Skip to main content
Privacy Compliance

IAB TCF vs a Regular Cookie Banner: Which Do You Need?

By , MarTech & Analytics Engineer

Published Updated

Quick answer: The IAB Europe Transparency & Consent Framework (TCF) is a voluntary standard that lets a consent banner pass one encoded record of the visitor’s choices, the TC String, to the ad-tech vendors behind an ad request. You need it if you sell ad space programmatically. Google also requires a TCF-integrated, Google-certified CMP if you serve personalized ads through AdSense, Ad Manager or AdMob. If you only buy ads and run your own tags, such as Google Ads, GA4, Meta or LinkedIn, a regular consent banner with Google Consent Mode is enough.

What is the IAB TCF?

The Transparency & Consent Framework (TCF) is a set of policies from IAB Europe and technical specifications from IAB Tech Lab for collecting consent and passing it through programmatic advertising. IAB Europe calls it “a cross-industry voluntary standard”. The terms you’ll meet:

  • CMP (consent management platform): the software that shows the banner and stores the visitor’s choice. A TCF CMP has to be registered with IAB Europe.
  • Global Vendor List (GVL): the public list of registered vendors and the purposes each one declares. Version 178 (September 24, 2026) has 1,029 active vendors, including Google Advertising Products (ID 755), Microsoft Advertising (1126), LinkedIn (804) and Criteo (91).
  • TC String: the encoded record of the visitor’s choices per purpose and per vendor, which the CMP stores and vendors read.
  • __tcfapi: the JavaScript function a TCF CMP exposes on the page so that scripts can read the current consent data.

You can watch it on any site that runs TCF. Paste this into the console:

__tcfapi('addEventListener', 2, function (tcData, success) {
	if (!success) return
	console.log(tcData.eventStatus, tcData.tcString)
	console.log('Purpose 1 consent:', tcData.purpose.consents[1])
	console.log('Google (755) consent:', tcData.vendor.consents[755])
})

Per the CMP API spec, the callback runs straight away with the current data and again whenever the TC String changes. eventStatus is tcloaded, cmpuishown or useractioncomplete. The older getTCData command has been deprecated since v2.2.

Which TCF version is current?

As of October 2026, IAB Europe calls the framework TCF v2.3, under version 5.0.b of the TCF Policies (May 29, 2026). IAB Tech Lab’s specification changelog labels the same May 2026 update “2.4”, so you’ll see both numbers.

VersionLaunchedWhat changed
v1.1April 25, 2018The first version. New v1.1 strings stopped on August 15, 2020.
v2.0August 21, 2019Replaced v1.1.
v2.1August 19, 2020Aligned with the CJEU’s Planet49 ruling and standardized how cookie lifetimes are disclosed.
v2.2May 16, 2023Consent became the only allowed legal basis for Purposes 3 to 6 (profiles and personalization). getTCData was deprecated in favor of event listeners. The deadline was November 20, 2023.
v2.32025 (IAB Europe’s pages say April and June)The Disclosed Vendors segment became mandatory. Strings created after February 28, 2026 without it are invalid.
Policies 5.0.b (“2.4” in the spec)May 2026Added a StandardTexts field to the GVL. Vendors that use only Special Purposes no longer have to be disclosed under legitimate interest.

What does TCF standardize?

TCF fixes the purposes you ask about and the words you use for them. Every TCF banner uses the same 11 purposes, with the names published in the GVL:

IDPurpose
1Store and/or access information on a device
2Use limited data to select advertising
3Create profiles for personalised advertising
4Use profiles to select personalised advertising
5Create profiles to personalise content
6Use profiles to select personalised content
7Measure advertising performance
8Measure content performance
9Understand audiences through statistics or combinations of data from different sources
10Develop and improve services
11Use limited data to select content

On top of those, TCF defines:

  • 3 Special Purposes that vendors can rely on without asking for consent: security and fraud prevention, delivering ads and content, and saving privacy choices. The third was added in the June 2024 policy update.
  • 3 Features: matching and combining data from other sources, linking devices, and identifying devices from information transmitted automatically.
  • 2 Special Features, which need an opt-in: precise geolocation, and identifying devices from actively requested information.

