Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

Apple ATT Changes in Europe: What the New Consent Commitments Mean for Mobile Teams

Prepare for expected changes to ATT consent experiences and understand how ATT and privacy consent should work together


Shay Olupona
Senior Staff Product Manager
September 22, 2026

Person using a smartphone to control a television in a living room, with the OneTrust logo in the upper-left corner.

Apple has made binding commitments to update aspects of its App Tracking Transparency (ATT) framework following an investigation by Germany's Federal Cartel Office. The confirmed commitments focus on creating more neutral consent experiences and giving third-party app providers greater flexibility to coordinate Apple's ATT request with separate data-protection consent requests. Specific implementation details remain subject to Apple's final guidance.

While ATT remains an important part of the mobile privacy landscape, the development is also an opportunity for organizations to review how ATT authorization and broader privacy consent work together throughout the mobile user journey.

Apple has committed to more closely aligned consent experiences, more neutral presentation for third-party requests, and greater flexibility for app providers to coordinate ATT with separate privacy consent requests. Detailed technical and design requirements should be validated against final Apple guidance.

Key Takeaways

  • Apple has committed to more neutral ATT consent experiences and greater flexibility for coordinating ATT with separate privacy consent requests.
  • Final technical and design requirements still depend on Apple's official implementation guidance, so reported prompt details should remain separate from confirmed commitments.
  • ATT authorization and privacy consent remain distinct signals. Mobile teams should understand where each signal applies and how both affect downstream advertising, analytics, attribution, or measurement activity.
  • OneTrust Mobile CMP customers should continue following current Apple and OneTrust guidance while reviewing existing journeys, signal handling, regional configurations, and downstream SDK behavior ahead of final guidance.

 

Why Apple Is Updating ATT

Apple introduced ATT in 2021. It requires apps to obtain permission before tracking a user's activity across other companies' apps and websites for advertising or measurement purposes. When a user declines, the app cannot access the device's advertising identifier, IDFA, for those purposes.

Germany's Federal Cartel Office raised concerns that Apple's framework created different consent experiences for Apple's own services and third-party applications. Apple subsequently made binding commitments intended to address those competition concerns.

What Apple Has Confirmed About the ATT Changes

The direction of the changes is clear, but complete technical and design requirements have not yet been validated through final Apple developer guidance. The sections below distinguish between commitments confirmed by the German regulator and implementation details reported by third-party publications.

More Neutral ATT Consent Requests

Apple has committed to making third-party ATT consent requests more visually and linguistically neutral, including addressing language or design elements that may discourage a particular choice. Public reporting has described possible changes to elements such as prompt wording, layout, button labels, formatting, access to additional information, and re-prompting. App teams should not treat those individual details as final requirements until Apple publishes or updates its official implementation guidance.

Greater Flexibility for App Providers

The confirmed commitments also give third-party app providers more freedom to coordinate Apple's ATT request with separate data-protection consent requests. This creates an opportunity to build a more cohesive experience while continuing to treat ATT authorization and privacy consent as separate signals.

For example, an app might use its privacy consent experience to explain advertising or analytics purposes before presenting the ATT request at the relevant point in the journey. The two requests remain separate, while the overall experience gives the user clearer context for why each choice appears.

 

Third-party reporting indicates that Apple may update ATT wording, presentation, response labels, formatting options, access to additional information, and re-prompting behavior. These details should be treated as reported changes until confirmed through official Apple documentation.

 

What Remains the Same

The announcement leaves the ATT framework in place and preserves the requirement to obtain ATT authorization for activities covered by Apple's framework. ATT authorization and privacy consent also remain separate permissions. 

Organizations should continue following current Apple requirements and their existing OneTrust Mobile CMP implementation while monitoring official guidance for changes that affect prompt presentation, journey design, or application behavior.

 

What OneTrust Customers Should Review Now

Based on the information currently available, OneTrust customers should not make implementation changes solely in response to individual design or technical details reported by third-party publications. Customers should continue following existing Apple and OneTrust guidance while reviewing their current ATT and Mobile CMP journey so they are prepared to assess final requirements when published.

  • Continue following current Apple ATT requirements.
  • Do not modify prompt sequencing, SDK logic, or re-prompting behavior solely on the basis of unconfirmed reporting.
  • Review OneTrust guidance and recommended journeys for coordinating ATT authorization with OneTrust Mobile CMP consent.
  • Confirm that ATT authorization and privacy consent are treated as separate signals.
  • Document where future Apple changes could affect supporting language, prompt sequencing, regional configuration, or downstream SDK behavior.
  • Monitor official Apple and OneTrust communications before implementing changes.

 

Changes to ATT are expected, but every reported implementation detail should go through confirmation before teams treat it as a final requirement. No immediate OneTrust Mobile CMP redesign is recommended based solely on current third-party reporting. Customers should review existing journeys now and validate any required configuration or application changes after Apple publishes final guidance.

