---
title: "GPP Guidelines and Changes"
canonical: "https://hub.freewheel.tv/space/BC/671711241/GPP%20Guidelines%20and%20Changes"
format: markdown
---
# Overview

The Global Privacy Protocol (GPP) is an IAB Tech Lab framework for communicating consumer privacy choices across multiple global privacy regulations. Buyer Cloud supports GPP consent signals defined under the Multi-State Privacy Agreement (MSPA) and ingests GPP strings provided by supported supply partners.

Buyer Cloud evaluates applicable GPP sections and enforces privacy restrictions in accordance with the consumer's preferences and the requirements of the applicable U.S. privacy law. 

Beeswax is a signatory to the IAB's and Limited Service Provider Agreement, so it ingests and complies with MSPA privacy strings provided by exchanges.

---

# Buyer Cloud GPP Protections

Buyer Cloud supports GPP signals in the following ways:

- Buyer Cloud supports GPP consent signals for the U.S. National section and participating state privacy frameworks.
- If an auction contains a supported GPP signal, Buyer Cloud evaluates the applicable consumer choices and enforces corresponding privacy restrictions.
- If no supported GPP signal is present, Buyer Cloud continues processing the auction according to existing privacy enforcement rules.

---

# Changed Fields in Log Files

Certain fields that are commonly used in RTB are considered “Personal Data”. To protect this data from being used or transferred outside of the Beeswax service, these fields are changed when passed in macros, bidding agent requests, augmentor requests, and log files. Specifically, for requests where MSPA applies and the user has opted out, the following fields are affected:

| **Raw Log Field Name** | **Proto Field Name** | **MSPA Handling** |
| --- | --- | --- |
| platform_device_ifa | Device.ifa | Blank |
| platform_device_idfa | Device.idfa | Blank |
| platform_device_didmd5 | Device.didmd5 | Blank |
| platform_device_didsha1 | Device.didsha1 | Blank |
| platform_device_dpidmd5 | Device.dpidmd5 | Blank |
| platform_device_dpidsha1 | Device.dpidsha1 | Blank |
| user_id | N/A | Blank |
| geo_lat | Device.lat | Truncated to 3 decimal places |
| geo_long | Device.long | Truncated to 3 decimal places |
| ua | Device.ua | Blank |
| ip_address | Device.ip | Truncated to 3 octets |
| ipv6_address | Device.ipv6 | Truncated to 6 octets |
| inventory_source_user_id | User.id | Blank |

Additionally, for records subject to MSPA handling and with a GPP string, the following fields are added:

| **Raw Log Field Name** | **Proto Field Name** | **Definition** |
| --- | --- | --- |
| GPP | RegulationsExtensions.gpp | Global Privacy Protocol string as defined by the IAB, and used to define the consent preferences governing the personal data contained within the associated bid request. |
| GPP_SID | RegulationsExtensions.gpp_sid | Global Privacy Protocol section identifier(s) as defined by the IAB and used to indicate which privacy framework(s) within the GPP string govern the personal data contained within the associated bid request. |

---

# Changes to Macro Values

When a request is subject to MSPA handling, macros change in the following way:

| **Macro** | **GDPR Handling** |
| --- | --- |
| {{USER_ID}} | Blank |
| {{IOS_ID}} | Blank |
| {{ANDROID_ID}} | Blank |
| {{LAT}} | Truncated to 3 decimal places |
| {{LONG}} | Truncated to 3 decimal places |
| {{USER_AGENT}} | Blank |
| {{IP_ADDRESS}} | Truncated to first 3 octets |
| {{IP_ADDRESS_IPV6}} | Truncated to first 6 octets |

The following three additional macros will expand when a GPP string is present in an auction:

| **Macro** | **Expansion** |
| --- | --- |
| {{GPP_STRING}} | The Global Privacy Protocol (GPP) string on the bid request used for privacy compliance. |
| {{GPP_STRING_ESC}} | The escaped Global Privacy Protocol (GPP) string on the bid request used for privacy compliance. |
| {{GPP_SID}} | The Global Privacy Protocol (GPP) section identifier(s) on the bid request used to identify the applicable privacy framework(s). |

---

# GPP Interaction with CCPA and GDPR

GPP does not replace Buyer Cloud's existing CCPA and GDPR compliance frameworks. Buyer Cloud continues to support both legacy CCPA privacy strings (US Privacy) and GDPR (TCF) strings provided by supported supply partners. When multiple frameworks across CCPA, GDPR, and GPP are present, Buyer Cloud evaluates the applicable privacy signals and applies the most restrictive outcome. This ensures that consumer privacy choices are respected regardless of whether they are communicated through US Privacy, TCF or GPP.

---

# Further Questions

For questions about Buyer Cloud’s GPP compliance not answered above, please reach out to your Customer Success Manager or Buyer Cloud Support.