Skip to main content
Promotional banner for the pentest readiness checklist
Category: TCF and Vendors

TCF v2.2

Also known as: TCF, IAB TCF 2.2, Transparency & Consent Framework v2.2, IAB Europe Transparency and Consent Framework version 2.2
Simply put

TCF v2.2 is a version of the IAB Europe Transparency & Consent Framework, an industry standard designed to help websites, advertising vendors, and consent tools handle user choices about data processing in the digital advertising ecosystem. It is intended to support compliance with the EU's General Data Protection Regulation (GDPR) and ePrivacy Directive, though using the framework does not by itself guarantee legal compliance. The framework provides a common technical language so that a user's consent and other signals can be communicated consistently among the parties involved in serving ads.

Formal definition

TCF v2.2 is a version of the IAB Europe Transparency & Consent Framework, for which the IAB Tech Lab stewards the technical specifications. The framework is designed to help parties in the digital advertising environment support compliance with the GDPR and the ePrivacy Directive by standardizing how consent, and other signals from users, are captured, encoded, and transmitted among consent management platforms (CMPs), publishers, and registered vendors. A notable policy change in TCF v2.2 is that vendors may only rely on consent, rather than legitimate interest, as the legal basis for processing personal data for advertising and content personalization purposes. The framework was subsequently succeeded by a later version (TCF v2.3), which repurposed the 'Disclosed Vendors' section and made it mandatory to address legitimate-interest ambiguity; the precise release timeline of v2.3 is not established by the evidence provided here. This entry does not resolve the framework's contested regulatory standing, and adoption of TCF v2.2 supports but does not substitute for independent legal judgment on GDPR and ePrivacy obligations.

Why it matters

The digital advertising ecosystem involves many parties, publishers, ad tech vendors, and consent tools, that must exchange information about a user's choices consistently. Without a shared technical standard, a consent signal captured on one site could be misinterpreted or lost as it passes between the vendors involved in serving an ad. TCF v2.2 matters because it provides a common technical language for encoding and transmitting these signals, which is intended to help parties support compliance with the EU's GDPR and ePrivacy Directive across a complex supply chain.

Who it's relevant to

Publishers and website operators
Publishers relying on programmatic and display advertising use the framework to communicate user choices consistently to the vendors in their supply chain. Under TCF v2.2, publishers should understand that vendors may only rely on consent, not legitimate interest, for advertising and content personalization purposes, which affects how consent flows are designed. Implementation choices remain the publisher's responsibility, and adoption of the framework does not guarantee compliance.
Ad tech vendors
Vendors registered within the framework receive and act on standardized consent signals. The TCF v2.2 policy change limiting advertising and content personalization to consent as the legal basis is particularly relevant to vendors that previously relied on legitimate interest for those purposes, as they may need to reassess their processing and registrations, including in light of the subsequent v2.3 changes to the 'Disclosed Vendors' section.
Consent management platform (CMP) providers
CMPs are the tools that capture user choices and encode them into the framework's format for transmission. Providers must keep their implementations aligned with the technical specifications stewarded by the IAB Tech Lab and with framework policies, including the version-specific changes introduced in v2.2 and later in v2.3. CMPs support compliance but do not replace the legal judgment that publishers and vendors must exercise.
Privacy officers and legal counsel
Data protection professionals and legal counsel evaluating advertising data flows should understand what the framework does and does not achieve. TCF v2.2 provides a shared technical language intended to support GDPR and ePrivacy compliance, but its regulatory standing has been contested and it does not substitute for independent legal analysis of consent standards and processing obligations in the relevant jurisdictions.

Inside TCF

Transparency and Consent Framework (TCF)
An industry standard developed by IAB Europe to help participants in the digital advertising ecosystem obtain, record, and communicate a user's consent and objections regarding the processing of personal data for advertising purposes under the ePrivacy Directive and the GDPR. TCF v2.2 is a specific version of this framework; it standardizes signals but does not itself constitute or guarantee legal compliance.
Consent Management Platform (CMP) role
TCF v2.2 relies on registered CMPs to present information to users, capture their choices, and generate the standardized consent signal. Participation requires CMPs to follow the framework's technical specifications and policies. The framework structures how choices are collected and transmitted but leaves legal responsibility for valid consent with the controllers involved.
TC String
The encoded Transparency and Consent String that captures a user's consent and objection choices per purpose, vendor, and legal basis. It is passed between participants so downstream vendors can read the signal. The TC String records choices but does not by itself demonstrate that those choices met the GDPR standard of freely given, specific, informed, and unambiguous consent.
Purposes and legal bases
TCF v2.2 defines a set of standardized processing purposes and the legal bases (such as consent or legitimate interest) that vendors may declare. The framework distinguishes between purposes users can consent to and those where a vendor asserts legitimate interest, subject to the user's right to object.
Global Vendor List (GVL)
A centrally maintained list of vendors participating in the framework, together with the purposes and legal bases each declares. CMPs reference the GVL when presenting choices, and TCF v2.2 introduced changes intended to improve the information disclosed about vendors.
v2.2 policy and UX changes
TCF v2.2 introduced adjustments aimed at improving transparency and user experience, including changes to how vendor information and the number of vendors are surfaced to users, restrictions on relying on legitimate interest for certain advertising purposes, and requirements around the clarity of information presented. The precise operational details are set out in IAB Europe's specifications and policies, which practitioners should consult directly.

Common questions

Answers to the questions practitioners most commonly ask about TCF.

