At a Glance
- IAB TCF v2.4 Specifications and the updated Global Vendor List (GVL) were published on July 23, 2026.
- CMPs must display new standard explanatory text and illustrations for each vendor Feature, sourced from the GVL.
- Special Feature 2 has been renamed “Identify devices based on information actively requested,” with updated Vendor Guidance on Client Hints.
- Publishers now have more flexibility to persist a user’s privacy choices across multiple devices, such as when a user is logged into an account.
- A legacy Legitimate Interest workaround for Special-Purpose-only vendors has been removed from the TC string.
- Web environments must comply by October 23, 2026; mobile and CTV environments by February 23, 2027.
The IAB’s Transparency & Consent Framework (TCF) is the industry standard for ensuring GDPR and ePrivacy Directive compliance in digital advertising. It defines how businesses explain data use, capture user consent, and share that consent with downstream partners.
This comprehensive guide explains everything publishers, advertisers, vendors, and consent management platforms (CMPs) need to know about IAB TCF v2.3. You’ll learn about the framework’s evolution, its compliance obligations, the role of the IAB CMP List, and how choosing an IAB-approved CMP supports both legal compliance and business growth.
What Is the IAB Transparency and Consent Framework?
The IAB’s Transparency & Consent Framework (TCF) is the industry standard for GDPR and ePrivacy Directive compliance in digital advertising. It defines how businesses explain data use, capture user consent, and share that consent with downstream partners.
This comprehensive guide explains everything publishers, advertisers, vendors, and consent management platforms (CMPs) need to know about IAB TCF v2.4. You’ll learn about the framework’s evolution, its compliance obligations, the role of the IAB CMP List, and how choosing an IAB-approved CMP supports both legal compliance and business growth.
The IAB Transparency & Consent Framework (TCF) was launched by IAB Europe to standardize how organizations comply with GDPR and the ePrivacy Directive when processing personal data for digital advertising.
How the Framework Works
At its core, the IAB TCF:
- Establishes a common language for describing data collection and processing purposes
- Provides standardized consent signals (TC String)
- Enables consent to be communicated across the advertising supply chain, from publishers, to vendors, to demand-side platforms
This standardization helps solve a fundamental challenge. Publishers and vendors often rely on dozens or even hundreds of partners in programmatic advertising. Without a common protocol, coordinating each partner’s receipt and handling of user consent would be almost impossible.
The IAB TCF has evolved from v1.1 to v2.0 and now to v2.4. CMPs must comply with TCF v2.4 in web environments by October 23, 2026, and in mobile app and CTV environments by February 23, 2027. Each iteration addresses regulatory developments, industry feedback, and enforcement actions by data protection authorities.What Is IAB TCF v2.4?
The IAB’s TCF v2.4 is the latest set of Transparency and Consent Framework (TCF) changes and guidelines as of 2026. The Framework enhances transparency and user control over personal data processing by publishers and advertisers in the digital advertising ecosystem. Building on v2.3’s work on Disclosed Vendors, v2.4 focuses on helping users better understand vendor Features, gives publishers more flexibility for cross-device consent, and simplifies how Special Purpose-only vendors are represented in the TC string.
The GVL now includes a standardTexts field, giving CMPs standard wording and illustrations to display alongside each Feature, clarifying that Features are means of processing used only in pursuit of Purposes for which users are given a choice. Special Feature 2 has been renamed “Identify devices based on information actively requested,” with updated Vendor Guidance on Client Hints for fingerprinting. Web environments must comply by October 23, 2026; mobile app and CTV environments by February 23, 2027.
What Was New in IAB TCF v2.3
The TCF v2.3 update made Disclosed Vendors a mandatory segment, enabling vendors to determine if they were allowed to process data under Special Purposes. Starting February 28, 2026, all new or updated consent signals had to include the Disclosed Vendors segment. Existing consent signals created before that date, without the v2.3 format, remained valid until the user updated or renewed their consent preferences.
Evolution from TCF v1.1 to v2.4
The technology landscape changes even faster than the regulatory one, so there have been a number of versions of the TCF since it first came out in 2018.
Here’s a timeline of its evolution, which underscores how the Framework has been adapted to regulatory and industry demands while maintaining its role as the backbone of GDPR-compliant digital advertising.
