---
title: "2023 US State Privacy Laws - Technical Frequently Asked Questions"
canonical: "https://hub.freewheel.tv/space/RCS/114229652/2023%20US%20State%20Privacy%20Laws%20-%20Technical%20Frequently%20Asked%20Questions"
format: markdown
---
Background What US state laws went into effect in 2023?  See  2023 US State Privacy Laws - General Frequently Asked Questions  for more details on the laws and their impact on FreeWheel. What is FreeWheel doing to support compliance with the 2023 US State privacy laws?  Since January 1st 2023, when the new California and Virginia laws went into effect, FreeWheel is able to honor an opt-out/opt-in for SPI, to restrict the use of audience segments identified as including SPI. FreeWheel receives this SPI specific opt-out/opt-in signal via the Global Privacy Platform (GPP)(see below), the new consent framework recently introduced by the IAB, similar to the Transparency and Consent Framework (TCF) and US Privacy Framework for CCPA.  IAB Global Privacy Platform  What is the GPP framework?  What are key components of the framework?   The  Global Privacy Platform (GPP)  is a new privacy framework created by the IAB which will enable all parties in the digital advertising chain to comply with regional privacy regulations more easily.  It is a single protocol which will contain privacy signals from multiple jurisdictions, including the existing TCF and CCPA US privacy signals, as well as new 2023 US Privacy signals.   The GPP iis implemented by Publishers and Consent Management platforms through a new  CMP API  and communicated to vendors via a new  consent string format .  I need to learn more about the GPP - where should I go?  Read more in the IAB GPP Spec here:  https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform How is FreeWheel adopting IAB GPP?   FreeWheel supports the two IAB standard parameters/macros (gpp and gpp_sid) to collect the GPP consent string when passed in the ad request by publishers integrating with the GPP. FreeWheel  parses the SPI opt-outs from the string and restricting audience targeting on any SPI flagged audiences. The full GPP string is then be passed downstream in the bid request.  Is FreeWheel still supporting US privacy signals?  FreeWheel continues to honor both US Privacy strings and GPP strings as they are sent to us in the ad request, and anticipate seeing less US Privacy strings as Publishers and CMPs transition fully to GPP SPI Audience Flagging How is Freewheel determining what segments are SPI? We are asking Publishers with 1st party data to flag which segments are SPI, as that determination will not be made by FreeWheel. We are separately working with 3rd party data providers to understand what 3rd party segments are SPI. Which audience products are supported with the SPI flag?  SPI flags will be supported in AIC and Datasuite. Implementation What did suppliers need to do by Jan 1st 2023?  Suppliers should integrate with the GPP CMP API (Spec here:  https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/blob/main/Core/CMP%20API%20Specification.md ), support the new US State sections (link out here), and Pass the  gpp  and  gpp_sid  values through the IAB parameters per the GPP String spec:  https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/blob/main/Core/Consent%20String%20Specification.md )  Additionally, suppliers with 1st party audiences should identify to FreeWheel which segments are SPI. What sections of the GPP contain SPI Opt outs? The highlighted sections below contain a field (SensitiveDataProcessing) which will indicate if a user has opted out of SPI.   Section ID Client-side API Prefix Description 1 tcfeuv1 EU TCF v1 section (deprecated) 2 tcfeuv2 EU TCF v2 section  (see note below) 3 GPP Header section (REQUIRED, see note below) 4 -- GPP signal integrity section 5 tcfca Canadian TCF section 6 uspv1 USPrivacy String  (Unencoded Format) 7 usnat US - national section  8 usca US - California section  9 usva US - Virginia section  10 usco US - Colorado section 11 usut US - Utah section  12 usct US - Connecticut section  How do I send the GPP String to FreeWheel? The GPP string should be sent to FreeWheel in the ad request through the following  Key Values  and macros:  Integration Types URL Parameter Corresponding Macro Representation in URL Direct XML Tag Based Active Display Tags LinkTag2 HTML5 SDK Flash