All Blog Posts

TCF v2.4: Requirements and Deadlines for the IAB Transparency and Consent Framework

Close
Read time
10 mins
Updated
Sep 15, 2026
Share
  • TCF Specifications v2.4 and the updated Global Vendor List (GVL) were published on July 23, 2026.
  • Publishers now have more flexibility to persist a user's privacy choices across multiple devices, such as when they're logged into an account.
  • CMPs must display new standard explanatory text and illustrations for each Feature, sourced from the GVL.
  • Special Feature 2 has been renamed "Identify devices based on information actively requested," with updated Vendor Guidance on Client Hints.
  • A legacy Legitimate Interest workaround for Special-Purpose-only vendors has been removed from the TC string.
  • Web environments must comply by October 23, 2026; mobile and CTV environments by February 23, 2027.

On February 2, 2022, the Belgian DPA found the IAB’s Transparency and Consent Framework (TCF) to be non-compliant with several provisions of the GDPR. It required the IAB to present an action plan to implement corrective measures that address the infringements and bring the TCF into compliance with the GDPR.

In response to feedback from the market, as well as evolving case law and guidelines from various national data protection authorities, the IAB implemented the TCF v2.2. The new framework aimed to improve the standardization of information presented to users, and give them more control over how their personal data is processed. The TCF v2.2 includes some measures related to the action plan that the IAB submitted to the Belgian DPA.

The TCF v2.3 had a compliance deadline of February 28, 2026. It was a smaller update in scope, focused on making the Disclosed Vendors segment mandatory in all new or updated consent signals, so vendors could better determine whether they were allowed to process data under Special Purposes. Existing consent signals created before that date remained valid without needing to resurface the CMP to users.

The Framework has since moved to TCF v2.4. IAB Tech Lab published the updated Specifications and a corresponding Global Vendor List (GVL) update on July 23, 2026. CMPs must implement the new disclosures in web environments by October 23, 2026, and in mobile app and CTV environments by February 23, 2027.

The TCF v2.4 update focuses on helping users better understand vendor Features, which don't carry an individual on/off control, unlike Purposes.

Following recommendations from CNIL, the French data protection authority, on cross-device consent, the Policies now give publishers more flexibility to persist a user's privacy choices across multiple devices, such as when a user is logged into an account. CMPs must inform users when their choices are being persisted this way, and publishers now have clearer rules for handling conflicts, such as when a user's in-session choices differ from those tied to their account before logging in.

Standard Explanatory Text for Features

The GVL now includes a standardTexts field, giving CMPs standard wording to display alongside each Feature. The text clarifies that Features are means of processing used only in pursuit of Purposes for which users are given a choice, so they aren't mistaken for a separate, controllable setting.

Mandatory Illustrations for Features

Each Feature must now be accompanied by an illustration in the CMP UI, bringing Features in line with the existing illustration requirement for Purposes.

Special Feature 2 Renamed, Vendor Guidance Updated

Special Feature 2, previously "Actively scan device characteristics for identification," has been renamed "Identify devices based on information actively requested." The Vendor Guidance under Chapter V, Appendix A(D) has also been updated to reflect the active request of Client Hints for fingerprinting purposes.

Removal of the Legitimate Interest Workaround for Special Purposes

TCF v2.4 removes a legacy technical workaround that required CMPs to set the Legitimate Interest bit to 1 for vendors declaring only Special Purposes. Since the Disclosed Vendors segment became mandatory under TCF v2.3, this workaround is no longer needed: vendors can now confirm they were disclosed to the user by reading the Disclosed Vendors segment directly.

How This Is Delivered

The GVL update and its translations were published July 23, 2026, and the new fields are ingested automatically by TCF-registered CMPs. The CMP UI changes to display the new text and illustrations still require an implementation update ahead of the deadlines above.

The Transparency and Consent Framework (TCF) v2.3 was a smaller update compared to v2.2. However, it was still important, introducing key adjustments to strengthen transparency and privacy compliance.

Disclosed Vendors Became a Mandatory Segment in TCF Signals

This enables vendors to better determine if they're allowed to process data under Special Purposes. Starting February 28, 2026, all new or updated consent signals had to include the Disclosed Vendors segment. Existing consent signals created before that date, without the v2.3 format, remained valid until the user updated or renewed their consent preferences. There was no requirement to resurface the CMP to all users.

The Transparency and Consent Framework (TCF) v2.2 was a significant update to the previous version, with policy changes aimed to increase transparency and provide users with more control over their consent choices.

