Skip to main content
Category: TCF and Vendors

TCF v2.3

Also known as: TCF, IAB TCF v2.3, Transparency and Consent Framework v2.3, IAB Europe TCF 2.3
Simply put

TCF v2.3 is a version of the Transparency and Consent Framework, an industry standard managed by IAB Europe that helps websites and advertising vendors communicate users' cookie and data choices to one another. This version was released in 2025 and focuses on giving clearer information about which vendors have been disclosed to users. It is designed to support, though it does not by itself guarantee, compliance with EU privacy rules in digital advertising.

Formal definition

TCF v2.3 is an update to IAB Europe's Transparency and Consent Framework, a standardized technical and policy specification intended to help publishers, consent management platforms (CMPs), and advertising vendors capture and signal user consent and legitimate interest states in a machine-readable form within the digital advertising ecosystem. According to the evidence, this version repurposes the 'Disclosed Vendors' section into a mandatory element in order to resolve ambiguity around legitimate interest and to clarify for certain vendors whether they have been disclosed to users. The framework is positioned as supporting GDPR and ePrivacy Directive compliance in EU-focused advertising contexts; however, adoption of the standard does not replace independent legal assessment, and its compliance status may be interpreted differently by data protection authorities and across jurisdictions. Contested regulatory questions surrounding the TCF, including debates over its legitimate interest and consent-signaling model, are not resolved by this definition and fall outside its scope based on the available evidence.

Why it matters

The Transparency and Consent Framework is one of the most widely used industry standards for signaling user consent and legitimate interest states across the digital advertising supply chain in the EU. Because so many publishers, consent management platforms, and advertising vendors rely on it to communicate choices to one another in a machine-readable way, changes to the standard, such as those introduced in TCF v2.3, can ripple across large numbers of websites and vendor integrations. For privacy officers and compliance teams, understanding what a given version changes is important because the framework structures how consent and legitimate interest are represented, which in turn affects how EU privacy rules under the GDPR and the ePrivacy Directive are operationalized in practice.

Who it's relevant to

Publishers and website operators in the EU
Organizations that run EU-focused advertising on their websites and rely on the TCF to signal user choices need to understand what TCF v2.3 changes, particularly the mandatory 'Disclosed Vendors' section, and to review whether their vendor lists and disclosures are accurate. Adopting the standard supports, but does not by itself guarantee, compliance with the GDPR and ePrivacy Directive, so independent legal assessment remains necessary.
Consent management platform (CMP) providers and integrators
CMPs implement the technical specification of the TCF, so a version change such as v2.3 generally requires updates to how consent and legitimate interest states are captured and signaled. Teams responsible for these tools should review the TCF v2.3 documentation and update their systems and processes accordingly, while recognizing that a compliant CMP configuration supports but does not replace legal judgment.
Advertising vendors
Vendors participating in the framework may be affected by changes to how they are disclosed to users. Per the evidence, TCF v2.3 aims to provide greater clarity for certain vendors on whether they have been disclosed to users, so vendors should confirm how the repurposed 'Disclosed Vendors' section applies to their status within the ecosystem.
Privacy officers and legal counsel
Compliance professionals overseeing EU digital advertising need to track how framework changes interact with obligations under the GDPR and ePrivacy Directive. Because contested regulatory questions surrounding the TCF's legitimate interest and consent-signaling model are not resolved by this version, legal teams should treat adoption as one input into a broader compliance assessment rather than a definitive answer, and should note that data protection authorities may interpret its status differently across jurisdictions.

Inside TCF

Transparency and Consent Framework (TCF)
An industry standard developed by IAB Europe that provides a standardized technical framework for capturing, storing, and communicating users' consent and objection choices across the digital advertising supply chain. TCF v2.3 is an iteration of this framework. It supports compliance efforts under EU law but does not itself guarantee compliance, which remains a matter of legal judgment based on how the framework is implemented.
Consent Management Platform (CMP) role
Within the TCF, a registered CMP collects user choices through a consent interface and encodes them into a standardized signal. The CMP acts as the interface between the user and the vendors relying on the framework, but its registration or use does not by itself ensure that the underlying consent meets the GDPR standards of being freely given, specific, informed, and unambiguous.
TC String (Transparency and Consent String)
A standardized encoded string that records the user's consent and legitimate-interest objection choices in a machine-readable format. It is intended to be passed along the advertising supply chain so that vendors can determine on what basis they may process data. Its presence documents a choice but does not substitute for lawful collection of that choice.
Global Vendor List (GVL) and purposes
A list of registered vendors and a defined set of processing purposes and features against which users express their choices. Purposes distinguish, for example, between different data-processing activities, and users may consent or object per purpose or vendor depending on the interface configuration.
Legal bases signalling (consent and legitimate interest)
The framework accommodates both consent and legitimate interest as legal bases under the GDPR for downstream processing, and separately reflects the ePrivacy requirement for consent to store or access information on a device. Because the ePrivacy Directive governs the placing of and access to information on a user's device while the GDPR governs any subsequent processing of personal data, both regimes may be engaged, and a signal captured for one does not automatically satisfy the other.
Scope and jurisdiction
The TCF is designed principally around EU (and, by extension, UK) legal expectations that generally require prior opt-in consent for non-essential cookies and similar technologies. It is not tailored to US state privacy frameworks such as the CCPA and CPRA, which often rely on opt-out mechanisms, and the framework's applicability varies by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about TCF.