Feature 3 is the one Google says it will register for as it starts using IP addresses for ads measurement in Europe. The Consent Mode post covers what that means for Google tags.

Do you need TCF?

It depends on whether you sell ad space or buy it.

Your siteTCF?Why
Serves personalized ads via AdSense, Ad Manager or AdMob to EEA, UK or Swiss visitorsYesGoogle requires a Google-certified CMP that integrates with TCF (EEA and UK since January 16, 2024, Switzerland since July 31, 2024). Without one, traffic “may be eligible for non-personalized ads or limited ads”.
Sells ad space through other SSPs, header bidding or ad networksUsuallyThe TC String travels with the ad request, and it’s how vendors in the auction learn what the visitor allowed. Check each partner’s requirements.
Only buys ads (Google Ads, Meta, LinkedIn, Microsoft) and runs analyticsNoGoogle “does not require advertisers to use a CMP from the partner Program” (policy help). Consent Mode carries the signals.
Needs to handle California visitorsNot the answerCalifornia’s law is opt-out: a “Do Not Sell or Share” link and honoring Global Privacy Control. Neither TCF nor an opt-in banner covers that on its own. See the Disney CCPA post.

What does TCF change in your banner?

TCF fixes the wording and parts of the layout. It doesn’t force you to list hundreds of vendors. From the TCF Policies, Appendix B and Policy 21:

  • Placement. The banner is “displayed prominently and separately from other information… in a modal or banner that covers all or substantially all of the content of the website or app”.
  • First layer. It lists the purposes “using at least the standardised names and/or Stack names” and states the number of third-party vendors, with a link to the list. It must also offer a call to action to consent and one to customize choices.
  • Fixed texts. A publisher “must not modify, or instruct its CMP to modify” the purpose names, definitions or their translations.
  • Defaults. Every choice starts at “no consent” or “off”.
  • Buttons. The two primary calls to action need “matching text treatment (font, font size, font style)” and a minimum contrast ratio of 5 to 1 for their text.

The vendor list is yours to choose. Policy 20(1) says “A Publisher may choose the Vendors for which it wishes to provide transparency”, and a commercial CMP “may not impose a list of Vendors”. IAB Europe even warns that listing “an unjustifiably large number of Vendors may impact users’ ability to make informed choices and increase Publisher and Vendor legal risk.”

For an advertiser, the real cost is different. You get purpose texts written for programmatic advertising, which read oddly on a B2B or ecommerce site, plus the layout rules above. On top of that, every Special Purpose and Feature that any listed vendor declares has to be shown. A regular banner still has to meet the GDPR’s conditions for consent. The difference is that you write the words.

How do Google tags read the TC String?

Only if you turn it on. Google’s TCF guide offers two switches. The CMP can set enableAdvertiserConsentMode in its TCData, or the page can set this before the Google tags load:

window['gtag_enable_tcf_support'] = true

Once it’s on, Google maps TCF purposes to Consent Mode like this:

Purpose deniedEffect on Google tags
1: Store and/or access information on a devicead_storage and ad_user_data denied
3 or 4: personalized ads profile or selectionad_personalization denied
7: Measure ad performancead_user_data denied, Google signals off in GA
9 or 10: audience research, product developmentGoogle signals off in GA

Two things to know:

  • No purpose maps to analytics_storage. Google says: “To control Google Analytics cookies, integrate with consent mode.” A TCF site still sends Consent Mode commands for GA4.
  • Slow CMPs fall back to defaults. If the CMP doesn’t respond within 500 milliseconds, or reports “error”, “stub” or “loading”, “the tag will proceed with default consent settings”. Set denied defaults, as shown in the Consent Mode post.

Google ad tech providers that aren’t on the GVL get their consent through Google’s Additional Consent string. It’s “intended only for use alongside IAB Europe’s Transparency & Consent Framework (TCF) v2”, and only a TCF-registered CMP may create it.

