Written by: Aaron Rovner, Founder, Saas Hero | Last updated: September 6, 2026
Key Takeaways
- 2026 introduces overlapping regulatory enforcement, technical mandates, and steep penalties across GDPR, CCPA/CPRA, and new U.S. state laws, so unified compliance frameworks now sit at the center of adtech operations.
- Adtech privacy compliance depends on mapping data flows, deploying certified consent management platforms, enforcing technical controls, auditing vendor contracts, and building consumer rights response processes.
- Recent enforcement actions, including the $12.75 million GM CCPA settlement and €40 million Criteo GDPR fine, show regulators now prioritize data minimization, consent documentation, and downstream vendor controls.
- TCF v2.3 and GPP frameworks are now mandatory for EEA/UK and U.S. state compliance respectively, which requires CMPs that support both standards and robust proof-of-consent logging.
- SaaSHero helps B2B companies running programmatic advertising maintain compliance alongside performance, and you can book a discovery call to audit your adtech compliance posture before the next enforcement wave.
Adtech Privacy Compliance: Definitions And Core Concepts
Adtech privacy compliance is the continuous process of aligning digital advertising operations, data flows, and tracking technologies with privacy regulations including GDPR, CCPA/CPRA, and emerging U.S. state laws. It requires mapping data collection, deploying consent management, enforcing technical controls, and auditing vendor relationships to ensure lawful processing of personal data in programmatic advertising.
Several frameworks and terms govern this space.
- GDPR: The EU General Data Protection Regulation requires opt-in consent for behavioral advertising and imposes fines up to €20 million or 4% of global annual revenue.
- CCPA/CPRA: California’s privacy law requires opt-out mechanisms, honors the Global Privacy Control signal, and carries penalties up to $7,988 per intentional violation.
- CMP (Consent Management Platform): Software that captures, stores, and signals user consent choices across the adtech stack.
- TCF (Transparency and Consent Framework): IAB Europe’s standard for communicating GDPR consent signals across publishers, vendors, and platforms in the EEA.
- GPP (Global Privacy Platform): IAB Tech Lab’s framework for signaling privacy choices across U.S. state laws and other regimes.
- Data Flow Mapping: The documented inventory of every party, system, and data category involved in collecting, processing, and transferring personal data in your adtech stack.
This article follows a five-step operational compliance framework: map data flows, deploy consent management, enforce technical controls, audit vendors, and build a consumer rights response process.
The 2026 Regulatory Landscape For Programmatic Advertising
Three regulatory regimes define the compliance perimeter for most programmatic advertisers operating in 2026.
Key Privacy Concerns In Adtech center on four practices. Cross-context behavioral advertising tracks users across sites without clear disclosure. Sale or sharing of personal data to DSPs, SSPs, and data brokers often occurs without adequate notice. Precise geolocation tracking reveals sensitive patterns of behavior. Programmatic data flows across the supply chain remain opaque for most consumers.
France’s Conseil d’État upheld a €40 million fine against Criteo on March 4, 2026, confirming that behavioral advertising requires consent under GDPR Article 6(1)(a). Legitimate interest does not cover tracker-based retargeting. The General Motors $12.75 million CCPA settlement shows regulators now treat data minimization and downstream data broker sharing as active enforcement priorities.
SaaSHero helps B2B companies navigate this regulatory patchwork while keeping paid media performance on track. Book a discovery call to map your exposure across GDPR, CCPA/CPRA, and applicable state laws.
The Five-Step Adtech Compliance Framework For 2026
Step 1: Map Every Data Flow In Your Adtech Stack
GDPR Article 30 requires controllers to maintain written records of processing activities, including purposes, data categories, recipients, transfer mechanisms, retention periods, and security measures. This record forms the baseline for a defensible data flow map and must be available to supervisory authorities on request.
Use these practical steps for adtech data flow mapping.
- Inventory every pixel, SDK, tag, and cookie firing on your properties using a tag management system audit.
- Identify all parties receiving data, including publishers, SSPs, DSPs, data brokers, measurement providers, and analytics vendors.
- Document the category of personal data each party receives, such as IP address, device ID, precise geolocation, and browsing behavior.
- Map transfer mechanisms for cross-border flows, including EU-U.S. Data Privacy Framework participation or Standard Contractual Clauses.
