IAB Europe TCF v2.3

    Your banner already works. TCF teaches it to speak ad-tech.

    If you monetise with programmatic advertising in Europe, your ad partners don't read your banner — they read a TC String. CookieLet generates a valid TCF v2.3 signal from the categories and consent flow you've already set up, so you switch it on rather than start over.

    yoursite.com / Advanced / TCF
    Premium
    IAB Europe TCF v2.3
    Adds the TCF layer to your existing banner
    Your CMP identity
    CMP ID
    GVLsynced today
    Vendors
    Full Global Vendor List
    Every registered vendor disclosed
    Synced
    Purposes
    1 · Store and/or access information on a device
    Consent
    7 · Measure advertising performance
    Consent Leg. interest
    Special Feature 1 · Precise geolocation
    Opt-in only

    Start here

    Most sites don't need TCF. Here's how to tell.

    TCF is a standard for the programmatic advertising supply chain. It exists so hundreds of ad-tech companies who never meet your visitor can still find out what that visitor agreed to. If you're not in that supply chain, turning TCF on adds a longer, denser banner and buys you nothing. We'd rather you skip it.

    You need TCF

    • You serve ads through Google AdSense, Ad Manager or AdMob to visitors in the EEA, the UK or Switzerland
    • You sell inventory programmatically through SSPs, exchanges or header bidding
    • An ad partner has asked you for a TC String, a CMP ID, or "TCF support"
    • Your fill rate or CPMs dropped in Europe and nobody can explain why

    You don't

    • You run a course site, SaaS product, shop or brochure site with no third-party ads
    • Your only trackers are analytics, a chat widget and a pixel or two
    • You show ads only through direct deals with named advertisers
    • Nobody in your stack has ever mentioned a vendor list

    Leave TCF off. Your standard CookieLet banner already covers you.

    Not sure

    • Run a cookie scan and look at what turned up
    • If you see cookies from ad exchanges, DSPs or SSPs you've never heard of, you're in the supply chain
    • Check whether any of those vendors appear on the Global Vendor List
    • Still unclear? Send us the scan and we'll tell you straight

    Plain English

    What the TCF actually is

    Strip away the acronyms and it's four agreements the industry made so that a consent decision taken on your site can travel, intact, to a company your visitor has never heard of.

    A shared vocabulary

    Eleven numbered purposes (store information on a device, measure advertising performance, create profiles for personalised advertising…), three special purposes, plus features and two special features. Everyone uses the same words in the same order, so "Purpose 3" means the same thing to your CMP and to a DSP in another country.

    A shared record

    The TC String — a compact, encoded record of exactly what a visitor agreed to, per purpose and per vendor. It's the thing that actually moves through the ad request. Your banner is the interface; the TC String is the output.

    A shared list

    The Global Vendor List — the register of ad-tech companies that have signed up to the framework, each with an ID, a declared set of purposes, a legal basis for each one, and stated storage durations. It's the register everyone draws from — nobody invents entries.

    Shared plumbing

    The CMP API — a standard JavaScript interface (__tcfapi) that any script on your page can call to ask "what did this visitor agree to?" and get a consistent answer, whoever built the script.

    The output

    This is what your banner is really producing

    Three dot-separated segments. CookieLet writes all of them, correctly, on every visit.

    CPzFR8APzFR8AAKAxAENDECsAP_gAEPgAAYgKptB.QVlAAAA9gAAAAAAA.YAAAAAAAAAA
    Core segment

    Who asked, when, in what language, under which vendor-list version — plus the visitor's consent and legitimate-interest position for every purpose and vendor.

    Disclosed vendors

    Which vendors were actually shown in the interface. Optional under v2.2, mandatory under v2.3 — this is the change that ended the guesswork.

    Publisher segment

    Your own restrictions and any publisher-specific purposes, kept separate from the standard vendor signal.

    Version

    v2.3 isn't optional any more

    IAB Europe released TCF v2.3 in April 2025 and ran a transition period that closed on 28 February 2026. Since 1 March 2026, newly created TC Strings are expected to be v2.3. Strings created before that date stay valid — but anything your site writes today needs to be current.

    v2.0
    Aug 2019
    v2.1
    Aug 2020
    v2.2
    May 2023
    v2.3
    Apr 2025 · mandatory since 1 Mar 2026
    Next
    Tracked, so you don't have to

    The headline change: proof of disclosure

    Under v2.2, a vendor receiving no consent couldn't tell whether the visitor had refused them or whether they'd simply never been shown. v2.3 makes the disclosed-vendors segment mandatory, so the string now says which of the two happened.

    Clearer storage disclosures

    Alongside v2.3, IAB Europe tightened the specifications for device storage duration and operational disclosures, so vendors describe what they store and for how long in more detail than before.

    No need to re-ask your visitors

    Moving to v2.3 is a change in how the string is written, not a change in what you asked for. Your existing consents aren't discarded and your visitors don't get the banner thrown back in their faces.

    What you get

    Built on top of what you already run

    One switch

    TCF mode, not a second product

    Your banner, your colours, your copy, your languages, your consent log — all of it stays. Switching on TCF adds the framework's required layers to the banner you already designed and starts emitting a TC String alongside your normal consent signal. Turn it off again and everything reverts. Nothing about your existing setup is thrown away to make room for it.

