IAB TCF vs a Regular Cookie Banner: Which Do You Need?
By Eli C., MarTech & Analytics Engineer
Published Updated
Quick answer: The IAB Europe Transparency & Consent Framework (TCF) is a voluntary standard that lets a consent banner pass one encoded record of the visitorâs choices, the TC String, to the ad-tech vendors behind an ad request. You need it if you sell ad space programmatically. Google also requires a TCF-integrated, Google-certified CMP if you serve personalized ads through AdSense, Ad Manager or AdMob. If you only buy ads and run your own tags, such as Google Ads, GA4, Meta or LinkedIn, a regular consent banner with Google Consent Mode is enough.
What is the IAB TCF?
The Transparency & Consent Framework (TCF) is a set of policies from IAB Europe and technical specifications from IAB Tech Lab for collecting consent and passing it through programmatic advertising. IAB Europe calls it âa cross-industry voluntary standardâ. The terms youâll meet:
- CMP (consent management platform): the software that shows the banner and stores the visitorâs choice. A TCF CMP has to be registered with IAB Europe.
- Global Vendor List (GVL): the public list of registered vendors and the purposes each one declares. Version 178 (September 24, 2026) has 1,029 active vendors, including Google Advertising Products (ID 755), Microsoft Advertising (1126), LinkedIn (804) and Criteo (91).
- TC String: the encoded record of the visitorâs choices per purpose and per vendor, which the CMP stores and vendors read.
__tcfapi: the JavaScript function a TCF CMP exposes on the page so that scripts can read the current consent data.
You can watch it on any site that runs TCF. Paste this into the console:
__tcfapi('addEventListener', 2, function (tcData, success) {
if (!success) return
console.log(tcData.eventStatus, tcData.tcString)
console.log('Purpose 1 consent:', tcData.purpose.consents[1])
console.log('Google (755) consent:', tcData.vendor.consents[755])
})
Per the CMP API spec, the callback runs straight away with the current data and again whenever the TC String changes. eventStatus is tcloaded, cmpuishown or useractioncomplete. The older getTCData command has been deprecated since v2.2.
Which TCF version is current?
As of October 2026, IAB Europe calls the framework TCF v2.3, under version 5.0.b of the TCF Policies (May 29, 2026). IAB Tech Labâs specification changelog labels the same May 2026 update â2.4â, so youâll see both numbers.
| Version | Launched | What changed |
|---|---|---|
| v1.1 | April 25, 2018 | The first version. New v1.1 strings stopped on August 15, 2020. |
| v2.0 | August 21, 2019 | Replaced v1.1. |
| v2.1 | August 19, 2020 | Aligned with the CJEUâs Planet49 ruling and standardized how cookie lifetimes are disclosed. |
| v2.2 | May 16, 2023 | Consent became the only allowed legal basis for Purposes 3 to 6 (profiles and personalization). getTCData was deprecated in favor of event listeners. The deadline was November 20, 2023. |
| v2.3 | 2025 (IAB Europeâs pages say April and June) | The Disclosed Vendors segment became mandatory. Strings created after February 28, 2026 without it are invalid. |
| Policies 5.0.b (â2.4â in the spec) | May 2026 | Added a StandardTexts field to the GVL. Vendors that use only Special Purposes no longer have to be disclosed under legitimate interest. |
What does TCF standardize?
TCF fixes the purposes you ask about and the words you use for them. Every TCF banner uses the same 11 purposes, with the names published in the GVL:
| ID | Purpose |
|---|---|
| 1 | Store and/or access information on a device |
| 2 | Use limited data to select advertising |
| 3 | Create profiles for personalised advertising |
| 4 | Use profiles to select personalised advertising |
| 5 | Create profiles to personalise content |
| 6 | Use profiles to select personalised content |
| 7 | Measure advertising performance |
| 8 | Measure content performance |
| 9 | Understand audiences through statistics or combinations of data from different sources |
| 10 | Develop and improve services |
| 11 | Use limited data to select content |
On top of those, TCF defines:
- 3 Special Purposes that vendors can rely on without asking for consent: security and fraud prevention, delivering ads and content, and saving privacy choices. The third was added in the June 2024 policy update.
