There was an unexpected error authorizing you. Please try again.
arrow-downarrow-leftarrow-rightarrow-upbiocircleclosedownloadext-link facebookgplus instagram linkedinmailmenuphoneplaysearchsharespinnertwitteryoutube

2026 IAB Diligence Platform Expansion: A Conversation with Industry Leaders

Privacy compliance is entering a new phase. Regulators increasingly expect organizations to not only publish compliant policies but also demonstrate structured oversight, documented decision-making, and accountable governance across their data systems and partners. The 2026 expansion of the IAB Diligence Platform reflects this shift, introducing new capabilities to support risk assessment, as well as tools to increase efficiency and speed to market. SafeGuard Privacy recently announced details of the expansion, highlighting how the platform continues to support scalable, standardized compliance across the digital advertising ecosystem.

In the conversation below, Michael Hahn, Executive Vice President and General Counsel at IAB and IAB Tech Lab, and Richy Glassberg, Co-Founder and CEO of SafeGuard Privacy, discuss the IAB Diligence Platform updates and their implications for organizations preparing for the next phase of privacy governance.

Why is this 2026 expansion such an important moment for the industry?

Michael Hahn:
We’re at an inflection point. Privacy compliance in digital advertising used to center on notice and choice. Today, it’s about governance, documentation, and demonstrable oversight. Regulators are asking not just whether you have a policy, but whether your organization can prove how decisions are made, how vendors are vetted, and how data flows are controlled.

For IAB members and companies in the digital ad ecosystem, that shift changes the stakes. The ecosystem is interconnected, and enforcement expectations reflect that. This update ensures the IAB Diligence Platform keeps pace with that reality.

Richy Glassberg:
The industry is moving from policy statements to evidence. That’s a big shift.

When regulators introduce executive attestation requirements and expand scrutiny around data transfers, compliance stops being a departmental issue and becomes a corporate governance matter. The question becomes: can you produce structured, auditable documentation that holds up under review? You need to, because your brand is on the line.

We’re building the industry compliance infrastructure that matches that level of accountability.

What do the new California regulations signal, particularly around executive accountability?

Hahn:
The new regulations introduce risk assessment requirements and reinforce attestation obligations at the executive level. Specifically, Article 10 of the regulations establishes a comprehensive framework for mandatory risk assessments, detailing specific triggers, content requirements, and reporting obligations.

The primary objective of the risk assessment is to evaluate whether the benefits of processing personal information—to the consumer, business, stakeholders, and public—are outweighed by the associated privacy risk. If the risk is greater than the benefit, then the processing activity must be restricted or prohibited.

This mandate is reinforced by a rigorous attestation requirement, to be completed by a named executive who is directly responsible for the processing activity and has sufficient knowledge to attest that the risk assessment is accurate. Critically, this attestation is submitted under penalty of perjury.

That’s significant. When you see attestation requirements that resemble Sarbanes-Oxley concepts, it signals that privacy governance is being treated more like financial governance. Oversight must be documented. Processes must be defensible.

For companies in the advertising ecosystem, that means privacy cannot operate informally. It must be structured.

Glassberg:
Executive accountability changes behavior. When certification and potential personal exposure enter the conversation, organizations start asking different questions:

Do we have consistent documentation?

Are our vendor reviews standardized?

Can we demonstrate oversight, not just intent?

The platform update directly addresses that. It embeds those regulatory expectations into standardized workflows so companies are not inventing governance from scratch.

Why are standards so critical at this stage of regulatory complexity?

Hahn:
Because fragmentation doesn’t scale. We all operate in a networked environment that includes data moving between brands, agencies, publishers, ad tech providers, and platforms. They all rely on one another. If each organization uses a different framework, different terminology, and different diligence expectations, compliance becomes duplicative, inefficient, and even painful.

Standards create predictability and reduce ambiguity. They allow the ecosystem to move together seamlessly rather than separately and defensively.

Glassberg:
There’s also a simple economic reality here. If every company sends every vendor a bespoke questionnaire, the system collapses under its own weight. Hundreds of questions, all worded differently, sometimes asking the same thing, and sometimes slightly differently. Ask anyone in privacy or infosec about it, and I guarantee you’ll hear a groan.

Standards are the only way to scale compliance across thousands of interconnected companies. Why recreate all the effort when you can reuse it? Standardized and defensible processes are how you reduce friction without lowering the bar.

Sorry, couldn’t help myself with the pun.

The platform is moving to a more open, friction-free participation model. Why?

Glassberg:
Standardization only works if the network scales. If vendors hesitate to participate because of the cost just to share information, the ecosystem fragments again. That defeats the purpose and doesn’t help anyone.

By offering requestors a friction-free option, we’re signaling that participation itself strengthens everyone. There are advanced features and automation for subscribers, but basic diligence sharing will not be gated.

Hahn:
We heard clearly from IAB members that subscriptions for respondents were a barrier to participation. If we want standardized diligence to work, vendors must be able to engage without unnecessary obstacles.

Allowing requestors to have a subscription option that eliminates the pay-to-join requirement for participation reduces friction while maintaining integrity. It encourages broader engagement and strengthens the platform’s overall network effect.

How will the new modules and updates to existing ones reshape how organizations assess data risk across their ecosystem?

Hahn:
Organizations must understand not only what data they collect, but where it originates, where it flows, and who ultimately accesses it. Embedding those questions into standardized modules ensures those conversations happen consistently.

For companies working with social media partners, we’ve released a brand new module to cover that relationship. We also added data supplier and sourcing questions to the existing modules to ensure diligence information isn’t left out.

Also, regulators increasingly care about data provenance and cross-border transfers. The DOJ bulk data transfer rules reflect growing national security considerations layered on top of privacy obligations.

Glassberg:
Data flow transparency used to be an appendix. Now it’s central.

Making sure supplier and upstream sourcing questions are included in the questionnaires for visibility across the supply chain is critical from a governance perspective. You can’t certify what you can’t see.

Where does Privacy Assist™ fit into this expansion?

Glassberg:
Compliance work is often repetitive and documentation-heavy. That doesn’t mean it’s unimportant—just that it’s labor-intensive.

Privacy Assist™ helps teams complete complex assessments faster by analyzing supporting documentation, suggesting responses to questions, and citing the evidence. It reduces manual effort while maintaining transparency when answering questions in our assessments or responding to external RFIs.

But I want to be clear: it does not override human judgment. The AI assists; it doesn’t decide, and humans are in the loop. The goal is to automate the tedious work, not the accountability.

Hahn:
From a legal perspective, that distinction matters. Regulators expect human oversight. Automation can improve efficiency, but responsibility remains with the organization.

Automation can support compliance, but responsibility ultimately remains with the organization.

What would you say to companies that haven’t yet joined the platform?

Hahn:
The regulatory environment is not getting simpler. The cost of misalignment grows each year. Engaging with a standardized platform is a proactive step toward privacy resilience.

Glassberg:
You can either build governance infrastructure on your own or participate in a standardized ecosystem that is evolving alongside regulatory expectations.

This expansion is about preparing the industry for what’s next, not reacting to what’s already happened.

The sooner companies align with standards, the easier it becomes to scale responsibly. Then everyone benefits.

Learn More About the IAB Diligence Platform

The 2026 expansion of the IAB Diligence Platform strengthens scalable privacy governance, helping safeguard consumer privacy while improving deal speed across the ecosystem. Request a demo here.

Authors

Author
Michael Hahn
Executive Vice President, General Counsel
at IAB & IAB Tech Lab

Author
Richy Glassberg
Co-Founder & CEO
at SafeGuard Privacy