Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: TCF and Vendors

IAB Tech Lab Standards

Also known as: Tech Lab Standards
Simply put

IAB Tech Lab Standards are a set of technical specifications developed by IAB Tech Lab, a non-profit organization, to create common ways for companies in the digital advertising industry to work together. They cover a range of areas, including how consumer privacy preferences are communicated across advertising systems. These standards aim to support consistency and trust in the digital ecosystem, though adopting them supports compliance efforts rather than guaranteeing legal compliance on its own.

Formal definition

IAB Tech Lab Standards are technology specifications produced by IAB Tech Lab, a non-profit that collaborates with global members to define interoperable standards for the digital advertising ecosystem. The portfolio spans multiple domains, including a privacy pillar focused on facilitating uniform communication of consumer privacy preference signals across the advertising supply chain, as well as broader initiatives (for example, agentic advertising and AI-related work). IAB Tech Lab also operates Compliance Programs, such as those for OM SDK, Data Transparency, and Podcast Measurement, through which participants can demonstrate adherence to specific standards. These standards define technical and signaling conventions but do not themselves constitute legal frameworks; conformance to a Tech Lab standard is a technical and industry-governance matter and should not be treated as equivalent to satisfying statutory consent or data-protection obligations under regimes such as the EU ePrivacy rules, the GDPR, the UK regime, or US state privacy laws. Legal sufficiency in any jurisdiction depends on facts and applicable law that fall outside the scope of the standards themselves.

Why it matters

The digital advertising ecosystem involves many participants, publishers, advertisers, ad tech intermediaries, and measurement providers, that must exchange data and signals reliably to function. IAB Tech Lab Standards matter because they provide common technical specifications that allow these parties to interoperate, including a privacy-focused pillar aimed at facilitating uniform communication of consumer privacy preference signals throughout the supply chain. Without shared conventions, privacy signals such as consent or opt-out preferences could be interpreted inconsistently or lost as they pass between systems, undermining both operational reliability and the trust the ecosystem depends on.

For privacy and compliance professionals, the significance lies in what these standards can and cannot do. Adopting a Tech Lab standard supports interoperability and can help operationalize the technical communication of privacy signals, but conformance is a technical and industry-governance matter rather than a legal determination. A standard does not by itself establish that consent has been validly obtained under the EU ePrivacy rules or the GDPR, that opt-out obligations under US state privacy laws have been met, or that any other statutory requirement is satisfied. Legal sufficiency depends on the specific facts and the applicable law in each jurisdiction, which fall outside the scope of the standards themselves.

Teams should therefore treat these standards as one component of a broader compliance program. IAB Tech Lab also operates Compliance Programs for certain standards, such as OM SDK, Data Transparency, and Podcast Measurement, through which participants can demonstrate adherence, but demonstrating adherence to a technical standard is distinct from demonstrating compliance with data-protection law and should not be conflated with it.

Who it's relevant to

Ad tech providers and platform engineers
Companies building or integrating advertising technology rely on these standards to interoperate with others in the supply chain, including the technical transmission of privacy preference signals. Engineering teams may also engage with IAB Tech Lab Compliance Programs, such as OM SDK, to demonstrate technical adherence, while recognizing that this is separate from legal compliance.
Publishers and their compliance teams
Publishers using ad tech that follows Tech Lab Standards need to understand how privacy preference signals are communicated onward, and to confirm that their own consent and notice practices meet the requirements of the jurisdictions they operate in. Conformance to a standard supports, but does not substitute for, that legal assessment.
Privacy officers and data protection professionals
Those responsible for compliance under regimes such as the EU ePrivacy rules, the GDPR, the UK regime, or US state privacy laws should treat these standards as tools that can help operationalize privacy signaling rather than as evidence of legal sufficiency. Legal adequacy depends on facts and applicable law outside the scope of the standards.
Legal counsel advising on digital advertising
Counsel evaluating ad tech arrangements or vendor claims should be able to distinguish between adherence to a Tech Lab technical standard or Compliance Program and satisfaction of statutory obligations. The former is an industry-governance and technical matter; the latter requires a jurisdiction-specific legal analysis.

