Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: TCF and Vendors

Disclosed Vendors Segment

Also known as: disclosedVendors segment, Disclosed Vendors
Simply put

The Disclosed Vendors Segment is a part of the technical consent record used in the IAB Europe Transparency and Consent Framework (TCF) that indicates which third-party vendors were actually shown to a user in the consent interface. It works as a signal that helps vendors know whether they were presented to the end user, which can be relevant to how they may rely on certain processing grounds. It is one component of the broader TCF consent string and does not by itself establish that valid consent was obtained.

Formal definition

Within IAB TCF v2.3, the Disclosed Vendors Segment is a segment of the TC String that encodes the vendor IDs disclosed (shown) to the end user, providing a binary per-vendor signal (1 = disclosed, 0 = not disclosed). According to the evidence, it is described as a mandatory segment in TCF signals, enabling vendors to determine whether they were disclosed and, on that basis, whether they may process data under Special Purposes. Per IAB Europe's transition guidance, vendors affected by the associated signalling ambiguity are expected to recognise and act on the disclosedVendors segment appropriately after 28 February 2026. This entry addresses the segment as a technical mechanism within the TCF only; it does not determine the validity of consent under the ePrivacy Directive or the GDPR, which require separately that any consent be freely given, specific, informed, and unambiguous. TCF policies and their interpretation may evolve, and the precise obligations tied to the segment depend on IAB Europe policy documentation and each vendor's registered purposes and Special Purposes, which are outside the scope of this definition.

Why it matters

The Disclosed Vendors Segment addresses a practical gap in how vendors within the IAB Europe Transparency and Consent Framework (TCF) understand their own position in a consent interaction. Because a vendor may process data on the basis of Special Purposes only where it can rely on having been disclosed to the end user, having a clear, machine-readable signal of whether it was actually shown matters for how that vendor justifies its processing. Without such a signal, vendors would be left to infer their status, creating ambiguity that undermines the transparency the TCF is intended to support.

This matters because the TCF is a technical layer that operates alongside, not in place of, the legal requirements of the ePrivacy Directive and the GDPR. Special Purposes within the TCF are processing activities for which users are informed but, in the framework's design, are not asked to give consent in the same way as ordinary purposes. The disclosedVendors segment helps ensure that a vendor relying on such a ground can point to evidence that it was in fact presented to the user, which is one input into a broader compliance assessment. It does not by itself establish that valid consent was obtained, nor does it resolve the separate legal question of whether any given processing ground is lawful in a particular jurisdiction.

IABEurope's transition guidance frames the segment as significant for vendors affected by an identified signalling ambiguity. According to that guidance, after 28 February 2026 those vendors are expected to recognise and act on the disclosedVendors segment appropriately. Organisations that rely on TCF signals should therefore treat the segment as part of their operational readiness, while recognising that framework compliance and legal compliance under EU data protection law are distinct questions that each require independent judgement.

Who it's relevant to

TCF-registered vendors and adtech providers
Vendors participating in the IAB Europe TCF are the primary audience, particularly those affected by the signalling ambiguity referenced in IAB Europe's transition guidance. According to that guidance, such vendors are expected to recognise and act on the disclosedVendors segment appropriately after 28 February 2026. Vendors relying on Special Purposes should assess whether their systems correctly read this segment to confirm whether they were disclosed to a user, while recognising that framework compliance does not on its own resolve legal questions under the GDPR or ePrivacy Directive.
Consent management platform (CMP) operators
CMPs generate and encode the TC String, including the Disclosed Vendors Segment. Operators need to ensure their platforms correctly populate the segment to reflect which vendors were actually shown to the user, consistent with TCF v2.3 specifications. As with all CMP functionality, correctly encoding this signal supports compliance efforts but does not by itself guarantee that any consent obtained is valid under applicable law.
Privacy officers and legal counsel overseeing adtech
Data protection professionals evaluating an organisation's use of the TCF should understand how the disclosedVendors segment functions and its limits. It is a technical signal that helps evidence disclosure for purposes such as Special Purposes, but it does not establish valid consent under the ePrivacy Directive or the GDPR, which impose separate requirements. Legal review remains necessary to assess whether a given processing ground is lawful in the relevant jurisdiction.
Publishers and web developers integrating TCF signals
Publishers and developers who implement CMPs and pass TCF signals to downstream partners should be aware that the disclosedVendors segment is described as a mandatory part of TCF signals. Ensuring the segment is correctly transmitted is part of technical readiness ahead of the transition timeline referenced in IAB Europe's guidance, though the specific obligations depend on IAB Europe policy documentation outside the scope of this entry.

