Skip to main content
Promotional banner for the pentest readiness checklist
Category: TCF and Vendors

CMP ID

Also known as: CMP ID, Consent Management Platform ID, CMP identifier
Simply put

A CMP ID is a unique number assigned to a consent management platform (CMP) when it registers with a framework operator such as IAB Europe. It identifies which registered tool collected a given user's consent, so that the source of the consent signal can be traced. Not every CMP has an ID, because a CMP only receives one after completing and being approved through the relevant registration process.

Formal definition

Within IAB frameworks such as the Transparency and Consent Framework (TCF) and the Global Privacy Platform (GPP), a CMP ID is a unique identifier issued to a consent management platform upon successful registration and approval by the framework operator (IAB Europe for the TCF). The ID is used to attribute a persisted consent or preference signal to the specific registered CMP that generated it, and is encoded in the relevant consent string or GPP payload. Under the GPP CMP API specification, regional section policy writers may require CMPs to register; where a CMP has an ID, it must be used, while CMPs that are not registered are handled differently by the specification. A CMP ID is an identification and framework-conformance mechanism only; possessing one does not itself establish that any particular consent collection or downstream personal-data processing satisfies the ePrivacy or GDPR requirements applicable in a given jurisdiction. The scope, availability, and obligations attached to CMP IDs depend on the specific framework and its rules, which fall outside this definition.

Why it matters

A CMP ID provides a traceable link between a persisted consent signal and the specific registered consent management platform that generated it. Within IAB frameworks such as the Transparency and Consent Framework (TCF) and the Global Privacy Platform (GPP), this attribution is what allows downstream parties in the advertising and analytics ecosystem to identify the source of a consent or preference signal encoded in a consent string or GPP payload. Without a consistent identifier, tracing which tool collected a given user's choices, and confirming that the tool operated within an approved framework, would be considerably harder.

Who it's relevant to

Privacy and data protection officers
For those overseeing consent operations, the CMP ID supports auditability by tying a persisted signal to the registered platform that generated it. It is worth understanding that the ID is an identification and framework-conformance mechanism only; possessing one does not by itself establish that any particular consent collection or downstream personal-data processing satisfies the ePrivacy or GDPR requirements applicable in a given jurisdiction. Legal judgment about compliance remains separate from the technical presence of an ID.
Web developers and adtech integrators
Developers implementing or integrating a CMP need to know whether the platform is registered and holds a CMP ID, because the GPP CMP API specification requires that a CMP ID be used where one exists, and treats unregistered CMPs differently. Correctly encoding the ID in the consent string or GPP payload is part of conforming to the relevant framework's technical requirements.
Publishers and vendors relying on framework signals
Parties that consume consent signals through the TCF or GPP use the CMP ID to identify the source of a signal within the framework. This matters for vendors that need to establish where a consent or preference decision originated, though the availability, scope, and obligations attached to CMP IDs depend on the specific framework and its rules.

Inside CMP ID

CMP identifier
A CMP ID is a unique numeric identifier assigned to a consent management platform that has registered with the IAB Europe Transparency and Consent Framework (TCF). It allows signals and consent records to be attributed to the specific CMP that generated them.
Association with the TC String
Within the TCF, the CMP ID is encoded as part of the Transparency and Consent String (TC String), so that vendors and other participants can identify which registered CMP created or last updated the consent signal.
CMP version reference
TCF signals typically accompany the CMP ID with a CMP version indicator, distinguishing between different releases of the same platform. The ID identifies the provider, while the version identifies the specific iteration.
Registration status
A CMP ID reflects that a platform has gone through IAB Europe's TCF registration process. Registration status can change over time, so an ID present in older records may correspond to a CMP whose status has since been updated.
Scope limited to the TCF ecosystem
The CMP ID is a construct of the IAB TCF and is meaningful primarily within that framework. It is not a legal accreditation and does not itself govern how consent is collected outside TCF-based advertising contexts.

Common questions

Answers to the questions practitioners most commonly ask about CMP ID.