Removal of legitimate interest

TCF v2.2 no longer allowed legitimate interest as a legal basis for data processing operations related to advertising and content personalization. Vendors can now only select explicit consent as an acceptable legal basis for these purposes.

Improved user interface (UI)

The information required in consent management platforms’ (CMP) UI was improved to include user-friendly standard texts, new features of processing, and real use case illustrations to make it easier for users to understand what they’re consenting to and what their options are.

Users were now able to change their minds about sharing their data with vendors, and they had to be able to re-access the CMP UI to change or withdraw consent at any time. The process to withdraw consent had be as easy as the process to give it. The practical implications of this were that the CMP UI must be easily accessible to users and not buried on the website or app where users must hunt to find it.

More vendor transparency

Detailed disclosures about vendors, regarding data categories and retention periods, were standardized under TCF v2.2 and must be provided to users in the secondary layer(s) of CMP UIs.

Enhanced compliance programs

New auditing mechanisms and differentiated enforcement procedures were implemented, including proactive auditing of a larger number of randomly selected CMPs and vendors each month.

Read more about the new IAB TCF v2.2 here. For more information about the technical modifications in IAB TCF v2.2, visit the IAB Tech Lab website.

Cookiebot CMP and the New IAB Framework (TCF v2.4)

CMPs must implement the new policies and specifications of TCF v2.4 in web environments by October 23, 2026, and in mobile app and CTV environments by February 23, 2027. Cookiebot CMP's IAB integration supports the new IAB framework (TCF v2.4).

Cookiebot CMP integration consists of an extra Ad Settings panel in the consent banner of websites registered with the IAB. From there, end users can choose between IAB Purposes and Vendors before submitting their consent.

We recommend using the IAB framework integration as a supplement, not a replacement, for the regular Cookiebot CMP solution. This is because IAB's consent model works by signaling the user's consent to advertising vendors, whereas the Cookiebot CMP consent model can block non-consented vendors.

This is a key difference because, according to the GDPR, it is the publisher (i.e., the website owner) who is liable for all tracking and personal data collection taking place on their domain, including by third parties.

Cookiebot CMP removes the dependency on vendors' good faith and gives real control to the website owner. Using Cookiebot CMP as an integration in the IAB framework (TCF v2.4) is part of how the platform helps support your GDPR compliance.

To help confirm that user consents are being honored by advertising vendors, the Cookiebot CMP patented scanning technology monitors all cookies and similar trackers used by vendors on the website and marks non-consensual ones in the scan report.

Read our technical support article here for more on implementation and technical details for the IAB framework (TCF v2.4) and Cookiebot CMP.

Cookiebot CMP also supports the IAB CCPA Compliance Framework. Read more here.

What Is the IAB Framework and How Does It Meet GDPR Requirements?

IAB Europe (Interactive Advertising Bureau) is a business organization for online advertisers and marketers that develops and governs industry standards and best practices, conducts research, and provides legal support.

In preparation for the enforcement of the General Data Protection Regulation (GDPR) in May 2018, the IAB Tech Lab developed a framework in collaboration with IAB Europe. That framework is called the IAB Europe Transparency & Consent Framework.

The IAB Framework establishes common ground for cooperation between publishers, advertisers, and consent management providers, helping smooth the process of meeting GDPR requirements for transparency and user consent. It works as a standardized means for communicating the state of user consent between first parties such as publishers, third parties such as advertisers, and the consent management system in use on the first party's website.

What Are the GDPR Requirements and What Do They Mean for Advertisers?

The GDPR sets out strict requirements for how the personal data of EU residents can be collected, stored, used, and shared.

In order for consent management to be GDPR-compliant, it must meet specific criteria. All data processing must take place under one of six legal bases: consent, contractual obligation, legal obligation, vital interests, public task, or legitimate interests. When consent is the legal basis used, it must be obtained before data collection and processing begins, and it must be as easy for the user to withdraw consent as it was to give it.

  • Freely given: Users cannot be manipulated into consenting or prevented from declining.
  • Specific: It must be clear what users are consenting to, and they must have granular options for each purpose. Offering only "Accept All" is not compliant.
  • Informed: What data is processed, for what purpose, and who may have access to it, must be presented clearly, with no jargon.
  • Unambiguous: Users must make an active choice through an explicit action, such as clicking a button. Pre-ticked checkboxes are not permitted.

Consent records must also be securely stored and kept up to date. In the event of an audit or a data subject request, you must be able to show what the user consented to, what information they were shown, and when the consent action was taken. The user also retains the right to have their personal data deleted on request, and all given consents must be documented as evidence that consent was given.

The GDPR is wide-ranging in geography, scope, and severity. Geographically, it covers all organizations operating within the EU, as well as organizations outside the EU that process the data of EU residents.

