Your banner already works. TCF teaches it to speak ad-tech.
If you monetise with programmatic advertising in Europe, your ad partners don't read your banner — they read a TC String. CookieLet generates a valid TCF v2.3 signal from the categories and consent flow you've already set up, so you switch it on rather than start over.
Start here
Most sites don't need TCF. Here's how to tell.
TCF is a standard for the programmatic advertising supply chain. It exists so hundreds of ad-tech companies who never meet your visitor can still find out what that visitor agreed to. If you're not in that supply chain, turning TCF on adds a longer, denser banner and buys you nothing. We'd rather you skip it.
You need TCF
- You serve ads through Google AdSense, Ad Manager or AdMob to visitors in the EEA, the UK or Switzerland
- You sell inventory programmatically through SSPs, exchanges or header bidding
- An ad partner has asked you for a TC String, a CMP ID, or "TCF support"
- Your fill rate or CPMs dropped in Europe and nobody can explain why
You don't
- You run a course site, SaaS product, shop or brochure site with no third-party ads
- Your only trackers are analytics, a chat widget and a pixel or two
- You show ads only through direct deals with named advertisers
- Nobody in your stack has ever mentioned a vendor list
Leave TCF off. Your standard CookieLet banner already covers you.
Not sure
- Run a cookie scan and look at what turned up
- If you see cookies from ad exchanges, DSPs or SSPs you've never heard of, you're in the supply chain
- Check whether any of those vendors appear on the Global Vendor List
- Still unclear? Send us the scan and we'll tell you straight
Plain English
What the TCF actually is
Strip away the acronyms and it's four agreements the industry made so that a consent decision taken on your site can travel, intact, to a company your visitor has never heard of.
A shared vocabulary
Eleven numbered purposes (store information on a device, measure advertising performance, create profiles for personalised advertising…), three special purposes, plus features and two special features. Everyone uses the same words in the same order, so "Purpose 3" means the same thing to your CMP and to a DSP in another country.
A shared record
The TC String — a compact, encoded record of exactly what a visitor agreed to, per purpose and per vendor. It's the thing that actually moves through the ad request. Your banner is the interface; the TC String is the output.
A shared list
The Global Vendor List — the register of ad-tech companies that have signed up to the framework, each with an ID, a declared set of purposes, a legal basis for each one, and stated storage durations. It's the register everyone draws from — nobody invents entries.
Shared plumbing
The CMP API — a standard JavaScript interface (__tcfapi) that any script on your page can call to ask "what did this visitor agree to?" and get a consistent answer, whoever built the script.
The output
This is what your banner is really producing
Three dot-separated segments. CookieLet writes all of them, correctly, on every visit.
Core segment
Who asked, when, in what language, under which vendor-list version — plus the visitor's consent and legitimate-interest position for every purpose and vendor.
Disclosed vendors
Which vendors were actually shown in the interface. Optional under v2.2, mandatory under v2.3 — this is the change that ended the guesswork.
Publisher segment
Your own restrictions and any publisher-specific purposes, kept separate from the standard vendor signal.
Version
v2.3 isn't optional any more
IAB Europe released TCF v2.3 in April 2025 and ran a transition period that closed on 28 February 2026. Since 1 March 2026, newly created TC Strings are expected to be v2.3. Strings created before that date stay valid — but anything your site writes today needs to be current.
The headline change: proof of disclosure
Under v2.2, a vendor receiving no consent couldn't tell whether the visitor had refused them or whether they'd simply never been shown. v2.3 makes the disclosed-vendors segment mandatory, so the string now says which of the two happened.
Clearer storage disclosures
Alongside v2.3, IAB Europe tightened the specifications for device storage duration and operational disclosures, so vendors describe what they store and for how long in more detail than before.
No need to re-ask your visitors
Moving to v2.3 is a change in how the string is written, not a change in what you asked for. Your existing consents aren't discarded and your visitors don't get the banner thrown back in their faces.
What you get
Built on top of what you already run
TCF mode, not a second product
Your banner, your colours, your copy, your languages, your consent log — all of it stays. Switching on TCF adds the framework's required layers to the banner you already designed and starts emitting a TC String alongside your normal consent signal. Turn it off again and everything reverts. Nothing about your existing setup is thrown away to make room for it.
