Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: TCF and Vendors

Transparency and Consent Framework

Also known as: TCF, IAB TCF, IAB Europe Transparency & Consent Framework, GDPR Transparency and Consent Framework
Simply put

The Transparency and Consent Framework (TCF) is an industry standard developed by IAB Europe that provides a common way for websites, advertisers, and technology providers to collect and share users' cookie and data-processing preferences. It aims to help these parties present consent choices to users and communicate whether users have granted or withheld consent, or objected to processing, in a standardized format. Adopting the framework supports compliance efforts but does not by itself guarantee that any organization meets its legal obligations.

Formal definition

The TCF is a set of technical specifications and policies, stewarded by IAB Europe with technical specifications maintained by the IAB Tech Lab, designed to standardize how consent and objection signals are captured and transmitted across the digital advertising supply chain in the context of the GDPR and the ePrivacy Directive. It defines mechanisms by which publishers, advertisers, and technology vendors register participation, present users with the ability to grant or withhold consent and exercise the right to object, and encode those preferences (for example via a Transparency and Consent String read by consent management platforms and vendors). The framework has been issued in successive versions (such as 2.2 and 2.3) that revise its policies and technical requirements. Its scope covers standardization of consent-signaling and vendor participation; it does not itself constitute or replace a legal basis, and its adequacy under EU law has been the subject of regulatory scrutiny, so organizations should not treat participation as a definitive assurance of compliance. Requirements and enforcement positions vary by jurisdiction and continue to evolve.

Why it matters

The Transparency and Consent Framework matters because digital advertising typically involves a complex chain of publishers, advertisers, and technology vendors, each of which may place cookies or similar technologies and process personal data. Without a common language for capturing and communicating user preferences, it would be difficult for these parties to know whether a given user has granted consent, withheld it, or exercised a right to object. The TCF attempts to solve this coordination problem by standardizing how consent and objection signals are encoded and transmitted across the supply chain, which is why many consent management platforms and vendors have adopted it.

At the same time, participation in the TCF should not be mistaken for a guarantee of legal compliance. The framework's adequacy under EU law has been the subject of regulatory scrutiny, and it has been issued in successive versions (such as 2.2 and 2.3) that revise its policies and technical requirements in response to that evolving landscape. The framework standardizes consent-signaling and vendor participation, but it does not itself constitute or replace a legal basis for processing under the GDPR, nor does it satisfy the separate requirements of the ePrivacy Directive governing the placing of and access to information on a user's device.

For organizations operating in the EU and other jurisdictions, this distinction is practically important. Enforcement positions and data protection authority guidance continue to evolve, and requirements differ across the EU, the UK, and elsewhere. Adopting the TCF may support an organization's compliance efforts by structuring how consent is presented and recorded, but legal judgment about whether a specific implementation meets applicable obligations remains necessary and cannot be delegated to the framework itself.

Who it's relevant to

Publishers and website operators
Publishers that monetize through programmatic or partner advertising may use the TCF to standardize how they collect and communicate user consent and objection signals to downstream vendors. They should treat participation as a mechanism that supports, but does not by itself establish, compliance with the GDPR and ePrivacy Directive, and should confirm that their consent interface and the version of the framework they use align with applicable regulatory expectations.
Advertisers and adtech vendors
Advertisers and technology providers in the digital advertising supply chain register as participants and rely on the standardized consent string to determine whether they may process a given user's data. They need to understand that reading a TCF signal does not relieve them of independent responsibility for having a valid legal basis, and that the framework's adequacy under EU law has been subject to regulatory scrutiny.
Consent management platform providers
CMP vendors implement the TCF's technical specifications to present consent choices and encode preferences. They must track successive framework versions and their revised policies and technical requirements, while making clear to their customers that the tool supports compliance efforts rather than guaranteeing them.
Privacy officers and legal counsel
Data protection professionals and legal advisers evaluating an organization's use of the TCF should assess it as one component of a broader compliance program. Because enforcement positions and guidance continue to evolve and vary by jurisdiction, they should apply their own legal judgment rather than treating framework participation as definitive assurance of lawful processing under EU or other applicable law.

Inside TCF

Global Vendor List (GVL)
A centrally maintained register of participating vendors (such as advertising and analytics providers) that declare the purposes for which they process data and the legal bases they rely on. CMPs reference this list to present vendor and purpose information to users.
Standardized purposes and features
A defined set of processing purposes (for example, storing information on a device, personalized advertising, audience measurement) and features that vendors map their activities to, intended to create consistency across participating sites and services.
Transparency and Consent String (TC String)
A machine-readable, encoded record capturing a user's consent and objection choices per purpose and vendor. It is designed to be passed through the advertising supply chain so downstream parties can read the signaled choices.
Consent Management Platform (CMP) integration
Registered CMPs implement the framework's technical specifications to collect user choices, generate the TC String, and make it available to vendors. The framework relies on CMPs to surface information and capture affirmative actions.
Governance and policies
A set of policies and technical specifications, administered by the industry body that maintains the framework, that participating CMPs and vendors agree to follow. These govern how the framework is implemented rather than constituting law themselves.

Common questions

Answers to the questions practitioners most commonly ask about TCF.

Does implementing the IAB Transparency and Consent Framework (TCF) make my cookie consent automatically compliant with the GDPR and ePrivacy rules?
No. The TCF is a technical and contractual standard designed to help support compliance by standardizing how consent and other legal bases are captured, signaled, and passed between publishers, consent management platforms, and vendors. It does not, on its own, guarantee that consent is valid or that your overall practices are lawful. Whether consent meets the GDPR standard of being freely given, specific, informed, and unambiguous, and whether the placing of cookies satisfies the ePrivacy rules, depends on how the framework is implemented in practice, the specifics of your banner design, and the legal judgment applied to your particular processing. Tools support compliance but do not replace it, and enforcement positions on the framework have themselves been contested.
Is the TCF a legal requirement I must adopt to run cookie consent in the EU?
No. The TCF is a voluntary industry framework, not a law or a mandatory standard. You are not obliged to adopt it to obtain valid consent or to comply with the ePrivacy and GDPR obligations that apply in EU jurisdictions. Some organizations use it to interoperate within the digital advertising ecosystem, while others rely on consent management platforms and approaches that do not use the framework at all. Adopting it is an implementation choice, and the underlying legal obligations apply regardless of whether you use it.
How does the TCF relate to the consent management platform (CMP) we already use?
Within the framework, a CMP typically acts as the component that presents choices to the user, captures their consent or objection signals, and encodes those signals in a standardized form that can be shared with participating vendors. A CMP may operate in a TCF-registered capacity or entirely outside the framework. If you rely on the TCF, you would generally need a CMP that is registered and configured to work with it, but using a CMP does not by itself mean you are using the framework. Confirm with your provider which mode you are operating in and what that entails for your record-keeping.
What should we consider before deciding to adopt the TCF for our site?
Relevant considerations generally include whether your advertising and analytics partners expect or rely on the framework, how it fits with the categories of cookies and similar technologies you deploy, how it handles the legal bases you intend to rely on, and how it interacts with your obligations to log and evidence consent. Because interpretations and regulatory positions on the framework have evolved and been contested in some EU jurisdictions, you should also seek current legal input rather than assuming adoption resolves compliance questions. The decision depends on facts specific to your organization that a general definition cannot resolve.
Does the TCF cover technologies other than cookies, such as pixels, local storage, or device fingerprinting?
The framework is primarily oriented toward signaling consent and other legal bases within the digital advertising ecosystem, which can involve technologies beyond cookies, including pixels, SDKs, local storage, and identifiers used for purposes such as fingerprinting. Under EU law these similar technologies generally fall within the same ePrivacy and GDPR rules as cookies when they involve storing or accessing information on a device or processing personal data. However, whether and how any specific technology is represented within the framework depends on implementation details, so you should verify coverage against your actual technology stack rather than assuming it is captured.
How does the TCF interact with signals like the Global Privacy Control or with US opt-out obligations?
The TCF originated in the context of EU-style consent, which in most EU jurisdictions is built on prior opt-in, whereas several US state privacy laws, such as those in California, often rely on an opt-out model and may recognize signals such as the Global Privacy Control. These are distinct mechanisms addressing different legal standards, and support for US frameworks may be handled through separate specifications or configurations rather than the core EU-focused framework. If you operate across the EU, the UK, and US states, you generally cannot assume a single signal or configuration satisfies all regimes; you should map each obligation to its applicable jurisdiction and confirm how your tools handle them.

Common misconceptions

Using an IAB TCF-registered CMP automatically makes a website compliant with EU cookie and data protection law.
The framework is an industry-developed standard that supports consistent signaling of consent choices; it does not by itself guarantee compliance. Compliance depends on how the framework is implemented and on independent legal judgment, and regulators and courts in some EU contexts have raised concerns about aspects of the framework. Tools support but do not replace legal assessment.
A TC String is a legally sufficient record of valid consent under the GDPR.
A TC String is a technical, machine-readable representation of signaled choices. Whether the underlying consent meets the GDPR standard of freely given, specific, informed, and unambiguous consent given by a clear affirmative action depends on the actual user experience and design, not on the existence of the string alone.
The framework applies the same way in every jurisdiction.
The framework originated primarily to address EU-style opt-in consent, but cookie and privacy obligations differ across the EU, the UK, and individual US states such as California under the CCPA and CPRA, which often rely on opt-out mechanisms. Signaling choices through the framework does not resolve differing legal requirements across these regimes.

Best practices

Treat a registered CMP and the framework as supporting infrastructure, and pair it with an independent legal assessment of your consent flows against the applicable regime (EU, UK, or relevant US state laws).
Ensure the consent experience presented through your CMP reflects a clear affirmative action, avoiding pre-ticked boxes, implied consent from continued browsing, and cookie walls where these are widely considered non-compliant in EU jurisdictions.
Confirm that strictly necessary or essential cookies are handled separately from purposes requiring consent, and that similar technologies such as pixels, local storage, SDKs, and fingerprinting are covered where they fall within the same rules.
Maintain your own consent logging and record-keeping alongside the TC String, so you can demonstrate the choices captured rather than relying on the encoded string as your sole evidence.
Review the framework's purposes, vendor list, and TC String configuration periodically, since participating vendors and processing purposes change and regulatory positions on the framework may evolve.
Map framework signals to jurisdiction-specific mechanisms where needed, and consider how opt-out signals such as Global Privacy Control are honored for users covered by US state privacy laws.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide