All Blog Posts

IAB Transparency and Consent Framework (TCF v2.4)

Close
Read time
11 mins
Updated
Sep 2, 2026
Share
  • TCF Specifications v2.4 and the updated Global Vendor List (GVL) were published on July 23, 2026.
  • Publishers now have more flexibility to persist a user's privacy choices across multiple devices, such as when they're logged into an account.
  • CMPs must display new standard explanatory text and illustrations for each Feature, sourced from the GVL.
  • Special Feature 2 has been renamed "Identify devices based on information actively requested," with updated Vendor Guidance on Client Hints.
  • A legacy Legitimate Interest workaround for Special-Purpose-only vendors has been removed from the TC string.
  • Web environments must comply by October 23, 2026; mobile and CTV environments by February 23, 2027.

On February 2, 2022, the Belgian DPA found the IAB’s Transparency and Consent Framework (TCF) to be noncompliant with several provisions of the GDPR. It required the IAB to present an action plan to implement corrective measures that address the infringements and bring the TCF into compliance with the GDPR.

In response to feedback from the market, as well as evolving case law and guidelines from various national data protection authorities, the IAB implemented the TCF v2.2. That framework aimed to improve the standardization of information presented to users, and give them more control over how their personal data is processed.

The TCF v2.3 had a compliance deadline of February 28, 2026. It was smaller update in scope, but continued to evolve the Framework to strengthen transparency and privacy compliance.

The Framework has since moved on to TCF v2.4. IAB Tech Lab published the updated Specifications and a corresponding Global Vendor List (GVL) update on July 23, 2026. CMPs must implement the new disclosures in web environments by October 23, 2026, and in mobile app and CTV environments by February 23, 2027.

The TCF v2.4 update focuses on helping users better understand vendor Features, which don't carry an individual on/off control, unlike Purposes.

Multi-Device Consent Handling

Following recommendations from CNIL, the French data protection authority, on cross-device consent, the Policies now give publishers more flexibility to persist a user's privacy choices across multiple devices, such as when a user is logged into an account. CMPs must inform users when their choices are being persisted this way, and publishers now have clearer rules for handling conflicts, such as when a user's in-session choices differ from those tied to their account before logging in.

Standard Explanatory Text for Features

The GVL now includes a standardTexts field, giving CMPs standard wording to display alongside each Feature. The text clarifies that Features are means of processing used only in pursuit of Purposes for which users are given a choice, so they aren't mistaken for a separate, controllable setting.

Mandatory Illustrations for Features

Each Feature must now be accompanied by an illustration in the CMP UI, bringing Features in line with the existing illustration requirement for Purposes.

Special Feature 2 Renamed, Vendor Guidance Updated

Special Feature 2, previously "Actively scan device characteristics for identification," has been renamed "Identify devices based on information actively requested." The Vendor Guidance under Chapter V, Appendix A(D) has also been updated to reflect the active request of Client Hints for fingerprinting purposes.

Removal of the Legitimate Interest Workaround for Special Purposes

TCF v2.4 removes a legacy technical workaround that required CMPs to set the Legitimate Interest bit to 1 for vendors declaring only Special Purposes. Since the Disclosed Vendors segment became mandatory under TCF v2.3, this workaround is no longer needed: vendors can now confirm they were disclosed to the user by reading the Disclosed Vendors segment directly, and the Vendor Legitimate Interest portion of the TC string only includes vendors that actually have a Legitimate Interest disclosure.

How This Is Delivered

The GVL update and its translations were published July 23, 2026, and the new fields are ingested automatically by TCF-registered CMPs. The CMP UI changes to display the new text and illustrations still require an implementation update ahead of the deadlines above.

The Transparency and Consent Framework (TCF) v2.3 was a smaller update compared to v2.2. However, it was still important, introducing key adjustments to strengthen transparency and privacy compliance.

Disclosed Vendors Became a Mandatory Segment in TCF Signals

This enables vendors to better determine if they’re allowed to process data under Special Purposes. Starting February 28, 2026, all new or updated consent signals had to include the Disclosed Vendors segment. Special Purposes can be processed under Legitimate Interest only, and with no right to object, but vendors must be explicitly disclosed through the CMP.

This had been handled through less optimal technical solutions, but with the v2.3 update, clarity on vendor disclosures improved.

Existing consent signals created before February 28, 2026, without the TCF v2.3 format, remained valid until the user updated or renewed their consent preferences. There was no requirement to resurface the CMP to all users.

The Transparency and Consent Framework (TCF) v2.2 was a significant update to the previous version, with policy changes aimed to increase transparency and provide users with more control over their consent choices.

Removal of Legitimate Interest

With the release of the TCF v2.2, legitimate interest is no longer allowed as a legal basis for data processing operations related to advertising and content personalization. Vendors can now only select explicit consent as an acceptable legal basis for these purposes.