Inside IAB Tech Lab Standards

Transparency and Consent Framework (TCF)
An IAB-associated framework designed to standardize how consent, and in some cases legitimate interest, is collected, signaled, and communicated across the digital advertising supply chain in the EU and UK. It defines standard purposes, vendor lists, and technical signals that CMPs and vendors can interpret consistently. The TCF is intended to support compliance with EU and UK requirements but does not itself guarantee that any given implementation is lawful.
Global Vendor List (GVL)
A centrally maintained list of vendors participating in the TCF, together with the purposes and legal bases each vendor declares. CMPs reference the GVL to present users with information about which third parties may process data and for what purposes.
Standardized purposes and features
A defined taxonomy of processing purposes (for example, storing information on a device, personalized advertising, and measurement) and features that vendors and CMPs use to describe data uses to users in a consistent way. These categories aim to make disclosures comparable across sites and vendors.
TC String (Transparency and Consent String)
An encoded technical signal that records the consent and, where applicable, legitimate interest choices a user has expressed, along with metadata such as the CMP and vendor list version. It is passed through the advertising supply chain so downstream parties can interpret the user's stated preferences.
CMP registration and certification
A process by which consent management platforms are registered with the IAB to operate within the TCF and are expected to follow the framework's technical and policy specifications. Registration indicates participation in the framework rather than a determination of legal compliance.
Related IAB Tech Lab technical specifications
Beyond the TCF, IAB Tech Lab publishes a range of technical standards used in digital advertising. Where these intersect with privacy signaling, they may reference or interoperate with consent frameworks, but their scope extends beyond cookie consent alone.

Common questions

Answers to the questions practitioners most commonly ask about IAB Tech Lab Standards.

Does implementing the IAB Transparency and Consent Framework (TCF) automatically make my cookie consent compliant with the GDPR and ePrivacy rules?
No. The TCF and other IAB Tech Lab standards provide a technical and contractual framework for signalling consent and other legal bases across the advertising supply chain, but adopting them does not by itself guarantee compliance. Valid consent under the GDPR must still be freely given, specific, informed, and unambiguous, and the underlying placement of cookies is governed by the ePrivacy Directive as implemented nationally. Some data protection authorities in the EU have raised concerns about aspects of the framework in the past, and interpretations continue to evolve. Using an IAB-based CMP supports compliance efforts but does not replace independent legal judgment about whether your specific implementation meets applicable requirements.
Is the IAB Tech Lab a regulator, and do its standards carry the force of law?
No. The IAB Tech Lab is an industry standards body, not a regulator or legislator. Its specifications, including the TCF, are voluntary technical and contractual standards developed by and for the digital advertising industry. They do not have the force of law, and conformance with them is not the same as compliance with the GDPR, the ePrivacy Directive and its national implementations, the UK regime, or US state privacy laws such as the CCPA and CPRA. Legal obligations flow from the applicable statutes and from guidance and enforcement by the relevant authorities, not from the standards themselves.
How does the TCF relate to a consent management platform (CMP) that I deploy on my website?
The TCF defines a common technical language and set of policies that a CMP can implement so that consent and other signals are communicated consistently to advertising vendors. A CMP that is registered with the framework can generate and pass standardized consent strings to participating vendors. However, a CMP is a tool that operationalizes signalling and record-keeping; the choices you make in configuring it, the categories and vendors you present, and the legal bases you rely on remain your responsibility. Deploying a TCF-registered CMP does not remove the need for legal review of your specific setup.
Do IAB Tech Lab standards cover technologies other than traditional cookies, such as pixels, SDKs, or local storage?
The IAB Tech Lab develops standards relevant to a range of digital advertising technologies, and the legal rules that the framework is meant to help address apply broadly to methods of storing or accessing information on a user's device. This can include pixels, software development kits (SDKs), local storage, and similar technologies, not only literal cookies. Whether a given standard addresses a specific technology depends on the particular specification. You should confirm scope against the relevant IAB documentation and assess each technology against the applicable ePrivacy and data protection requirements rather than assuming uniform coverage.
What record-keeping or consent-logging considerations arise when using an IAB-based framework?
Frameworks such as the TCF typically involve generating consent signals, often encoded as consent strings, that record which purposes and vendors a user has consented to or objected to. These signals can support the accountability and record-keeping expectations associated with demonstrating a lawful basis, but the format and retention of such records, and whether they are sufficient for a given regulator, depend on your implementation and applicable guidance. You should verify how your CMP stores and retains these records and confirm that your logging practices align with the requirements of the jurisdictions in which you operate, as expectations differ between the EU, the UK, and US state regimes.
Should I rely on IAB standards for compliance across the EU, the UK, and US states alike?
IAB Tech Lab standards are not a substitute for jurisdiction-specific analysis. Cookie consent and related obligations differ across the EU, the UK, and individual US states such as California under the CCPA and CPRA, with EU and UK regimes generally relying on prior opt-in consent for non-essential technologies and several US state laws relying more on opt-out mechanisms. Some IAB frameworks are oriented toward particular regions or signalling models. You should map any framework you adopt to the specific legal scope you need to cover and treat the standards as one component of a broader, jurisdiction-aware compliance approach.

