DEVLOPN Audit

Rejected twice by Apple for two popups in the wrong order — ATT and CMP

Apple's ATT prompt on one side, your GDPR CMP on the other — the order and purpose linking that pass review, and guideline 5.1.1 that rejects otherwise.

My app got rejected by Apple. Twice.

The culprit: two miserable consent popups, in the wrong order.

If you do iOS with OneTrust, you'll hit this wall. Apple's ATT prompt on one side, your GDPR CMP on the other. Everyone thinks showing both is enough.

That's where it breaks!

ATT + CMP: the right order — pre-prompt, ATT prompt (IDFA), CMP banner (GDPR), then SDKs launch. No tracker before both prompts

What compliance actually requires

  • No tracker starts until both prompts are resolved.
  • If the user declines ATT, your CMP must never re-ask consent for tracking — otherwise instant rejection, guideline 5.1.1.

My recommendation to pass review

An educational pre-prompt, then ATT, then CMP. And purpose linking forces the linked category to OFF when ATT is declined.

That will save you hours of review lost over this.

And you — ATT before or after your CMP?