Prepare for expected changes to ATT consent experiences and understand how ATT and privacy consent should work together
Shay Olupona
Senior Staff Product Manager
September 22, 2026
Apple has made binding commitments to update aspects of its App Tracking Transparency (ATT) framework following an investigation by Germany's Federal Cartel Office. The confirmed commitments focus on creating more neutral consent experiences and giving third-party app providers greater flexibility to coordinate Apple's ATT request with separate data-protection consent requests. Specific implementation details remain subject to Apple's final guidance.
While ATT remains an important part of the mobile privacy landscape, the development is also an opportunity for organizations to review how ATT authorization and broader privacy consent work together throughout the mobile user journey.
Apple has committed to more closely aligned consent experiences, more neutral presentation for third-party requests, and greater flexibility for app providers to coordinate ATT with separate privacy consent requests. Detailed technical and design requirements should be validated against final Apple guidance.
Apple introduced ATT in 2021. It requires apps to obtain permission before tracking a user's activity across other companies' apps and websites for advertising or measurement purposes. When a user declines, the app cannot access the device's advertising identifier, IDFA, for those purposes.
Germany's Federal Cartel Office raised concerns that Apple's framework created different consent experiences for Apple's own services and third-party applications. Apple subsequently made binding commitments intended to address those competition concerns.
The direction of the changes is clear, but complete technical and design requirements have not yet been validated through final Apple developer guidance. The sections below distinguish between commitments confirmed by the German regulator and implementation details reported by third-party publications.
Apple has committed to making third-party ATT consent requests more visually and linguistically neutral, including addressing language or design elements that may discourage a particular choice. Public reporting has described possible changes to elements such as prompt wording, layout, button labels, formatting, access to additional information, and re-prompting. App teams should not treat those individual details as final requirements until Apple publishes or updates its official implementation guidance.
The confirmed commitments also give third-party app providers more freedom to coordinate Apple's ATT request with separate data-protection consent requests. This creates an opportunity to build a more cohesive experience while continuing to treat ATT authorization and privacy consent as separate signals.
For example, an app might use its privacy consent experience to explain advertising or analytics purposes before presenting the ATT request at the relevant point in the journey. The two requests remain separate, while the overall experience gives the user clearer context for why each choice appears.
Third-party reporting indicates that Apple may update ATT wording, presentation, response labels, formatting options, access to additional information, and re-prompting behavior. These details should be treated as reported changes until confirmed through official Apple documentation.
The announcement leaves the ATT framework in place and preserves the requirement to obtain ATT authorization for activities covered by Apple's framework. ATT authorization and privacy consent also remain separate permissions.
Organizations should continue following current Apple requirements and their existing OneTrust Mobile CMP implementation while monitoring official guidance for changes that affect prompt presentation, journey design, or application behavior.
Based on the information currently available, OneTrust customers should not make implementation changes solely in response to individual design or technical details reported by third-party publications. Customers should continue following existing Apple and OneTrust guidance while reviewing their current ATT and Mobile CMP journey so they are prepared to assess final requirements when published.
Changes to ATT are expected, but every reported implementation detail should go through confirmation before teams treat it as a final requirement. No immediate OneTrust Mobile CMP redesign is recommended based solely on current third-party reporting. Customers should review existing journeys now and validate any required configuration or application changes after Apple publishes final guidance.
ATT authorization and privacy consent epresent separate permissions. They answer different questions, and some use cases require evaluation of both signals before affected advertising or measurement technologies are enabled.
| Signal | What it addresses | Implementation consideration |
| ATT authorization | Whether Apple permits covered tracking across other companies' apps and websites. | Use ATT status when Apple's framework requires authorization for the relevant activity. |
| Privacy consent | Whether the organization has permission for the relevant processing purpose. | Use the CMP preference to determine whether the applicable analytics, advertising, personalization, or data-sharing purpose is allowed. |
ATT addresses Apple's authorization for covered tracking. Privacy consent addresses permission for the underlying processing purpose. Depending on the use case, a technology may require both conditions to be satisfied.
For example, ATT authorization might be granted while the user declines the relevant advertising purpose through the privacy consent experience. In that scenario, the privacy consent signal still informs whether the affected activity proceeds. If privacy consent is present while ATT authorization is declined, covered tracking that requires ATT authorization remains subject to the ATT status.
ATT addresses Apple's authorization for covered tracking. Privacy consent addresses permission for the underlying processing purpose. Depending on the use case, a technology may require both conditions to be satisfied.
ATT is one signal within a broader mobile privacy and consent strategy. OneTrust Mobile CMP supports the privacy consent experience surrounding ATT by helping organizations present choices, capture purpose-level preferences, provide ongoing preference management, and apply those choices to covered mobile technologies.
OneTrust provides guidance and recommended journeys for organizations that collect both ATT authorization and privacy consent. This guidance helps mobile teams consider:
The appropriate implementation depends on the application, technologies in use, regional requirements, and the organization's legal assessment. OneTrust guidance supports journey design and implementation planning, while each organization remains responsible for determining the configuration appropriate to its use case.
OneTrust guidance describes considerations for coordinating ATT authorization with broader mobile privacy consent. The appropriate sequence depends on the app experience, processing activities, regional requirements, and applicable Apple guidance. The following illustrates one possible journey and should not be interpreted as a new requirement resulting from Apple's announced commitments.
This is a general example, not a universal implementation sequence. Teams should select and validate a journey based on their processing activities, user experience, legal requirements, and Apple's final guidance.
Apple has made binding commitments to update the neutrality and coordination of ATT consent requests in the European Union. Although more detailed changes have been described in public reporting, organizations should wait for official Apple guidance before treating those details as implementation requirements.
In the meantime, OneTrust Mobile CMP customers should review how ATT authorization and privacy consent work together, confirm that the signals remain distinct, and and map where future Apple guidance affects prompt presentation, journey design, regional configuration, or downstream SDK behavior. That preparation gives teams a clearer starting point when final implementation requirements are published.
Apple's commitments create a useful point to review how ATT authorization and privacy consent work together across the mobile experience. Review OneTrust Mobile CMP guidance for coordinating these signals and assess your current journey now, so your team has a clear implementation baseline when Apple publishes final guidance.
No. The confirmed commitments concern aspects of ATT presentation and coordination with separate privacy consent requests. The ATT framework remains in place, and teams should continue following current Apple requirements while awaiting final implementation guidance.
No. ATT is an Apple platform authorization for covered tracking. Privacy consent addresses the organization's permission for the relevant processing purpose. Mobile teams should identify which activities depend on ATT, which depend on privacy consent, and where both signals inform the same downstream technology or use case.
The announcement does not itself establish a requirement for a new configuration. Customers should review their current journey, use OneTrust guidance, and assess future changes communicated through official Apple and OneTrust channels before changing prompt sequencing, regional configuration, SDK logic, or related consent behavior.
Start with the journey and enforcement map. Document where each request appears, how each request is explained, which regional experience applies, which SDKs depend on ATT authorization, which depend on privacy consent, and how relevant combinations of those signals affect downstream behavior.