    • Keeps your existing banner design and placement
    • Non-TCF cookies keep working the way they do now
    • Enable per site, not across your whole account
    • Reversible — switch it off and you're back where you were
    TCF v2.3
    On for yoursite.com
    Standard cookie banner
    Categories, scanner, policy
    Google Additional Consent
    For partners outside the GVL
    Both signals emitted. Existing consents preserved.
    Vendors

    The whole Global Vendor List, kept current

    CookieLet holds a synced copy of the GVL and discloses all of it. Every registered vendor appears in your banner's vendor list and takes its own position in the TC String, carrying the IDs, declared purposes and legal bases the list itself specifies — so the version you're disclosing is never out of date with the version your partners are reading.

    It's the safe default rather than the elegant one. Nothing you rely on can be silently missing from the signal, and what your banner shows always matches what the string marks as disclosed. The cost is bluntness: visitors are asked about companies you've never worked with, and the string is longer than your stack warrants. Letting you narrow it to the partners actually firing on your pages is the next thing we're building — see where we stand.

    • GVL kept in sync — new versions pulled automatically
    • Every registered vendor disclosed — nobody you use is left out
    • Vendor count shown on the first layer, as the framework requires
    • Banner and disclosed-vendors segment can't drift apart
    Global Vendor List
    synced
    All registered vendors
    Disclosed in the banner and in the string
    Google Advertising ProductsDisclosed
    Xandr, Inc.Disclosed
    Magnite, Inc.Disclosed
    …and every other GVL vendorDisclosed
    Choose your own vendors — on the roadmap
    Purposes

    Purposes and legitimate interest, handled properly

    This is where most TCF implementations go wrong. Five of the eleven purposes — storing information on a device, and everything to do with creating or using profiles for personalised advertising and content — can only run on consent. The other six may run on consent or legitimate interest, which means an objection control rather than an opt-in. Special features like precise geolocation and device fingerprinting need their own explicit opt-in, off by default. CookieLet builds those distinctions into the interface instead of flattening everything into one row of toggles.

    • Standard purpose names, worded as the framework specifies
    • Consent and legitimate-interest controls kept separate
    • Special features off until explicitly switched on
    • Special purposes disclosed, with no fake choice attached
    Preferences · second layer
    3 · Create profiles for personalised advertising
    Consent only — no legitimate interest
    7 · Measure advertising performance
    Consent or legitimate interest
    Special Feature 1 · Precise geolocation
    Opt-in, off by default
    Special Purpose · Security & fraud prevention
    Disclosed — no toggle offered
    Signal

    A string your partners can actually read

    Generating a TC String is easy. Generating one that survives contact with the supply chain is the work: the right vendor-list version, the right disclosed-vendors bitfield, the right legal bases, exposed through the standard __tcfapi interface early enough that your ad scripts find it when they look. CookieLet handles the encoding and the timing, and pairs it with Google's Additional Consent signal for partners who aren't on the GVL.

    • Valid v2.3 strings with the disclosed-vendors segment
    • Standard CMP API, available before your ad tags fire
    • Additional Consent signal for non-GVL partners
    • Decode any string from the dashboard to see what it says
    String inspector
    CPzFR8APzFR8AAKAxAEN….QVlAAAA9gAA.YAAAAAA
    Purposes consented1, 2, 7, 9, 10
    Vendors disclosedAll GVL
    Special featuresNone opted in
    Evidence

    Every TCF choice lands in the same consent log

    You don't get a separate system to check. TCF decisions are recorded in the Consent Log next to everything else — what was shown, which vendors were disclosed, which purposes were accepted or objected to, and the string that resulted. When a partner disputes a signal or you want to know what your banner looked like three months ago, it's one place, not two.

    • TCF and non-TCF consents in one log
    • The generated string kept alongside the record
    • Visitors can reopen preferences and change their minds
    • Withdrawal is as reachable as the original choice
    Consent log
    06 Aug 2026, 09:14
    Partial · 3 purposes accepted
    TCF v2.3
    06 Aug 2026, 09:11
    Rejected all optional
    TCF v2.3
    06 Aug 2026, 09:08
    Accepted all
    TCF v2.3
    05 Aug 2026, 22:47
    Analytics only
    Standard
    Languages

    Standard wording, in every language you serve

    TCF asks you to present the framework's purpose names as written, which means translations aren't a place to get creative. CookieLet carries the official wording through to every language your banner speaks, so a visitor in Warsaw and a visitor in Lisbon read the same eleven purposes — while your own category descriptions, the ones you wrote, stay in your voice.

    • Framework wording used as specified, per language
    • Your own copy stays yours
    • Language recorded in the string, as the spec requires
    • New languages inherit the standard text automatically
    Purpose 1 · across languages
    ENStore and/or access information on a device
    DEInformationen auf einem Gerät speichern und/oder abrufen
    FRStocker et/ou accéder à des informations sur un appareil
    ESAlmacenar la información en un dispositivo y/o acceder a ella
    Where we stand today

    Three things to know before you switch it on

    Publishers get told to "use a certified CMP" without anyone explaining that two separate approvals are involved, granted by two different organisations, for two different things. Here's exactly where CookieLet sits on each — plus the one piece of TCF we haven't finished building. The first two you can verify independently, and you should.