In scope, its definition of personal data is broad. Not just data directly tied to an individual, such as a name or ID number, but also data that can be combined with other data to identify a person. For example, location data paired with professional interests, or data related to someone's physical, physiological, genetic, mental, economic, cultural, or social identity. In practice, this means marketing cookies and other tracking technologies that record, store, or share user behavior and preferences fall under the GDPR.

In severity, fines for noncompliance can reach four percent of global annual turnover or EUR 20 million, whichever is higher.

    What Is the Purpose of the IAB Framework?

    The purpose of the IAB Framework is to create standardized cooperation among online publishers, advertisers, and consent management providers in meeting GDPR requirements for transparency and user consent. Within the Framework, these three groups are called "publishers," "vendors," and "CMPs" (consent management providers).

    Publishers, Vendors, and CMPs Under the IAB Framework

    • Publishers are digital media that publish content online. They generally represent the first party, i.e., the website the user has come to. Publishers are often dependent on displaying third-party advertisements to monetize views, typically through an ad network that directs relevant ads to visitors. In the IAB Framework, these ad networks and advertisers are called "vendors."
    • Vendors are the third-party advertiser partners of publishers. They display third-party content on the publisher's site and set the marketing cookies on the end user's browser used to serve relevant ads.
    • CMPs supply the technology that enables obtaining user consent for data processing on the publisher's website, signaling the end user's consent settings to the vendors operating on that site.

    How Does the IAB Framework Work?

    In practice, the IAB Framework communicates the state of user consent between first parties (publishers), third parties (advertisers), and the consent management provider in use on the first party's website.

    Publishers select their vendors of choice from a list of vendors that have enrolled in the Framework, called the Global Vendor List (GVL). To participate, a vendor agrees to a set of conditions, including:

    • Updating their code so cookies are not set unless they've received a consent signal from a CMP, or unless an applicable legal basis exists.
    • Not processing personal data for a consent-based purpose until they've received a consent signal directly from a CMP.

    The Global Vendor List functions as a registry of vendors that have committed to the Framework's rules. When a publisher enrolls, they select one or more vendors from the GVL to partner with. The user's consent status is stored in a first-party cookie in their browser and shared down the advertisement chain of information. Once a user has made their selection, only those vendors have access to processing that user's data for the relevant disclosed purposes.

    Cookiebot CMP Compliance Support for the GDPR and CCPA Through the IAB

    Cookiebot CMP, as your website's consent management platform, supports compliance with the GDPR, CCPA, and many other U.S. and global privacy regulations and frameworks. With Cookiebot CMP's IAB Framework (TCF v2.4) integration, advertisers and publishers get an additional layer of support for compliant data collection and processing across the board.

    Keep your ad vendors accountable

    The IAB's framework signals consent down the vendor chain, but you're still the one liable for what fires on your site. Cookiebot CMP's scanning technology gives you an independent check on every advertising vendor, so consent choices are backed by enforcement, not just goodwill. Try it free for 14 days.

    USA_Swimming_logo
    Blockchain_logo
    Nissan
    Volvo_Car
    Subaru
    Kawasaki

    Frequently asked questions

    The IAB Transparency and Consent Framework is a standardized means for online advertisers and marketers of communicating the state of user consent between first parties, third parties and the consent management system in use on the first party’s website.

    Try Cookiebot CMP IAB TCF integration for free

    IAB Transparency and Consent Framework works as a system for communicating the state of user consent between first parties (i.e. publishers), third parties (i.e. advertisers), and the consent management platform in use on the first party’s website. Publishers select their vendors of choice from a list of vendors that have enrolled in the Framework. When a publisher enrolls in the IAB Framework, they select one or more vendors from the Global Vendor List. The consent state of the user is stored in a first-party cookie in the user’s browser and shared down the advertisement chain of information in the IAB Framework.

    Try Cookiebot CMP free for 14 days… or forever if you have a small website.

    The IAB Transparency and Consent Framework 2.2 expands the ability for users to give, withhold or revoke consent and to object to their data being processed. Users are able to control whether Vendors are allowed to use their personal data and publishers are able to restrict the purposes for which Vendors process personal data on publisher’s websites.

    Try Cookiebot CMP free for 14 days… or forever if you have a small website.

    Cookiebot CMP integrates with the IAB Transparency and Consent Framework 2.2 through an extra panel in the consent banner of websites registered with the IAB. From Ad Settings, end-users are able to choose between IAB Purposes and Vendors before submitting their consent.

    Learn more about Cookiebot CMP and try free for 14 days