Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / Publisher and AdTech Consent Software

Publisher and AdTech Consent Software

Keep consent signals accurate and advertising systems connected with TCF v2.3, GPP, Google consent requirements, server-side enforcement and continuous scanning.

Publishers & AdTech

Privacy software built for advertising revenue.

Keep consent signals accurate, advertising systems connected and unauthorized trackers under control.

Captain Compliance helps publishers collect, communicate and enforce privacy choices across the advertising ecosystem — with support for IAB TCF, GPP, regional requirements, client-side tags, server-side events and continuously changing vendor stacks.

Audit My Consent StackBook a Publisher Demo

// Framework support, technical enforcement, continuous monitoring and hands-on implementation.

Consent signal flowIllustrative
Visitor
↓
Captain Compliance CMP
TCF string generatedGPP section activeVendor disclosedGPC detectedTag blockedReceipt preserved
↓
Downstream participants
Ad serverConsent granted
SSPConsent granted
ExchangeLI objection
DSPConsent denied
MeasurementServer-side restricted
AnalyticsConsent granted
Data platformTag blocked

A signaling and enforcement problem

One visitor choice must travel through an entire advertising ecosystem.

A publisher’s privacy experience does more than display a banner. It must collect a valid choice, represent that choice accurately, communicate it to downstream participants, control which technologies operate and preserve evidence of what happened.

When those steps break, publishers can face:

Lost advertising revenueLimited or nonpersonalized adsInvalid or missing consent stringsVendors operating without the expected signalTags firing before consentClient vs. server-side conflictsRegulatory scrutinyDemand letters and litigationLoss of reader trust

Captain Compliance connects the choice shown to the visitor with the technologies and advertising workflows operating behind it.

TCF v2.3

Built for the current Transparency & Consent Framework.

IAB Europe released TCF v2.3 on 19 June 2025 to remove ambiguity around vendor disclosure by making the Disclosed Vendors segment mandatory. The transition period ran through the end of February 2026, and every TC string generated on or after 1 March 2026 must conform to v2.3. Strings created before that date under v2.1 or v2.2 remain valid.

Purpose configuration

Configure the purposes and features presented to users based on the publisher’s actual processing and vendor relationships.

Vendor disclosure

Present and maintain the applicable vendor information, including the mandatory Disclosed Vendors segment.

Consent and objections

Capture consent and applicable objections to processing based on legitimate interests.

TC string generation

Generate and communicate the applicable Transparency and Consent string to participating technologies.

Withdrawal

Allow users to return to their choices and withdraw consent clearly.

Implementation monitoring

Detect missing strings, outdated implementations, undisclosed vendors and technologies that do not follow the intended consent state.

// Google began validating the Disclosed Vendors segment on 2 March 2026 and introduced TCF error code 1.4 for requests where it is missing, malformed or omits Google (Global Vendor List ID 755). Participation in the TCF can support standardized transparency and signaling, but it does not by itself guarantee compliance with GDPR, ePrivacy rules or other applicable laws. Official TCF documentation →

Global Privacy Platform

Carry privacy choices across the U.S. advertising ecosystem.

The IAB Tech Lab Global Privacy Platform provides a standardized mechanism for communicating consent and privacy-preference signals to downstream advertising participants across multiple jurisdictions.

Signal layers

U.S. national signalState-specific sectionsApplicable consumer choicesSale and sharing preferencesTargeted-advertising preferencesSensitive-data choicesGlobal Privacy ControlDownstream vendor communication

Captain Compliance capabilities

Generate applicable GPP stringsSupport relevant national and state sectionsCommunicate preferences downstreamRecognize Global Privacy ControlApply regional experiencesMaintain versioned consent evidenceMonitor specification and jurisdiction changes

// The GPP specification continues to evolve, so supported sections are configuration rather than a fixed list. Last framework review: August 2026. IAB Tech Lab GPP →

Google publisher requirements

Protect eligibility for personalized advertising.

Google requires publishers using AdSense, Ad Manager or AdMob to use a Google-certified CMP integrated with the IAB Transparency and Consent Framework when serving personalized ads to users in the EEA, United Kingdom and Switzerland. TCF v2.3 became mandatory for newly generated strings on 1 March 2026. Missing or invalid consent signals can cause affected ad requests to default to Limited Ads, which may affect revenue.