    Registered CMP with IAB Europe

    Done

    CookieLet is a registered Consent Management Platform under the TCF with its own CMP ID — CMP ID: fill in — which is what lets us generate valid TC Strings the framework recognises as ours.

    Google CMP certification

    In progress

    Separate from IAB registration, Google requires publishers serving ads in the EEA, UK and Switzerland to use a CMP it has certified itself. Ours isn't complete yet. Until it is, don't move your AdSense or Ad Manager traffic over to us — we'll tell you the day that changes.

    Choosing your own vendors

    Building it

    Today we disclose the entire Global Vendor List rather than a list you curate. That's valid and it's safe — but it means your visitors are asked about vendors you don't use. Narrowing it to your real partners is what we're working on next.

    Why we're saying this out loud. Google publishes its certified CMP list openly and updates it regularly, so any claim we made here would take you about thirty seconds to check — and you'd find out about the vendor list the first time you opened the banner. We'd rather you hear both from us. If Google ad serving is your main reason for wanting TCF, wait for us; everything else in CookieLet works exactly as it does today.

    Included

    The full list

    TCF v2.3 strings

    Current-version TC Strings with the mandatory disclosed-vendors segment.

    Standard CMP API

    The __tcfapi interface your ad scripts expect, loaded early.

    Global Vendor List sync

    Kept current automatically, so vendor IDs and legal bases stay right.

    Full vendor disclosure

    Every GVL vendor shown and signalled, so no partner is missed.

    All 11 purposes

    Presented with the framework's own wording and correct legal bases.

    Legitimate interest handling

    Objection controls where LI applies, kept distinct from consent.

    Special features

    Geolocation and device scanning as explicit opt-ins, off by default.

    Two-layer banner

    Vendor count and clear choices up front, full detail one click away.

    Additional Consent

    Google's AC signal for partners who aren't on the GVL.

    Consent logging

    TCF decisions recorded alongside your standard consent records.

    Multi-language

    Framework wording carried into every language you publish in.

    String inspector

    Decode any TC String from the dashboard and read it in plain terms.

    FAQ

    Questions worth asking

    Will turning on TCF make my banner worse?

    Longer, yes. TCF requires you to show the number of vendors up front and make the full purpose and vendor detail reachable, which is more than a three-category banner asks of anyone. That's the trade you're making for access to the programmatic supply chain.

    Which is exactly why we put the "do you need this?" section at the top of this page. If ads aren't how you make money, leave it off.

    Is the TCF legally settled?

    It has been through a long dispute with the Belgian data protection authority. In May 2025 the Belgian Market Court found that IAB Europe acts as a joint controller only for the creation and use of the TC String, not for what participants do with data further down the chain, and in January 2026 it annulled key parts of the authority's earlier decision. The framework was not struck down and continues in use.

    What that doesn't do is transfer your own responsibilities to anyone else. Using a framework is not the same as being compliant — you're still accountable for the vendors you enable and the choices you present. We're a tool, not a legal shield, and we're not your lawyers.

    What happens if I'm still emitting TCF v2.2 strings?

    The transition period ended on 28 February 2026. Strings created before then remain valid, but new strings are expected to be v2.3, and platforms across the supply chain increasingly treat an outdated signal as no signal — which typically means your inventory gets served non-personalised or limited ads instead of the personalised inventory it would otherwise be eligible for.

    Do my visitors have to consent again when I switch on TCF?

    Moving between TCF versions doesn't require re-prompting on its own. But switching TCF on for the first time is a real change to what you're disclosing and who you're disclosing it for, so you should expect to collect fresh consent for the vendors and purposes you're newly introducing.

    Can I run TCF on one site and not another?

    Yes. It's a per-site setting. Run TCF on the ad-monetised property and leave your standard banner alone everywhere else — both live under the same login, with the same scanner and the same consent log.

    What about vendors who aren't on the Global Vendor List?

    That's what Google's Additional Consent specification is for, and CookieLet emits that signal alongside the TC String. Be aware it's a Google specification rather than part of the TCF itself, so support for it depends on the partner.

    Can I choose which vendors my banner discloses?

    Not yet. CookieLet currently discloses the full Global Vendor List. Nothing you rely on gets left out of the signal, and the banner matches the string exactly — but your visitors are shown vendors you have no relationship with, and the string is longer than your stack needs.

    Curated vendor selection is the feature we're building next. If a short, precise vendor list is a hard requirement for you today, tell us and we'll be straight about the timeline.

    Does TCF replace my cookie banner and cookie policy?

    No. TCF sits on top. Your categories, your scanner results and your generated cookie policy carry on doing their job — TCF adds the standardised vendor and purpose layer that the ad supply chain needs on top of them.

    Switch on TCF v2.3 when you are ready

    Keep the banner you already run. Turn on TCF mode, choose your vendors, and start handing your partners a TC string they can read.