SDK iOS SDK Android SDK gpp GPP_STRING_XXXXX (XXXXX is numeric GPP ID - the ID of the vendor on the GPP ID List who is expecting this URL call) &gpp=${GPP_STRING_XXX} gpp_sid GPP_SID &gpp_sid=${GPP_SID} The GPP ID for Freewheel will be 285, the same ID as Freewheel's GVL Vendor ID Below is a more detailed description of these macros: Macro Possible Values Purpose ${GPP_STRING_XXX} Url-safe base64-encoded GPP string. Encodes the GPP string, as obtained from the CMP JS API or OpenRTB ${GPP_SID} The section ID(s) in force for the current transaction. In most cases, this field should have a single section ID. In rare occasions where such a single section ID can not be determined, the field may contain up to 2 values, separated by a comma. As the GPP String may encode user preferences for multiple jurisdictions, this field indicates to the callee which section of the string is considered “in force” by the caller. This should match the value returned by the CMP API (see below). What Will FreeWheel be reading to understand if there is an Opt-Out or No Consent for SPI? The SensitiveDataProcessing field (as seen in the US National, California, Virginia, Colorado, Utah, and Connecticut sections) will capture whether or not a user has opted-out or not consented (depending on the state's requirements)  How do I indicate to Freewheel what 1st party segments are created with SPI? For Data Suite/ Audience Manager Ingestions, segment taxonomy files will need to be updated with a new column (SPI indicator) which will indicate if the segment is created using SPI. Values are below: Y- is an SPI segment N-not an SPI segment  For Audience Integration Center (AIC)/ DE Ingestion,  the data provider will have to provide a separate file (no change in regular DE ingestion process) comprising of SPI segments (one segment key per line).  The data provider will have to drop the file at sftp location  /mnt/sftponly/<data_provider_folder>/ files/audience/ingest/spi_segments with the below file name convention -  spi_<network_id>_<data_provider_id>_YYYYMMDDHHMMSS.csv The files they drop must have unique name. Example  File name: spi_169843_169843_20221102090000.csv File contents: cat_lover dog_lover ... What happens if suppliers don't send the IAB GPP signal?   If suppliers do not send the GPP signal, FreeWheel will be unable to parse SPI opt outs/ins and will not be able to pass this GPP signal on.    What happens if data providers don't send the SPI flag?  Any audiences which are not flagged as SPI will not be subject to SPI restriction in the event of an SPI Opt-Out or no SPI Opt-in. It's the Data providers responsibility to notify FreeWheel which Segments are created with SPI. Can we opt out all users from Virginia/California/Colorado/Utah/Connecticut by default if we do not have a valid GPP string available? Yes, FreeWheel does support default opt-out settings in the absence of an explicit opt out signal in ad calls, and this opt-out can be set state by state for Virginia/California/Colorado/Utah/Connecticut. Please reach out to your FreeWheel account team for more information. Can FreeWheel integrate directly with the GPP CMP API to retrieve the GPP string? Yes, for customers relying on our SDK integrations, we do support retrieving the GPP string using the GPP CMP API. How will FreeWheel handle the GPP Opt Out Of Sale, Opt Out of Sharing, and Opt Out of Advertising? As of the 6.56.0 Release F reeWheel will support the new Opt-Out of Sale, Opt-Out of Sharing, and Opt-Out of Advertising GPP signals. The features impacted by these Sharing/Sale/Advertising opt outs are listed below: Area Details Analytics and Reporting The following data elements will be removed from FreeWheel's V4 transactional logs if a user opt-out: IP Address, Device IDs, User IDs. In addition, the unique user count in FreeWheel's Analytics will be affected as the opted-out users are removed from calculation. Audience Targeting Data Provider user syncing triggered by FreeWheel ad response will be suppressed if a user opt-out, such as those utilized to sync cookie spaces between FreeWheel and DMPs. Audience targeting for all direct and programmatic placements in MRM will be suppressed. Note, audience targeting based on custom key-values in requests will continue to function, it is the responsibility of individual publishers to avoid sending PI as custom key-values in case of user opt-out. User Syncing Cookie-based user syncs triggered by FreeWheel ad response will be suppressed if a user opt-out, including MRM-SFX user sync. Forecasting Both Portfolio and Transactional forecasting results will be affected by user opt-out due to its reliance on historical traffic from multiple clients.  Market Module FreeWheel will send OpenRTB bid to DSP without personal information if there is an opt out. Macros By default, macros containing PI will not expand for all 3rd-party tags (including Server-Side Translation Framework) if user opted-out:  #{request.clientAddress} #{request.deviceId} #{request.keyValue("_fw_did")} #{request.keyValue("_fw_did_idfa")} #{request.keyValue("_fw_did_android_id")} #{request.keyValue("_fw_did_google_advertising_id")}  #{request.keyValue("_fw_vcid2")} #{request.keyValue("_fw_vcid")} #{request.keyValue("_fw_extra_lookup_id")} #{request.keyValue("ltlg")} #{request.keyValue("_fw_h_x_state")} #{request.keyValue("_fw_h_x_dma")} #{request.keyValue("_fw_h_x_postal_code")} #{request.keyValue("_fw_h_x_city)} #{request.keyValue("_fw_zipcode")} #{request.keyValue("_fw_zone")} #{request.keyValue("_fw_postalcode")} #{request.keyValue("_fw_zipcode")}   The following areas will be impacted if a user opts out of Sale, Sharing, or Advertising  for SFX: Area Details User Syncing Cookie-based user syncs triggered by FreeWheel ad response will be suppressed if user opt-out, including MRM-SFX user sync. Macros {ip}, {viewerId} will not expand if a user opt-out Bidding FreeWheel will send OpenRTB bid to DSP without personal information if there is an opt out. What Will FreeWheel be reading to understand if there is an Opt-Out or No Consent for SPI? The SensitiveDataProcessing field (as seen in the US National, California, Virginia, Colorado, Utah, and Connecticut sections) will capture whether or not a user has opted-out or not consented (depending on the state's requirements)  How do I indicate to Freewheel what 1st-party segments are created with SPI? For Data Suite/ Audience Manager Ingestions, segment taxonomy files will need to be updated with a new column (SPI indicator) which will indicate if the segment is created using SPI. Values are below: Y- is an SPI segment N-not an SPI segment  For Audience Integration Center (AIC)/ DE Ingestion,  the data provider will have to provide a separate file (no change in regular DE ingestion process) comprising of SPI segments (one segment key per line).  The data provider will have to drop the file at sftp location  /mnt/sftponly/<data_provider_folder>/ files/audience/ingest/spi_segments with the below file name convention -  spi_<network_id>_<data_provider_id>_YYYYMMDDHHMMSS.csv The files they drop must have unique name. Example  File name: spi_169843_169843_20221102090000.csv File contents: cat_lover dog_lover ... What happens if suppliers don't send the IAB GPP signal?   If suppliers do not send the GPP signal, FreeWheel will be unable to parse SPI opt-outs/ins and will not be able to pass this GPP signal on.    What happens if data providers don't send the SPI flag?  Any audiences that are not flagged as SPI will not be subject to SPI restriction in the event of an SPI Opt-Out or no SPI Opt-in. It's the Data provider's responsibility to notify FreeWheel which Segments are created with SPI. Can we opt out all users from Virginia/California/Colorado/Utah/Connecticut by default if we do not have a valid GPP string available? Yes, FreeWheel does support default opt-out settings in the absence of an explicit opt-out signal in ad calls, and this opt-out can be set state by state for Virginia/California/Colorado/Utah/Connecticut. Please reach out to your FreeWheel account team for more information. Can FreeWheel integrate directly with the GPP CMP API to retrieve the GPP string? Yes, for customers relying on our SDK integrations, we do support retrieving the GPP string using the GPP CMP API. How will FreeWheel handle the GPP Opt Out Of Sale, Opt Out of Sharing, and Opt Out of Advertising? As of the 6.56.0 release, F reeWheel will support the new Opt-Out of Sale, Opt-Out of Sharing, and Opt-Out of Advertising GPP signals. The features impacted by these Sharing/Sale/Advertising opt-outs are listed below: Area Details Analytics and Reporting The following data elements will be removed from FreeWheel's V4 transactional logs if a