Privacy Studio Release Notes - October 9, 2024

Release Details

Platform Application: Privacy Studio 

Release: 2024.10.01

Release Date: Oct 9, 2024

Summary

The following new enhancements and functionality will be deployed on October 9, 2024:

Cookie Consent Manager (CCM)

Cookie Consent Manager

CCM Pro

Enhanced Tracker Rule Management

Benefits

This enhancement enables users to create and manage Tracker Rules simultaneously across multiple instances and tracker types.

Details

When creating a new tracker rule, users can now select one or more (or all) trackers from the Tracker Type dropdown menu. This enhancement also allows users to search for a specific tracker type when reviewing for compliance.

A user can also select one or more (or all) consent managers from the Scan and Consent dropdown menu.

Users can move the selected trackers to their desired cookie category from multiple scan instances. They can preview the changes by selecting a scan instance from the dropdown menu. 

The Save and Apply button only applies the changes to the currently selected Consent Manager (CM) instance in the Preview section. The Save button applies the changes to all selected CM instances. In addition, when they modify a category name, any existing tracker rules associated with the old category will not apply to the new category name. The new category name will need an updated tracker rule if a tracker rule is desired for it.

Improved Handling of Global Privacy Control (GPC) Signal

Benefits

This feature introduces significant enhancements to handling the GPC signal in compliance with the California Privacy Rights Act (CPRA).

Details

CCM’s handling of the GPC signal is improved to automatically respect the GPC setting in the user’s browser. When users enable GPC, the system now opts users out of cookie categories based on the GPC preference they set in the GPC Consent dropdown menu. 

Users can now select from the following GPC Consent options:

  • Apply & Ignore Previous Consents - When this GPC Consent option and the GPC browser signal are enabled, the system will execute the GPC flow when there is no existing consent.
    • When users visit without consent, GPC consent will be applied.
    • When users visit with consent, the GPC will be ignored.

  • Apply & Override Previous Consents - When this GPC Consent option and the GPC browser signal are enabled, the system will execute the GPC flow when GPC has not been honored yet.
    • When users visit without consent, GPC consent will be applied.
    • When users visit with consent, the system will check if GPC has been honored previously. If not, GPC consent will be applied.

  • Do Not Apply - When this GPC Consent option is enabled, the system will not execute the GPC flow.

CCM Advanced

Improved Handling of Global Privacy Control (GPC) Signal

Benefits

This feature introduces significant enhancements to the handling of the GPC signal in compliance with the California Privacy Rights Act (CPRA).

Details

CCM’s handling of the GPC signal is improved to automatically respect the GPC setting in the user’s browser. When users enable GPC, the system now opts users out of cookie categories based on the GPC preference they set from the following GPC Consent options:

  • Apply & Ignore Previous Consents - When this GPC Consent option and the GPC browser signal are enabled, the system will execute the GPC flow when there is no existing consent.
    • When users visit without consent, GPC consent will be applied.
    • When users visit with consent, the GPC will be ignored.
    • However, when CPRA and Stored Consent are enabled and implemented, the system’s behavior will be like Apply & Override Previous Consents

  • Apply & Override Previous Consents - When this GPC Consent option and the GPC browser signal are enabled, the system will execute the GPC flow when GPC has not been honored yet.
    • When users visit without consent, GPC consent will be applied.
    • When users visit with consent, the system will check if GPC has been honored previously. If not, GPC consent will be applied.

  • Do Not Apply - When this GPC Consent option is enabled, the system will not execute the GPC flow.

IAB GPP Enhancements

Benefits

The IAB Global Privacy Platform (GPP) framework integration with CCM is enhanced for a more comprehensive consent management experience while offering greater flexibility in configuration and consistency in user experience.

Details

CCM now supports different country settings for GPP, TCF, and standard layouts within the same instance, which allows for tailored consent management. When configured for GPP, it detects the site visitor’s jurisdiction and displays the appropriate GPP-regulated consent layout with specific purposes. 

Purpose Mapping to Categories

This enhancement introduces the new Display Cookie Categories feature. When this is enabled, the Cookie Categories will be displayed along with Purposes in the GPP layout. Each Purpose must be mapped with a Category to show vendors under each Purpose. When disabled, the mapped Purposes can be used to collect consent on Cookie Categories. 

This provides the ability to map purposes to specific categories (buckets) such as "functional" and "advertising" to ensure detailed consent management. Users can indicate which categories can be mapped to additional purposes specified as part of GPP or choose not to assign a category.

  • If standard categories are enabled:
    • When setting up, a purpose can be assigned one of these statuses:
      • Do not assign category - Purpose shows no vendors under it.
      • Not applicable - Purpose does not appear in the layout. The only two purposes that can be assigned as "Not applicable" are Known Child Consent and Sensitive Data Processing.
      • Assigned to <Category name> - Vendors assigned to the category appear under the purpose. All categories (except Required) are visible to the user in their instance and can be selected from the list. A purpose can only be mapped to one bucket. Required category cannot be mapped to any purpose.

  • If standard categories are not enabled:
    • When setting up, a purpose can be assigned one of these statuses:
      • Do not assign category - Purpose shows no vendors under it.
      • Not applicable - Purpose does not appear in the layout. The only two purposes that can be assigned as "Not applicable" are Known Child Consent and Sensitive Data Processing.
      • Assigned to <Category name> - Vendors assigned to the category appear under the purpose. All categories (except Required) are visible to the user in their instance and can be selected from the list. A purpose can only be mapped to one bucket. Required category cannot be mapped to any purpose.

If standard buckets are not enabled and are also not mapped to a purpose, the system will apply default consent (Required only) to standard categories. This ensures that users are opted out of other categories while remaining opted in only to Required cookies

Categories Display within Layout

Site owners can enable or disable standard categories in the GPP layout based on regulatory requirements.

  • If standard categories are enabled:
    • The vendors are displayed under both the standard categories and the assigned purposes.
    • The cookies are dropped or allowed based on consent provided for the standard categories.
    • CCM records the Purposes' consent in the GPP string and is provided on the platform.

  • If standard categories are not enabled:
    • The system does not show the standard categories and only shows the vendors under the purposes.
    • The cookies are dropped or allowed based on consent provided for mapped purposes.
    • CCM records the Purposes' consent in the GPP string and is provided on the platform.

Consent Conflict Handling: In case of multiple conflicting consents within the same bucket, the most restrictive consent applies. For instance, if there is a conflict between a 'Yes' and a 'No', the 'No' will take precedence to ensure compliance with user privacy choices.

Support for GPC/DNT Settings

If GPC (Global Privacy Control) or DNT (Do Not Track) is enabled/disabled for the mapped category at the browser level, CCM supports GPC values for that category before loading the layout.

NOTE: This feature does not support Autoblock for GPP.

GPP CM with Standard Categories

GPP CM with No Standard Categories (No Vendors)

GPP CM with No Standard Categories (With Vendors)