TCF v1.1 (2018)
- First industry attempt to harmonize consent under the GDPR
- Provided a basic structure for consent signals
- Faced criticism for limited user transparency and reliance on legitimate interest
TCF v2.0 (2020)
- Introduced more granular controls for publishers
- Added flexibility for vendors to declare legal bases
- Improved user interface guidelines
- Still faced scrutiny from regulators
TCF v2.2 (2023)
- Responded to concerns from European data protection authorities, especially the Belgian Data Protection Authority ruling on IAB Europe’s role as a joint controller
- Removed legitimate interest for advertising purposes
- Simplified purpose descriptions for users
- Expanded vendor disclosure requirements
TCF v2.3 (2026)
- Adds a mandatory Disclosed Vendors section to all TC strings (clear binary indicator to users whether a vendor has disclosed data processing activities)
- Resolves ambiguity for vendors processing data under Legitimate Interest for Special Purposes
- Reinforces transparency and user control by introducing stricter disclosure and consent requirements for CMPs and vendors
TCF v2.4 (2026)
- Removes the legacy Legitimate Interest workaround for Special Purpose-only vendors in the TC string
- Introduces standard explanatory text and mandatory illustrations for vendor Features in the CMP UI
- Renames Special Feature 2 to “Identify devices based on information actively requested,” with updated Vendor Guidance on Client Hints
- Gives publishers more flexibility to persist user privacy choices across multiple devices
Why the IAB TCF Matters for Publishers and Advertisers
Digital advertising is undergoing a profound shift toward privacy-led marketing. Regulations like the GDPR, platform policies, and user expectations require companies to rethink how they collect and use data.
By adopting the TCF, publishers and advertisers can:
- Support GDPR compliance: Align with the most widely recognized industry framework
- Maintain monetization opportunities: Many demand sources require TCF compliance to transact programmatic advertising
- Build user trust: Clearer consent information helps establish credibility with audiences
- Reduce compliance risk: Demonstrates proactive alignment with regulatory guidance
- Streamline partner relationships: Standardized consent signals support smoother data sharing with vendors
Case study: Learn about how Conrad Electronic meets privacy compliance and Google business requirements at scale with Usercentrics, including using the TCF for Google Ads.
How Does the TCF Affect App Publishers?
The TCF gives power back to users who can share, refuse, or revoke consent at any time. To avoid the risk of non-compliance, app publishers must comply with privacy standards when collaborating with third-party vendors.
User Consent Management
App publishers are required to explicitly mention what technologies they use to collect personal data and how they process that data.
Publishers need to provide users with the ability to refuse consent or to change or withdraw previously granted consent at any time. This needs to be as easy to do as giving consent.
App developers must disclose the user data they collect, for what purposes, and what third parties it may be shared with, among other requirements.
Publisher Restrictions
App publishing companies can now exercise more control over how their vendors and tech partners access and handle user data.
For example, publishers can set custom requirements specifying how every vendor can process collected user data. App companies can also limit the purpose of data processing to a single activity, such as ad personalization or visitor analytics.
Vendors can register as capable of operating under multiple legal bases, and publishers can specify their preferred legal bases for partnering with vendors. This enables vendors and publishers to navigate markets with varying legal requirements for processing personal data.
Enhanced Transparency
Publishers are required to provide a full list of all vendors (third-party partners) involved in data collection and processing operations, with links to their privacy policies. Additionally, for consent requests to be valid, users must be provided with the following information for each vendor:
- Purposes (for data processing) and any special purposes
- Associated legal bases for the purposes
- Retention period for personal data for stated purpose
- Features and special features
- Categories of data collected and processed
If a publisher is using legitimate interest as the legal basis, they must provide a full list of all vendors (third-party partners) involved in data collection and processing operations, with links to their privacy policies, as well as the following information for each vendor:
- Purposes (for data processing) and special purposes
- Associated legal bases for the purposes and a link to each vendor’s explanation of its legitimate interest(s) at stake
- Retention period for personal data re. fulfilling each stated purpose
- Features and special features
- Categories of data collected and processed
By providing this information in advance of data processing, individuals are empowered to make informed decisions about their data.
Vendor Compliance
While not an absolute legal requirement, app publishers are advised to work with vendors that comply with the TCF v2.4 and are on the IAB’s vendors list. By doing so, all parties involved agree to follow the same standards, which reduces the overall risk of non-compliance.
Usercentrics App CMP is on the TCF List and is fully integrated with the TCF. It’s also a Gold Tier Google-certified CMP partner and supports Google’s Additional Consent, so the CMP collects and signals consent for ad tech providers that are not part of the TCF, but are listed on Google’s Ad Tech Providers (ATPs) list.
