Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: TCF and Vendors

TCF-Compliant CMP

Also known as: CMP, TCF-registered CMP, IAB Europe TCF-compliant Consent Management Platform, TCF v2.3-compliant CMP
Simply put

A TCF-compliant CMP is a consent management platform, the software behind cookie banners and consent notices, that has been built to meet the rules of IAB Europe's Transparency & Consent Framework (TCF). Such a platform displays notices to users, collects their choices, and shares those choices with other companies in a standardised way. Meeting TCF requirements is intended to support compliance with certain EU privacy rules, but it does not by itself guarantee that an organisation is fully compliant.

Formal definition

A TCF-compliant CMP is a Consent Management Platform that satisfies the technical and policy requirements of IAB Europe's Transparency & Consent Framework (currently TCF v2.3) and has passed its associated compliance process, which per IAB Europe comprises a pre-implementation validation stage and a post-implementation enforcement stage in which live CMPs are monitored. Functionally, the CMP develops notices (for example cookie banners) to inform users, captures and manages their consent and preferences, and encodes and shares those signals with participating vendors in the standardised format defined by the Framework. IAB Europe positions the TCF as an accountability and standardisation tool intended to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR; TCF compliance concerns adherence to the Framework's specifications and should not be treated as a substitute for an independent legal assessment of consent validity under the ePrivacy Directive (which governs storage of and access to information on a device) and the GDPR (which governs subsequent processing of personal data). Scope note: the evidence provided does not address the geographic applicability of the TCF beyond the EU context, national data protection authority positions on the Framework, or requirements under UK or US state privacy regimes; those matters are out of scope for this definition.

Why it matters

For publishers, advertisers, and ad-tech vendors operating in the EU digital advertising ecosystem, a TCF-compliant CMP provides a standardised way to collect user consent and pass those signals down the supply chain. Because many vendors participate in IAB Europe's Transparency & Consent Framework, using a CMP that speaks the same standardised format is often a practical prerequisite for exchanging consent signals with programmatic advertising partners. The Framework is positioned by IAB Europe as an accountability tool intended to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR.

At the same time, TCF compliance and legal compliance are not the same thing. Meeting the technical and policy requirements of the Framework does not by itself guarantee that an organisation has obtained valid consent or is otherwise compliant with applicable law. Consent standards under the GDPR require that consent be freely given, specific, informed, and unambiguous, and the ePrivacy Directive separately governs the placing of and access to information on a user's device. A CMP can implement the Framework correctly while an organisation's overall consent practices still fall short, which is why the CMP should be treated as a supporting mechanism rather than a substitute for independent legal assessment.

The distinction matters because the TCF has itself been the subject of regulatory scrutiny in the EU, and data protection authority positions on the Framework continue to evolve. Organisations relying on a TCF-compliant CMP should therefore monitor guidance relevant to their jurisdictions rather than assume that registration or compliance status resolves all legal questions. The evidence here does not address national authority positions in detail, and those matters remain an important area for organisations to track independently.

Who it's relevant to

Publishers and website operators
Organisations that run websites or apps and participate in programmatic advertising often adopt a TCF-compliant CMP so that consent signals can be shared in the standardised format expected by advertising vendors. They should treat the CMP as a supporting tool and still confirm, through independent legal assessment, that the consent they collect meets applicable ePrivacy and GDPR requirements.
Ad-tech vendors and advertising partners
Vendors that receive and act on consent signals depend on CMPs encoding user choices in the Framework's standardised format. A TCF-compliant CMP allows these vendors to read consent and preference signals consistently across the supply chain, though it does not relieve them of their own accountability for the processing they carry out.
Privacy officers and legal counsel
Data protection professionals evaluating a CMP need to distinguish TCF compliance, adherence to the Framework's specifications and its validation and enforcement stages, from legal compliance under the ePrivacy Directive and the GDPR. They should assess consent validity independently and monitor evolving regulatory positions on the Framework relevant to their jurisdictions.
Web developers and implementation teams
Technical teams responsible for deploying cookie banners and consent flows work directly with the CMP to display notices, capture preferences, and pass standardised signals to vendors. Because the compliance programme includes post-implementation monitoring of live CMPs, correct and maintained implementation matters beyond initial deployment.

