Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: TCF and Vendors

Global Vendor List

Also known as: GVL, TCF Vendor List, IAB TCF Global Vendor List
Simply put

The Global Vendor List (GVL) is a publicly available list of companies that have registered under the IAB Europe Transparency and Consent Framework (TCF) to participate in digital advertising. It records information about each approved vendor, such as their name, country, and the services they provide, so that this information can be shown to users and processed by consent tools. It is designed to be machine-readable, meaning software can automatically read and use it.

Formal definition

The Global Vendor List (GVL) is a publicly available, machine-readable list maintained within the IAB Europe Transparency and Consent Framework (TCF) that catalogues vendors who have registered under, and been approved for participation in, the framework. Each entry typically includes attributes such as a unique Vendor ID, vendor name, country, territorial scope, environment, type of service, and international transfer information. Consent management platforms (CMPs) reference the GVL to present vendor and purpose information to end users and to structure consent signals accordingly. The GVL evolves across TCF versions; for example, TCF v2.2 introduced changes to the GVL intended to provide greater transparency to end users. The GVL is a framework-specific technical and organizational artifact and does not itself determine the lawfulness of any given vendor's data processing, which remains subject to applicable legal requirements and independent assessment.

Why it matters

The Global Vendor List sits at the heart of how the IAB Europe Transparency and Consent Framework operates. When a consent management platform presents a consent notice to a user, the vendors, purposes, and processing information it displays are drawn from the GVL. This means the list functions as a shared reference point across the digital advertising ecosystem, allowing consent signals captured by one CMP to be interpreted consistently by the many parties that participate in the framework. For privacy officers and compliance teams, understanding which vendors appear on the GVL, and what attributes are recorded against them, is important when assessing the scope of third parties a website may be exposing users to.

Because the GVL is publicly available and machine-readable, it also supports transparency and accountability efforts. Interested parties can inspect the list to see which companies have registered under the framework, their stated country and territorial scope, and details such as international transfer information. The TCF v2.2 update introduced changes to the GVL intended to provide greater transparency to end users, reflecting the framework's ongoing evolution in response to feedback and regulatory expectations.

At the same time, inclusion on the GVL should not be mistaken for a guarantee of lawful processing. The list records that a vendor has registered under and been approved for participation in the TCF, but it does not itself determine whether any given vendor's data processing complies with the ePrivacy rules governing access to information on a user's device or with the GDPR requirements that apply to any resulting processing of personal data. Those questions remain subject to applicable legal requirements and independent assessment, and organizations should not treat the GVL as a substitute for their own due diligence.

Who it's relevant to

Privacy and data protection officers
Officers assessing which third parties a site relies on can consult the GVL to see which vendors have registered under the TCF and what attributes, such as country, territorial scope, and international transfer information, are recorded against them. This supports transparency and record-keeping efforts, though it does not by itself establish that a vendor's processing meets applicable ePrivacy or GDPR requirements.
Web developers and CMP integrators
Teams implementing consent management platforms need to understand that the CMP references the machine-readable GVL to present vendor and purpose information and to structure consent signals. Because the GVL changes across TCF versions, developers should account for how updates such as those introduced in TCF v2.2 affect the vendor and purpose information displayed to users.
Vendors participating in digital advertising
Companies that register under the TCF have their information included in the publicly available GVL once they are approved and operational. Vendors should ensure the details recorded against their entry, such as name, country, type of service, and international transfer information, are accurate, while recognizing that GVL inclusion reflects framework registration rather than a determination of lawful processing.
Legal and compliance counsel
Counsel advising on advertising and consent arrangements can use the GVL as a reference to the vendors involved, but should treat it as one input rather than a compliance conclusion. The lawfulness of any vendor's processing remains subject to applicable legal requirements and independent assessment, and the GVL is specific to the TCF rather than a universal standard across the EU, UK, US states, or other regimes.

Inside GVL

Registered vendors
A centralized list of third-party companies (advertising, measurement, and data-processing vendors) that have registered to participate in the IAB Europe Transparency and Consent Framework (TCF). Each vendor is assigned a unique identifier used within TCF consent signals.
Declared purposes and legal bases
For each vendor, the list records the data processing purposes the vendor declares (such as storing information on a device, selecting personalized ads, or measuring performance) and whether the vendor relies on consent or on legitimate interest for each purpose. Note that the availability of legitimate interest as a basis for certain processing has been contested by data protection authorities.
Features and special purposes/features
Metadata describing additional processing characteristics a vendor may use, such as matching and combining data or using precise geolocation, which typically require specific disclosure to users.
Vendor-specific policy and retention information
Links to a vendor's privacy policy and, where provided within the framework, information about data retention periods, intended to support the informed element of consent.
Role within the TCF signal
The Global Vendor List is referenced by consent management platforms (CMPs) to build the user-facing choices and to encode a user's consent or objection status into the TC String that is passed to downstream vendors.

Common questions

Answers to the questions practitioners most commonly ask about GVL.

