T/TAF 267.1-2025: advertising SDK personal-info protection requirements (10 Feb 2025)
Analysis
By UA Ledger staff — 2 min read

TAF’s T/TAF 267.1—2025 (advertising SDK) was published and implemented on 10 February 2025. It is a group standard for ad SDK operators—not a CAC fine schedule or a CPI chart.
The Telecommunications Terminal Industry Association (电信终端产业协会, TAF) PDF T/TAF 267.1—2025, opened on 20 September 2026, is titled Technical requirements for user rights and personal information protection of Software Development Kits (SDK)—Part 1: Advertising category. The cover states 发布 / 实施 2025-02-10. Drafters listed include China Academy of Information and Communications Technology (中国信息通信研究院), 北京巨量引擎网络技术有限公司 (Ocean Engine), 北京火山引擎科技有限公司, and several OEMs.
Scope on the page
Clause 1 applies the file to advertising SDK developers/operators and to supervisors or third-party assessors. Clause 3.3 defines “advertising activities” to include request, display, monitoring, attribution, anti-fraud, and delivery analysis/optimisation. Collection rules in 5.1 require, among other points, that where the SDK user relies on end-user consent, the ad SDK operator must prompt the SDK user not to use the SDK to obtain personal information before that consent; that personal information is obtained in scenarios where the SDK user elects to call the ad SDK; and that aggregation SDKs collect only what is necessary for aggregation and default-configure third-party SDK collection within a controllable scope.
Storage (5.2), use/processing including personalised ads with consent (5.3), encrypted transmission preferably HTTPS for monitoring data (5.4), and contractual minimum-necessary sharing with advertisers/DSP/MMP-style parties (5.5) are spelled out. User-rights clause 6 ties personalised-ad disclosures and end-user rights handling to contracts/rules with the SDK user, and references T/TAF 078.7—2023 against deceptive forced downloads.
What this standard is not
This is a TAF group standard, not a CAC administrative penalty decision, not an App Store policy, and not a measurement of OAID/IDFA fill rates in live campaigns. Compliance with T/TAF 267.1 does not by itself prove a specific SDK build is lawful under PIPL for a named game.
Operator action
| Field | Evidence |
|---|---|
| Standard ID | T/TAF 267.1—2025 |
| Publish / implement | 2025-02-10 / 2025-02-10 |
| Part | Advertising category SDK |
| Consent gate (5.1 a) | Do not collect via ad SDK before end-user consent when consent is the legal basis |
| Aggregation SDK | Necessary-range collection; default-configure third-party SDK scope |
| UA implication | Ad SDK / MMP stacks used in China apps should map OAID/IDFA and sharing disclosures to this standard’s consent, necessity and contract clauses |
Download the standard card. Pair with the push-SDK sibling T/TAF 267.2 when reviewing re-engagement stacks.
Research checked 20 September 2026. Local draft; human editorial review pending.
Featured
Related posts
measurement
platforms
·1 min read
When to turn rewarded ads off for payers (and how to measure the loss)
measurement
platforms
·1 min read
When custom product pages need their own MMP campaign mapping
measurement
platforms
·1 min read
Season pass refund rate versus standard IAP refund rate
measurement
platforms
·1 min read
Pre-reg cohort quality vs post-launch paid cohort quality
More from the Measurement desk
measurement
platforms
·2 min read
AppLovin Ad Review drops user-level journeys for aggregate-only reporting
measurement
platforms
·2 min read
Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets
measurement
platforms
·1 min read
Pity-adjusted expected value versus player-facing banner claims
measurement
platforms
·1 min read