COMPLIANCE

GDPR and CCPA Consent for Streaming Apps: A Practical Compliance Playbook

Published April 19, 2026 Updated September 18, 2026 8 min read OTTEngine Team

Every OTT app collects device IDs, IP addresses and viewing behaviour, and ad-supported apps add an advertising identifier on top. Consent is not just a web problem any more: GDPR applies to a Roku channel the same way it applies to a website, 19 US states now have comprehensive privacy laws in force, and the IAB's consent signals have changed twice since 2024. This playbook covers the rules, the signals ad tech expects on every request, and what each TV platform's own ad-tracking setting requires of your app.

The rules you must respect

  • GDPR and ePrivacy (EU and UK): consent for tracking. Every processing purpose needs a lawful basis under GDPR (ICO). Advertising tracking needs consent, and where the ePrivacy rules (PECR in the UK) apply, so does storing or reading non-essential information on the viewer's device, such as an advertising ID (ICO). Under the EU GDPR, fines reach EUR 20 million or 4% of worldwide annual turnover, whichever is higher (Article 83).
  • US state privacy laws: opt-out. Viewers must be able to stop the sale or sharing of their data, including for targeted advertising. California's CCPA/CPRA came first; by September 2026, 19 states have comprehensive laws in force, and Oklahoma, Louisiana, Alabama and Vermont follow between 2027 and 2028 (IAPP, Venable).
  • Children's privacy: COPPA. Stricter rules for anything directed at children under 13, covered in its own section below.

Geo-detect, then apply the right model

Detect the viewer's region from their IP address at session start and apply the matching model: consent before tracking in the EU and UK, opt-out rights for US viewers, and local rules elsewhere, such as Brazil's LGPD and Canada's PIPEDA. Store the region with the consent record and check it again after app updates. Region detection decides which consent flow a viewer sees, not whether GDPR applies: if your business is established in the EU or UK, the GDPR or UK GDPR covers your processing wherever your viewers are.

With 19 US state laws in force, "show Californians an opt-out and everyone else a notice" no longer holds. Giving every US viewer the same opt-out controls is a useful simplification over a state-by-state matrix, but not a complete compliance programme, because the laws still differ on points such as sensitive data and minors. The US National section of GPP, covered below, is the matching signal for companies that have signed the IAB's Multi-State Privacy Agreement (MSPA).

Designing the consent UX for TV

A remote control makes complex consent screens miserable. What works:

  • Ask before you first collect non-essential data, not before the viewer can browse.
  • Offer Accept all, Reject all and Manage choices on the first screen, with Reject all as easy to reach with the remote as Accept all. Making refusal harder than acceptance is the kind of dark pattern European regulators have called non-compliant.
  • Keep the first screen short enough to read from the couch, and put vendor lists behind Manage choices.
  • Remember the choice. Do not re-prompt on every launch, and let viewers change their mind from the app's settings.

IAB TCF: the European consent signal

The Transparency and Consent Framework (TCF) turns a viewer's choices into a TC string that ad-tech vendors read. Version 2.3, released in June 2025, is now mandatory: TC strings created since 1 March 2026 must include its disclosed-vendors segment, while strings created before then stay valid until viewers renew or change their choices (IAB Europe). Version 2.4 is next, and IAB Europe's compliance deadlines for CMPs are 23 October 2026 on the web and 23 February 2027 for mobile and CTV apps (IAB Europe).

Use a consent management platform (CMP) registered with IAB Europe that ships SDKs for every TV platform you publish on; a web-only CMP does not help a Roku channel. Pass the TC string with each ad request. In an IAB VAST tag that means the [GDPRCONSENT] macro alongside [REGULATIONS], and many ad servers read a gdpr_consent URL parameter instead. Our VAST ad-tag macros guide maps these across IAB, Google Ad Manager and Roku.