Inside Disclosed Vendors Segment

Vendor disclosure list
The set of third-party vendors identified to a user when consent is being sought, so that a user can be considered informed about who may place or access information on their device and process their personal data. Under the GDPR, informed consent generally requires that users be told the identity of the controllers relying on the consent.
IAB TCF vendor registration
Within the IAB Transparency and Consent Framework, vendors register on a Global Vendor List, and the CMP signals which of those vendors have been disclosed to and, where applicable, consented to by the user. The 'disclosed' status reflects that a vendor was surfaced to the user, which is distinct from whether consent or a legal basis was actually established.
Purposes and legal bases
Disclosure is typically tied to the purposes for which each vendor processes data and the legal basis claimed (for example consent or, where asserted, legitimate interests). The ePrivacy rules govern the placing of and access to information on the device, while the GDPR governs the subsequent processing of any personal data, and these should not be conflated.
Consent signal and scope
The record of which disclosed vendors the user has permitted, communicated via a consent string or similar mechanism. This scope can differ by vendor, purpose, and jurisdiction, and an opt-out model may apply in some US state frameworks rather than the EU/UK opt-in approach.
Consent logging and record-keeping
Documentation of what was disclosed, to whom, and what the user chose, supporting accountability. Maintaining an auditable record of the disclosed vendor set at the time of consent is generally considered part of demonstrating valid consent under the GDPR.

Common questions

Answers to the questions practitioners most commonly ask about Disclosed Vendors Segment.

Does listing a vendor in the disclosed vendors segment mean the user has consented to that vendor?
No. The disclosed vendors segment identifies which vendors are being disclosed to the user, but disclosure and consent are distinct steps. Under EU frameworks, valid consent must be freely given, specific, informed, and unambiguous, requiring a clear affirmative action for the relevant vendors and purposes. A vendor appearing in the disclosed segment indicates transparency about that vendor's involvement; it does not by itself establish that the user has taken any affirmative action to permit that vendor's processing. Whether a legal basis such as consent exists is a separate determination that depends on the choices the user actually made and how those choices were captured and recorded.
If a vendor is in the disclosed vendors segment, does that mean it is compliant to use that vendor?
Not necessarily. Inclusion in the disclosed vendors segment reflects that the vendor has been surfaced to the user as part of the transparency information; it is not a compliance certification. Compliance depends on multiple factors, including whether an appropriate legal basis exists for both the placing of or access to information on the device (generally governed by the ePrivacy rules and their national implementations in the EU) and any subsequent processing of personal data (governed by the GDPR in the EU), as well as the accuracy and completeness of the disclosures and the contractual and organizational arrangements with the vendor. The segment is a technical and transparency mechanism that can support compliance but does not replace legal judgment about a given vendor.
How should the disclosed vendors segment be kept up to date as vendors change?
The disclosed vendors segment should generally reflect the vendors actually involved in processing at any given time, so it typically requires ongoing maintenance rather than a one-time configuration. As vendors are added, removed, or change the purposes for which they operate, the disclosures presented to users should be reviewed and updated accordingly. Where consent has been obtained on the basis of a prior set of disclosed vendors, changes may raise questions about whether the earlier consent still covers the current arrangement, since consent is expected to be specific and informed. The precise handling of such changes can depend on the framework and on data protection authority guidance, which continues to evolve, so this is an area to review with legal input.
How does the disclosed vendors segment relate to a CMP and the IAB Transparency and Consent Framework?
A consent management platform (CMP) typically manages the presentation of vendor disclosures and the capture of user choices, and the disclosed vendors segment can be one of the constructs a CMP uses to determine which vendors to surface. In implementations aligned with the IAB Transparency and Consent Framework (TCF), vendor disclosure and the recording of user preferences follow the framework's defined structures. It is important to note that using a CMP or operating within the TCF supports transparency and consent workflows but does not on its own guarantee compliance; the underlying configuration, the accuracy of vendor and purpose information, and the applicable legal requirements still need to be assessed independently.
What records should be kept regarding vendors shown in the disclosed vendors segment?
Organizations should generally consider maintaining records that evidence which vendors and purposes were disclosed to users and what choices users made, consistent with consent logging and record-keeping expectations. This can include the state of the disclosed vendors segment at the relevant time, the version of the disclosures presented, and the user's captured preferences. Such records can help demonstrate accountability, particularly in EU jurisdictions where the ability to demonstrate valid consent is expected. The specific record-keeping obligations and retention practices depend on the applicable legal regime and guidance, so the scope of what to log should be determined with reference to the relevant framework.
How does the disclosed vendors segment apply across different jurisdictions?
The role of the disclosed vendors segment can differ by jurisdiction because the underlying legal requirements differ. In most EU jurisdictions, disclosure supports an opt-in consent model in which vendors and purposes generally require prior consent before non-essential technologies are used, alongside the ePrivacy rules on device access and the GDPR on personal data processing. The UK follows a broadly similar approach under its own implementation. Several US state frameworks, such as those in California, often rely on an opt-out model rather than opt-in, which can change how vendor disclosures and user choices operate in practice. Because obligations vary by region and enforcement positions evolve, the segment should be configured with the specific applicable jurisdictions in mind rather than assuming a single universal standard.

Common misconceptions

If a vendor appears in the disclosed vendors segment, the user has consented to that vendor.
Disclosure means a vendor was surfaced to the user; it does not by itself establish consent. Valid consent under the GDPR must be freely given, specific, informed, and unambiguous through a clear affirmative action, and a disclosed vendor may still have no consent or may rely on a separately asserted legal basis.
Disclosing vendors within an IAB TCF setup guarantees compliance.
Frameworks and CMPs support compliance but do not replace legal judgment or guarantee a lawful outcome. Whether disclosure and the surrounding consent flow are adequate depends on the facts and on evolving guidance from data protection authorities in the relevant jurisdiction.
The same disclosed vendors segment satisfies obligations everywhere.
Requirements vary by jurisdiction. In most EU and UK contexts an opt-in, prior-consent model applies to non-essential cookies and similar technologies, whereas several US state laws (such as the CCPA/CPRA in California) often rely on an opt-out approach, so the meaning and legal effect of disclosure can differ by region.

Best practices

Present the full list of vendors that may place or access information on the device or process personal data before non-essential technologies are activated, so consent can be considered prior and informed in EU and UK contexts.
Keep the disclosed vendor set aligned with the vendors actually used, and update the list when vendors are added, removed, or change purposes, rather than treating it as static.
Distinguish clearly between disclosure, the legal basis claimed by each vendor, and whether the user actually consented, and reflect these as separate states in your consent records.
Maintain auditable consent logs capturing which vendors were disclosed and what the user chose at the time, to support accountability under the GDPR.
Configure vendor disclosure and consent handling to reflect the applicable jurisdiction, recognizing that EU/UK opt-in expectations differ from opt-out models under some US state laws.
Treat CMPs and framework registrations (such as the IAB TCF and its Global Vendor List) as tools that support compliance, and validate the vendor configuration against your own legal assessment rather than assuming it guarantees a lawful outcome.
Application Security Isn’t Optional Anymore.