 

How ATT and Consent Work Together

ATT authorization and privacy consent  epresent separate permissions. They answer different questions, and some use cases require evaluation of both signals before affected advertising or measurement technologies are enabled.

SignalWhat it addressesImplementation consideration
ATT authorizationWhether Apple permits covered tracking across other companies' apps and websites.Use ATT status when Apple's framework requires authorization for the relevant activity.
Privacy consentWhether the organization has permission for the relevant processing purpose.Use the CMP preference to determine whether the applicable analytics, advertising, personalization, or data-sharing purpose is allowed.

 

ATT addresses Apple's authorization for covered tracking. Privacy consent addresses permission for the underlying processing purpose. Depending on the use case, a technology may require both conditions to be satisfied.

For example, ATT authorization might be granted while the user declines the relevant advertising purpose through the privacy consent experience. In that scenario, the privacy consent signal still informs whether the affected activity proceeds. If privacy consent is present while ATT authorization is declined, covered tracking that requires ATT authorization remains subject to the ATT status.

 

ATT addresses Apple's authorization for covered tracking. Privacy consent addresses permission for the underlying processing purpose. Depending on the use case, a technology may require both conditions to be satisfied.

 

Where OneTrust Mobile CMP Fits

ATT is one signal within a broader mobile privacy and consent strategy. OneTrust Mobile CMP supports the privacy consent experience surrounding ATT by helping organizations present choices, capture purpose-level preferences, provide ongoing preference management, and apply those choices to covered mobile technologies.

OneTrust provides guidance and recommended journeys for organizations that collect both ATT authorization and privacy consent. This guidance helps mobile teams consider:

  • The order in which the Mobile CMP experience and ATT request are presented.
  • The language used to explain why each request appears.
  • How to avoid implying that one permission replaces the other.
  • How privacy preferences and ATT status inform downstream SDK behavior.
  • How the journey should be reviewed across applicable regions and app experiences.

The appropriate implementation depends on the application, technologies in use, regional requirements, and the organization's legal assessment. OneTrust guidance supports journey design and implementation planning, while each organization remains responsible for determining the configuration appropriate to its use case.

 

A Practical ATT and Mobile Consent Journey

OneTrust guidance describes considerations for coordinating ATT authorization with broader mobile privacy consent. The appropriate sequence depends on the app experience, processing activities, regional requirements, and applicable Apple guidance. The following illustrates one possible journey and should not be interpreted as a new requirement resulting from Apple's announced commitments.

  1. Present a privacy consent experience through OneTrust Mobile CMP.
  2. Collect purpose-level choices for advertising, analytics, personalization, or data sharing.
  3. Determine whether ATT authorization is required for the intended tracking activity.
  4. Present the ATT request at a contextually appropriate point, using supporting language that explains why authorization is being requested.
  5. Evaluate both ATT status and privacy consent before enabling affected advertising, attribution, or measurement SDK behavior.

This is a general example, not a universal implementation sequence. Teams should select and validate a journey based on their processing activities, user experience, legal requirements, and Apple's final guidance.

Questions Mobile Teams Should Review Before Final Guidance

  • When is the ATT request shown today?
  • How does it relate to the OneTrust Mobile CMP experience?
  • Do users receive clear context for why they are seeing separate requests?
  • Which SDKs or activities depend on ATT authorization?
  • Which SDKs or activities depend on privacy consent?
  • Are enforcement decisions based on the appropriate combination of signals?
  • Do regional configurations and supporting language accurately reflect the implemented journey?

 

Preparing for the Next ATT Update

Apple has made binding commitments to update the neutrality and coordination of ATT consent requests in the European Union. Although more detailed changes have been described in public reporting, organizations should wait for official Apple guidance before treating those details as implementation requirements. 

In the meantime, OneTrust Mobile CMP customers should review how ATT authorization and privacy consent work together, confirm that the signals remain distinct, and and map where future Apple guidance affects prompt presentation, journey design, regional configuration, or downstream SDK behavior. That preparation gives teams a clearer starting point when final implementation requirements are published.

Apple's commitments create a useful point to review how ATT authorization and privacy consent work together across the mobile experience. Review OneTrust Mobile CMP guidance for coordinating these signals and assess your current journey now, so your team has a clear implementation baseline when Apple publishes final guidance.

Key Questions Apply ATT Changes

 

No. The confirmed commitments concern aspects of ATT presentation and coordination with separate privacy consent requests.  The ATT framework remains in place, and teams should continue following current Apple requirements while awaiting final implementation guidance.

The announcement does not itself establish a requirement for a new configuration. Customers should review their current journey, use OneTrust guidance, and assess future changes communicated through official Apple and OneTrust channels before changing prompt sequencing, regional configuration, SDK logic, or related consent behavior.

Start with the journey and enforcement map. Document where each request appears, how each request is explained, which regional experience applies, which SDKs depend on ATT authorization, which depend on privacy consent, and how relevant combinations of those signals affect downstream behavior.