Home / Guides / What is IAB TCF

Google Consent Mode

What is IAB TCF

What is IAB TCF: IAB Europe’s Transparency and Consent Framework for standardized consent strings and vendor signals in digital ads—when publishers need it, how it differs from Consent Mode, and how to verify live consent with a scanner.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

July 2026

Reading time

5 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

Define What is IAB TCF in plain language: the IAB Europe Transparency and Consent Framework for sharing consent signals across digital advertising vendors—and clarify when it matters versus Consent Mode v2, plus state that GDPRChecker is not an IAB TCF CMP.

This guide is written for Publishers, marketers, and website owners evaluating IAB Europe Transparency and Consent Framework requirements versus Consent Mode and a normal cookie banner.

What it means

What is IAB TCF? It is the IAB Europe Transparency and Consent Framework: a standardized way for Consent Management Platforms (CMPs) and ad tech vendors to record and share user consent and transparency choices for digital advertising.

TCF uses purpose and vendor lists plus a compact TC String so participating partners can read the same consent signal instead of inventing proprietary formats.

CMPs that implement TCF typically expose an API (often referred to as __tcfapi) so tags and wrappers can query consent state before loading personalized ads.

IAB TCF is not the same as Google Consent Mode v2. Consent Mode tells Google tags how to behave for storage and ads parameters; TCF is an industry consent-sharing protocol used heavily in the open web ad ecosystem.

Google Certified CMP requirements for certain publisher products (for example AdSense, Ad Manager, or AdMob in regulated regions) commonly sit on top of TCF-capable CMPs—confirm on Google’s current documentation for your product.

Most SaaS and lead-gen sites that only run GA4/GTM/Google Ads measurement need a lawful Reject-capable banner plus Consent Mode and tag gating—not automatically a full TCF publisher stack.

GDPRChecker is not an IAB TCF CMP, does not issue TC Strings, and does not provide __tcfapi or Partner/Certified onboarding. Use it to scan for pre-consent cookies and Consent Mode-related behavior on your live URL.

Why it matters

Teams searching What is IAB TCF often confuse TCF certification marketing with the Consent Mode work they actually need for GA4.

Publisher and agency stacks fail audits when they assume any cookie banner equals TCF compliance for Google publisher ads.

A clear definition page anchors the TCF cluster and routes readers to Path A (Consent Mode + banner + scan) or Path B (Certified/TCF CMP elsewhere).

Common mistakes

  • Assuming IAB TCF is required for every EU website that uses Google Analytics.
  • Equating Consent Mode v2 configuration with TCF certification.
  • Buying a “TCF CMP” for a measurement-only site while leaving GTM unconstrained before consent.
  • Claiming GDPRChecker is IAB TCF compliant or a Google Certified CMP.
  • Treating a TC String as proof that no pre-consent cookies exist without verifying Network behavior.
  • Copying outdated TCF version notes without checking current IAB Europe and Google product docs.

Practical checklist

  1. Classify your stack: measurement (GA4/GTM/Ads tags) vs publisher ad monetization (AdSense/Ad Manager/AdMob).
  2. If measurement-only: implement Reject-capable consent UX, Consent Mode v2 denied defaults before tags, and verify with a clean-session scan.
  3. If publisher ads require Certified CMP / TCF: select a listed CMP and follow Google’s and IAB Europe’s current requirements outside GDPRChecker.
  4. Do not list TC String, __tcfapi, or Certified status as GDPRChecker deliverables.
  5. Private-window test: no non-essential cookies/requests before interaction; Reject keeps marketing tags blocked.
  6. Run GDPRChecker on the production URL for technical evidence; rescan after CMP or GTM publishes.

How GDPRChecker helps

GDPRChecker’s free scanner helps answer a practical follow-up to What is IAB TCF: does your live site still set cookies or fire ad tech before any choice—regardless of which CMP framework you use?

Use scan findings to fix script order and blocking for Path A (Consent Mode) stacks; keep TCF Certified CMP work with a listed vendor when Path B applies.

GDPRChecker supports Consent Mode v2-oriented diagnostics and runtime checks; it is not an IAB TCF CMP and does not replace TCF certification.

FAQ

What is IAB TCF?
IAB TCF is the IAB Europe Transparency and Consent Framework. It standardizes how CMPs capture consent for advertising purposes and how vendors read that signal (including via a TC String) so publishers and ad partners can operate with shared transparency and consent records.
What does TCF stand for?
Transparency and Consent Framework. It is maintained under IAB Europe’s policy and technical specifications for digital advertising consent signalling.
Is IAB TCF the same as Google Consent Mode?
No. Consent Mode is Google’s tag signalling API (defaults and updates for parameters such as analytics_storage and ad_storage). TCF is an industry framework for CMP–vendor consent sharing. Many Google publisher products expect a Certified CMP that implements TCF; measurement sites often need Consent Mode even when they do not run a full TCF publisher stack.
Do I need IAB TCF if I only use GA4?
Usually no. GA4 and many Google Ads measurement setups need valid consent UX, Consent Mode v2, and tag gating. TCF-centric Certified CMP requirements are primarily tied to specific Google publisher advertising products in regulated regions—confirm on Google’s current docs for your products.
What is a TC String?
A TC String is the encoded consent record produced by a TCF-implementing CMP. Participating vendors can decode it to learn which purposes and vendors were consented. GDPRChecker does not generate or validate TC Strings as a TCF CMP.
Is GDPRChecker an IAB TCF CMP?
No. GDPRChecker is not an IAB TCF CMP, does not implement __tcfapi for certification, and is not a Google Certified CMP or Partner product. It provides consent banner/runtime options and scanners for technical verification alongside whatever CMP your use case requires.
Where should I go next after this definition?
Read Consent Mode v2 vs Google Certified CMP and Google CMP Requirements for the Path A vs Path B decision, Google CMP Setup Guide for the clarified setup fork, then run a GDPRChecker scan on your live URL.

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification