution, and in-store audience measurement under privacy constraints → Retail / Commerce Media Measurement](https://nofluffadvisory.com/standards/retail-commerce-media-measurement/)
- [Voluntary emissions estimation frameworks and the supply-chain data they depend on → Sustainable Media & Carbon Measurement](https://nofluffadvisory.com/standards/sustainable-media-carbon-measurement/)

### Operating playbooks

- [Enterprise Data Collaboration](https://nofluffadvisory.com/services/playbooks/multicloud-data-orchestration/)
- [Semantic Infrastructure](https://nofluffadvisory.com/services/playbooks/multicloud-data-orchestration/ecosystem-surfaces/semantic-infrastructure/)
- [Agentic Transformation](https://nofluffadvisory.com/services/playbooks/agentic-transformation/)
- [Mobile App Growth](https://nofluffadvisory.com/services/playbooks/mobile-app-growth/)

### Topics & essays

- [Embeddings](https://nofluffadvisory.com/topics/embeddings/)
- [Signal Containerization](https://nofluffadvisory.com/writing/signal-containerization-agentic-advertising/)
- [The Context Economy](https://nofluffadvisory.com/writing/the-context-economy/)

*Validate, don’t assume*

## Primary sources to validate.

Standards references last validated: September 2026. Specifications, APIs, public-comment status, release candidates, certification programs, and implementation guidance change. Validate against official documentation before implementation.

### Primary sources to validate (20 sources)

- [Global Privacy Platform (GPP) — IAB Tech Lab page](https://iabtechlab.com/gpp/) — IAB Tech Lab. Official standards page; confidence: primary; checked 2026-06-12. GPP is the protocol for transmitting privacy, consent, and consumer choice signals from sites and apps to ad tech providers across jurisdictions. Spec v1.0 finalized September 28, 2022; CMP API v1.1 (June 2023); jurisdiction sections include TCF EU, TCF Canada, the MSPA US National string, and US state strings. Supports: GPP definition, GPP v1.0 finalization (Sept 28, 2022), Jurisdiction sections.
- [Global-Privacy-Platform (spec repository)](https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform) — IAB Tech Lab (GitHub). Official GitHub; confidence: primary; checked 2026-06-12. Hosts the GPP Consent String Specification, Consent Management API Specification, and Supported Sections docs; maintained by IAB Tech Lab's Global Privacy Working Group, with ongoing releases for new US state sections. Supports: GPP technical spec documents, Governance, Active per-state section releases.
- [GDPR Transparency and Consent Framework (TCF) — IAB Tech Lab standards page](https://iabtechlab.com/standards/gdpr-transparency-and-consent-framework/) — IAB Tech Lab. Official standards page; confidence: primary; checked 2026-09-15. Current operating version is TCF v2.3 — launched April 2025 with an adoption deadline of February 28, 2026, now passed. It makes the Disclosed Vendors segment a mandatory part of the TC String, closing the legitimate-interest ambiguity carried by v2.2. The technical layer did not renumber with it: the CMP API remains v2.2 and the Global Vendor List stays at format v3.0. Until September 2026 this entry recorded v2.2 as operating and v2.3 as an unfinished draft — beneath a page card that already had v2.3 right, so the rendered page contradicted itself. Verified against iabeurope.eu, 2026-09-15. Supports: TCF operating version (v2.3; adoption deadline Feb 28, 2026, passed), Disclosed Vendors mandatory in the TC String, CMP API v2.2 / GVL format v3.0 — technical layer unchanged by v2.3, Policy/technical split.
- [GDPR-Transparency-and-Consent-Framework (spec repository)](https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework) — IAB Tech Lab (GitHub). Official GitHub; confidence: supporting; checked 2026-06-12. Hosts the TCF technical specifications (CMP API, consent string and vendor list formats, implementation guidelines). The top-level README's version narrative is dated — use the iabtechlab.com page for current-version claims. Supports: TCF spec document inventory.
- [Privacy Taxonomy — IAB Tech Lab standards page](https://iabtechlab.com/standards/privacy-taxonomy/) — IAB Tech Lab. Official standards page; confidence: primary; checked 2026-06-12. The Privacy Taxonomy is a classification language for data elements, data uses, and data subjects, supporting privacy compliance and data subject rights. Public comment opened September 2024; Implementation Guidelines comment ended April 17, 2025. No formal version number verified — avoid assigning one. Supports: Privacy Taxonomy definition (data / uses / subjects), Public-comment timeline.
- [IAB Tech Lab Unveils New Privacy Taxonomy for Public Comment](https://iabtechlab.com/press-releases/iab-tech-lab-unveils-new-privacy-taxonomy-for-public-comment/) — IAB Tech Lab. Official press release; confidence: supporting; checked 2026-06-12. September 2024 announcement of the Privacy Taxonomy for 30-day public comment, developed under the Privacy Implementation & Accountability Task Force (PIAT). Supports: Privacy Taxonomy launch (September 2024), PIAT attribution.
- [Data Deletion Request Framework — IAB Tech Lab standards page](https://iabtechlab.com/standards/data-deletion-request-framework/) — IAB Tech Lab. Official standards page; confidence: primary; checked 2026-06-12. The standardized mechanism for transmitting data deletion ('Right to Delete') request signals through the ad supply chain — request sequence/propagation, request packets, signatures, response codes, identifiers, and discovery. Finalized 2024; no version number published. Supports: DDRF definition and components, Finalized 2024 (no version number), Right to Delete scope.
- [IAB Tech Lab Finalizes Data Deletion Request Framework](https://iabtechlab.com/press-releases/iab-tech-lab-finalizes-data-deletion-request-framework-to-streamline-digital-ad-supply-chain-privacy-compliance-press-release/) — IAB Tech Lab. Official press release; confidence: supporting; checked 2026-06-12. Press release (dated June 5, 2024 on the page) announcing the finalized framework: validation of request origins, requester authenticity, receipt confirmation, and cryptographic signatures. Supports: DDRF finalized status (2024), Framework capabilities.
- [Accountability Platform — IAB Tech Lab standards page](https://iabtechlab.com/standards/accountability-platform/) — IAB Tech Lab. Official standards page; confidence: primary; checked 2026-06-12. A specification for open, auditable data structures and standard logging practices to detect miscommunication of user privacy preference signals (e.g., GPP/TC strings) across the ad supply chain. Version 1.0 spec finalized November 5, 2024 — a specification, not a verified live operated service. Supports: Accountability Platform definition, v1.0 spec (Nov 5, 2024), Spec-not-service framing.
- [IAB Tech Lab Privacy Pillar (portfolio overview)](https://iabtechlab.com/standards/privacy/) — IAB Tech Lab. Official standards page; confidence: context-only; checked 2026-06-12. Umbrella page for IAB Tech Lab's privacy standards portfolio, linking GPP, TCF, Privacy Taxonomy, Data Deletion Request Framework, and Accountability Platform materials. Supports: Framing the five frameworks as one privacy portfolio.
- [Update on Plans for Privacy Sandbox Technologies](https://privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies) — Google Privacy Sandbox. Official blog; confidence: primary; checked 2026-06-12. Google's October 17, 2025 announcement retiring most Privacy Sandbox ad APIs — including Topics, Protected Audience, and Attribution Reporting (Chrome and Android) — citing ecosystem feedback and low adoption. CHIPS, FedCM, and Private State Tokens continue. No concrete removal dates published. Supports: Current Privacy Sandbox status, Which APIs are retired vs continuing, Why Google retired the ad APIs.
- [Next steps for Privacy Sandbox and tracking protections in Chrome](https://privacysandbox.google.com/blog/privacy-sandbox-next-steps) — Google Privacy Sandbox. Official blog; confidence: primary; checked 2026-06-12. Google's April 22, 2025 announcement that Chrome will keep third-party cookies under the existing user-choice settings and will not roll out a standalone cookie prompt — reversing earlier deprecation plans. Supports: Third-party cookie status in Chrome, Cookie-deprecation reversal (April 2025).
- [Privacy Sandbox feature status](https://privacysandbox.google.com/overview/status) — Google Privacy Sandbox. Official docs; confidence: primary; checked 2026-06-12. Per-API status table (last updated October 17, 2025): Topics, Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage/SelectURL, and Related Website Sets marked 'Deprecate and remove'; CHIPS, FedCM, and Private State Tokens continue. The live tracker for validating current status. Supports: Per-API deprecation status, Live phase-out tracker.
- [Topics API — developer documentation](https://privacysandbox.google.com/private-advertising/topics) — Google Privacy Sandbox. Official docs; confidence: primary; checked 2026-06-12. Canonical Topics API docs: interest-based advertising without sharing the specific sites a user visited. Carries a phase-out banner — historically important, being retired; validate current status before building on it. Supports: What the Topics API does, Phase-out caveat.
- [Protected Audience API — developer documentation](https://privacysandbox.google.com/private-advertising/protected-audience) — Google Privacy Sandbox. Official docs; confidence: primary; checked 2026-06-12. Canonical Protected Audience (formerly FLEDGE) docs: on-device ad auctions run by the browser for remarketing / custom-audience ads without cross-site third-party tracking. Carries the same phase-out banner — validate current status. Supports: What Protected Audience does, Phase-out caveat.
- [Attribution Reporting API — developer documentation](https://privacysandbox.google.com/private-advertising/attribution-reporting) — Google Privacy Sandbox. Official docs; confidence: primary; checked 2026-06-12. Canonical Attribution Reporting docs: browser-generated reports matching ad interactions to conversions without cross-site tracking. Carries the same phase-out banner — validate current status. Supports: What Attribution Reporting does, Phase-out caveat.
- [SKAdNetwork — Apple Developer documentation](https://developer.apple.com/documentation/storekit/skadnetwork) — Apple Developer. Official docs; confidence: primary; checked 2026-06-12. Apple's privacy-preserving install-validation API. Documents version 4: up to three conversion windows (starting iOS 16.1), up to three postbacks, and a winning postback plus up to five runner-up postbacks. Only two methods are deprecated — not the framework; Apple recommends AdAttributionKit for new ad campaigns. Supports: What SKAdNetwork does, SKAdNetwork version 4 specifics, Apple's AdAttributionKit recommendation.
- [AdAttributionKit — Apple Developer documentation](https://developer.apple.com/documentation/AdAttributionKit) — Apple Developer. Official docs; confidence: primary; checked 2026-06-12. Apple's newer attribution framework (iOS/iPadOS/Mac Catalyst 17.4+): install and re-engagement attribution for ads in the App Store and alternative marketplaces, no ATT authorization required, cryptographically signed postbacks containing no user- or device-specific data. Supports: What AdAttributionKit does, OS availability (17.4+), Re-engagement and alternative-marketplace support.
- [Understanding AdAttributionKit and SKAdNetwork interoperability](https://developer.apple.com/documentation/adattributionkit/adattributionkit-skadnetwork-interoperability) — Apple Developer. Official docs; confidence: supporting; checked 2026-06-12. The authoritative reference for how AdAttributionKit and SKAdNetwork interact when delivering ad impressions — the two frameworks coexist and interoperate; neither has fully replaced the other. Supports: AdAttributionKit–SKAdNetwork relationship.
- [App Tracking Transparency — Apple Developer documentation](https://developer.apple.com/documentation/apptrackingtransparency) — Apple Developer. Official docs; confidence: primary; checked 2026-06-12. ATT requires apps to declare NSUserTrackingUsageDescription and request user authorization (ATTrackingManager.requestTrackingAuthorization) before accessing app-related data for cross-app/website tracking. Available iOS/iPadOS 14.0+; no deprecation notes — ATT remains in force. Supports: What ATT does and requires, OS availability.

> Platform capabilities and naming change quickly. Last validated: 2026-09-08. Check current documentation before implementation. Standards references last validated: September 2026. Specifications, APIs, public-comment status, release candidates, certification programs, and implementation guidance change. Validate against official documentation before implementation.