user opts out: IP Address, Device IDs, User IDs. In addition, the unique user count in FreeWheel's Analytics will be affected as the opted-out users are removed from calculation. Audience Targeting Data Provider user syncing triggered by FreeWheel ad response will be suppressed if a user opts out, such as those utilized to sync cookie spaces between FreeWheel and DMPs. Audience targeting for all direct and programmatic placements in MRM will be suppressed. Note, audience targeting based on custom key-values in requests will continue to function; it is the responsibility of individual publishers to avoid sending PI as custom key-values in case of user opt-out. User Syncing Cookie-based user syncs triggered by FreeWheel ad response will be suppressed if a user opts out, including MRM-SFX user sync. Forecasting Both Portfolio and Transactional forecasting results will be affected by user opt-out due to its reliance on historical traffic from multiple clients.  Market Module FreeWheel will send OpenRTB bid to DSP without personal information if there is an opt-out. Macros By default, macros containing PI will not expand for all 3rd-party tags (including Server-Side Translation Framework) if the user opted out:  #{request.clientAddress} #{request.deviceId} #{request.keyValue("_fw_did")} #{request.keyValue("_fw_did_idfa")} #{request.keyValue("_fw_did_android_id")} #{request.keyValue("_fw_did_google_advertising_id")}  #{request.keyValue("_fw_vcid2")} #{request.keyValue("_fw_vcid")} #{request.keyValue("_fw_extra_lookup_id")} #{request.keyValue("ltlg")} #{request.keyValue("_fw_h_x_state")} #{request.keyValue("_fw_h_x_dma")} #{request.keyValue("_fw_h_x_postal_code")} #{request.keyValue("_fw_h_x_city)} #{request.keyValue("_fw_zipcode")} #{request.keyValue("_fw_zone")} #{request.keyValue("_fw_postalcode")} #{request.keyValue("_fw_zipcode")} The following areas will be impacted if a user opts out of Sale, Sharing, or Advertising  for SFX: Area Details User Syncing Cookie-based user syncs triggered by FreeWheel ad response will be suppressed if the user opts out, including MRM-SFX user sync. Macros {ip}, {viewerId} will not expand if a user opts out Bidding FreeWheel will send OpenRTB bid to DSP without personal information if there is an opt-out. What will FreeWheel be reading to understand if there is an Opt-Out or No Consent for SPI? The SensitiveDataProcessing field (as seen in the US National, California, Virginia, Colorado, Utah, and Connecticut sections) will capture whether or not a user has opted out or not consented (depending on the state's requirements)  How do I indicate to Freewheel what 1st-party segments are created with SPI? For Data Suite/ Audience Manager Ingestions, segment taxonomy files will need to be updated with a new column (SPI indicator), which will indicate if the segment is created using SPI. Values are below: Y- is an SPI segment N-not an SPI segment  For Audience Integration Center (AIC)/ DE Ingestion,  the data provider will have to provide a separate file (no change in regular DE ingestion process) comprising of SPI segments (one segment key per line).  The data provider will have to drop the file at sftp location  /mnt/sftponly/<data_provider_folder>/ files/audience/ingest/spi_segments with the below file name convention -  spi_<network_id>_<data_provider_id>_YYYYMMDDHHMMSS.csv The files they drop must have unique name. Example  File name: spi_169843_169843_20221102090000.csv File contents: cat_lover dog_lover ... What happens if suppliers don't send the IAB GPP signal?   If suppliers do not send the GPP signal, FreeWheel will be unable to parse SPI opt-outs/ins and will not be able to pass this GPP signal on.    What happens if data providers don't send the SPI flag?  