- 3 Features: matching and combining data from other sources, linking devices, and identifying devices from information transmitted automatically.
- 2 Special Features, which need an opt-in: precise geolocation, and identifying devices from actively requested information.
Feature 3 is the one Google says it will register for as it starts using IP addresses for ads measurement in Europe. The Consent Mode post covers what that means for Google tags.
Do you need TCF?
It depends on whether you sell ad space or buy it.
| Your site | TCF? | Why |
|---|---|---|
| Serves personalized ads via AdSense, Ad Manager or AdMob to EEA, UK or Swiss visitors | Yes | Google requires a Google-certified CMP that integrates with TCF (EEA and UK since January 16, 2024, Switzerland since July 31, 2024). Without one, traffic âmay be eligible for non-personalized ads or limited adsâ. |
| Sells ad space through other SSPs, header bidding or ad networks | Usually | The TC String travels with the ad request, and itâs how vendors in the auction learn what the visitor allowed. Check each partnerâs requirements. |
| Only buys ads (Google Ads, Meta, LinkedIn, Microsoft) and runs analytics | No | Google âdoes not require advertisers to use a CMP from the partner Programâ (policy help). Consent Mode carries the signals. |
| Needs to handle California visitors | Not the answer | Californiaâs law is opt-out: a âDo Not Sell or Shareâ link and honoring Global Privacy Control. Neither TCF nor an opt-in banner covers that on its own. See the Disney CCPA post. |
What does TCF change in your banner?
TCF fixes the wording and parts of the layout. It doesnât force you to list hundreds of vendors. From the TCF Policies, Appendix B and Policy 21:
- Placement. The banner is âdisplayed prominently and separately from other information⌠in a modal or banner that covers all or substantially all of the content of the website or appâ.
- First layer. It lists the purposes âusing at least the standardised names and/or Stack namesâ and states the number of third-party vendors, with a link to the list. It must also offer a call to action to consent and one to customize choices.
- Fixed texts. A publisher âmust not modify, or instruct its CMP to modifyâ the purpose names, definitions or their translations.
- Defaults. Every choice starts at âno consentâ or âoffâ.
- Buttons. The two primary calls to action need âmatching text treatment (font, font size, font style)â and a minimum contrast ratio of 5 to 1 for their text.
The vendor list is yours to choose. Policy 20(1) says âA Publisher may choose the Vendors for which it wishes to provide transparencyâ, and a commercial CMP âmay not impose a list of Vendorsâ. IAB Europe even warns that listing âan unjustifiably large number of Vendors may impact usersâ ability to make informed choices and increase Publisher and Vendor legal risk.â
For an advertiser, the real cost is different. You get purpose texts written for programmatic advertising, which read oddly on a B2B or ecommerce site, plus the layout rules above. On top of that, every Special Purpose and Feature that any listed vendor declares has to be shown. A regular banner still has to meet the GDPRâs conditions for consent. The difference is that you write the words.
How do Google tags read the TC String?
Only if you turn it on. Googleâs TCF guide offers two switches. The CMP can set enableAdvertiserConsentMode in its TCData, or the page can set this before the Google tags load:
window['gtag_enable_tcf_support'] = true
Once itâs on, Google maps TCF purposes to Consent Mode like this:
| Purpose denied | Effect on Google tags |
|---|---|
| 1: Store and/or access information on a device | ad_storage and ad_user_data denied |
| 3 or 4: personalized ads profile or selection | ad_personalization denied |
| 7: Measure ad performance | ad_user_data denied, Google signals off in GA |
| 9 or 10: audience research, product development | Google signals off in GA |
Two things to know:
- No purpose maps to
analytics_storage. Google says: âTo control Google Analytics cookies, integrate with consent mode.â A TCF site still sends Consent Mode commands for GA4. - Slow CMPs fall back to defaults. If the CMP doesnât respond within 500 milliseconds, or reports âerrorâ, âstubâ or âloadingâ, âthe tag will proceed with default consent settingsâ. Set
denieddefaults, as shown in the Consent Mode post.
Google ad tech providers that arenât on the GVL get their consent through Googleâs Additional Consent string. Itâs âintended only for use alongside IAB Europeâs Transparency & Consent Framework (TCF) v2â, and only a TCF-registered CMP may create it.
