Global Vendor List
The Global Vendor List (GVL) is a publicly available list of companies that have registered under the IAB Europe Transparency and Consent Framework (TCF) to participate in digital advertising. It records information about each approved vendor, such as their name, country, and the services they provide, so that this information can be shown to users and processed by consent tools. It is designed to be machine-readable, meaning software can automatically read and use it.
The Global Vendor List (GVL) is a publicly available, machine-readable list maintained within the IAB Europe Transparency and Consent Framework (TCF) that catalogues vendors who have registered under, and been approved for participation in, the framework. Each entry typically includes attributes such as a unique Vendor ID, vendor name, country, territorial scope, environment, type of service, and international transfer information. Consent management platforms (CMPs) reference the GVL to present vendor and purpose information to end users and to structure consent signals accordingly. The GVL evolves across TCF versions; for example, TCF v2.2 introduced changes to the GVL intended to provide greater transparency to end users. The GVL is a framework-specific technical and organizational artifact and does not itself determine the lawfulness of any given vendor's data processing, which remains subject to applicable legal requirements and independent assessment.
Why it matters
The Global Vendor List sits at the heart of how the IAB Europe Transparency and Consent Framework operates. When a consent management platform presents a consent notice to a user, the vendors, purposes, and processing information it displays are drawn from the GVL. This means the list functions as a shared reference point across the digital advertising ecosystem, allowing consent signals captured by one CMP to be interpreted consistently by the many parties that participate in the framework. For privacy officers and compliance teams, understanding which vendors appear on the GVL, and what attributes are recorded against them, is important when assessing the scope of third parties a website may be exposing users to.
Because the GVL is publicly available and machine-readable, it also supports transparency and accountability efforts. Interested parties can inspect the list to see which companies have registered under the framework, their stated country and territorial scope, and details such as international transfer information. The TCF v2.2 update introduced changes to the GVL intended to provide greater transparency to end users, reflecting the framework's ongoing evolution in response to feedback and regulatory expectations.
At the same time, inclusion on the GVL should not be mistaken for a guarantee of lawful processing. The list records that a vendor has registered under and been approved for participation in the TCF, but it does not itself determine whether any given vendor's data processing complies with the ePrivacy rules governing access to information on a user's device or with the GDPR requirements that apply to any resulting processing of personal data. Those questions remain subject to applicable legal requirements and independent assessment, and organizations should not treat the GVL as a substitute for their own due diligence.
Who it's relevant to
Inside GVL
Common questions
Answers to the questions practitioners most commonly ask about GVL.

