pixellint

Blog · GPP

CM360 started reading GPP National v2. A US Privacy 1YNN string is not that hop.

Campaign Manager 360 started reading GPP National v2 in September 2025 and still reads v1. A US Privacy 1YNN string is not that hop. TCF stuffed into gpp is rejected.

The CM360 help article says it in the first sentence. Starting in September 2025, Google will support GPP National v2. Google will also continue to support GPP National v1. IAB TCF stays the GDPR hop. TCF strings sent through the GPP will not be accepted. GPP support for IAB TCF is incoming at a future date. That is the mix-up this month: a CMP upgrade that writes the TC String into gpp, or a leftover us_privacy=1YNN with no gpp_sid.

Pixel URLs still need two macros: gpp and gpp_sid. INS tags can pick the string up from the CMP APIs if the macros were not filled. A four-character CCPA leftover is a different parameter on a different generation of the spec. Google's own US-states page says Campaign Manager 360 will not support the GPP for the US Privacy String. Keep 1YNN if a partner still reads us_privacy. Do not call it National v2.

What Google actually reads

Campaign Manager 360, Search Ads 360, and Display and Video 360 can read a TCF v2.2 Transparency and Consent string for ad serving, tracking, and conversion tags. They still accept TCF v2.1 and want CMPs to follow IAB's move to v2.2. Floodlight tags are shared between CM360 and Search Ads 360, so permissions received in Campaign Manager are inherited by SA360.

GPP is the US path. CM360 supports the Global Privacy Platform US National string, including US states. The same article that announces National v2 also lists what Google does with that string. Restricted data processing triggers if the user opted out of sale, sharing, or processing for targeted advertising. Google only reads those fields of the US National string. Extra bits you encoded for a state law Google does not consume are not a second product.

State strings have their own RDP rules. California: sale or sharing opt-out. Colorado, Connecticut, Virginia, and Florida: sale or targeted advertising opt-out. Kids parameters exist on National and on states, with TFCD and RDP depending on the age band. You do not need to memorize every age row to traffic the tag. You do need gpp and gpp_sid on the live URL so those rows have a string to read.

The macros are gpp and gpp_sid, with a vendor id

The primary mechanism is macros. GPP macros on Campaign Manager 360 tags are gpp=${GPP_STRING_xxxxx} where xxxxx is the global vendor list id of the vendor receiving the string, and gpp_sid=${GPP_SID} for the section in force. TCF still uses gdpr, gdpr_consent=${GDPR_CONSENT_xxxxx}, and addtl_consent. Those are parallel hops, not aliases.

IAB's consent string specification says the same URL pair. An image URL must include gpp=${GPP_STRING_123} and gpp_sid=${GPP_SID}. gpp_sid is the section ID or IDs in force, normally one integer, at most two comma-separated. The header in a GPP string is type 3. A TC String pasted into gpp decodes as type 2. IAB's implementation guidelines say the standalone TC String must still ride in transaction headers for GDPR until IAB Europe deprecates it, and that the US Privacy section inside GPP is deprecated. Use MSPA US National or the state sections.

Advertisers check Include TCF or Include GPP macros when they download tags. The macros insert automatically. You can add them by hand. For placement tags, the publisher CMP passes the strings if the macros are present. INS tags collect through the TCF or GPP APIs if the macros are empty. Macros inside raw HTML5 or rich media are not supported. If the creative makes its own third-party calls, the creative needs its own CMP lookup.

Google interprets gdpr=1 as TCF applies. If gdpr=1 and gdpr_consent is present, it must be a valid TC String or an ad may not be served or measured. If purpose 1 consent is missing, replace ad.doubleclick.net with pagead2.googlesyndication.com on the listed tag types. Invalid addtl_consent currently does not block serving. None of that logic reads us_privacy.

1YNN is still US Privacy, not National v2

The IAB US Privacy string is four characters: a version digit plus notice, opt-out of sale, and LSPA. 1YNN is the textbook yes-notice, no-opt-out, no-LSPA value. IAB Tech Lab deprecated that signal on 31 January 2024 in favor of GPP. CM360's US-states article says Google has integrated with the IAB CCPA Framework v1.0 technical specifications, and separately that CM360 will not support GPP for the US Privacy String, IAB Canada TCF, Utah, or IAB EU TCF v2.2. Those are GPP sections Google is not consuming on this product.

