Apple · Apple App Store Review Guidelines · View original document ↗

AppTrackingTransparency Consent Requirement

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Apple Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Apps must ask for your explicit permission before tracking your activity across other apps and websites for advertising purposes, and cannot penalize you or offer you fewer features if you decline.

This analysis describes what Apple's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a consent gate that users must pass through before cross-app and cross-website behavioral tracking for advertising can occur, and prohibits retaliatory restriction of app functionality for users who decline.

Recent Activity

This document changed recently

Medium Jun 9, 2026

The updated guidelines state that developers must ensure kids receive age-appropriate experiences within their apps and must remove user-generated content that violates the guidelines, terms of service, or community standards. Under the revised policy, if Apple identifies policy-violating content, the developer will be asked to remove it and provide a compliance improvement plan. Based on the developer's response, the app may be removed from the App Store until compliance is demonstrated. This establishes a formal escalation pathway where developer inaction or inadequate remediation can result in app suspension or removal.

View change record →

Clause Stability Mostly Stable

1
Change
3
Months Monitored
May 12, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 3350 other provisions on other platforms.
This clause has changed once in 3 months of monitoring.

Change history

added Jun 9, 2026

This new provision establishes mandatory user consent for cross-app tracking and prevents functionality discrimination based on tracking consent, reflecting heightened privacy enforcement standards.

View full change record →

Consumer impact (what this means for users)

Consumers are required to receive an explicit opt-in prompt before an app may track their activity across other apps or websites for advertising or measurement purposes; declining this prompt is expressly protected from adverse app functionality consequences under the guidelines.

How other platforms handle this

Twilio Medium

TrustArcWrapper.withTrustArc(analytics, { alwaysLoadSegment: true }).load(segmentKey, cookieConfig);

Threads Medium

You must be at least 13 years old (or the minimum age required in your country) to use Threads. If you are under 18, you must have your parent or legal guardian's permission to use Threads.

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

See all platforms with this clause type →

Monitoring

Apple has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Apps that use device data from third-party apps and websites to target ads or to measure advertising campaign effectiveness must request permission to track using the App Tracking Transparency framework. Apps must not track users who have not granted permission to be tracked. Apps must not offer different functionality or content in response to a user's decision to not allow tracking.

— Excerpt from Apple's Apple App Store Review Guidelines

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The AppTrackingTransparency requirement engages with GDPR consent requirements (enforced by EU data protection authorities, particularly regarding behavioral advertising and the legal basis of consent), ePrivacy Directive obligations, and CCPA opt-out rights. The FTC has examined behavioral advertising consent practices under the FTC Act. The guidelines prohibit apps from conditioning functionality on tracking consent, which aligns with GDPR requirements that consent be freely given. GOVERNANCE EXPOSURE: High. Developers using advertising SDKs or measurement tools that collect cross-app or cross-website behavioral data must implement ATT prompts and cannot gate core functionality behind tracking consent. Non-compliance exposes developers to App Store rejection and potential regulatory enforcement, particularly in the EU where GDPR consent requirements for behavioral advertising are actively enforced. JURISDICTION FLAGS: EU developers must ensure ATT implementation satisfies GDPR consent standards, including that the consent request is specific, informed, and freely given. California developers should assess whether ATT consent also satisfies CCPA opt-out obligations or whether supplemental mechanisms are needed. CONTRACT AND VENDOR IMPLICATIONS: Advertising and measurement SDK vendors integrated into apps must operate within ATT permissions. Vendor contracts should address what happens when users decline tracking, including data minimization obligations and audit rights over vendor data processing. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that ATT prompt language accurately describes the tracking purpose, that tracking does not begin before permission is granted, and that app functionality does not degrade for users who decline. SDK audit processes should confirm that embedded advertising tools respect ATT permissions and do not employ alternative tracking methods that circumvent the consent requirement.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive and unfair data practices including behavioral advertising tracking without adequate consumer disclosure or consent
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
TCPA
United States Federal
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Apple App Store Review Guidelines
Entity
Apple
Document last updated
May 5, 2026
Tracking information
First tracked
April 28, 2026
Last verified
May 12, 2026
Record ID
CA-P-011498
Document ID
CA-D-00025
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
307db15d06f03003277f88a1476a1308e92cc7cba75906b4fac341d1054f5040
Analysis generated
April 28, 2026 08:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Apple
Document: Apple App Store Review Guidelines
Record ID: CA-P-011498
Captured: 2026-04-28 08:36:55 UTC
SHA-256: 307db15d06f03003…
URL: https://conductatlas.com/platform/apple/apple-app-store-review-guidelines/apptrackingtransparency-consent-requirement/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Apple's AppTrackingTransparency Consent Requirement clause do?

This provision establishes a consent gate that users must pass through before cross-app and cross-website behavioral tracking for advertising can occur, and prohibits retaliatory restriction of app functionality for users who decline.

How does this clause affect you?

Consumers are required to receive an explicit opt-in prompt before an app may track their activity across other apps or websites for advertising or measurement purposes; declining this prompt is expressly protected from adverse app functionality consequences under the guidelines.

Is ConductAtlas affiliated with Apple?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Apple.