Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Consent Records

TC String

Also known as: TC String, Transparency and Consent String, Transparency & Consent String
Simply put

A TC String is a compact, encoded piece of data that records the consent and preference choices a user makes on a website that uses the IAB Europe Transparency and Consent Framework (TCF). It captures what a user was told and how they responded regarding the processing of their personal data by advertising vendors. In a case concerning the TCF, the Court of Justice of the European Union concluded that a TC String constitutes personal data within the meaning of Article 4(1) of the GDPR.

Formal definition

A TC String (Transparency and Consent String) is the standardized, encoded output of the IAB Europe Transparency and Consent Framework (TCF) that encapsulates the information disclosed to a user and the expression of their preferences regarding the processing of their personal data. Structurally, the TC String requires a mandatory Core String segment to precede all other segments, which may be followed by additional segments such as disclosedVendors and PublisherTC. The TCF is presented by IAB Europe as an accountability tool relying on standardization to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR; it does not by itself guarantee compliance, and the framework's status has been the subject of regulatory and judicial scrutiny. Notably, the Court of Justice of the European Union has held that a TC String constitutes personal data within the meaning of Article 4(1) of the GDPR, meaning its generation, storage, and transmission are subject to GDPR obligations independent of the underlying consent it records. The geographic and legal scope described here reflects the EU/EEA context; the treatment of TC Strings and the TCF may differ under the UK regime, US state privacy laws, and other frameworks, which are outside the scope of this entry.

Why it matters

The TC String sits at the technical heart of how consent choices are communicated across the online advertising ecosystem in the EU/EEA. Because it encodes what a user was told and how they responded regarding the processing of their personal data by advertising vendors, it functions as the machine-readable record on which downstream vendors rely to determine whether they may process data. If the disclosures behind the string are inadequate, or the consent it records does not meet the GDPR standard of being freely given, specific, informed, and unambiguous, then the string may propagate a defective legal basis throughout the supply chain.

A significant reason the TC String matters is that the Court of Justice of the European Union has held that a TC String constitutes personal data within the meaning of Article 4(1) of the GDPR. This means the generation, storage, and transmission of the string are themselves subject to GDPR obligations, independent of the underlying consent the string records. Organisations relying on the IAB Europe Transparency and Consent Framework (TCF) therefore cannot treat the string as a neutral technical artifact; the string carries its own data protection implications.

It is important to note that the TCF is presented by IAB Europe as an accountability tool that relies on standardisation to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR. It does not by itself guarantee compliance, and the framework has been the subject of regulatory and judicial scrutiny. The treatment described here reflects the EU/EEA context; the position under the UK regime, US state privacy laws, and other frameworks may differ and is outside the scope of this entry.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy officers need to understand that a TC String is treated as personal data under the GDPR in the EU/EEA following the CJEU's ruling, which means its generation, storage, and transmission fall within GDPR obligations independent of the consent it records. This affects how the string is documented, retained, and accounted for.
Legal counsel and compliance teams
Counsel advising on the use of the TCF should note that the framework is presented by IAB Europe as an accountability tool to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR, but does not by itself guarantee compliance and has faced regulatory and judicial scrutiny. Legal judgment remains necessary to assess whether the disclosures and consent recorded in the string meet applicable standards.
Web developers and CMP integrators
Developers implementing consent management platforms need to handle the TC String's segment structure correctly, ensuring the mandatory Core String precedes other segments such as disclosedVendors and PublisherTC. They should also recognise that the string carries data protection implications and is not merely a technical token.
Publishers and advertising vendors
Publishers and vendors participating in the TCF rely on the TC String to communicate and interpret user preferences across the ecosystem. They should be aware that a defectively obtained consent recorded in a string may carry compliance risk downstream, and that the string's status as personal data in the EU/EEA affects how it may be processed.

Inside TC String

Encoded consent signal
A TC String is a compact, base64-encoded string that encodes a user's consent and objection choices in a machine-readable format for use within the IAB Transparency and Consent Framework (TCF).
Purposes and legal bases
It records which processing purposes (as defined in the TCF's standardized purpose taxonomy) the user has consented to or, where applicable, has not objected to under a legitimate interest basis. The interpretation of these bases must still align with GDPR requirements.
Vendor permissions
It captures the user's choices with respect to registered vendors participating in the TCF (identified via the framework's Global Vendor List), indicating for which vendors consent has been given or objections raised.
Metadata and versioning
It typically includes metadata such as the version of the framework, the identity of the CMP that captured the choices, and a timestamp reflecting when the consent state was recorded, which may support consent record-keeping obligations.
Scope indicators
It may indicate whether the choices apply on a service-specific or global basis within the framework, affecting how the signal is shared among participating parties.

Common questions

Answers to the questions practitioners most commonly ask about TC String.

