🎉 OneTrust 202609.2.0 Released!
September 25th, 2026
We are excited to announce the following enhancements in the OneTrust Developer Portal as part of OneTrust 202609.2.0.
For more information about the release and our product updates in the OneTrust Platform, refer to the OneTrust Release Notes page. Learn more about environment maintenance on the Current and Historic Maintenance page, and subscribe to proactive environment notifications on our System Status and Scheduled Maintenance page.
Data Subject Rights (DSR) Automation
Fixed
- The request schema for the Add Targeted Data Discovery Results Summary to Request API has been updated to correctly reflect supported functionality. The
isRedactrequest parameter has been removed from the API documentation because attachment redaction is supported only by the Add Data Points to Targeted Data Discovery Results Summary API.
Existing Public Preview Features
- New DROP Management APIs
Added the Create Data Subject Request for DROP Record API, Update DROP Record API, and Get List of DROP Records API to create, update, and retrieve Delete Request and Opt-out Platform (DROP) requests, respectively. These APIs support California-registered data brokers in managing DROP requests for deleting or opting out data subjects permanently.
Mobile App Consent
Existing Public Preview Features
- Consent Management Platform APIs
The following APIs are available for retrieving the interface attributes needed to display the banner and preference center, retrieving active IAB and Google vendor information, logging consent interactions, and submitting global opt-out data subject access requests. These APIs enable developers to retrieve the data required for banner and preference center experiences, disclose vendor information to end users, capture consent preferences, and support Global Opt-Out workflows across devices and services.
Third-Party Risk Management
Fixed
- Resolved an issue that prevented the Search Contracts API from returning configured contract attribute values in the
attributeValuesobject of the response.
Universal Consent & Preference Management
General Availability
- Enhancements to Consent Receipts APIs
Updated the Create Consent Receipts API, Create Identified Consent Receipts API, and Create Consent Receipts in Bulk API to support theInteractionDaterequest parameter under thepurposesobject. This enhancement enables purpose-level consent interactions to be recorded independently, providing more granular consent tracking, auditing, and reporting.
Fixed
- Resolved an issue that caused the Update Data Subject Group V4 API to return an error when allowed primary identifier types contained spaces.
October 6, 2026 - cmpapi-202609.2.0
Mobile App Consent
Fixed
- Resolved an issue where age range enforcement for Age Gate configurations depended on the Age Gate Prompt being enabled. Age range restrictions can now be enforced using externally provided age signals without requiring the Age Gate Prompt to be displayed, while preserving existing category mappings, runtime behavior, and audit logging when both prompt and enforcement settings are enabled.
- Resolved an issue in the Log Consent API where requests returned a
400error whenageGate.upperBoundwas not provided forAGEGATE_RANGEinteractions. Age range validation now supports an undefinedupperBoundvalue and correctly treats it as an open-ended range, while continuing to return validation errors whenupperBoundis less thanlowerBound.
New Public Preview Features
- Enhancements to Consent Management Platform (CMP) APIs
The following enhancements have been made to the CMP APIs:- Updated the Get Preference Center Data API and Get Banner Data API to include the
toggleDisableHintsresponse parameter. This enhancement provides localized guidance for age-restricted preference toggles. - Updated the Get Preference Center Data API to include the
disabledToggleAriaLabelresponse parameter. This enhancement improves accessibility support for disabled controls through standardized ARIA labels. - Updated the Get IAB and Google Vendors API, Get Banner Data API, Get Preference Center Data API, and the Log Consent API to include the
closeButtonAriaLabelresponse parameter within theappConfigobject of the response. - Enhanced Global Privacy Protocol (GPP) support for the Get IAB and Google Vendors API, Get Banner Data API, Get Preference Center Data API, and the Log Consent API to include
Maryland,Indiana,Kentucky,Rhode Island, andMinnesotawithin thetemplateTypeparameter of theappConfigobject of the response. This enhancement expands GPP string generation and retrieval capabilities to support state-specific privacy signals, consent requirements, and regulatory mappings, and enables developers to retrieve and inspect these state sections using existing CMP API functionality. - Updated the Get Preference Center Data API to include the
isConsentDisabledandisLegIntDisabledparameters within thepurposesobject of the response. These enhancements enable you to distinguish Age Gate-restricted purposes from other disabled consent controls and provide more accurate handling of consent and legitimate interest statuses in consent experiences. - Added support for the
OT-Is-Anonymous-Userrequest header across CMP APIs. When set totrue, the header explicitly identifies the request as anonymous and prevents data subject profile creation, even when anOT-Identifieris present. When set tofalseor omitted, existing identifier evaluation behavior is preserved for backward compatibility.
- Updated the Get Preference Center Data API and Get Banner Data API to include the
