In February 2022, Belgium’s Data Protection Authority ruled that the IAB Europe Transparency and Consent Framework, the mechanism behind the vast majority of cookie consent banners across the European ad-supported web, violated the GDPR. The ruling found that the framework’s original design let personal data flow to hundreds of advertising vendors based on consent signals that weren’t collected in a way the law actually recognized as valid. It is one of the more consequential privacy enforcement decisions of the last decade, and yet the framework it targeted is more embedded in how the internet monetizes itself today than it was before the ruling, not less. Understanding why requires understanding what the Transparency and Consent Framework actually is, what problem it solves, and how thoroughly it has been rebuilt since that ruling forced the issue.
What the Transparency and Consent Framework Actually Is
The Transparency and Consent Framework, universally shortened to TCF, is an industry standard maintained by IAB Europe that lets websites, advertising vendors, and consent management platforms communicate a user’s privacy choices to each other in a common, machine-readable format. It exists because of a structural problem specific to programmatic advertising: a single ad impression on a single webpage can pass through dozens or hundreds of different vendors, ad exchanges, data brokers, and analytics providers in the time it takes a page to load, and under GDPR, each of those parties needs a valid legal basis to process the visitor’s personal data. Without a shared standard, a publisher would need to individually negotiate and technically integrate a consent mechanism with every vendor in that chain, which is not commercially realistic at real-time bidding scale.
TCF solves this by standardizing three things: a taxonomy of processing purposes that vendors must map their activity to, a registry of every vendor participating in the framework called the Global Vendor List, and a compact, encoded signal called the Transparency and Consent String, or TC String, that captures exactly what a specific user consented to, or objected to, and travels with the ad request to every vendor downstream.
The Building Blocks
Purposes and Special Purposes. TCF defines a fixed list of processing purposes, covering things like storing information on a device, creating personalized advertising profiles, and measuring ad performance, along with a smaller list of special purposes that don’t require consent in the same way, such as security and fraud prevention. Every vendor on the Global Vendor List has to declare which purposes it processes data for and which legal basis, consent or legitimate interest, it relies on for each one.
The Global Vendor List (GVL). A centrally maintained, publicly available registry of every advertising vendor participating in TCF, along with their declared purposes and legal bases. A publisher’s consent management platform loads this list so it knows which vendors to present to users and which purposes to ask about.
The Consent Management Platform (CMP). The actual software running on a publisher’s site that displays the consent interface, collects the user’s choices, encodes them into a TC String, and makes that string available to every other script on the page through a standardized API. This is the piece most people actually interact with, even though it’s the smallest part of the overall framework.
The TC String. A compact, base64-encoded string that represents a specific user’s consent and objection choices across every purpose, special feature, and vendor defined by the framework. This string is what actually travels downstream to ad exchanges and vendors as evidence of what the user agreed to, and it is the artifact regulators and courts increasingly scrutinize when a consent claim is challenged.
How a Regulatory Failure Became a Rebuild
The Belgian DPA’s 2022 decision centered on a specific structural criticism: TCF was built as shared infrastructure for distributing consent signals, but IAB Europe itself was found to act as a data controller for the initial collection of that consent, without a valid legal basis of its own for that role, and the framework as designed made it too easy for publishers to rely on “legitimate interest” for advertising purposes that should have required affirmative consent. The ruling didn’t just criticize dark-pattern banner design in the abstract; it targeted the legal architecture underneath the entire system.
IAB Europe’s response was TCF v2.2, released in 2023, which made the framework’s compliance posture considerably more defensible. Publishers were required to present a reject option with genuine parity to the accept option in the very first layer of the consent interface, closing the long-standing pattern of banners that made accepting one click and rejecting a multi-step process. The scope for relying on legitimate interest as a legal basis for advertising purposes was narrowed. Publishers gained a mandatory device storage disclosure so users could see specifically how long data would be retained and by which vendors. And critically, the framework introduced stricter reconsent requirements, meaning that when a publisher’s vendor list or purpose configuration changed materially, previously collected consent could no longer simply be carried forward as valid.
Older consent strings generated under the pre-2.2 architecture were given a sunset date and stopped being treated as valid, which meant every CMP, publisher, and vendor in the ecosystem had a hard deadline to migrate or lose access to programmatic demand relying on TCF signals. That pattern, a regulatory or enforcement pressure point exposing a gap, followed by a framework revision with a hard cutover date, is now the recurring lifecycle TCF operates on, and it is worth understanding as a pattern rather than a one-time event, since the framework has continued to evolve on that same cycle since.