Does storing or reading a TC String on a user's device count as obtaining valid consent?
No. A TC String is a technical representation that encodes a user's consent and preference choices within the IAB Transparency and Consent Framework (TCF); it is not consent itself. The string only records what a user has (or has not) chosen. Whether the underlying consent is valid depends on whether it met the applicable legal standard, which under the GDPR generally requires that consent be freely given, specific, informed, and unambiguous through a clear affirmative action. A well-formed TC String does not, on its own, demonstrate that these conditions were satisfied, and the presence of a string should not be treated as evidence of lawful consent without regard to how it was collected.
Is using the TCF and generating TC Strings enough to make a site compliant?
Not by itself. The TCF and its TC String format are industry tools that help standardize how consent signals are captured and communicated between parties in the advertising ecosystem, primarily for EU and UK contexts. Adopting the framework can support compliance efforts, but it does not guarantee compliance. Legal obligations under the ePrivacy rules and the GDPR depend on facts the framework does not resolve on its own, such as whether information was placed on or read from a device lawfully and whether any resulting personal data processing had a valid basis. Tools like the TCF support compliance but do not replace legal judgment, and the framework itself has been the subject of regulatory scrutiny.
Where is a TC String typically stored, and how is it accessed?
A TC String is commonly stored in the user's browser, often in a cookie or in local storage, and made available to vendors and other participants through the consent management platform's TCF API. Because placing information on or accessing information stored on a user's device is itself governed by ePrivacy rules in most EU jurisdictions, teams should consider how the string is stored, not only how it is used. The specific storage mechanism and retention approach may vary between CMP implementations, so consult your CMP's documentation for exact behavior.
How should we handle TC String changes when a user updates their preferences?
When a user changes their choices, the CMP generally generates a new TC String reflecting the updated preferences, which then supersedes the prior value. Downstream vendors are expected to read the current string rather than rely on a cached earlier version. Implementers should ensure that preference updates propagate promptly and that processing which is no longer permitted stops accordingly. The precise timing and propagation behavior depend on your CMP and vendor integrations, so testing the update flow is advisable.
Should we log or retain TC Strings for record-keeping purposes?
Maintaining records that demonstrate how and when consent was obtained can support accountability obligations, and a TC String may form part of such records because it encodes the choices captured at a point in time. However, a stored string may need to be accompanied by additional context, such as the version of the consent notice presented and the timestamp, to be meaningful as evidence. Any retention of TC Strings that relate to identifiable individuals should itself be considered under applicable data protection principles, including storage limitation. What constitutes adequate consent records is not fully settled and may vary by jurisdiction and by the guidance of the relevant data protection authority.
How do TC Strings relate to non-cookie technologies like pixels, SDKs, or local storage?
The TC String communicates the user's recorded choices to participating vendors regardless of the specific technology they use, so a vendor deploying a pixel, an SDK, or reading from local storage is expected to check the applicable signals before acting. This matters because, in most EU jurisdictions, the rules on placing and accessing information on a device apply to these technologies in the same way they apply to cookies. The TC String is a signaling mechanism only; it does not change whether a given technology requires consent, and it does not enforce vendor behavior, so reliance on vendors honoring the signal remains a governance consideration.

Common misconceptions

Generating a valid TC String means a website is GDPR-compliant.
A TC String is a technical mechanism for communicating consent choices; it does not by itself guarantee compliance. The underlying consent must still be freely given, specific, informed, and unambiguous, and the ePrivacy rules on storing or accessing information on a device must also be satisfied. Tools such as CMPs and the TCF support compliance but do not replace legal judgment.
The TCF and its TC String are legally mandated or officially endorsed everywhere.
The TCF is an industry framework, not a law. Its use is voluntary, and its approach has been the subject of regulatory scrutiny and evolving guidance from data protection authorities in the EU. Adopting it does not automatically satisfy obligations, which vary between the EU, the UK, and other jurisdictions.
A TC String reflecting a legitimate interest basis is equivalent to consent for those purposes.
The framework distinguishes between consent and legitimate interest signals. Reliance on legitimate interest for certain purposes is contested, and some data protection authorities have questioned its use for activities such as targeted advertising. The string records the choice but does not resolve whether that legal basis is appropriate.

Best practices

Treat the TC String as one component of a broader consent management approach, and separately confirm that consent meets GDPR standards and that ePrivacy rules on device storage and access are addressed.
Retain TC Strings together with associated metadata such as timestamps and CMP identity to support consent record-keeping, but verify these records satisfy the demonstrability expectations relevant to your jurisdiction.
Review how your CMP handles legitimate interest signals within the string, given contested regulatory positions, and align configuration with current data protection authority guidance.
Do not assume the TCF or its TC String applies uniformly across the EU, UK, and US state regimes; map the framework against the specific obligations of each market you serve, including opt-out-based models where relevant.
Monitor the version of the framework encoded in the string and update your implementation as the framework and applicable regulatory guidance evolve.
Seek legal review of your overall consent flow rather than relying on the presence of a valid TC String as evidence of compliance.
Application Security Isn’t Optional Anymore.