Does having a CMP ID mean my consent management platform is certified as compliant?
No. A CMP ID is an identifier assigned to a consent management platform that has registered with a framework such as the IAB Transparency and Consent Framework (TCF); it does not certify that the CMP, or the way you have configured it, meets legal requirements. Registration typically signals that the CMP has agreed to follow the framework's technical specifications and policies, but compliance with the ePrivacy rules on storing or accessing information on a device and with the GDPR when personal data is processed depends on your specific implementation, disclosures, and consent practices. Tools support compliance but do not replace legal judgment, and the scope of any obligation varies between the EU, the UK, and other jurisdictions.
Is a CMP ID a globally recognized identifier that applies across all privacy regimes?
Not necessarily. A CMP ID is generally specific to the framework that issued it, most commonly the IAB TCF, rather than a universal identifier recognized under every legal regime. Frameworks that rely on opt-in consent, as is typical in most EU jurisdictions, differ from US state approaches such as those in California, which often rely on opt-out mechanisms and signals like Global Privacy Control. A CMP ID from one framework does not automatically carry meaning or obligations under another, so you should treat its scope as limited to the framework in which it was assigned.
Where does the CMP ID appear in the signals a consent management platform generates?
Within frameworks such as the IAB TCF, the CMP ID is typically encoded into the consent string alongside other metadata, allowing downstream parties to identify which registered platform generated the record. The exact field structure and encoding are defined by the framework's technical specifications rather than by law. Because implementations differ and framework versions evolve, you should confirm the current specification for the framework you use rather than assume a fixed format.
How do I obtain and register a CMP ID for my platform?
A CMP ID is generally issued through the registration process operated by the framework, such as the IAB TCF, which typically requires agreeing to the framework's policies and technical requirements. The precise application steps, eligibility criteria, and any associated obligations are set by the framework operator and can change over time, so you should follow that operator's current registration guidance. Registration is an organizational and technical step and does not by itself resolve the underlying legal questions of whether your consent is valid in a given jurisdiction.
Should I log the CMP ID as part of my consent records?
Recording which CMP generated a given consent, including the CMP ID where a framework provides one, can support consent logging and record-keeping practices that help demonstrate how and where consent was collected. In most EU jurisdictions, being able to evidence that consent was freely given, specific, informed, and unambiguous is generally important, and the CMP ID can be one element that ties a record to the platform that produced it. What records you must keep, and for how long, depends on the applicable regime and your own risk assessment, so treat the CMP ID as supporting metadata rather than a complete record of valid consent.
What should I check if the CMP ID in a consent record is missing or unrecognized?
An absent or unrecognized CMP ID may indicate that the signal was not generated by a registered platform, that a different framework or version is in use, or that there is a configuration or encoding issue. Because downstream parties may rely on the CMP ID to interpret a consent signal, you would typically investigate the source of the record, confirm the framework version and specification in use, and verify your CMP configuration. Whether such a record can be relied upon for the placing of cookies or similar technologies, or for any subsequent processing of personal data, is a legal question that depends on the facts and the applicable jurisdiction, and is outside what the identifier alone can establish.

Common misconceptions

Having a registered CMP ID means a website's cookie consent is compliant with the GDPR and the ePrivacy Directive.
A CMP ID indicates registration within the IAB TCF, not legal compliance. Consent must still meet the applicable standards under EU law, generally freely given, specific, informed, and unambiguous, and the ePrivacy rules on placing or accessing information on a device must be satisfied separately. Tools such as CMPs support compliance but do not replace legal judgment, and the TCF itself has been the subject of contested regulatory interpretation.
The CMP ID is a universal, cross-jurisdictional identifier that governs consent everywhere.
The CMP ID is specific to the IAB Europe TCF ecosystem and is most relevant to TCF-based digital advertising. Consent obligations differ across the EU, the UK, and individual US states such as California under the CCPA and CPRA, and many of those regimes, particularly US opt-out frameworks, do not rely on the TCF or its identifiers at all.
A CMP ID uniquely identifies an individual user or their consent choices.
A CMP ID identifies the consent management platform provider, not the user. The user's specific preferences are conveyed by the broader consent signal (such as the TC String) that the CMP generates; the ID only attributes that signal to a particular registered platform.

Best practices

Treat the CMP ID as an attribution and interoperability tool within the TCF, not as evidence of legal compliance; assess consent validity separately against the applicable EU, UK, and relevant US state requirements.
Record and retain the CMP ID together with the associated consent signal and CMP version as part of your consent logging and record-keeping, so consent events can be traced to the platform that produced them.
Verify your CMP's TCF registration status periodically, since registration status can change over time and older records may reference a status that has since been updated.
Do not rely on a TCF CMP ID for jurisdictions or contexts outside the framework, such as US opt-out regimes or non-advertising cookie use; implement appropriate separate mechanisms where the TCF does not apply.
Confirm that the consent your CMP collects meets the substantive standard for your target markets, typically a clear affirmative action in most EU jurisdictions, rather than assuming the presence of a CMP ID satisfies that standard.
Involve legal or data protection advisers when interpreting how TCF participation and the CMP ID interact with your obligations, given evolving regulatory guidance and the contested interpretation of the framework.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide