T/TAF 267.2-2025: push SDK personal-info protection requirements (10 Feb 2025)

Analysis

By UA Ledger staff2 min read

T/TAF 267.2-2025: push SDK personal-info protection requirements (10 Feb 2025)

TAF’s T/TAF 267.2—2025 (push SDK) was published and implemented on 10 February 2025. It restricts forced collection of immutable device IDs when not necessary for the service—relevant to re-engagement UA stacks.

The TAF PDF T/TAF 267.2—2025, opened on 20 September 2026, is Part 2: Push category of the same SDK personal-information series as 267.1. Cover dates: 发布 / 实施 2025-02-10. Drafters include CAICT, 每日互动, vivo, Umeng, Kuaishou, Weibo and others.

Collection and device IDs

Clause 4.1 states that, in addition to T/TAF 188—2023 and 189—2023, push SDKs must satisfy: (a) non-service-essential and without a reasonable scenario, do not forcibly collect immutable device identifiers; (b) location-based push frequency for location collection should be set reasonably by the SDK user; (c) when aggregating third-party push SDKs, assess their personal-info protection capability and configure optional features and optional personal information to minimise end-user impact.

Storage, use (including personalised push only after informing via the SDK user and obtaining consent), encrypted transmission of sensitive personal information, sharing with separate consent, and deletion on stop-of-operations are set out in 4.2–4.7. Clause 5 adds content filters, bans on misleading titles, and a 15-day complaint response expectation.

What this standard is not

This is a group standard for push SDKs, not a CAC enforcement notice and not proof that any named MMP or OEM push channel already meets the rule. “Immutable device identifiers” are constrained when not necessary; the PDF does not by itself invent a universal OAID ban for all ads.

Operator action

Reference table
FieldEvidence
Standard IDT/TAF 267.2—2025
Publish / implement2025-02-10 / 2025-02-10
PartPush category SDK
Immutable device IDs (4.1 a)Do not forcibly collect when not necessary and no reasonable scenario
Personalised pushInform via SDK user; obtain consent
UA implicationRe-engagement / push vendors in China game builds should document necessity for durable device IDs and consent paths

Download the standard card. Read with T/TAF 267.1 advertising SDK when reviewing full China SDK stacks.

Research checked 20 September 2026. Local draft; human editorial review pending.

Featured

Related posts

measurement

platforms

·

1 min read

When to turn rewarded ads off for payers (and how to measure the loss)

measurement

platforms

·

1 min read

When custom product pages need their own MMP campaign mapping

measurement

platforms

·

1 min read

Season pass refund rate versus standard IAP refund rate

measurement

platforms

·

1 min read

Pre-reg cohort quality vs post-launch paid cohort quality

More from the Measurement desk

measurement

platforms

·

2 min read

AppLovin Ad Review drops user-level journeys for aggregate-only reporting

measurement

platforms

·

2 min read

Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets

measurement

platforms

·

1 min read

Pity-adjusted expected value versus player-facing banner claims

measurement

platforms

·

1 min read

MMP install count vs store first-open: F2P reconciliation lab