Inside CMP

TCF (Transparency and Consent Framework)
An industry standard developed by IAB Europe that defines a technical protocol for capturing, storing, and communicating user consent and objections regarding cookies and similar technologies to advertising and other vendors. A TCF-compliant CMP implements this specification so that consent signals can be shared in a standardized format across participating parties.
CMP (Consent Management Platform)
The software layer that presents consent choices to users, records their decisions, and makes those decisions available to other systems. When described as TCF-compliant, the CMP has been registered with IAB Europe and follows the framework's technical and policy requirements, though registration and technical conformance are distinct from any legal determination of validity.
TC String (Transparency and Consent String)
The standardized, encoded record produced under the TCF that represents a user's consent and objection choices across defined purposes and vendors. It is passed to downstream parties so they can determine whether they may process data. It is a technical artifact and, on its own, is not proof that consent met legal standards.
Purposes and vendors
The TCF organizes data processing into defined purposes (such as storing information on a device, or measuring content performance) and a registered list of vendors. A TCF-compliant CMP surfaces these to users so choices can be made at that level of granularity, which supports the specific and informed elements of consent expected in most EU jurisdictions.
Consent and legitimate interest signalling
The framework distinguishes processing based on consent from processing a vendor claims under legitimate interest, and a compliant CMP conveys both types of signals. The appropriateness of relying on legitimate interest for particular purposes is contested and depends on the legal analysis of the controller, not on the framework itself.
Scope and legal basis
The TCF was designed primarily with the EU ePrivacy and GDPR context in mind. Placing or accessing information on a device is governed by the ePrivacy Directive as implemented nationally, while any subsequent processing of personal data is governed by the GDPR. A TCF-compliant CMP addresses the mechanics of gathering and transmitting signals but does not by itself resolve either set of obligations.

Common questions

Answers to the questions practitioners most commonly ask about CMP.

Does using a TCF-compliant CMP mean my cookie consent is automatically GDPR-compliant?
No. Registration or certification against the IAB Transparency and Consent Framework signals that a CMP adheres to the framework's technical specifications and policies, but it does not by itself guarantee compliance with the GDPR or the ePrivacy Directive. The TCF governs how consent signals are structured and communicated among participating vendors; it does not replace the underlying legal requirement that consent be freely given, specific, informed, and unambiguous. A CMP is a tool that supports compliance, and its configuration, the information presented to users, and the surrounding processing still require independent legal judgment. Note that aspects of the framework itself have been the subject of regulatory scrutiny in the EU, and interpretations continue to evolve.
Is a TCF-compliant CMP required or suitable everywhere I operate?
Not necessarily. The TCF was developed primarily to address consent under EU law and the ePrivacy Directive as implemented in EU member states, and it reflects an opt-in model. It is not a universal standard. Obligations differ in the UK and across individual US states such as California under the CCPA and CPRA, which often rely on opt-out mechanisms and signals like Global Privacy Control rather than the affirmative opt-in that the TCF is oriented toward. Whether a TCF-based approach fits a given market depends on the applicable legal regime, and some jurisdictions may call for different or additional consent handling. Confirm the geographic scope of your obligations before assuming the framework applies.
How do I decide which vendors to enable in a TCF-compliant CMP?
Vendor selection should generally be driven by which third parties actually process personal data or place or access information on the user's device in connection with your site, rather than by enabling the full list of registered vendors. The framework maintains a vendor list identifying participants and their declared purposes, but including vendors you do not use can undermine the requirement that consent be specific and informed. Reviewing each vendor's declared purposes and data uses, and documenting why each is included, supports a more defensible configuration. The appropriateness of any particular vendor set depends on facts specific to your deployment and warrants legal review.
What should I configure regarding the distinction between consent and legitimate interest in the CMP?
The framework allows certain purposes to be signaled on a legal basis of legitimate interest rather than consent, and CMP configuration typically lets you set which basis applies per purpose or vendor. Because the placing of and access to information on a device is generally governed by the ePrivacy rules requiring prior consent, relying on legitimate interest for activities that trigger those rules can be contested, and regulatory positions on this point in the EU have evolved. Treat the choice of legal basis for each purpose as a legal determination rather than a default setting, and avoid assuming that a legitimate-interest signal available in the tool is appropriate for your use.
How does a TCF-compliant CMP support consent record-keeping?
TCF-based CMPs typically generate and store a consent string that encodes the user's choices across purposes and vendors, which can contribute to demonstrating what was consented to and when. This can support record-keeping and accountability obligations, but the consent string is a technical artifact and may not on its own capture everything needed to evidence valid consent, such as the exact information presented to the user at the time. Organizations generally remain responsible for maintaining adequate records of consent, and how long and in what form these are retained should be assessed against applicable data protection requirements. What constitutes sufficient evidence can depend on the relevant supervisory authority's expectations.
Does a TCF-compliant CMP handle technologies other than cookies, such as pixels, SDKs, or fingerprinting?
The consent signals a TCF-based CMP produces can in principle cover a range of tracking technologies, because the underlying EU rules on placing and accessing information on a device apply to pixels, local storage, mobile SDKs, and fingerprinting techniques as well as to literal cookies. However, whether these technologies actually respect the CMP's signal depends on how vendors and your own implementation are integrated; a consent decision recorded by the CMP has effect only if the relevant scripts, tags, and SDKs are gated to honor it. Verifying that non-cookie technologies are wired to the consent state is an implementation task that the framework specification alone does not accomplish.