Any audiences that are not flagged as SPI will not be subject to SPI restriction in the event of an SPI Opt-Out or no SPI Opt-in. It's the Data provider's responsibility to notify FreeWheel which Segments are created with SPI. Can we opt out all users from Virginia/California/Colorado/Utah/Connecticut by default if we do not have a valid GPP string available? Yes, FreeWheel does support default opt-out settings in the absence of an explicit opt-out signal in ad calls, and this opt-out can be set state by state for Virginia/California/Colorado/Utah/Connecticut. Please reach out to your FreeWheel account team for more information. Can FreeWheel integrate directly with the GPP CMP API to retrieve the GPP string? Yes, for customers relying on our SDK integrations, we do support retrieving the GPP string using the GPP CMP API. How will FreeWheel handle the GPP Opt Out Of Sale, Opt Out of Sharing, and Opt Out of Advertising? As of the 6.56.0 Release F reeWheel will support the new Opt-Out of Sale, Opt-Out of Sharing, and Opt-Out of Advertising GPP signals. The features impacted by these Sharing/Sale/Advertising opt outs are listed below: Area Details Analytics and Reporting The following data elements will be removed from FreeWheel's V4 transactional logs if a user opts out: IP Address, Device IDs, User IDs. In addition, the unique user count in FreeWheel's Analytics will be affected as the opted-out users are removed from calculation. Audience Targeting Data Provider user syncing triggered by FreeWheel ad response will be suppressed if a user opts out, such as those utilized to sync cookie spaces between FreeWheel and DMPs. Audience targeting for all direct and programmatic placements in MRM will be suppressed. Note, audience targeting based on custom key-values in requests will continue to function, it is the responsibility of individual publishers to avoid sending PI as custom key-values in case of user opt-out. User Syncing Cookie-based user syncs triggered by FreeWheel ad response will be suppressed if a user opts out, including MRM-SFX user sync. Forecasting Both Portfolio and Transactional forecasting results will be affected by user opt-out due to its reliance on historical traffic from multiple clients.  Market Module FreeWheel will send OpenRTB bid to DSP without personal information if there is an opt-out. Macros By default, macros containing PI will not expand for all 3rd-party tags (including Server-Side Translation Framework) if user opted out:  #{request.clientAddress} #{request.deviceId} #{request.keyValue("_fw_did")} #{request.keyValue("_fw_did_idfa")} #{request.keyValue("_fw_did_android_id")} #{request.keyValue("_fw_did_google_advertising_id")}  #{request.keyValue("_fw_vcid2")} #{request.keyValue("_fw_vcid")} #{request.keyValue("_fw_extra_lookup_id")} #{request.keyValue("ltlg")} #{request.keyValue("_fw_h_x_state")} #{request.keyValue("_fw_h_x_dma")} #{request.keyValue("_fw_h_x_postal_code")} #{request.keyValue("_fw_h_x_city)} #{request.keyValue("_fw_zipcode")} #{request.keyValue("_fw_zone")} #{request.keyValue("_fw_postalcode")} #{request.keyValue("_fw_zipcode")} The following areas will be impacted if a user opts out of Sale, Sharing, or Advertising  for SFX: Area Details User Syncing Cookie-based user syncs triggered by FreeWheel ad response will be suppressed if user opts out, including MRM-SFX user sync. Macros {ip}, {viewerId} will not expand if a user opts out Bidding FreeWheel will send OpenRTB bid to DSP without personal information if there is an opt-out. Programmatic What did demand partners need to do by Jan 1st 2023?  Since January 1st, Freewheel sends the GPP string (when it is available in the ad request) through the GPP OpenRTB extension. No specific action is needed as SPI data is already not being sent in the bid request, and it is the responsibility of the DSP to honor the GPP per their own legal guidance. How will the GPP be sent in the bid request?  If a GPP signal is received in a request, it should be passed in bid request through the following OpenRTB Regs fields ext.gpp ext.gpp_sid Will the US State GPP Signals for Opt-out of Sale, Opt-out of Sharing, and Opt-out of Advertising be incorporated into the existing CCPA US Privacy logic for Opt-Out of Sale? As of the MRM 6.56 Release, an Opt-out of Sale, Opt-out of Sharing, or Opt-out of Advertising in the US Sections of the GPP will result in personal data being removed from the bid request. However, in that opted-out request, FreeWheel will continue to send personal data if the DSP is a signatory to the MSPA. Can we block bid requests in the event of a GPP signal? DSPs will have the following bid restriction options with regard to GPP opt-outs.  Do not send CCPA/GPP opt out of Sale/Sharing/Advertising requests - PG Deals only Do not send CCPA/GPP opt out Sale/Sharing/Advertising requests - Non-PG deals and auction rules Do not send SPI no consent requests - PG Deals only Do not send SPI no consent requests - Non-PG deals and auction rules