Does implementing TCF v2.3 make our cookie consent automatically compliant with the GDPR and ePrivacy rules?
No. TCF v2.3 is a technical and governance framework maintained by IAB Europe that standardises how consent and other transparency signals are captured and communicated between publishers, CMPs, and vendors. It can support compliance efforts, but adopting it does not by itself guarantee that your consent meets the GDPR standard of being freely given, specific, informed, and unambiguous, nor that your handling of device storage satisfies ePrivacy obligations. The framework itself has been the subject of regulatory scrutiny in the EU, and legal judgment remains necessary. Whether any given deployment is lawful depends on facts beyond the framework's specification.
Is TCF v2.3 a legal standard that applies everywhere, or something we're required to use?
TCF is an industry framework, not a law, and it is not mandated by any regulator. It was designed primarily around EU and UK requirements and the digital advertising ecosystem, so it does not map cleanly onto US state privacy regimes such as the CCPA and CPRA, which generally rely on opt-out mechanisms rather than the opt-in model common in the EU. Using TCF is a commercial and operational choice, typically driven by the need to interoperate with advertising vendors, rather than a legal obligation. Its suitability depends on your jurisdiction, your vendor relationships, and your specific processing.
How does TCF v2.3 interact with our consent management platform (CMP)?
In a TCF deployment, the CMP is the component that presents the consent interface, captures user choices, and encodes them into the standardised TC String that is shared with participating vendors. To operate within the framework, a CMP generally needs to be registered and to follow the framework's technical and policy requirements. The CMP handles the mechanics of signalling, but you remain responsible for how the interface is designed, what information is presented, and whether the resulting consent is valid. The CMP supports these tasks rather than removing your accountability for them.
What is the TC String and where is it used in practice?
The TC String is the encoded representation of a user's transparency and consent signals under the framework, capturing which purposes and vendors a user has consented to or objected to. It is passed to vendors so they can determine whether they have a basis to process data for a given purpose. Practically, it is generated by the CMP and made available to downstream partners in the advertising supply chain. Note that a TC String records the signal but does not itself prove that the underlying consent was collected in a valid way; separate record-keeping and interface evidence generally remain important.
Do we still need to keep our own consent records if we use TCF v2.3?
Generally yes. While the framework standardises how consent signals are represented and transmitted, organisations subject to the GDPR are typically expected to be able to demonstrate that valid consent was obtained. Relying solely on a transmitted signal may not satisfy accountability expectations, so many organisations maintain their own consent logs alongside the framework's mechanisms. The precise record-keeping approach depends on your role, your CMP configuration, and guidance applicable in your jurisdiction, so this should be assessed with your compliance function.
How does TCF v2.3 handle technologies other than cookies, such as pixels, SDKs, or fingerprinting?
The framework's purposes and signals are technology-agnostic in the sense that they concern the processing activities vendors carry out, not only classic cookies. Similar tracking technologies such as pixels, mobile SDKs, local storage, and device fingerprinting generally fall within the same EU consent rules as cookies because they involve storing or accessing information on a device or processing personal data. However, whether and how each vendor and technology is correctly reflected in your TCF setup depends on your specific vendor configuration and requires review; the framework does not resolve this automatically.

Common misconceptions

Implementing a TCF-registered CMP automatically makes cookie and tracking practices legally compliant.
The TCF and its CMPs are technical and organizational tools that support compliance by standardizing how choices are captured and communicated. They do not replace legal judgment, and compliance depends on how the framework is configured and whether the consent obtained actually meets applicable standards. Tools support compliance but do not guarantee it.
A TC String recording consent under the framework satisfies all legal requirements for cookies and data processing at once.
The ePrivacy Directive governs placing and accessing information on a device, while the GDPR governs the processing of any resulting personal data. A signal generated to reflect a choice does not by itself demonstrate that consent was freely given, specific, informed, and unambiguous, nor that both regimes' distinct requirements have been met.
The TCF applies uniformly across all jurisdictions, including the US.
The framework is designed principally around EU and UK expectations, which generally rely on prior opt-in consent for non-essential technologies. US state laws such as the CCPA and CPRA often follow an opt-out model, so the framework's relevance and configuration differ by geography, and it should not be treated as a universal solution.

Best practices

Treat a TCF-registered CMP as a supporting tool rather than a compliance guarantee, and validate its configuration against the applicable legal requirements with qualified legal input.
Configure consent interfaces so that choices are captured through a clear affirmative action, avoiding pre-ticked boxes, reliance on continued browsing, or cookie walls, which are widely considered non-compliant in most EU jurisdictions.
Address the ePrivacy and GDPR obligations separately, ensuring that consent to store or access information on a device and any legal basis for subsequent processing are each properly established rather than assumed from a single signal.
Confirm that non-essential cookies and equivalent technologies such as pixels, SDKs, local storage, and fingerprinting are not deployed before the relevant consent is captured, since these fall within the same rules even though they are not literally cookies.
Retain records of the consent choices captured through the framework to support consent-logging and record-keeping expectations, keeping these logs available for accountability purposes.
Do not rely on the TCF as a cross-jurisdictional solution; assess separately how US state frameworks such as the CCPA and CPRA and other regimes treat cookie choices, since they often rely on opt-out rather than opt-in.