Improved User Interface (UI)

The information required in consent management platforms’ (CMP) UI was improved to include user-friendly standard texts, new features of processing, and real use case illustrations to make it easier for users to understand what they’re consenting to and what their options are.

Users are better enabled to change their minds about sharing their data with vendors, and to re-access the CMP UI to change or withdraw consent at any time. The process to withdraw consent must be as easy as the process to give it. The practical implications of this are that the CMP UI must be easily accessible to users and not buried on the website where users must hunt to find it.

More Vendor Transparency

Detailed disclosures about vendors regarding data categories and retention periods were standardized under TCF v2.2 and must be provided to users in the secondary layer of the CMP.

Enhanced Compliance Programs

New auditing mechanisms and differentiated enforcement procedures were implemented, including proactive auditing of a larger number of randomly selected CMPs and vendors each month.

In doubt about whether your website is GDPR-compliant? Test it with the free Cookiebot CMP compliance test.

Cookiebot CMP and the New IAB Framework (TCF v2.4)

CMPs must implement the new policies and specifications of TCF v2.4 in web environments by October 23, 2026, and in mobile app and CTV environments by February 23, 2027. This includes displaying the new standard explanatory text and illustrations for each Feature, and reflecting the renamed Special Feature 2, in the CMP UI. Cookiebot CMP's IAB integration supports the new IAB framework (TCF v2.4).

Cookiebot CMP integration with the IAB Transparency and Consent Framework v2.4 continues to be an optional supplement to the core consent framework in the Cookiebot CMP solution.

Cookiebot CMP integration consists of an extra panel in the consent banner of websites registered with the IAB. The panel is called "Ad Settings," and from there, end users can choose between IAB Purposes and Vendors before submitting their consent.

We recommend using the IAB framework integration as a supplement and not a replacement for the regular Cookiebot CMP solution. This is because IAB's consent model works through signaling the user's consent to advertising vendors, whereas the Cookiebot CMP consent model works through blocking non-consented vendors.

This is a key difference because, according to the GDPR, it is the publisher (i.e. website owner) who is liable for all tracking and personal data collection taking place on their domain, including by third parties.

Cookiebot CMP eliminates the dependency on the good faith of the vendors and gives true control to the website owner. By using Cookiebot CMP as an integration in the IAB framework (TCF v2.4), supporting your ongoing GDPR compliance.

To confirm that user consents are being honored by advertising vendors, the Cookiebot CMP patented scanning technology monitors all cookies and similar trackers used by vendors on the website and marks them as non-consensual in the scan report.

Cookiebot CMP also supports the IAB CCPA Compliance Framework.

Cookiebot CMP's Patented Scanning Technology Supports Ongoing Privacy Compliance

Cookiebot CMP is one of the few consent management platforms on the market that supports full privacy compliance with privacy regulations around the world.

Cookiebot CMP's unmatched scanning technology finds all cookies and trackers in use on your website, then takes automatic control to block them from firing until users have given their consent, in line with the requirements of the EU's General Data Protection Regulation and ePrivacy Directive.

Cookiebot CMP performs monthly deep scans of your domain to make sure that you always know what tracking technologies are loading on your website as your operations change. Your scan report can be published as a cookie declaration on your website, e.g., as an integrated part of your website’s privacy or cookie policy.

Consent must be renewed regularly. Every 12 months is fairly standard, however, some national data protection guidelines recommend more frequent renewal, like every six months. Check your local data protection guidelines, and if you need to comply with regulations in multiple jurisdictions, choose the shortest renewal period as a best practice.

Learn more about website tracking and how to make it compliant with requirements of global privacy regulations.

What Is the IAB Framework and How Does It Meet GDPR Requirements?

The Interactive Advertising Bureau Europe (IAB Europe) is a business organization for online advertisers and marketers, that develops and governs industry standards and best practices, conducts research, and provides legal support.

In preparation for the enforcement of the EU law on data protection and privacy, the General Data Protection Regulation (GDPR) in May 2018, the IAB Tech Lab developed a framework in collaboration with IAB Europe. That is the IAB Europe Transparency & Consent Framework (TCF).

The TCF establishes a common ground for cooperation among publishers, advertisers, and consent management providers that can help smooth the process of achieving and maintaining GDPR compliance.

The TCF works as a standardized means for communicating the state of user consent between first parties like publishers, third parties like advertisers, and the consent management solution in use on the first party’s website.

What Are the GDPR Requirements and What Do They Mean for Advertisers?

The GDPR sets out strict requirements for how the personal data of European residents can be collected, stored, used, and shared.

In order for your consent management to be GDPR-compliant, it must meet specific criteria. All data processing must take place under one of six legal bases: consent, contractual obligation, legal obligation, vital interests, public task, or legitimate interests. When consent is used, it must be obtained before or when data collection and processing begins, and it must be as easy to withdraw consent as it was to give it.

GDPR Consent Requirements

GDPR Consent Requirements
Freely given

Users cannot be manipulated into consenting or prevented from declining.

Specific

It must be clear what users are consenting to, and they must have granular options for all purposes. Only offering "Accept All" is not compliant.

Informed

What data is processed and for what purpose? Who may have access to it? This information must be presented clearly, with no jargon.

Unambiguous

Users must make an active choice with an explicit action to provide consent, e.g., clicking a button. No pre-ticked checkboxes.

Consent information must also be securely stored and kept updated over time. In the case of an audit or data subject request, you must be able to provide details about what the user consented to, what information they were presented, and when the consent action was taken.

What Is the Purpose of the IAB Framework?

The purpose of the IAB Framework is to create a standardized cooperation between online publishers, advertisers, and the tech companies supplying consent management, when it comes to meeting GDPR requirements for transparency and user consent.

Within the Framework, these three groups are called “publishers”, “vendors”, and “CMP’s” (consent management providers).

Publishers, Vendors, and CMPs Under the IAB TCF

IAB TCF Categories

IAB TCF Categories
Publishers

Under the IAB Framework this includes digital media that publishes content online. Publishers generally represent the first party, i.e., the website that the user visits. In digital advertising, publishers are often are dependent on displaying third-party advertisements on their websites as a form of monetization. This usually involves an ad network that directs relevant ads to website visitors.

Vendors

Under the TCF include ad networks and advertisers, the third-parties that publishers partner with to run ads on their sites. The vendors display third-party content on the publishers’ websites. They set marketing cookies on the end user’s browser to enable displaying relevant ads.

Consent management solution providers

They supply the platform that enables publishers to obtain valid user consent to collect and process personal data on their sites. The consent management platform then signals end users’ consent choices to the vendors operating on the current website to control what data is collected and processed for advertising functions like personalization.

How Does the IAB TCF Work?

The IAB Framework enables communicating the state of user consent among the publishing and advertising ecosystem of publishers' websites, vendors, and consent management platforms.

In the TCF, publishers select their vendors of choice from a list of those that have enrolled in the TCF. This list is called the Global Vendor List or GVL.

In order to participate in the TCF, the vendor has agreed to a set of conditions:

  • Updating their code so that cookies are not set unless they have received a consent signal from a CMP, or unless they have an applicable legal basis to set a cookie.
  • Not processing personal data for a purpose that relies on consent until they have received a consent signal directly from a CMP.

The Global Vendor List is a sort of registry of allowlisted vendors that have committed to the TCF's rules. When a publisher enrols, they select one or more vendors from the Global Vendor List that they want to partner with.

A users' consent status is stored via a first-party cookie in their browser and shared down the TCF's advertisement information chain. Once the user has made their consent choice, these vendors — and no others — have access to processing the user’s data for relevant disclosed purposes.

Kantar
Revolut
TUI
Nissan
Lindt
Swatch

Keep your ad vendors accountable

IAB's framework signals consent down the vendor chain, but you're still the one liable for what fires on your site. Cookiebot CMP's scanning technology gives you an independent check on every advertising vendor, so consent choices are backed by enforcement, not just goodwill. Try it free for 14 days.

Frequently asked questions

The Interactive Advertising Bureau Europe's Transparency and Consent Framework (TCF) is a standardized means for online advertisers and marketers to communicate the state of user consent among first parties like publishers, third parties like vendors, and the consent management platform in use on the first party’s website. The latest version of the TCF is 2.3.

Try Cookiebot CMP IAB TCF integration for free

IAB Transparency and Consent Framework (TCF) works as a system for communicating the state of user consent between first parties (publishers), third parties (advertisers), and the consent management platform in use on the first party’s website. Publishers select their vendors of choice from a list of vendors that have enrolled in the TCF. When a publisher enrolls, they select one or more vendors from the Global Vendor List. The consent state of the user is stored in a first-party cookie in the user’s browser and shared down the advertisement chain of information in the TCF.

Try Cookiebot CMP free for 14 days… or forever if you have a small website.

The TCF v2.4 update introduces new disclosures to help users better understand vendor Features:

  • Standard explanatory text for each Feature, sourced from the GVL, must now appear in the CMP UI
  • Illustrations are now mandatory for every Feature, matching the existing requirement for Purposes
  • Special Feature 2 has been renamed "Identify devices based on information actively requested," with updated Vendor Guidance on Client Hints for fingerprinting

Web environments must comply by October 23, 2026; mobile app and CTV environments by February 23, 2027.

Cookiebot CMP integrates with the IAB Transparency and Consent Framework v2.4 through an extra panel in the consent banner of websites registered with the IAB. From Ad Settings, end users are able to choose between IAB Purposes and Vendors before submitting their consent.

The TCF v2.4 requirements apply to CMPs, not directly to website owners. Cookiebot CMP handles the implementation on your behalf: web environments must comply by October 23, 2026, and mobile app and CTV environments by February 23, 2027. No action is required on your end beyond keeping your Cookiebot CMP integration up to date.