Does implementing TCF v2.2 mean my cookie consent is automatically compliant?
No. The TCF is an industry framework that standardizes how consent and other legal bases are communicated between publishers, CMPs, and vendors, but adopting it does not by itself guarantee compliance with the ePrivacy rules or the GDPR. A CMP built to TCF v2.2 supports compliance workflows, yet the lawfulness of your setup still depends on factors such as how you present choices, whether consent meets the freely given, specific, informed, and unambiguous standard, and how you handle the personal data processing that follows. Legal judgment, and often review by a data protection professional, remains necessary. The framework itself has also been the subject of regulatory scrutiny in the EU, so treating it as a compliance guarantee would be a mistake.
Is the TCF a legal requirement that all websites must use?
No. The TCF is a voluntary, self-regulatory standard developed by IAB Europe, not a law or a mandatory regulatory scheme. Websites and apps can obtain and manage cookie consent without participating in the TCF at all. It is most relevant to organizations operating within the programmatic advertising ecosystem that want a common language for signaling consent and legal bases to participating vendors. The underlying legal obligations flow from the ePrivacy Directive as implemented nationally and from the GDPR, not from the framework, so you should not assume that being outside the TCF means being non-compliant, nor that being inside it discharges your legal duties.
What is the practical difference between the consent and legitimate interest legal bases within TCF v2.2?
TCF v2.2 allows vendors to declare, for each purpose, whether they rely on consent or on legitimate interest, and it removed certain purposes from being available under legitimate interest compared with earlier versions. In practice this affects what users see and control: consent-based purposes require a clear affirmative action, while legitimate interest purposes are typically presented with an ability to object. Note that the placing of or access to information on a device is generally governed by the ePrivacy rules, which in most EU jurisdictions require prior consent regardless of the GDPR legal basis chosen for the subsequent processing. The appropriateness of relying on legitimate interest for any given purpose is fact-specific and has been contested, so this should be assessed rather than assumed.
How does TCF v2.2 handle the information shown to users about vendors?
TCF v2.2 introduced changes aimed at improving transparency, including standardized descriptions of purposes and features and clearer disclosure of the vendors involved. The framework maintains a Global Vendor List that CMPs draw on to present participating vendors and their declared purposes and legal bases. From an implementation standpoint, this means your CMP configuration should surface the required vendor and purpose information in the user interface. Whether that presentation actually meets the informed element of valid consent in your jurisdiction is a separate assessment, since the level of detail and layering that regulators expect can vary and continues to evolve.
What should I check when choosing or configuring a CMP for TCF v2.2?
Look for whether the CMP is registered and validated against the TCF specifications, how it stores and communicates the Transparency and Consent String, and whether it keeps records that let you demonstrate what a user was shown and chose. Consider how it handles updates to the Global Vendor List, how it manages user withdrawal and re-prompting, and how it integrates with the vendors you actually work with. Because a CMP supports rather than replaces compliance, you should also confirm that its default configuration reflects the consent standards applicable in your target jurisdictions, since the same tool can be set up in more or less compliant ways.
Does TCF v2.2 address consent record-keeping and the ability to demonstrate consent?
The framework provides a standardized mechanism, the Transparency and Consent String, that encodes the choices a user has made and the vendors and purposes involved, which can support record-keeping. However, the string is a technical signal, and organizations subject to the GDPR generally need to be able to demonstrate that valid consent was obtained, which may call for logging additional context such as the interface presented and the timestamp. You should treat the TC String as one component of an accountability approach rather than a complete audit record, and confirm that your retention and logging practices meet the expectations applicable in your jurisdiction.

Common misconceptions

Implementing TCF v2.2 through a registered CMP automatically makes cookie and advertising practices legally compliant.
TCF v2.2 is an industry framework that standardizes how consent and objection signals are collected and communicated. It supports compliance efforts but does not replace legal judgment or guarantee that consent meets the GDPR standard or the ePrivacy consent requirement. Controllers remain responsible for the lawfulness of their processing, and adoption of the framework has itself been the subject of regulatory scrutiny in the EU.
TCF v2.2 governs all cookie use worldwide.
The framework was developed by IAB Europe with the EU legal environment (the ePrivacy Directive and the GDPR) primarily in mind. It does not by itself satisfy obligations under other regimes, such as UK requirements or US state privacy laws like the CCPA and CPRA, which often rely on opt-out rather than opt-in mechanisms and may recognize signals such as Global Privacy Control. Scope should always be assessed per jurisdiction.
A valid TC String is proof that a user gave valid consent.
The TC String records the choices captured by a CMP, but the existence of a signal does not demonstrate that the underlying consent was freely given, specific, informed, and unambiguous, or that essential-versus-non-essential technologies were handled correctly. Whether consent was validly obtained depends on how it was presented and collected, which is a factual and legal question beyond the string itself.

Best practices

Treat TCF v2.2 as a supporting mechanism rather than a compliance guarantee, and keep an independent legal assessment of whether your consent collection meets the GDPR standard and the applicable ePrivacy consent requirement in each relevant EU jurisdiction.
Use a registered CMP that implements the current TCF specifications and policies, and consult IAB Europe's own documentation directly rather than relying on secondhand summaries for version-specific requirements and effective dates.
Confirm that non-essential technologies, including pixels, SDKs, local storage, and fingerprinting, are only activated after valid consent is captured, since these fall within the same rules as cookies even though they are not literally cookies.
Verify that the vendor information, purposes, and legal bases presented to users are accurate and drawn from the Global Vendor List, and review any reliance on legitimate interest against the framework's v2.2 restrictions and your own legal analysis.
Maintain consent records and logs so that captured choices can be evidenced, while recognizing that the TC String alone does not prove that consent was validly obtained.
Assess whether TCF-based signals are sufficient for jurisdictions outside the EU, and implement separate mechanisms where needed for the UK and US state privacy laws, including honoring opt-out signals such as Global Privacy Control where they apply.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide