Skip to content

IAB TCF ​

The Transparency and Consent Framework is how programmatic advertising asks for consent. If you sell inventory through an ad exchange, a supply-side platform or a header-bidding setup, your partners almost certainly require a TC string — without one they treat every visitor as having refused, and your fill rate shows it.

If you do not sell programmatic advertising, you do not need this. The standard banner covers the GDPR on its own, and turning TCF on would ask your visitors a longer and more detailed question than your site actually poses.

Not live yet

TCF requires a CMP ID issued by IAB Europe, and CookieWave's registration is in progress. Until it is issued, a site with TCF enabled keeps serving the standard banner — the setup you save is kept and applied the moment the ID lands. A placeholder ID is not an option: it would produce strings every validator rejects and attribute them to whoever does own that number.

Turning it on ​

The IAB TCF checkbox in the banner designer opens a five-step setup. Every field it collects has a real default of "everything", and everything is the wrong answer for all of them — an empty partner list discloses all ~1,200 vendors on the Global Vendor List, which is both untrue and the slowest possible banner. That is why it is a wizard and not a checkbox.

1. Partners ​

Pre-selected from your own site. The scanner's cookie findings are matched against the storage disclosures every GVL vendor publishes, so the partners already active on your pages are ticked when the step opens, each with the cookie names that identified it behind the question mark.

Review them. A scan is evidence, not an answer: a partner integrated server-side leaves no trace in the browser, and a cookie from a partner you dropped last year may still be sitting in someone's browser. Search adds anyone the scan could not see, by company name or by the vendor ID your partner quoted you.

A partner you cannot find

IAB Europe withdraws vendors from the framework. A withdrawn vendor stays in the published list so old consent strings still decode, but it can never be disclosed again — so it is not offered here, and if one was in your saved list it is removed with a note saying which. Roughly one in seven entries on the list is in this state.

2. Purposes ​

The eleven purposes IAB Europe defines. Their wording is fixed and the banner shows it verbatim in the visitor's language — a CMP that rephrases them fails certification, so this is a choice of which to declare, not what to call them.

Each purpose can additionally be declared under legitimate interest, which means visitors are told it happens and may object, rather than being asked first. Regulators have repeatedly rejected that basis for advertising personalisation, and purpose 1 can never use it at all. If you are unsure, leave them unticked — consent is the defensible default.

3. Restrictions ​

Optional, and most publishers declare none.

A publisher restriction overrides one partner's own declaration for one purpose. You can forbid it outright, or insist it rests on consent rather than legitimate interest — or the reverse. The restriction travels in the consent string, so partners see it and are bound by it, and the banner stops offering visitors a switch for anything you have taken away.

"Legitimate interest only" is sometimes a removal

A partner can only be moved to the other legal basis if it declared that purpose as flexible. Where it did not, insisting on the basis it did not declare takes the purpose away from it entirely. The setup says which will happen for the partner and purpose you are looking at — read it before saving.

4. Details ​

  • Special features — precise location and active device scanning. Both always require explicit opt-in and are never pre-ticked. Most sites need neither.
  • Country you publish from — encoded into every string as the publisher's country. It tells vendors whose implementation of the GDPR governs the consent they received, so it is where your business is established, not where your visitors are.
  • Handle purpose 1 outside TCF — only if you already collect consent for device storage somewhere else entirely. Leave it off unless a partner asked.
  • Out-of-band vendors — partners that obtain consent through their own dialog rather than the framework. Most publishers do not need it.

5. Google's advertising partners ​

Google works with ad tech partners that are not on the Global Vendor List, and handles them with a second signal alongside the TC string, built from a list it publishes. Selecting partners here is what makes that signal say anything — leave it empty and no consent is passed for any of them, which is correct unless AdSense, Ad Manager or AdMob is how you monetise.

What changes for your visitors ​

The banner becomes a TCF one: purposes and features rather than categories, a searchable list of the partners you declared, and a per-partner breakdown of what each may do and for how long it keeps the data. Reject is exactly as prominent and as reachable as accept, on the first layer.

Two standard cookies are written alongside CookieWave's own:

CookieContents
euconsent-v2The TC string — the framework's own encoding of the decision
addtl_consentGoogle's Additional Consent string, if you selected partners

Your tags read them through window.__tcfapi, the framework's standard API, which CookieWave installs before anything else on the page so a tag that asks early does not miss the answer. See Consent signals for the non-TCF equivalents.

Switching asks every visitor again

Turning TCF on — or off — re-prompts everyone who has already decided, including visitors who chose yesterday.

The two frameworks store different things. The standard banner records category choices in cw_consent; TCF requires a TC string, which encodes purposes, partners and legal bases that a category decision never captured. There is no honest conversion between them, and inventing a string a visitor never gave is not an option. Expect a second wave of banner impressions after the switch, and do not make it during a campaign whose conversion figures you need to read.

Editing the wording ​

Most of it is not yours to edit. The purpose and feature texts are IAB Europe's, shown verbatim, and the translations editor marks them locked. What you can change is the banner's own chrome — the title, the introductory paragraph, the buttons — in every language you publish. See Languages.

On a TCF site, Google's Consent Mode signals are derived from TCF purposes rather than from categories, following Google's own published mapping. The table is in Google Consent Mode v2.

CookieWave consent management