- Keeps your existing banner design and placement
- Non-TCF cookies keep working the way they do now
- Enable per site, not across your whole account
- Reversible — switch it off and you're back where you were
The whole Global Vendor List, kept current
CookieLet holds a synced copy of the GVL and discloses all of it. Every registered vendor appears in your banner's vendor list and takes its own position in the TC String, carrying the IDs, declared purposes and legal bases the list itself specifies — so the version you're disclosing is never out of date with the version your partners are reading.
It's the safe default rather than the elegant one. Nothing you rely on can be silently missing from the signal, and what your banner shows always matches what the string marks as disclosed. The cost is bluntness: visitors are asked about companies you've never worked with, and the string is longer than your stack warrants. Letting you narrow it to the partners actually firing on your pages is the next thing we're building — see where we stand.
- GVL kept in sync — new versions pulled automatically
- Every registered vendor disclosed — nobody you use is left out
- Vendor count shown on the first layer, as the framework requires
- Banner and disclosed-vendors segment can't drift apart
Purposes and legitimate interest, handled properly
This is where most TCF implementations go wrong. Five of the eleven purposes — storing information on a device, and everything to do with creating or using profiles for personalised advertising and content — can only run on consent. The other six may run on consent or legitimate interest, which means an objection control rather than an opt-in. Special features like precise geolocation and device fingerprinting need their own explicit opt-in, off by default. CookieLet builds those distinctions into the interface instead of flattening everything into one row of toggles.
- Standard purpose names, worded as the framework specifies
- Consent and legitimate-interest controls kept separate
- Special features off until explicitly switched on
- Special purposes disclosed, with no fake choice attached
A string your partners can actually read
Generating a TC String is easy. Generating one that survives contact with the supply chain is the work: the right vendor-list version, the right disclosed-vendors bitfield, the right legal bases, exposed through the standard __tcfapi interface early enough that your ad scripts find it when they look. CookieLet handles the encoding and the timing, and pairs it with Google's Additional Consent signal for partners who aren't on the GVL.
- Valid v2.3 strings with the disclosed-vendors segment
- Standard CMP API, available before your ad tags fire
- Additional Consent signal for non-GVL partners
- Decode any string from the dashboard to see what it says
Every TCF choice lands in the same consent log
You don't get a separate system to check. TCF decisions are recorded in the Consent Log next to everything else — what was shown, which vendors were disclosed, which purposes were accepted or objected to, and the string that resulted. When a partner disputes a signal or you want to know what your banner looked like three months ago, it's one place, not two.
- TCF and non-TCF consents in one log
- The generated string kept alongside the record
- Visitors can reopen preferences and change their minds
- Withdrawal is as reachable as the original choice
Standard wording, in every language you serve
TCF asks you to present the framework's purpose names as written, which means translations aren't a place to get creative. CookieLet carries the official wording through to every language your banner speaks, so a visitor in Warsaw and a visitor in Lisbon read the same eleven purposes — while your own category descriptions, the ones you wrote, stay in your voice.
- Framework wording used as specified, per language
- Your own copy stays yours
- Language recorded in the string, as the spec requires
- New languages inherit the standard text automatically
Three things to know before you switch it on
Publishers get told to "use a certified CMP" without anyone explaining that two separate approvals are involved, granted by two different organisations, for two different things. Here's exactly where CookieLet sits on each — plus the one piece of TCF we haven't finished building. The first two you can verify independently, and you should.
Registered CMP with IAB Europe
CookieLet is a registered Consent Management Platform under the TCF with its own CMP ID — CMP ID: fill in — which is what lets us generate valid TC Strings the framework recognises as ours.
Google CMP certification
Separate from IAB registration, Google requires publishers serving ads in the EEA, UK and Switzerland to use a CMP it has certified itself. Ours isn't complete yet. Until it is, don't move your AdSense or Ad Manager traffic over to us — we'll tell you the day that changes.
Choosing your own vendors
Today we disclose the entire Global Vendor List rather than a list you curate. That's valid and it's safe — but it means your visitors are asked about vendors you don't use. Narrowing it to your real partners is what we're working on next.
Why we're saying this out loud. Google publishes its certified CMP list openly and updates it regularly, so any claim we made here would take you about thirty seconds to check — and you'd find out about the vendor list the first time you opened the banner. We'd rather you hear both from us. If Google ad serving is your main reason for wanting TCF, wait for us; everything else in CookieLet works exactly as it does today.
Included
The full list
TCF v2.3 strings
Current-version TC Strings with the mandatory disclosed-vendors segment.
Standard CMP API
The __tcfapi interface your ad scripts expect, loaded early.
Global Vendor List sync
Kept current automatically, so vendor IDs and legal bases stay right.
Full vendor disclosure
Every GVL vendor shown and signalled, so no partner is missed.
All 11 purposes
Presented with the framework's own wording and correct legal bases.
Legitimate interest handling
Objection controls where LI applies, kept distinct from consent.
Special features
Geolocation and device scanning as explicit opt-ins, off by default.
Two-layer banner
Vendor count and clear choices up front, full detail one click away.
Additional Consent
Google's AC signal for partners who aren't on the GVL.
Consent logging
TCF decisions recorded alongside your standard consent records.
Multi-language
Framework wording carried into every language you publish in.
String inspector
Decode any TC String from the dashboard and read it in plain terms.
FAQ
Questions worth asking
Will turning on TCF make my banner worse?
Longer, yes. TCF requires you to show the number of vendors up front and make the full purpose and vendor detail reachable, which is more than a three-category banner asks of anyone. That's the trade you're making for access to the programmatic supply chain.
Which is exactly why we put the "do you need this?" section at the top of this page. If ads aren't how you make money, leave it off.
Is the TCF legally settled?
It has been through a long dispute with the Belgian data protection authority. In May 2025 the Belgian Market Court found that IAB Europe acts as a joint controller only for the creation and use of the TC String, not for what participants do with data further down the chain, and in January 2026 it annulled key parts of the authority's earlier decision. The framework was not struck down and continues in use.
What that doesn't do is transfer your own responsibilities to anyone else. Using a framework is not the same as being compliant — you're still accountable for the vendors you enable and the choices you present. We're a tool, not a legal shield, and we're not your lawyers.
What happens if I'm still emitting TCF v2.2 strings?
The transition period ended on 28 February 2026. Strings created before then remain valid, but new strings are expected to be v2.3, and platforms across the supply chain increasingly treat an outdated signal as no signal — which typically means your inventory gets served non-personalised or limited ads instead of the personalised inventory it would otherwise be eligible for.
Do my visitors have to consent again when I switch on TCF?
Moving between TCF versions doesn't require re-prompting on its own. But switching TCF on for the first time is a real change to what you're disclosing and who you're disclosing it for, so you should expect to collect fresh consent for the vendors and purposes you're newly introducing.
Can I run TCF on one site and not another?
Yes. It's a per-site setting. Run TCF on the ad-monetised property and leave your standard banner alone everywhere else — both live under the same login, with the same scanner and the same consent log.
What about vendors who aren't on the Global Vendor List?
That's what Google's Additional Consent specification is for, and CookieLet emits that signal alongside the TC String. Be aware it's a Google specification rather than part of the TCF itself, so support for it depends on the partner.
Can I choose which vendors my banner discloses?
Not yet. CookieLet currently discloses the full Global Vendor List. Nothing you rely on gets left out of the signal, and the banner matches the string exactly — but your visitors are shown vendors you have no relationship with, and the string is longer than your stack needs.
Curated vendor selection is the feature we're building next. If a short, precise vendor list is a hard requirement for you today, tell us and we'll be straight about the timeline.
Does TCF replace my cookie banner and cookie policy?
No. TCF sits on top. Your categories, your scanner results and your generated cookie policy carry on doing their job — TCF adds the standardised vendor and purpose layer that the ad supply chain needs on top of them.
Switch on TCF v2.3 when you are ready
Keep the banner you already run. Turn on TCF mode, choose your vendors, and start handing your partners a TC string they can read.