Why TCF Still Matters Even Though It Was Found Non-Compliant
The apparent paradox, a framework a regulator called illegal remaining the dominant consent mechanism on the ad-supported web, resolves once you separate the framework’s architecture from its implementation at a point in time. The Belgian ruling targeted specific design choices, not the concept of a shared, machine-readable consent signal itself. A shared standard for communicating consent across a fragmented vendor ecosystem solves a real and otherwise unsolvable coordination problem, and no viable alternative to that coordination function has displaced it. What changed is the rigor with which the framework now has to demonstrate that the consent it’s transmitting was actually validly obtained, which is a meaningfully higher bar than the framework operated under before 2022.
For publishers and vendors, this means TCF participation today carries real compliance obligations, not just a technical integration checkbox. Major demand-side platforms and ad exchanges, including Google’s ad products operating in the EEA, require a valid TCF consent signal before serving personalized advertising, which makes framework compliance a direct revenue dependency, not just a legal one.
A Practical Compliance Framework for Organizations Operating Under TCF
- Confirm your CMP is current on the latest TCF version, not just technically integrated. A CMP that still passes technical validation on an old configuration can be quietly out of compliance if it hasn’t adopted the current version’s reject-option and legitimate interest requirements.
- Audit your reject option for genuine first-layer parity with accept. This remains the single most common defect regulators and plaintiffs’ firms cite when challenging a consent banner, TCF-integrated or not.
- Review every vendor’s declared legal basis on your site’s configuration, not just its presence on the Global Vendor List. A vendor being listed doesn’t mean its declared purposes and legal bases are still accurate for how it’s actually processing your visitors’ data.
- Build a reconsent trigger process tied to any change in your vendor or purpose configuration. Consent collected under one configuration doesn’t automatically remain valid when the underlying vendor list changes; treat this as an ongoing operational requirement, not a one-time setup task.
- Maintain a documented compliance record of your CMP configuration, vendor reviews, and any reconsent events. This is the evidence that matters if a regulator, ad partner, or plaintiff’s firm ever questions your compliance timeline.
- Treat framework version updates as a recurring operational cadence, not isolated migration projects. Given TCF’s revision history, the organizations caught flat-footed by each cutover are consistently the ones treating the framework as a one-time integration rather than a maintained compliance program.
- Work with a CMP that holds independent IAB TCF validator certification. Self-reported compliance and independently validated compliance are not the same evidentiary position if your implementation is ever challenged.
TCF is Not Static
The Transparency and Consent Framework is best understood not as a single static standard but as an evolving compliance obligation with real revenue consequences attached to falling behind it. It exists to solve a genuine coordination problem in programmatic advertising, it was rebuilt in direct response to a regulator finding its original architecture unlawful, and it continues to tighten on a predictable cycle of enforcement pressure followed by revision. Organizations that treat TCF compliance as an ongoing operational program, rather than a one-time technical integration, are the ones that stay ahead of each cutover instead of scrambling to catch up to it.
Frequently Asked Questions
What does TCF stand for and who maintains it?
TCF stands for Transparency and Consent Framework. It is maintained by IAB Europe and serves as the industry standard for communicating user consent signals across publishers, advertising vendors, and consent management platforms under GDPR.
Why was the original TCF found non-compliant?
Belgium’s Data Protection Authority ruled in 2022 that IAB Europe acted as a data controller for the initial collection of consent without a valid legal basis of its own, and that the framework’s design made it too easy for publishers to rely on legitimate interest for advertising purposes that should have required affirmative consent.
What is a TC String?
A TC String is a compact, encoded signal generated by a consent management platform that represents a specific user’s consent and objection choices across every purpose, special feature, and vendor defined by the framework. It travels downstream with ad requests as the record of what the user agreed to.
Do I need to use a TCF-compliant CMP to run programmatic advertising in the EEA?
Major demand-side platforms and ad exchanges, including Google’s advertising products operating in the EEA, require a valid TCF consent signal before serving personalized advertising, making framework compliance a direct revenue dependency for publishers relying on that demand.
How often does the TCF framework change?
TCF has undergone multiple major revisions since its original 2018 release, most significantly in response to the 2022 Belgian DPA ruling. Each major revision has historically come with a hard cutover date after which older consent strings and non-updated CMP implementations stop being treated as valid.
Captain Compliance’s CMP holds IAB TCF validator certification and manages consent for 8,000+ websites processing over 50 million consent choices per month. Schedule a privacy audit to see how we keep your framework implementation current as TCF continues to evolve.