Impact on Revenue
The TCF can impact app companies’ revenue. If informed users decide to opt out of personalized ads, app publishers could lose programmatic ad revenue.
Publishers that get most of their traffic in the EU or UK could experience this revenue drop the most due to the region’s regulations and requirements being levied by large digital platform providers.
Even so, it’s best to adopt the TCF v2.4 no matter where you operate, since most programmatic ad platforms will eventually stop advertising on websites and applications that haven’t implemented it.
Not meeting the latest standards and requirements could result in an even greater revenue hit from critical third parties. For example, Google requires European advertisers to use a certified CMP that integrates with the IAB TCF v2.3, or else they will not be able to do personalized advertising.
TCF Considerations for Digital Advertising and Monetization
In the mobile advertising landscape, the TCF v2.2 introduced essential guidelines and requirements for advertisers for privacy compliance, user transparency, and effective ad targeting strategies. These were expanded under TCF v2.3, and TCF v2.4 adds further disclosure requirements for vendor Features. Companies delivering digital ads should pay close attention to the following TCF framework components.
1. Vendor Lists
The TCF requires app publishers to disclose the total number of vendors on their vendor list on the first layer of their CMP. Displaying too many vendors can make it hard for users to make informed choices. It’s better to limit the vendor list to include only those that you work with closely.
2. Purposes
The TCF restricts use of legitimate interest as a legal basis for certain purposes. Vendors must establish consent as their legal basis for the following purposes:
- Create a personalized ads profile
- Select personalized ads
- Create a personalized content profile
- Select personalized content
The TCF has also replaced the currently mandatory legal disclaimers with user-friendly descriptions. You’ll need to include illustrations on the CMP’s second layer to clarify what the different purposes mean. TCF v2.4 extends this illustration requirement to vendor Features as well, alongside new standard explanatory text for each Feature sourced from the GVL.
3. Consent for Personalized and Non-Personalized Ads
The TCF requires publishers to capture user consent for serving both personalized and non-personalized ads to enable compliance with user preferences and data protection regulations.
4. Consent Signals
Before the TCF, vendors struggled with interoperability because they used two sets of guidelines — one from IAB Europe and another from Google — to transmit consent signals to ad tech partners. Google supports the TCF, so you can follow a consistent set of guidelines for all ad tech companies.
To work with Google AdSense, Ad Manager, or AdMob, publishers must implement a TCF v2.3-certified CMP, so Google’s ad tags and SDKs can easily receive the transparency and consent (TC) string from that CMP.
5. Requirements for Demand-Side Platforms (DSPs)
Demand-side platforms (DSPs) must comply with the following guidelines to meet TCF requirements.
- Register as a vendor in the global vendor list
- Vendors must have a mechanism that supports TC String consumption for processing real-time bidding requests
- A legal basis is mandatory for processing sensitive user data
6. Requirements for Vendors
Vendors will also have to provide some additional information during registration:
- Categories of data collected and processed
- Details of the data retention period
- A webpage link that reveals a vendor’s legitimate interests
The IAB CMP List: Finding an IAB-Approved CMP
The IAB CMP List includes all consent management platforms approved by IAB Europe to implement the Framework. Only CMPs on this list can issue valid TCF 2.4 consent strings.
An IAB-approved CMP supports:
- Consent banners that meet technical standards
- Accurate recording and transmission of user choices
- Vendor reliance on consent signals for GDPR compliance
Choosing a certified CMP is essential for both regulatory compliance and business continuity. Usercentrics is proud to be on IAB Europe’s CMP List, offering a CMP for publishers that integrates fully with the TCF.
Challenges and Opportunities for Publishers
Global coverage of privacy regulations continues to expand, and existing laws, guidelines, and platforms’ policies are getting more strict. So unsurprisingly there are growing challenges for companies, including with TCF requirements.
However, these go hand in hand with opportunities for companies to build more sustainable business operations and enjoy competitive advantages.
