What Apple announced and who is affected

Apple confirmed EU-specific changes to App Tracking Transparency (ATT). Starting with iOS and iPadOS 27.2, developers will be able to display an alternative system prompt to request tracking permission. The definition of “tracking” and the cases in which permission must be requested do not change; the ATT technical framework and its APIs remain intact. Apple frames these adjustments as part of agreements with European competition authorities rather than a global privacy update for other regions.

The geographic scope is the EU, with one particularity: due to legal requirements, in Germany, France, Italy, Poland, and Romania only the alternative version of the prompt may be used. In the remaining Member States, developers can choose between the standard or the alternative prompt, depending on the use case and their consent strategy.

What exactly changes in the consent flow

The alternative prompt introduces two operational novelties. First, it modifies the format and language of the prompt to reduce ambiguity. Second, it adds an “Additional Information” button that lets you link to more detailed explanations of why permission is requested to link data with third parties or to share it with a data broker. This extra space can help align, with a single user action, the ATT consent and the information required under GDPR, avoiding double screens provided the implementation is clear and not coercive.

In addition, Apple enables annual re-prompting: in the EU, you may present the system prompt again once 12 months have passed since the user’s previous choice, whether they accepted or declined. If the person disables “Allow Apps to Request to Track” in Settings (renamed in the EU to “Allow apps to request to link your activity across companies”), they cannot be re-prompted. These rules coexist with the usual limitations: you may not incentivize or gate features based on tracking acceptance, nor resort to dark patterns.

Versions and timeline

The changes are tied to iOS/iPadOS 27.2. Apple hasn’t specified a public availability date in its documentation; therefore, planning should align with the 27.2 release cycle and App Store submission windows. For the rest of EU business updates (unified terms and new distribution/payment options), Apple sets general applicability to October 1, 2026 for accounts that accept the terms, though this runs in parallel to ATT and does not directly alter its requirements.

In practice: apps distributed in the EU should detect the OS version and the distribution region to decide which ATT prompt to show, and in five countries they will be required to use the alternative variant from the first day devices are running 27.2.

Regulatory context: competition and the DMA

Apple presents these measures as the result of agreements with European competition authorities. In Germany, the Bundeskartellamt has investigated potential exclusionary effects of ATT since 2022. In August 2026, the German authority accepted Apple’s commitments and closed the proceedings, which explains the obligation to use the alternative prompt there and its potential signaling effect for other EU markets.

This adjustment coexists with the DMA and other European processes. The European Commission has designated Apple a ‘gatekeeper’, and the changes in stores and distribution terms for the EU fit within that framework. The nuance here matters: the alternative ATT prompt does not rewrite the concept of tracking nor introduce technical exceptions to consent; it changes the wrapper, language, and information options to address competition concerns and perceived transparency.

Practical impact: developers, advertisers, and users

For product and marketing teams, the primary impact lies in flow design and messaging. The Additional Information button allows more precise explanations of user value (for example, recommendations or discounts based on off-app activity) and to detail legal bases or privacy controls. It also opens the door to better integrate ATT with existing GDPR consent modules without overwhelming the user, always keeping a neutral tone and avoiding any misleading practice.

For advertisers and measurement, annual re-prompting can stabilize audiences with a predictable cadence and enable A/B tests on copy and screen order. However, because the rules on what counts as “tracking” do not change and the use of alternative identifiers remains prohibited without permission, attribution models will continue to rely on aggregated solutions and on-device signal. For users, the direct benefit is a less alarming prompt with more context, without compromising the ability to clearly say no.

What teams should do now

1) Review regional detection and OS version checks to enable the alternative prompt across the EU and enforce it in Germany, France, Italy, Poland, and Romania. 2) Prepare content for the Additional Information button (concise, specific, and free of dark patterns), and align the purpose text with your privacy policy and SDK inventory. 3) Define a 12‑month re-prompt policy and document the logic that prevents re-prompting if the system setting blocks it.

4) Update analytics and advertising SDKs to ensure no identifiers or fingerprinting signals are collected without permission. 5) Sync with legal and privacy to validate legal bases and data retention. 6) Establish prudent success metrics: opt-in rates, flow abandonment, time spent on “Additional Information,” and periodic compliance audits.

Limits and open questions

Although the prompt’s language changes, the definition of tracking and restrictions on alternative identifiers remain, so drastic attribution leaps are unlikely without redesigning your data strategy. It’s also too early to infer uniform effects on consent rates: they will vary by category, country, and copy quality. Teams should experiment with conservative hypotheses and avoid decisions that hinge on a single channel.

It also remains to be seen whether the obligation to use the alternative variant in five countries will expand to other Member States through new regulatory decisions or case law, and how these changes will interact with any forthcoming EU design guidance against dark patterns. In any case, the operational rule remains clear: without explicit permission in the ATT prompt, there is no interapp tracking nor use of shared identifiers.