01
Visitor receives consent experience
02
CMP records the visitor’s choices
03
TCF v2.3 string is generated
04
Google and participating vendors read the signal
05
Eligible ad behavior is applied
06
Consent evidence is preserved

// Google states that its certification review does not determine full legal or TCF compliance. Confirm current certification status with the Captain Compliance team for your deployment. Google consent requirements →

Enforcement

A consent signal is only useful when the technology follows it.

Pre-consent blocking

Stop designated advertising and measurement technologies from operating before the required choice.

Vendor-aware enforcement

Connect disclosed vendors, purposes, consent states and objections to applicable technology behavior.

Server-side coordination

Communicate applicable choices to supported server-side systems so client-side consent does not become disconnected from downstream processing.

Tag-manager integration

Coordinate consent states with Google Tag Manager and other supported deployment workflows.

Consent Mode

Apply supported Google Consent Mode signals based on the visitor’s choices and regional configuration.

GPC recognition

Detect applicable Global Privacy Control signals and apply the configured opt-out behavior.

Continuous scanningIdentify new pixels, tags, cookies, vendors and unapproved changes across publisher properties.

Consent receipts

Preserve the signal, purposes, vendors, banner version, notice version, jurisdiction, timestamp and preference changes.

// Support for a specific ad server, SSP, DSP, header-bidding system or server-side platform depends on the integrations currently available for your deployment.

Revenue without dark patterns

Build a clear choice without unnecessarily sacrificing revenue.

Publishers need privacy experiences that are understandable, legally supportable, technically enforceable and compatible with advertising operations. Captain Compliance helps teams evaluate:

Accept, reject and customize presentationEqual-prominence requirements where applicablePurpose and vendor disclosuresConsent ratesLimited-ad behaviorContextual-advertising optionsUser re-prompting rulesWithdrawal and preference accessSubscription and consent experiencesRegional variationsMobile usabilityPage-speed impact

// The aim is to help protect advertising eligibility, reduce avoidable signal loss, preserve compliant advertising options and improve the technical reliability of consent. Outcomes vary by deployment — no consent-rate or revenue increase is promised.

Multi-property operations

Manage every publication from one privacy operation.

Central property management

Manage multiple domains, brands, applications and regional configurations.

Reusable configurations

Deploy approved templates across related publisher properties while preserving local differences.

Team access

Give privacy, legal, engineering, ad operations and agencies appropriate access.

Bulk deployment

Roll out approved changes across selected property groups.

Vendor governance

Review and approve advertising vendors, purposes, integrations and changes.

Cross-property reporting

Monitor consent behavior, tracker changes, configuration status and unresolved findings.

Agency and partner supportAllow approved agencies and implementation partners to assist across properties.

Publisher litigation risk

Advertising technology can create more than regulatory exposure.

// The presence of an advertising technology does not automatically establish a legal violation. The analysis depends on the publisher, user relationship, information transmitted, consent, configuration, disclosure, jurisdiction and controlling law.

Publisher consent audit

Test what happens before and after the visitor’s choice.

States tested

  • ·Initial page load
  • ·No interaction
  • ·Accept all
  • ·Reject all
  • ·Customized preferences
  • ·Global Privacy Control
  • ·Returning visitor
  • ·Changed preferences
  • ·Different jurisdictions
  • ·Logged-in and logged-out journeys where authorized

Report outputs

  • ·Tracker and vendor inventory
  • ·Pre-consent activity
  • ·Post-rejection activity
  • ·Signal-generation observations
  • ·TCF and GPP implementation findings
  • ·Client-side and observable server-side behavior
  • ·Screenshots and technical evidence
  • ·Prioritized remediation recommendations

Request a Publisher Consent Audit

Connected platform

Everything publishers need to control consent and prove it.

Implementation and support

Superhuman support for a complicated advertising stack.

Captain Compliance works with privacy, engineering, product and advertising teams to configure consent experiences, review vendors, connect applicable signals, test technology behavior and remediate implementation gaps.

Implementation assistance where contractually availableFramework configurationTag-manager supportVendor reviewRegional setupMigration assistanceTesting and validationTechnical troubleshootingOngoing monitoringHuman privacy support

// Timelines vary. Complex ad stacks, custom server-side deployments and multi-property migrations are scoped individually rather than promised on a fixed schedule.

Compliance Shield

Consent protection backed by Captain Compliance.

Qualifying Captain Compliance customers may receive additional protection through Compliance Shield when Captain Compliance technology is properly deployed and maintained under the applicable agreement.

Approved consent configurationsContinuous scanningConsent recordsTechnical evidenceClaim-response assistanceHuman support

Explore Compliance Shield

// Compliance Shield is subject to eligibility requirements, approved configurations, continued use and the terms, limitations and exclusions of the applicable written agreement. Not every publisher claim qualifies.

Questions

Publisher consent, answered plainly.

What is a publisher consent management platform?

A CMP collects a visitor’s privacy choices, encodes them into standardized signals such as a TCF TC string or GPP string, communicates those signals to downstream advertising participants, controls which technologies may operate and preserves evidence of what was shown and chosen.

What is IAB TCF v2.3?

The current version of IAB Europe’s Transparency & Consent Framework, released 19 June 2025. It standardizes how publishers communicate consent, legitimate-interest objections, purposes and vendor disclosure to participating advertising vendors.

What changed in TCF v2.3?

One structural change: the Disclosed Vendors segment is now mandatory in every TC string, resolving ambiguity about whether a vendor was actually shown in the CMP interface. Legal bases, purposes and UI requirements did not change, and re-consent is generally not required solely because of this update.

What is the Global Privacy Platform?

An IAB Tech Lab specification for communicating consent and privacy-preference signals across multiple jurisdictions, including U.S. national and state-specific sections covering choices such as sale, sharing, targeted advertising and sensitive data.

What happens if a publisher sends an invalid or missing TCF string?

Google may default the affected ad request to Limited Ads or drop it, which reduces personalization and can materially affect revenue. Google began validating the Disclosed Vendors segment on 2 March 2026 and reports failures under TCF error code 1.4, including when Google (Global Vendor List ID 755) is not disclosed.

Does a publisher need a Google-certified CMP?

Google requires a Google-certified CMP integrated with the TCF for publishers serving personalized ads to users in the EEA, UK and Switzerland through AdSense, Ad Manager or AdMob. Confirm current certification status for your specific deployment with the Captain Compliance team.

Does TCF participation guarantee GDPR compliance?

No. The TCF standardizes transparency and signaling. It does not by itself establish compliance with the GDPR, ePrivacy rules or other applicable law, and Google states its certification review does not determine full legal or TCF compliance.

Can Captain Compliance recognize Global Privacy Control?

Yes. GPC signals can be detected and the configured opt-out behavior applied according to your regional settings and applicable requirements.

Does Captain Compliance support server-side consent signals?

Applicable choices can be communicated to supported server-side systems so client-side consent does not become disconnected from downstream processing. Which server-side platforms are supported depends on the integrations available for your deployment.

Can one account manage multiple publisher properties?

Yes. Multiple domains, brands, applications and regional configurations can be managed centrally, with reusable templates, bulk deployment across property groups, role-based team access and cross-property reporting.

How does Captain Compliance detect unauthorized pixels?

Continuous scanning identifies cookies, pixels, scripts and vendors across your properties and flags new or changed technologies, including tags firing before consent or continuing after rejection.

Can Captain Compliance help with VPPA exposure?

Yes. Video journeys are scanned for technologies that may transmit viewing information alongside identifiers, with pre-consent blocking and consent evidence available. See the VPPA page for detail.

What does the free publisher audit include?

Testing across initial load, no interaction, accept, reject, customize, GPC, returning visitor and multiple jurisdictions — producing a tracker and vendor inventory, pre-consent and post-rejection activity, TCF and GPP implementation findings, technical evidence and prioritized remediation recommendations.

How does Compliance Shield work?

Qualifying customers with properly deployed and maintained technology may receive defined support under the applicable written agreement. Eligibility, obligations, limitations and exclusions are governed by that agreement.

Get started

Keep your advertising stack connected to every privacy choice.

Audit your consent signals, vendors, pixels and enforcement behavior — and find the gaps that can cost revenue or create legal exposure.

Audit My Consent StackTalk to a Publisher Specialist

Last framework review: August 2026. Captain Compliance provides privacy technology, implementation and support. It does not provide legal advice. Framework participation and certification do not establish legal compliance, and available integrations depend on your deployment.