IAB TCF Challenges and Opportunities
Data privacy is complex, and meeting TCF requirements may seem daunting. But as privacy regulations become nearly globally ubiquitous, and meeting privacy standards increasingly becomes critical to business success, companies need to be prepared to meet these challenges and seize opportunities.
| Challenges | Opportunities |
|---|---|
| Managing privacy compliance in-house is complex and grows more so, especially if multiple laws are applicable. This can strain tech and legal resources. | CMPs’ automation functions can streamline maintenance to help reduce resource strain, manage regulatory updates, and provide compliance peace of mind. |
| Apps can see lower consent rates as users leave or avoid ones that fail TCF UI or UX standards, especially as banner requirements for CMPs change. | A TCF-compliant CMP helps provide a better user experience and supports trust. |
| CMPs face stricter registration and compliance checks. | Meeting strict privacy requirements shows proof of respect to audiences and ad partners for legal requirements and users’ data and privacy. |
| Publishers must adapt to new banner requirements. | Privacy compliance can open access to premium demand sources. |
| Vendors must provide more granular disclosures and maintain them as technologies in use and operations change. | Transparency with users and optimal user experience is a competitive advantage. |
| Both coverage of privacy laws and frameworks and authorities’ enforcement are likely to increase. | Early adopters can position themselves as leaders in privacy-compliant advertising. |
| Confirming a vendor was actually disclosed to the user, and handling inconsistent implementations across CMPs. | The mandatory Disclosed Vendors segment gives cleaner signals, fewer disputes, and consistent read/write behavior across the ecosystem. |
| CMPs must implement new standard explanatory text and illustrations for every vendor Feature, and update Special Feature 2 naming, ahead of the October 2026 deadline. | Clearer Feature-level disclosures reduce user confusion about what they can and can’t control, and position early movers as trust leaders. |
| Handling conflicts when a user’s persisted choices differ across devices, such as a logged-in account versus a new browser session. | More consistent privacy experience for users across devices, and clearer account-based consent handling for publishers. |
A Usercentrics study revealed 90 percent of EU apps reviewed didn’t comply with the GDPR or ePrivacy requirements. Learn where apps are failing and how to protect your ad revenue.
TCF and GDPR Compliance
The TCF framework is closely aligned with the GDPR’s principles. Adopting the TCF demonstrates to regulators and partners that your organization takes privacy compliance seriously and has integrated GDPR requirements effectively.
TCF & GDPR Compliance
Consent must be explicit
Language must be clear and consent choices must be equally accessible, no legal jargon or pre-ticked boxes.
Transparency is key
Users must understand what they’re agreeing to, and be able to access granular information about processors.
Vendors must justify processing
Legal basis and retention periods must be clear, and legitimate interest is no longer allowed for several functions; consent is mandatory for those.
Accountability applies
Publishers, vendors, and CMPs all share responsibility for data privacy compliance.
Transparency and Consent Framework Best Practices
Achieving and maintaining privacy compliance with the TCF may seem challenging, but it is achievable. All you need is the right tools to set up an ecosystem that enables you to seamlessly connect with and manage vendors and users.
These best practices will help you stay privacy-compliant:
TCF Best Practices
Provide users with the complete required list of data processing partners and legal bases used by your organization.
Explicitly mention data storage, retention, and use policies that publishers and their third-party partners follow.
Obtain user consent for the use of technologies like tracking cookies before collecting users’ personal data (where required), including for IP addresses and device identifiers as varying laws dictate.
Enable users to access the list of third parties (aka vendors) that may process user data.
Inform users about the consequences of declining consent, such as certain functions that may not work correctly or at all, or the inability to provide personalized experiences.
Give users the ability to update, withdraw, or revoke their consent choices as easily as they provide it.
Notify users if legitimate interest is being used as the legal basis for data processing, but remember that user consent is now the exclusive allowed legal basis for advertising and content personalization.
All call-to-action buttons for consent choices must be equally visible. “Accept” and “Reject” options must appear equal and be equally accessible.
Ensure vendor Features display the new standard explanatory text and illustrations required under TCF v2.4, and reflect the updated name for Special Feature 2.
Clearly communicate to users when their privacy choices are being persisted across devices, and handle conflicts consistently if a signed-in user’s choices differ from a prior session.
The IAB TCF 2.4 and the Future of Digital Advertising
The IAB Transparency & Consent Framework is the cornerstone of GDPR-compliant digital advertising, and its pace of change is accelerating: three policy updates in under three years. The Framework will continue to evolve to meet the demands of new technologies, consumer expectations, and legal developments.
By addressing regulator concerns and strengthening user rights, the TCF provides a more transparent and trustworthy approach to data-driven marketing, gives users more control over their data, and makes companies more attractive advertising partners.
For publishers and advertisers navigating an increasingly complex privacy landscape, staying current with the TCF isn’t a one-time project. It’s an ongoing commitment that pays off in user trust and sustained ad revenue. Choosing a CMP that keeps pace with each update, without requiring a manual overhaul every time, is what makes that commitment sustainable.