Does inclusion on the Global Vendor List mean a vendor is compliant with the GDPR or ePrivacy rules?
No. Registration on the Global Vendor List (GVL) indicates that a vendor has signed up to IAB Europe's Transparency and Consent Framework (TCF) policies and declared its data-processing purposes and legal bases, but it does not certify that the vendor's actual processing is lawful. Compliance depends on how the vendor operates in practice, the validity of the consent or other legal basis relied upon, and the requirements of the applicable regime. The GVL is an administrative and technical registry, not a regulatory approval, and it does not replace independent legal assessment.
Is the Global Vendor List a legal requirement for cookie consent?
No. The GVL is a component of the IAB Europe TCF, which is a voluntary industry standard rather than a legal mandate. Organizations can obtain and manage consent for cookies and similar technologies without participating in the TCF or referencing the GVL at all. The list is relevant primarily to those who choose to implement the TCF, typically in the digital advertising context. Consent obligations themselves flow from the ePrivacy rules (for placing or accessing information on a device) and the GDPR (for any resulting processing of personal data), not from the GVL.
How does a consent management platform use the Global Vendor List?
A CMP operating within the TCF generally retrieves the GVL to display the participating vendors and their declared purposes to the user, and to record and encode the user's choices in a standardized signal (such as the TC String). This supports downstream vendors in determining what they may do. The GVL functions as a shared reference so that consent choices can be communicated consistently. Note that this describes the technical role only; the CMP's use of the GVL does not by itself guarantee that the consent collected meets the standards of any particular jurisdiction.
How often is the Global Vendor List updated, and why does that matter for implementation?
The GVL is updated periodically by IAB Europe as vendors are added, amended, or removed. From an implementation standpoint, systems relying on the list generally need to fetch current versions rather than hard-coding vendor data, so that newly added vendors and changes to declared purposes are reflected and outdated or removed vendors are handled appropriately. You should confirm the specific update and caching practices with your CMP provider and the current TCF technical specifications rather than assuming a fixed schedule.
What should we do about vendors that are not on the Global Vendor List?
Vendors absent from the GVL are simply not registered within the TCF; this does not make them unlawful, nor does it exempt them from consent or other legal-basis requirements. If you work with such vendors, you generally need to manage the legal basis for placing or accessing information on the device and for any personal data processing through other means, such as your own CMP configuration outside the TCF or contractual and direct disclosure mechanisms. The appropriate approach depends on the vendor's role and the applicable jurisdiction's rules.
Does using the Global Vendor List cover cookie consent obligations outside the EU, such as in the UK or US states?
Not automatically. The GVL and the TCF were designed principally around the EU framework. UK requirements broadly track the EU approach but are administered separately, and US state privacy laws such as the CCPA and CPRA in California typically rely on opt-out mechanisms rather than the prior opt-in model reflected in much of the TCF. Organizations operating across jurisdictions generally need additional or different mechanisms to address those regimes. You should treat the GVL as one input into a broader, jurisdiction-specific compliance strategy and confirm current requirements for each applicable region.

Common misconceptions

Being listed on the Global Vendor List means a vendor is GDPR-compliant and its data processing is lawful.
Registration reflects a vendor's participation in and declarations under the TCF; it is not a regulatory certification. Inclusion does not guarantee that a vendor's processing satisfies the GDPR or the ePrivacy Directive, and the lawfulness of specific processing depends on facts outside the list. Aspects of the TCF itself have faced regulatory scrutiny in the EU.
Using the Global Vendor List and a TCF-integrated CMP automatically makes a website's cookie consent compliant.
These tools support consent management but do not replace legal judgment. Whether consent is valid still depends on how choices are presented, whether consent is freely given, specific, informed, and unambiguous, and how the site actually loads technologies. The framework governs signaling rather than guaranteeing compliance in any single jurisdiction.
The Global Vendor List sets the rules that apply to every jurisdiction.
The TCF and its Global Vendor List were designed primarily around the EU legal context (the GDPR and the ePrivacy Directive). Obligations differ in the UK and across US states such as California under the CCPA and CPRA, which often rely on opt-out rather than opt-in, so reliance on the list does not address all regimes.

Best practices

Do not treat a vendor's presence on the Global Vendor List as evidence of legality; independently assess each vendor's purposes, declared legal bases, and data practices against the GDPR and applicable ePrivacy rules.
Review the purposes and any legitimate-interest claims declared by vendors, since reliance on legitimate interest for certain advertising-related processing has been questioned by data protection authorities in the EU.
Ensure your CMP presents vendor and purpose information in a way that supports freely given, specific, informed, and unambiguous consent, and avoid pre-ticked boxes, implied consent, or cookie walls in EU-facing implementations.
Keep the vendor list your CMP uses up to date and periodically audit which vendors are actually active on your site, so consent signals match real data flows and technologies (including pixels, SDKs, and local storage).
Maintain consent logs and records that capture which vendors and purposes a user consented to or objected to, to support accountability and record-keeping obligations.
Assess whether the TCF-based approach alone meets your obligations across all relevant jurisdictions (EU, UK, and individual US states), and supplement it where opt-out signals such as Global Privacy Control or state-specific requirements apply.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.