🎉 OneTrust 202609.2.0 Released!

We are excited to announce the following enhancements in the OneTrust Developer Portal as part of OneTrust 202609.2.0.

👍

For more information about the release and our product updates in the OneTrust Platform, refer to the OneTrust Release Notes page. Learn more about environment maintenance on the Current and Historic Maintenance page, and subscribe to proactive environment notifications on our System Status and Scheduled Maintenance page.

Data Subject Rights (DSR) Automation

Fixed

Existing Public Preview Features

Mobile App Consent

Existing Public Preview Features

Third-Party Risk Management

Fixed

  • Resolved an issue that prevented the Search Contracts API from returning configured contract attribute values in the attributeValues object of the response.

Universal Consent & Preference Management

General Availability

Fixed

October 6, 2026 - cmpapi-202609.2.0

Mobile App Consent

Fixed

  • Resolved an issue where age range enforcement for Age Gate configurations depended on the Age Gate Prompt being enabled. Age range restrictions can now be enforced using externally provided age signals without requiring the Age Gate Prompt to be displayed, while preserving existing category mappings, runtime behavior, and audit logging when both prompt and enforcement settings are enabled.
  • Resolved an issue in the Log Consent API where requests returned a 400 error when ageGate.upperBound was not provided for AGEGATE_RANGE interactions. Age range validation now supports an undefined upperBound value and correctly treats it as an open-ended range, while continuing to return validation errors when upperBound is less than lowerBound.

New Public Preview Features

  • Enhancements to Consent Management Platform (CMP) APIs
    The following enhancements have been made to the CMP APIs:
    • Updated the Get Preference Center Data API and Get Banner Data API to include the toggleDisableHints response parameter. This enhancement provides localized guidance for age-restricted preference toggles.
    • Updated the Get Preference Center Data API to include the disabledToggleAriaLabel response parameter. This enhancement improves accessibility support for disabled controls through standardized ARIA labels.
    • Updated the Get IAB and Google Vendors API, Get Banner Data API, Get Preference Center Data API, and the Log Consent API to include the closeButtonAriaLabel response parameter within the appConfig object of the response.
    • Enhanced Global Privacy Protocol (GPP) support for the Get IAB and Google Vendors API, Get Banner Data API, Get Preference Center Data API, and the Log Consent API to include Maryland, Indiana, Kentucky, Rhode Island, and Minnesota within the templateType parameter of the appConfig object of the response. This enhancement expands GPP string generation and retrieval capabilities to support state-specific privacy signals, consent requirements, and regulatory mappings, and enables developers to retrieve and inspect these state sections using existing CMP API functionality.
    • Updated the Get Preference Center Data API to include the isConsentDisabled and isLegIntDisabled parameters within the purposes object of the response. These enhancements enable you to distinguish Age Gate-restricted purposes from other disabled consent controls and provide more accurate handling of consent and legitimate interest statuses in consent experiences.
    • Added support for the OT-Is-Anonymous-User request header across CMP APIs. When set to true, the header explicitly identifies the request as anonymous and prevents data subject profile creation, even when an OT-Identifier is present. When set to false or omitted, existing identifier evaluation behavior is preserved for backward compatibility.