- Record retention periods for each data category and each vendor.
- Treat the map as a living document and update it whenever you add, change, or remove a vendor or tracking technology.
Step 2: Deploy A Compliant Consent Management Platform
TCF v2.3 became mandatory on March 1, 2026, and any new TC string without a disclosedVendors segment is invalid. Google requires publishers serving ads to EEA or UK users through AdSense, Ad Manager, or AdMob to use a Google-certified CMP integrating the TCF. A non-compliant CMP silently drops ad requests to limited ads, which reduces revenue without triggering an obvious error.
Focus on these CMP deployment requirements.
- Select a CMP registered on the IAB Europe CMP list that supports TCF v2.3 and GPP.
- Configure the CMP to capture proof of consent per EDPB Guidelines 05/2020, including timestamp, notice shown, purpose accepted, and withdrawal state.
- Ensure refusal is as easy as acceptance, with no pre-ticked boxes and no consent walls.
- Offer separate consent choices for each processing purpose rather than bundled approval.
- Configure consent renewal at intervals not exceeding 12 months, consistent with CNIL recommendations.
- For U.S. traffic, configure GPP to signal opt-out choices across applicable state privacy laws.
Step 3: Enforce Technical Controls
Consent signals only protect you when technical controls enforce them. A user who opts out must experience an actual cessation of tracking, not just a banner acknowledgment.
- Use a tag management system to block non-essential tracking scripts when users opt out or withhold consent.
- Configure Google Consent Mode to derive behavior directly from TCF signals, using the
gtag_enable_tcf_supportparameter. - Apply data minimization and collect only the data categories necessary for the stated purpose.
- Apply encryption and secure transfer protocols for all personal data in transit and at rest.
- Honor Global Privacy Control signals as valid opt-out requests under CCPA and applicable state laws.
- Configure consent withdrawal to propagate through downstream systems without undue delay.
Step 4: Audit Vendor Contracts And Data Processing Agreements
Tractor Supply’s $1.35 million CPPA enforcement order specifically cited insufficient service provider agreements and absence of required contractual provisions with advertising technology companies. Vendor contract failures now sit squarely in the enforcement spotlight.
Use this vendor audit checklist.
- Confirm each vendor has a signed Data Processing Agreement or service provider contract in place before data flows.
- Verify the contract prohibits the vendor from selling or sharing personal data, using it for purposes outside the contract, or retaining it after the relationship ends.
- Ask each vendor how they support TCF v2.3, how they handle opt-out requests, and what their data retention periods are.
- Confirm audit rights and liability clauses are included.
- For GDPR, confirm joint controller arrangements under Article 26 where applicable, since the Conseil d’État found Criteo’s Article 26 arrangements lacking.
- Build a third-party inventory identifying every recipient of consumer data, the privacy policy category covering it, and the legal basis for the transfer.
Step 5: Build A Consumer Rights Response Process
Consumer rights requests now function as mandatory workflows with strict timeframes. Under CCPA, businesses must respond to access, deletion, and correction requests within 45 calendar days and to opt-out requests within 15 business days. Virginia-model state laws require responses within 30 days.
- Establish documented intake workflows for access, deletion, correction, and opt-out requests.
- Implement identity verification procedures that do not impose undue burden, since American Honda was fined $632,500 for requiring excessive personal information before processing opt-out requests.
- Honor Global Privacy Control signals automatically as opt-out requests.
- Propagate deletion requests to service providers and data brokers.
- Document every request, response, and outcome for audit readiness.
- Train staff on escalation paths and response timelines.
Consent Management Frameworks: TCF And GPP In Practice
Two complementary frameworks now govern consent and privacy signaling across the programmatic ecosystem in 2026.
The TCF is IAB Europe’s standard for GDPR consent signaling in the EEA, connecting CMPs with the Global Vendor List to communicate user choices to publishers, SSPs, DSPs, and measurement vendors. TCF v2.3’s key change made the disclosedVendors segment mandatory in the TC string, which closed an ambiguity in vendor disclosure that existed under v2.2. A further update, TCF v5.0.b policy, opened for public comment on May 29, 2026, and addresses multi-device consent persistence and CTV environments, with web compliance required by mid-October 2026.
The GPP is IAB Tech Lab’s global platform for signaling privacy choices across U.S. state laws. On August 11, 2026, IAB Tech Lab opened proposed GPP updates for public comment, including changes to support the Fifth Amended and Restated Multi-State Privacy Agreement and simplify bid-request signaling.
Use each framework in these scenarios.
- TCF v2.3: Required for any programmatic advertising served to EEA or UK users and mandatory for Google-certified CMP eligibility.
- GPP: Required for U.S. state privacy law compliance signaling, including CCPA opt-out and state-specific consent choices.
- Both: A CMP supporting both frameworks now represents the standard configuration for advertisers operating across geographies.
Apply clear CMP selection criteria and verify IAB Europe registration, TCF v2.3 certification, GPP support, proof-of-consent logging, and Google certification status before deployment.
Recent Enforcement Actions And Lessons For Your Program
The enforcement record of the past twelve months provides the clearest signal of where regulators now direct attention.
FTC v. Cox Media Group (August 2026): The $930,000 combined settlement with Cox Media Group, MindSift, and 1010 Digital Works arose from deceptive claims about an AI active listening service. The companies marketed a product they claimed could target ads based on conversations captured from smart devices, while actually relying on resold email lists from data brokers collected without consumer consent. The compliance lesson focuses on substantiation of every claim about data collection, consumer consent, and AI capabilities, including statements in sales decks and vendor marketing materials.
FTC v. Kochava (May 2026): The proposed order prohibits Kochava from selling sensitive location data without affirmative express consent and a direct consumer relationship. The compliance lesson highlights precise geolocation data as high-risk and subject to explicit consent and strict downstream-use controls before any monetization.
FTC v. OkCupid (March 2026): The first Section 5 privacy action under Chair Ferguson arose from OkCupid sharing user photos and location data with an AI company for facial recognition model training, which occurred in 2014 but was settled in 2026. The compliance lesson emphasizes accurate privacy policies that describe downstream data sharing, including AI training uses, and shows that historical data-sharing decisions remain within regulatory reach.
California AG v. General Motors (May 2026): The $12.75 million settlement arose from GM selling OnStar driving and location data to data brokers without adequate notice. The settlement requires deletion of retained driving data within 180 days and a five-year stop on selling driving data to consumer reporting agencies. The compliance lesson underscores data minimization and deletion obligations across connected data ecosystems and highlights downstream data broker sharing as a current enforcement focus.
CNIL v. Criteo (March 2026): France’s Conseil d’État upheld the €40 million fine, confirming that behavioral advertising requires consent under GDPR Article 6(1)(a). Legitimate interest no longer serves as a lawful basis for tracker-based retargeting at scale. The compliance lesson directs any programmatic advertising program serving EEA users to rest on valid, documented consent.
SaaSHero’s data governance approach helps clients avoid these enforcement patterns while maintaining paid media performance. Book a discovery call to review your current compliance posture against the 2026 enforcement landscape.
Adtech Compliance Checklist For 2026
The following checklist covers operational requirements across the five-step framework and works as a pre-audit reference.
Data Flow Mapping
- Complete Article 30 records of processing activities for all adtech data flows.
- Inventory every pixel, SDK, tag, and cookie on all properties.
- Document all third-party recipients and their data categories.
- Map cross-border transfer mechanisms and safeguards.
- Record retention periods for each data category and vendor.
Consent Management
- Deploy a TCF v2.3-certified CMP for EEA and UK traffic.
- Configure GPP for U.S. state privacy law signaling.
- Capture proof of consent, including timestamp, notice shown, and purpose accepted.
- Ensure refusal is as easy as acceptance and avoid pre-ticked boxes.
- Set consent renewal intervals that do not exceed 12 months.
- Honor Global Privacy Control signals as valid opt-out requests.
Technical Controls
- Block non-essential tracking scripts via a tag management system when consent is withheld.
- Configure Google Consent Mode to align with TCF signals.
- Apply data minimization across all collection points.
- Apply encryption for personal data in transit and at rest.
- Propagate consent withdrawal to downstream systems without delay.
Vendor Contracts
- Confirm a signed Data Processing Agreement or service provider contract for every vendor before data flows.
- Verify contracts prohibit data sale, sharing, and retention beyond the relationship.
- Confirm TCF v2.3 support and opt-out handling with each vendor.
- Establish Article 26 joint controller arrangements where applicable under GDPR.