GPP: the US signal that replaced the US Privacy String

IAB Tech Lab deprecated the four-character US Privacy String on 31 January 2024 (IAB Tech Lab). Its replacement is GPP, launched as the Global Privacy Platform and renamed the Global Privacy Protocol in February 2025 (IAB Tech Lab). A single GPP string can carry several sections at once:

  • US National (section 7, usnat), which lets MSPA signatories meet the highest common denominator of state requirements in one string, instead of sending state sections (GPP implementation guidance). It is not a compliance guarantee: it only helps if your ad partners support the section and follow the MSPA, so confirm that with each one.
  • State sections (sections 8 to 27), one per state, from California and Virginia to Kentucky and Rhode Island.
  • TCF sections for the EU and Canada. GPP covers only the jurisdictions it defines sections for, so markets such as Brazil still need their own handling.

How the string reaches your demand partners:

WhereGPP stringApplicable sections
IAB VAST ad tag[GPPSTRING][GPPSECTIONID]
OpenRTB 2.6 bid requestregs.gppregs.gpp_sid
URL macros in ad server tagsgpp=${GPP_STRING_XXXXX}gpp_sid=${GPP_SID}

OpenRTB 2.6 lists the old regs.us_privacy field as deprecated. Some older integrations may still read it, so confirm with each partner before you stop sending it.

Honour Global Privacy Control where it applies

About a dozen US states, including California and Colorado, require businesses to treat an opt-out preference signal such as Global Privacy Control (GPC) as a valid opt-out (summary). Regulators are checking: in September 2025, California's privacy agency and the attorneys general of California, Colorado and Connecticut announced a joint sweep of GPC compliance (announcement).

The GPC specification covers browsers, so it mainly affects your web player and sign-up pages. On TV devices, the equivalent signal your app actually sees is the platform's own ad-tracking setting.

Each TV platform's ad ID and opt-out setting

Every major TV platform gives viewers a system-level switch for ad tracking. An ad-supported app must read it, pass it on with ad requests and respect it; consent collected inside your app does not override it.

PlatformAdvertising IDViewer settingWhat your app must do
RokuRIDA: GetRIDA(), IsRIDADisabled()Privacy > Advertising > Limit ad trackingNo targeting when it is on. The RIDA becomes a temporary 30-day ID that still goes on ad requests for frequency capping.
Amazon Fire TVAdvertising ID: advertising_id, limit_ad_trackingPreferences > Privacy Settings > Interest-based AdsNo interest-based ads or profiles. Contextual ads, frequency capping, conversion tracking, reporting and fraud detection remain allowed.
Android TV and Google TVAdvertising ID; apps need the AD_ID permission from Android 13Privacy > Ads > Delete advertising ID (Google TV)A deleted ID reads as zeros. No personalised ads.
Apple TVIDFA, gated by App Tracking Transparency on tvOS 14.5 and laterSettings > General > Privacy & Security > TrackingAsk for tracking permission before you track. If the viewer declines, the IDFA is all zeros.
Samsung TizenTIFA: webapis.adinfo.getTIFA(), isLATEnabled()Interest-Based Advertisements, under Terms & PolicyWhen limited, no interest-based ads. Send ifa, ifa_type=tifa and lmt with ad requests.
LG webOSNo public advertising-ID API; LG's ad APIs are for contracted partnersLimit AD Tracking, per the NAI's TV guideWork through LG's partner programme. If you cannot read the setting, the safe default is to treat the viewer as opted out.

Children's content and COPPA

If your app, or any section of it, is directed at children under 13, the FTC's amended COPPA Rule has applied in full since 22 April 2026. You need separate verifiable parental consent before disclosing children's data to third parties, including for targeted advertising, plus a written data retention policy and an information security program (Federal Register).

Advertising is still possible without that consent, within limits. The rule lets you collect a persistent identifier, and no other personal information, solely to support the app's internal operations, which it defines to include serving contextual ads and capping ad frequency, as long as you give the notice it requires. Without parental consent, that identifier must not be used for behavioural advertising or to build a profile of a child (16 CFR 312.2, 312.5). Our recommended policy for child-directed apps is simpler still: contextual ads only, with the child-directed flag your ad server defines set on every request; in an IAB VAST tag, that is [REGULATIONS] with coppa. Labelling matters as much as ad settings: in September 2025, Disney agreed to pay $10 million to settle FTC allegations tied to YouTube videos that were not marked as made for kids (FTC).

What it costs not to do this

The legal exposure is real. Beyond GDPR's EUR 20 million or 4% of turnover, California's fines currently run up to $2,663 per violation and $7,988 per intentional violation or violation involving known under-16s (California Privacy Protection Agency). Penalties are counted per violation, so one consent flaw repeated across many viewers adds up quickly.

The more immediate cost is commercial. Buyers expect a valid consent signal on every request, and bids that depend on personal data drop out when it is missing.

The bottom line

Build consent in from the first release: detect the region, collect choices with a CMP that covers your TV platforms, send TCF and GPP signals on every ad request, and respect each platform's own ad-tracking switch. Start a free trial to try OTTEngine with your own content.

Frequently Asked Questions

Does GDPR apply to my Roku channel?

If you offer the channel to viewers in the EU or UK, or track their viewing, yes. It can also apply because of where your business is established: an EU establishment brings its processing under GDPR wherever its viewers are, and a viewer's location alone does not settle the question (EDPB guidelines). Assess UK GDPR separately, on similar territorial principles.

Do I need a Consent Management Platform (CMP)?

If you serve programmatic ads to EU or UK viewers, effectively yes: TCF consent strings must come from a CMP registered with IAB Europe. Choose one with SDKs for every TV platform you ship.

What replaced the US Privacy String?

IAB Tech Lab's GPP, the Global Privacy Protocol. The four-character US Privacy String was deprecated on 31 January 2024. A GPP string carries the US National section, individual state sections and TCF in one signal, passed in IAB VAST tags as [GPPSTRING] and [GPPSECTIONID].

Which TCF version applies in 2026?

TCF v2.3. Since 1 March 2026, every newly created consent string must include its disclosed-vendors segment; strings created before then stay valid until viewers renew or change their choices. IAB Europe's next version, v2.4, has CMP deadlines of 23 October 2026 on the web and 23 February 2027 for mobile and CTV apps.

Can I show ads to kids if my app is COPPA-compliant?

Yes, within limits. Without parental consent you can serve contextual ads, and COPPA's internal-operations exception lets you use a persistent identifier for purposes such as frequency capping, provided you give the required notice and never use it for behavioural advertising or profiling. Behavioural targeting needs verifiable parental consent, and disclosing a child's data to third parties for targeted advertising needs separate consent. Contextual-only is the simplest policy.

What is Global Privacy Control (GPC)?

A signal, set in a browser or browser extension, telling sites that the user opts out of the sale or sharing of their data. About a dozen US states, including California and Colorado, require businesses to honour it. On TV devices, the platform's own ad-tracking setting is the signal your app sees.

Do I need consent to use a TV's advertising ID?

In the EU and UK, generally yes for advertising: where the ePrivacy rules apply, an app needs consent before it reads non-essential information from the device. In the US, respect the platform's own opt-out and pass its limit-ad-tracking flag with every ad request. On Apple TV you must also get App Tracking Transparency permission before tracking, or the IDFA reads as zeros.

Which US states have comprehensive privacy laws?

As of September 2026, 19 states have laws in force: California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. Oklahoma, Louisiana, Alabama and Vermont have passed laws that take effect between 2027 and 2028.

What is the difference between TCF and GPP?

TCF is IAB Europe's framework for recording consent under European law in a TC string. GPP is IAB Tech Lab's wider protocol: one GPP string can carry TCF sections for the EU and Canada alongside the US National and individual US state sections, so a single signal carries every jurisdiction GPP defines a section for. It has none for other markets, such as Brazil.

✍️
OTTEngine Team
Streaming technology experts helping publishers launch on Roku, Fire TV, and Apple TV.

Ready to launch your streaming channel?

Try OTTEngine free for 7 days - no setup fees and no long-term contract.

Start Free Trial

Related articles