Do Meta, LinkedIn and Microsoft tags read TCF?

Mostly not. Here’s what the vendors’ documentation and tag code showed as of October 2026:

TagGVL IDReads the TC String?How it takes consent
Google tags755Yes, once enabledConsent Mode, or the TCF mapping above
Microsoft UET1126Yes, unless you set UET consent yourselfUET consent mode (ad_storage)
LinkedIn Insight Tag804Not documented, and insight.min.js has no __tcfapi callBlock it in GTM until consent
Meta PixelNot on the GVLNofbq('consent', 'revoke') and fbq('consent', 'grant')
Microsoft ClarityNot on the GVLNot documentedClarity’s own consent API

So a TCF site still needs GTM consent settings for the tags that don’t read it. Map your CMP’s categories or purposes to consent types and set Require additional consent for tag to fire on the LinkedIn and Meta tags, typically with ad_storage. That’s the same work as with a regular banner. Microsoft says UET reads TCF only “If you don’t implement Consent Mode directly on your website”, so decide which source it should follow.

No. TCF is a format for recording and passing choices, not a legal shield. Its Policies say participants “may voluntarily choose to adhere” and that it “is not a substitute for individual participants taking responsibility for their obligations under the law.” The case law so far:

  • Belgian DPA, February 2, 2022 (decision 21/2022). It found that the TCF mechanism infringed the GDPR, fined IAB Europe €250,000 and required an action plan.
  • CJEU, IAB Europe (C-604/22, March 7, 2024). It held that “the TC String contains information concerning an identifiable user and therefore constitutes personal data within the meaning of the GDPR”. IAB Europe can be a joint controller, subject to checks by the national court.
  • Belgian Market Court, May 14, 2025. It annulled the decision on procedural grounds but “endorses the reasoning of the Belgian DPA and confirms the fine of 250,000 euros”. It rejected joint controllership for processing “entirely within the OpenRTB protocol”.

Two practical points follow. First, the TC String is personal data, so your privacy notice and records need to cover it. Second, whether consent is valid still depends on your banner and on what your vendors do with the data, whether you use TCF or not.

Choosing between TCF and a regular CMP, and wiring either one into GTM, is part of my consent mode work.

Frequently asked questions

Is the IAB TCF legally required under the GDPR?

No. It's a voluntary industry standard, and IAB Europe says it isn't a substitute for each participant's own legal obligations. Google makes it a condition only for publishers serving personalized ads through AdSense, Ad Manager or AdMob, through a Google-certified CMP.

Does Google Ads require TCF for conversion tracking?

No. Advertisers can send consent through Google Consent Mode, and Google doesn't require them to use a CMP from its partner program. If your site does run TCF, Google tags can read the TC String once TCF support is enabled, but GA4 cookies still follow Consent Mode's analytics_storage.

Do I have to list every vendor in the Global Vendor List?

No. The TCF Policies let publishers choose their vendors and forbid commercial CMPs from imposing a vendor list. They also warn that listing an unjustifiably large number of vendors increases legal risk.

What is the difference between the TC String and the AC String?

The TC String records the visitor's choices for TCF purposes and for vendors on the Global Vendor List. The AC String is Google's Additional Consent string, used alongside TCF for Google ad tech providers that aren't on the list. Only a TCF-registered CMP may create it.

Sources

  1. The Transparency & Consent Framework (IAB Europe)
  2. TCF Policies (IAB Europe)
  3. Consent string and vendor list formats v2 (IAB Tech Lab)
  4. CMP API v2 (IAB Tech Lab)
  5. Global Vendor List, JSON (IAB Europe)
  6. Use TCF strings with Google tags (Google Tag Platform)
  7. Google-certified CMP requirement (AdSense Help)
  8. Google's Additional Consent Mode technical specification (Ad Manager Help)
  9. CJEU, IAB Europe (C-604/22), press release
  10. The Market Court rules in the IAB Europe case (Belgian DPA)