Common misconceptions

Using a TCF-compliant CMP guarantees that a website's cookie practices are lawful.
TCF compliance means the CMP conforms to IAB Europe's technical and policy specification and can register with the framework. It does not, on its own, establish that consent was freely given, specific, informed, and unambiguous, nor that ePrivacy and GDPR obligations are met. Tools support compliance but do not replace legal judgment, and the standing of the framework itself has been the subject of regulatory scrutiny.
A TCF-compliant CMP satisfies consent requirements everywhere.
The TCF was designed principally for the EU context, where consent is generally required before non-essential cookies are set. Other regimes differ: the UK follows its own implementation of ePrivacy rules, and US state laws such as the CCPA and CPRA in California typically rely on opt-out mechanisms rather than opt-in consent. A TCF signal may not map to those requirements without additional configuration.
If a vendor relies on legitimate interest within the TCF, no consent is needed for that processing.
The framework can transmit legitimate interest signals, but whether legitimate interest is an appropriate legal basis is a contested, fact-specific question. Placing or accessing information on a device generally still requires consent under EU ePrivacy rules regardless of the basis claimed for later processing, and this remains an area of evolving regulatory interpretation.

Best practices

Treat TCF compliance of your CMP as one input to your compliance program, not as evidence that consent is legally valid; obtain and document your own legal analysis of your cookie and processing practices.
Verify that the CMP is configured so that non-essential cookies and similar technologies (including pixels, local storage, SDKs, and fingerprinting) are not set before a clear affirmative action, and that pre-ticked options are not used, consistent with expectations in most EU jurisdictions.
Map TCF purposes and vendors against the technologies actually deployed on your site so that the choices presented to users accurately reflect the processing that occurs, supporting the specific and informed elements of consent.
Configure or supplement the CMP for the jurisdictions you serve, recognizing that the EU, the UK, and individual US states such as California impose different obligations and that opt-out signals may need to be honored separately.
Retain records of consent decisions, including the relevant TC String and configuration, to support consent logging and record-keeping obligations, while confirming with counsel what retention is appropriate.
Monitor guidance and enforcement positions relating to the TCF and update your configuration and documentation as interpretations evolve, since the framework's standing and regulatory expectations continue to develop.
Promotional banner for the Penetration Report Template Kit