T/TAF 267.1-2025: advertising SDK personal-info protection requirements (10 Feb 2025)

Analysis

By UA Ledger staff2 min read

T/TAF 267.1-2025: advertising SDK personal-info protection requirements (10 Feb 2025)

TAF’s T/TAF 267.1—2025 (advertising SDK) was published and implemented on 10 February 2025. It is a group standard for ad SDK operators—not a CAC fine schedule or a CPI chart.

The Telecommunications Terminal Industry Association (电信终端产业协会, TAF) PDF T/TAF 267.1—2025, opened on 20 September 2026, is titled Technical requirements for user rights and personal information protection of Software Development Kits (SDK)—Part 1: Advertising category. The cover states 发布 / 实施 2025-02-10. Drafters listed include China Academy of Information and Communications Technology (中国信息通信研究院), 北京巨量引擎网络技术有限公司 (Ocean Engine), 北京火山引擎科技有限公司, and several OEMs.

Scope on the page

Clause 1 applies the file to advertising SDK developers/operators and to supervisors or third-party assessors. Clause 3.3 defines “advertising activities” to include request, display, monitoring, attribution, anti-fraud, and delivery analysis/optimisation. Collection rules in 5.1 require, among other points, that where the SDK user relies on end-user consent, the ad SDK operator must prompt the SDK user not to use the SDK to obtain personal information before that consent; that personal information is obtained in scenarios where the SDK user elects to call the ad SDK; and that aggregation SDKs collect only what is necessary for aggregation and default-configure third-party SDK collection within a controllable scope.

Storage (5.2), use/processing including personalised ads with consent (5.3), encrypted transmission preferably HTTPS for monitoring data (5.4), and contractual minimum-necessary sharing with advertisers/DSP/MMP-style parties (5.5) are spelled out. User-rights clause 6 ties personalised-ad disclosures and end-user rights handling to contracts/rules with the SDK user, and references T/TAF 078.7—2023 against deceptive forced downloads.

What this standard is not

This is a TAF group standard, not a CAC administrative penalty decision, not an App Store policy, and not a measurement of OAID/IDFA fill rates in live campaigns. Compliance with T/TAF 267.1 does not by itself prove a specific SDK build is lawful under PIPL for a named game.

Operator action

Reference table
FieldEvidence
Standard IDT/TAF 267.1—2025
Publish / implement2025-02-10 / 2025-02-10
PartAdvertising category SDK
Consent gate (5.1 a)Do not collect via ad SDK before end-user consent when consent is the legal basis
Aggregation SDKNecessary-range collection; default-configure third-party SDK scope
UA implicationAd SDK / MMP stacks used in China apps should map OAID/IDFA and sharing disclosures to this standard’s consent, necessity and contract clauses

Download the standard card. Pair with the push-SDK sibling T/TAF 267.2 when reviewing re-engagement stacks.

Research checked 20 September 2026. Local draft; human editorial review pending.

Featured

Related posts

measurement

platforms

·

1 min read

When to turn rewarded ads off for payers (and how to measure the loss)

measurement

platforms

·

1 min read

When custom product pages need their own MMP campaign mapping

measurement

platforms

·

1 min read

Season pass refund rate versus standard IAP refund rate

measurement

platforms

·

1 min read

Pre-reg cohort quality vs post-launch paid cohort quality

More from the Measurement desk

measurement

platforms

·

2 min read

AppLovin Ad Review drops user-level journeys for aggregate-only reporting

measurement

platforms

·

2 min read

Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets

measurement

platforms

·

1 min read

Pity-adjusted expected value versus player-facing banner claims

measurement

platforms

·

1 min read

MMP install count vs store first-open: F2P reconciliation lab