LiveRamp still documents both hops for US pixel traffic. GPP goes on gpp and gpp_sid. US-National is gpp_sid 7. California is 8, Virginia 9, Colorado 10, Utah 11, Connecticut 12, Florida 13, and so on. US Privacy is us_privacy= or LiveRamp's ct=3 and cv=. LiveRamp says you must not send the IAB US Privacy query and the custom ct/cv pair at the same time. That is a LiveRamp pixel rule. It is not Google accepting 1YNN as a GPP National v2 section.

National v2 is a breaking change inside the US National section. IAB incremented the section version because SensitiveDataProcessing added categories 13 through 16 and KnownChildSensitiveDataConsents grew a new age range. Google said it will support v2 and continue v1. A CMP that still emits v1 is not automatically wrong for CM360 this month. A 1YNN in the gpp slot is wrong for every version.

The URL people will traffic first

A TC String in gpp with TCF section id 2, plus a CCPA leftover. CM360 does not accept TCF through GPP.

https://ad.doubleclick.net/ddm/trackimp/src=1234567;type=invmedia;cat=abcde0;ord=1;us_privacy=1YNN;gpp=CPXxRfAPXxRfAAfKABENB-CgAAAAAAAAAAYgAAAAAAAA;gpp_sid=2?

That request looks thorough. It has a privacy parameter, a long base64 blob, and a section id. The blob is a TCF v2 string. Google's CM360 article says TCF strings sent through the GPP will not be accepted. gpp_sid=2 is the TCF section, which is the hop Google is not reading from GPP yet. us_privacy=1YNN is the deprecated four-character signal on a product that wants National or a supported state section for US GPP.

The US National hop looks like a GPP string whose header type is 3, often a DB prefix, with gpp_sid=7. LiveRamp's example is gpp=<string>&gpp_sid=7 on the pixel. CM360 uses ${GPP_STRING_xxxxx} so the vendor id is in the macro name. If Include GPP macros is unchecked, the downloaded tag never had a slot to fill. Publishers outside GPP can strip the macros the same way they strip unused TCF parameters. Stripping them on US inventory that needs RDP is how the string never arrives.

Names that do not translate

Floodlight and the Google tag still speak TCF separately

Legacy Floodlight tags that are not the Google tag need the TCF macros on the tag, or you re-download them. Floodlight via gtag or GTM integrates with the TCF API if you set window['gtag_enable_tcf_support'] = true in the global header. That flag does not enable GPP. US GPP still needs the GPP macros or an INS tag that can see the GPP API.

If the CMP is slow, Google Tag Manager and the Google tag wait 500 milliseconds. If the CMP returns error, stub, or loading, the tag proceeds restricted: advertising cookies limited, Analytics advertising features treated as all purposes denied, remarketing off. That timeout is a TCF readiness rule. It is not a decoder for National v2.

As of April 2025, Display and Video 360 already accepted IAB US National plus California, Virginia, Colorado, Connecticut, and Florida via GPP. The September CM360 sentence is specifically National v2 plus continued v1. If your DSP path already sent gpp_sid=7 and your Floodlight tag still only has us_privacy, the two Google products are not seeing the same US signal. That is a trafficking bug, not a v2 decoder bug.

Starting in September 2025, Google will support GPP National v2. We will also continue to support GPP National v1. TCF strings sent through the GPP won't be accepted.

Campaign Manager 360 Help: Integration with the IAB Transparency and Consent Framework

What to do

Re-download placement, tracking, and Floodlight tags with Include GPP macros checked. Confirm the fired URL has gpp and gpp_sid, not the unexpanded ${GPP_STRING_xxxxx} token. Decode the header. Type 3 is GPP. Type 2 is a TC String in the wrong slot. For US National, sid 7. Keep gdpr and gdpr_consent for EEA. Keep us_privacy only for partners that still document that parameter, and never as a stand-in for gpp.

Ask the CMP which US National version it emits. v1 still works on CM360. v2 is the new support. Do not invent a migration by putting 1YNN into gpp. IAB's implementation guidelines already say the US Privacy section is deprecated and that TCF still needs the standalone TC String on the wire for GDPR.

The contract page for the pixel pair is the GPP doc. This post is the market fact: CM360 reads National v2 as of September 2025, and 1YNN is not that hop. Pixellint is not affiliated with Google or IAB Tech Lab. Passing a linter means the artifact matches the published envelope. It does not mean Google triggered restricted data processing, and it does not mean the CMP encoded the right age flags.

Checklist

Sources

Contract pages

The dated argument is above. These pages are the field lists.

Read GPP Docs