Do Meta, LinkedIn and Microsoft tags read TCF?
Mostly not. Hereâs what the vendorsâ documentation and tag code showed as of October 2026:
| Tag | GVL ID | Reads the TC String? | How it takes consent |
|---|---|---|---|
| Google tags | 755 | Yes, once enabled | Consent Mode, or the TCF mapping above |
| Microsoft UET | 1126 | Yes, unless you set UET consent yourself | UET consent mode (ad_storage) |
| LinkedIn Insight Tag | 804 | Not documented, and insight.min.js has no __tcfapi call | Block it in GTM until consent |
| Meta Pixel | Not on the GVL | No | fbq('consent', 'revoke') and fbq('consent', 'grant') |
| Microsoft Clarity | Not on the GVL | Not documented | Clarityâs own consent API |
So a TCF site still needs GTM consent settings for the tags that donât read it. Map your CMPâs categories or purposes to consent types and set Require additional consent for tag to fire on the LinkedIn and Meta tags, typically with ad_storage. Thatâs the same work as with a regular banner. Microsoft says UET reads TCF only âIf you donât implement Consent Mode directly on your websiteâ, so decide which source it should follow.
Does TCF make your consent legally valid?
No. TCF is a format for recording and passing choices, not a legal shield. Its Policies say participants âmay voluntarily choose to adhereâ and that it âis not a substitute for individual participants taking responsibility for their obligations under the law.â The case law so far:
- Belgian DPA, February 2, 2022 (decision 21/2022). It found that the TCF mechanism infringed the GDPR, fined IAB Europe âŹ250,000 and required an action plan.
- CJEU, IAB Europe (C-604/22, March 7, 2024). It held that âthe TC String contains information concerning an identifiable user and therefore constitutes personal data within the meaning of the GDPRâ. IAB Europe can be a joint controller, subject to checks by the national court.
- Belgian Market Court, May 14, 2025. It annulled the decision on procedural grounds but âendorses the reasoning of the Belgian DPA and confirms the fine of 250,000 eurosâ. It rejected joint controllership for processing âentirely within the OpenRTB protocolâ.
Two practical points follow. First, the TC String is personal data, so your privacy notice and records need to cover it. Second, whether consent is valid still depends on your banner and on what your vendors do with the data, whether you use TCF or not.
Choosing between TCF and a regular CMP, and wiring either one into GTM, is part of my consent mode work.
Frequently asked questions
Is the IAB TCF legally required under the GDPR?
No. It's a voluntary industry standard, and IAB Europe says it isn't a substitute for each participant's own legal obligations. Google makes it a condition only for publishers serving personalized ads through AdSense, Ad Manager or AdMob, through a Google-certified CMP.
Does Google Ads require TCF for conversion tracking?
No. Advertisers can send consent through Google Consent Mode, and Google doesn't require them to use a CMP from its partner program. If your site does run TCF, Google tags can read the TC String once TCF support is enabled, but GA4 cookies still follow Consent Mode's analytics_storage.
Do I have to list every vendor in the Global Vendor List?
No. The TCF Policies let publishers choose their vendors and forbid commercial CMPs from imposing a vendor list. They also warn that listing an unjustifiably large number of vendors increases legal risk.
What is the difference between the TC String and the AC String?
The TC String records the visitor's choices for TCF purposes and for vendors on the Global Vendor List. The AC String is Google's Additional Consent string, used alongside TCF for Google ad tech providers that aren't on the list. Only a TCF-registered CMP may create it.
Sources
- The Transparency & Consent Framework (IAB Europe)
- TCF Policies (IAB Europe)
- Consent string and vendor list formats v2 (IAB Tech Lab)
- CMP API v2 (IAB Tech Lab)
- Global Vendor List, JSON (IAB Europe)
- Use TCF strings with Google tags (Google Tag Platform)
- Google-certified CMP requirement (AdSense Help)
- Google's Additional Consent Mode technical specification (Ad Manager Help)
- CJEU, IAB Europe (C-604/22), press release
- The Market Court rules in the IAB Europe case (Belgian DPA)