- Audit vendor contracts at least annually and whenever you add a new vendor.
Consumer Rights Processes
- Establish documented workflows for access, deletion, correction, and opt-out requests.
- Meet CCPA’s 45-day response window for access and deletion and the 15-business-day window for opt-outs.
- Implement identity verification that avoids undue burden.
- Propagate deletion requests to service providers and data brokers.
- Document every request and response for audit readiness.
Monitoring And Governance
- Conduct data flow mapping reviews at least annually.
- Monitor regulatory enforcement actions and framework updates for TCF and GPP.
- Maintain audit-ready documentation for all compliance decisions.
- Train staff on consumer rights escalation paths and response timelines.
SaaSHero can audit your current adtech compliance posture and identify gaps before your next regulatory review. Book a discovery call to get started.
Frequently Asked Questions
How GDPR And CCPA Differ For Adtech Programs
GDPR operates as an opt-in regime, so behavioral advertising requires freely given, specific, informed, and unambiguous consent before any tracking or targeting occurs. Legitimate interest does not qualify as a lawful basis for tracker-based behavioral advertising. CCPA and CPRA operate as an opt-out regime, so businesses may collect and use personal data for advertising unless the consumer actively opts out via a Do Not Sell or Share My Personal Information link or a Global Privacy Control signal.
The two regimes also differ in enforcement structure. GDPR is enforced by national data protection authorities across the EEA, while CCPA and CPRA are enforced concurrently by the California Privacy Protection Agency and the California Attorney General. A GDPR-compliant program still must meet CCPA’s opt-out link requirements, GPC signal recognition obligations, and service provider contract provisions.
Why U.S.-Only Advertisers Still Need A CMP
CCPA and CPRA require opt-out mechanisms for the sale or sharing of personal information, and businesses must honor Global Privacy Control signals as valid opt-out requests. Colorado, Oregon, New Jersey, and Montana also require honoring universal opt-out mechanisms. A CMP supporting the GPP framework helps manage multi-state compliance by signaling opt-out choices across applicable state laws through a single technical implementation.
Even when your current audience is entirely domestic, a CMP provides the operational infrastructure for honoring consumer rights at scale and demonstrating compliance to regulators.
How Often To Audit Adtech Vendors
Plan vendor audits at least annually and immediately whenever you add or change a vendor, modify data flows, or expand into a new geography. The FTC’s OkCupid enforcement action shows that data-sharing decisions made over a decade ago remain within regulatory reach. Tractor Supply’s $1.35 million CPPA settlement specifically cited the absence of required contractual provisions with advertising technology companies.
Vendor audits should cover Data Processing Agreement terms, TCF v2.3 support, opt-out handling procedures, data retention periods, and audit rights. Build the annual vendor review into your compliance calendar as a standing obligation.
Typical Penalties For Adtech Privacy Non-Compliance
Penalties vary by jurisdiction and violation type. Under CCPA and CPRA, fines reach $7,988 per intentional violation, assessed on a per-violation basis with no cure period for most violations since 2023. Under GDPR, fines can reach €20 million or 4% of global annual revenue, whichever is higher.
State laws carry penalties ranging from $7,500 per violation in Virginia, Indiana, and Kentucky to $10,000 per violation in Rhode Island and $20,000 per violation in Colorado. FTC enforcement can result in monetary penalties, injunctive relief, and mandatory compliance programs. The General Motors CCPA settlement reached $12.75 million, and the Criteo GDPR fine reached €40 million, which now represent the current enforcement ceiling.
How TCF And GPP Work Together
TCF, or Transparency and Consent Framework, is IAB Europe’s framework for collecting and communicating GDPR consent signals in the EEA. It connects CMPs with the Global Vendor List to transmit user choices to publishers, SSPs, DSPs, and measurement vendors through a standardized TC string. TCF v2.3 is the mandatory version as of March 1, 2026.
GPP, or Global Privacy Platform, is IAB Tech Lab’s framework for signaling privacy choices across U.S. state privacy laws and other regimes outside the EEA. GPP supports the Multi-State Privacy Agreement and handles the opt-out signaling requirements of CCPA, Colorado, Virginia, and other state laws through a single bid-request signal. The two frameworks work together, with TCF governing EEA consent and GPP governing U.S. state opt-out signaling, and a properly configured CMP supports both.