Skip to content

App Tracking Transparency in the EU: the iOS 27.2 prompt

Filip LuchianencoUpdated 4 min read

Last updated: 2026-10-03

On September 16, 2026, Apple announced changes to App Tracking Transparency in the European Union. App Tracking Transparency (ATT) is the iOS prompt an app must show before tracking a user across other companies' apps and websites or accessing the advertising identifier (IDFA). From Apple's notice: "Beginning with iOS 27.2 and iPadOS 27.2, developers will have the option to use an alternative version of the App Tracking Transparency system prompt in the EU. [...] Due to legal requirements, only the alternative version of the system prompt is available for apps distributed in Germany, France, Italy, Poland, and Romania." The notice attributes the change to "agreements with select European competition authorities". On August 17, 2026, the Bundeskartellamt, Germany's competition authority, announced that it had declared Apple's ATT commitments binding.

Apple's notice adds: "The requirements for when you must seek permission to track users will remain the same". In the EU, the prompt shows the developer's Markdown text, can include an Additional Information button that opens the app's own consent controls, and is shown again a year after the user's last answer.

What changes in the ATT prompt in iOS 27.2?

The new method, requestTrackingAuthorization(preferExpandedInterface:additionalInformationAction:completionHandler:), adds "the option of requesting a full-page sheet, Markdown-formatted text, and an optional Additional Information button". The text comes from a new Info.plist key, NSUserTrackingMarkdownUsageDescription. As of October 3, 2026, the iOS & iPadOS 27.2 release notes cover beta 2, and neither they nor the notice gives a release date for iOS 27.2.

The EU version requires "the device to be located in a specific European Union country and signed in with an Apple Account with a specific EU country or region".

Prompt element France, Germany, Italy, Poland, Romania Other EU countries Outside the EU
Form Full-page sheet Full-page sheet if preferExpandedInterface is true System alert
Purpose text Markdown key if supplied Markdown key if supplied, in the sheet NSUserTrackingUsageDescription
Additional Information button If the app supplies an action If the app supplies an action None
Re-prompt One year after the last answer One year after the last answer No yearly re-prompt

Source: Apple's documentation for the method and the Markdown key, 2026-10-03.

What happens when a user taps Additional Information?

From the method's documentation: "If someone taps Additional Information, the sheet dismisses without recording an answer". The yearly re-prompt follows approval or denial, unless the user has turned off the Settings switch Apple has renamed in the EU to "Allow Apps to Request to Link Your Activity Across Companies".

Under Apple's User Privacy and Data Use FAQ, an EU app can use the Additional Information button "to surface additional information and more granular consent controls" for ePrivacy or GDPR, and those controls "are entirely your responsibility". On the IDFA, the same page states: "you cannot access the device’s advertising identifier [...] until the user has granted your app permission in that prompt."

What did the Bundeskartellamt decide about Apple's ATT?

The Bundeskartellamt's preliminary assessment, from its release: "The wording, design and selection options of the request used for Apple’s own offerings had the potential to encourage users to give their consent, whereas they had the potential to discourage consent for third-party apps." According to the release, Apple "considers its rules ... to be compliant with competition law" and offered commitments, in a proceeding based on Section 19a of the German Competition Act and Article 102 TFEU.

The FAQ for case B7-54/25 lists the commitments:

  • Removal of "the warning hand symbol and “tracking”, a term app publishers perceive as alarming".
  • A "Customizable Purpose String" of "up to 4,000 characters", against Apple's current "one to two sentences".
  • Three options where a GDPR consent management platform (CMP) overlaps: one combined prompt with a second-layer page; a separate CMP plus an ATT prompt noting the consent given, shown again "12 months after the last display"; or separate prompts as before.

The FAQ dates the decision August 13, 2026. Apple has four months from service to implement the commitments; neither the release nor the FAQ gives the service date. The commitments apply for seven years from implementation, under a monitoring trustee, and cover "users with App Store billing addresses and devices located in Germany". According to the FAQ, the competition authorities of France, Italy, Romania and Poland "have conducted or are still conducting separate proceedings". On March 31, 2025, France's Autorité de la concurrence fined Apple €150,000,000 over its implementation of ATT. On December 22, 2025, Italy's competition authority, the AGCM, fined Apple Inc., Apple Distribution International Ltd and Apple Italia S.r.l. €98,635,416.67 over the ATT policy.

What a CanITrustThat scan and capture show for ATT

An iOS build that can show the prompt has NSUserTrackingUsageDescription in its Info.plist, plus NSUserTrackingMarkdownUsageDescription where the developer supplies EU text; code that requests the IDFA links Apple's AdSupport framework. A CanITrustThat scan lists these artifacts and the build's ad and attribution SDKs, each with file and line. That establishes that prompt code and IDFA code are present in the build; only a capture shows what was sent.

A test-device run records each request: whether the IDFA, the all-zero value Apple returns without authorization, or the identifier for vendor (IDFV) was sent, to which host, and before or after the ATT choice. The prompt version shown depends on device location and account region; a run records one device on one date, and what a recipient does with an identifier is outside a capture. See what a scan checks and the limits of a scan. The EFF study on ad SDKs and precise location covers SDK data sent once a permission is granted.

I run these checks for lawyers and for researchers working with lawyers, on one app or a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.