Common misconceptions

Implementing the IAB TCF or using a TCF-registered CMP makes a website compliant with the GDPR and ePrivacy rules.
The TCF is intended to standardize how consent and preferences are collected and communicated, but participation or registration does not itself guarantee compliance. Compliance depends on how consent is actually obtained, whether it meets the freely given, specific, informed, and unambiguous standard under the GDPR, and how the placing of and access to information on devices is handled under the ePrivacy Directive and its national implementations. Legal judgment is still required, and enforcement positions from data protection authorities continue to evolve.
The TCF and its TC String apply globally as a universal consent standard.
The TCF was designed primarily around EU and UK requirements, which generally rely on opt-in consent. It does not automatically address the differing obligations of individual US state privacy laws, which often rely on opt-out mechanisms, or other regimes. The geographic and legal scope of any consent signal should be assessed against the applicable jurisdiction rather than assumed to be universal.
The TC String is a substitute for keeping your own records of consent.
The TC String encodes and transmits a user's stated choices through the supply chain, but organizations may still have independent obligations to maintain records demonstrating that valid consent was obtained. The signal supports interoperability rather than replacing an organization's own consent logging and record-keeping responsibilities, which should be evaluated in light of applicable requirements.

Best practices

Treat TCF participation and CMP registration as supporting tools rather than proof of compliance; validate independently that consent meets the applicable EU or UK standard of being freely given, specific, informed, and unambiguous, and that the placing of information on devices is handled consistently with ePrivacy rules.
Confirm the geographic and legal scope you are operating in before relying on the TCF, and implement separate mechanisms where jurisdictions such as US states rely on opt-out signals rather than opt-in consent.
Keep your Global Vendor List references and CMP versions current, and periodically review which vendors and purposes are being disclosed to users to ensure disclosures remain accurate.
Maintain your own consent logging and record-keeping in addition to the TC String, so you can demonstrate how and when consent was obtained rather than relying solely on the transmitted signal.
Ensure that consent obtained through a TCF implementation is not treated as automatically satisfying separate GDPR processing obligations; document the legal basis for any personal data processing that follows.
Involve legal or data protection expertise when configuring standardized purposes, legitimate interest signaling, and vendor lists, since these settings carry compliance implications that a tool alone cannot resolve, and monitor evolving guidance from relevant data protection authorities.
Application Security Isn’t Optional Anymore.