InteractiveAdvertisingBureau / GDPR-Transparency-and-Consent-Framework

Technical specifications for IAB Europe Transparency and Consent Framework that will help the digital advertising industry interpret and comply with EU rules on data protection and privacy - notably the General Data Protection Regulation (GDPR) that comes into effect on May 25, 2018.
855 stars 359 forks source link

Updated TCF specifications based on changes required for TCF v2.2 #334

Closed HeinzBaumann closed 1 year ago

HeinzBaumann commented 1 year ago

Update the files Tech Lab - Consent string and vendor list formats v2.md and Tech Lab - CMP API v2.md based on the latest policy changes and tech specs. In detail: Update several sections to introduced retention periods for all purposes, removal of legitimate interest for purposes 3 to 6, the introduction of data categories used in conjunction with the purposes, support for legitimate interest claim urls, adding support for localized policy urls. Removed references to v1.1 where that information was no longer required. Update the GVL list section accordingly: Updated the API specification: Deprecated the API getTCData as well as some other small tweaks. Removed references to v1.1 where that information was no longer required.

bretg commented 1 year ago

@HeinzBaumann - is there a requirements doc? Specifically I'd like to better understand the "data category" concept and whether there's a potential processing implication or if this is just informational to show up in the CMP.

Prebid Server interprets this file and we need to confirm that there aren't updates required beyond the location of the GVL file. Here are the changes gathered from the PR:

HeinzBaumann commented 1 year ago

@bretg There are Policy updates for all these changes that will be made available. The dataCategory is based of the need to have vendors disclose the type of data the collect/process. This is information for the user to help them make a more informed decision. CMP will need to read and display that information. There is no additional action needed by vendors receiving the TC string.