Last Updated: March 25, 2026
The IAB EU's TCF is intended to do two things: (1) their personal data will be collected and processed for interest-based advertising purposes, and (2) translate a user's consent into a standardized value that can be interpreted and honored by those companies utilizing the Framework. Version 2.0 of the TCF adds additional processing purposes (10 vs 5), keeps the same number of Features as before (3), adds new Special Features (2) and new Special Purposes (2).
The TCF also allows IAB EU Vendors to detect if an end-user is within the scope of GDPR in order to determine acceptable courses of action for IAB EU Vendors regarding prior notice and consent. The TCF works with TrustArc CMPs configured for both TMS/API integration (in both zero and non-zero cookie load configurations) as well as vendor opt-outs and provides appropriate zero-cookie load capability for IAB EU Vendors.
The IAB EU TCF is supported through the use of a compliant user interface. TCF v2 has more stringent UI requirements compared to v1 and integration of the functionality with other TrustArc UIs is not supported. See the Content Required by the IAB EU section below for more details. Full function of the TCF requires deployment of a script stub along with the TrustArc CMP script. This script is created and maintained by TrustArc using guidelines set by the IAB EU and enables the TCF to set opt-in preferences through the TrustArc CMP as well as to allow IAB EU Vendors to determine if a user is within the scope of GDPR. The stub needs to be initialized before or very near the time when the CMP script runs as some of the IAB actions depend on the CMP running.
Additionally, please note that a declaration of adherence to the IAB EU TCF is required to be made, such as within your privacy statement. You can find more information under the Notable Items section.
Finally, while the TrustArc CMP does support a variety of design and styling customizations, the IAB EU incorporates accessibility into their requirements. The two primary calls to action (such as Accept All and Decline All buttons) on the 1st layer have matching text treatment and, for each, a minimum contrast ratio of 5:1. You will need to ensure your styling changes meet this standard.
Your dedicated Technical Account Manager (TAM) will reach out to you to set up a call, generally an hour in length, to go over the details of what you can expect during the onboarding, implementation, and deployment phases. This is your chance to learn more about the process, ask questions, and prepare to get your CMP live and operational. You will cover:
a. A demo of the TrustArc Website Monitoring manager to get you familiar with how the scan functions and the results it captures will be provided.
a. Your TAM will gather the necessary details needed to configure your CMP's behavior to align to your expectations.
a. You will be informed of your design styling options. Note that the IAB EU does have some UI requirements that must be followed in order to be considered compliant with the TCF (more details below).
a. TrustArc's Website Monitoring Manager will capture the various 3rd party vendors in operation on your site(s). We will then provide you the results of the scan(s), broken down into default categorizations. Non-IAB EU vendors will be allocated to Required, Functional, or Advertising groupings (unless you are using custom categorizations) while IAB EU Vendors will be grouped into purposes and/or stacks, per the IAB EU's TCF. Note that you will have control over the categorization of non-IAB EU vendors and use of their default groupings is not required. However, IAB EU Vendors cannot be moved or changed from the purposes and/or stacks they belong to under the TCF.
Example:
a. As stated above, IAB EU Vendors are pre-set to certain purposes and/or stacks. This is controlled by the IAB EU's Global Vendor List (GVL). TCF v2 has become more granular in the amount and type of processing purposes, of which there are now a possible 10. To help provide a better user experience and not initially present too many choice options, the TCF v2 supports the use of 'stacks', which are simply combinations of purposes.
When viewing the scan results, we will provide you with a list of the possible purpose/stack options available for you to use in your CMP, based on the IAB EU vendors that were detected to be operating on your site(s) and the information provided by the GVL. Please review the non-IAB EU vendor categorizations, as well as the possible stack/purpose combinations with your legal team to determine how you would like to account for these 3rd parties.
While there are no specific requirements on which purpose/stack combination is used, you may choose to use the combination that offers the fewest number of choice options to site visitors for user experience purposes.
One of the main differences between v1 and v2 of the TCF is an additional level of transparency that the IAB EU now requires. This means new/additional content when it comes to what must be displayed in the CMP UI compared to v1. TrustArc as a registered CMP of the IAB TCF, is required to meet the policy requirements of the IAB. The language in the banner and modal have been carefully vetted to comply with these policies.
Previous IAB Expressed design aligns with WCAG 2.2 Standard
Updated IAB Expressed design aligns with WCAG 2.2 Standard
*For reference only. Since the UI is dynamic, this example shows content and choice options that may not be applicable to your implementation.
The content has been color-coded to indicate the following:
For example:
This sentence indicates that the website and 3rd parties collect and process personal information and provides at least one example of what that data is.
This content indicates that some Vendors are not relying on user consent as their legal basis for collecting and processing personal data. Instead, they are using Legitimate Interest. If this applies to any Vendor in use by the CMP, then some form of this disclosure is required by the IAB EU. If no Vendors are using Legitimate Interest, then this verbiage should not be used.
Previous Verbiage
Updated Verbiage
This content does two things: 1) It indicates that the user's preferences will be applied exclusively to the website they are currently visiting. 2) The second sentence clearly states that a user can withdraw or change their preferences in the future and provides an indication of how they can do so.
Layer 2 of the CMP UI will provide a comprehensive list of all IAB EU and non-IAB EU content and vendors, as well as give users additional granularity in the control of their data.
All IAB EU-specific content starts under the PURPOSES tab and carries down to the PARTNERS section below. Any applicable Purposes, Special Purposes, Features, and Special Features will be displayed to users for them to submit a preference for.
Additional content details and what the TCF does/does not allow
A stub script (found on the IAB EU Stub Script section) must be added to your site(s) and initialized before or at the same time as the TrustArc CMP script. The stub needs to be present on every page where the TrustArc CMP script is also present. The script can be run in the <head> section of the page or deployed through a TMS. For testing and QA purposes, you may want to set up an implementation within your staging environment.
A main function of the IAB EU stub is to determine if a user is a.) within the scope of GDPR and b.) if the TrustArc CMP script has run. This is done so that IAB EU Vendors are able to know if consent is needed prior to cookies being dropped and also when it is appropriate to query for consent information. Two boolean variables are used for these purposes:
cmpLoaded
'True/False'. Indicates if the TrustArc CMP script is running or if just the stub script is running. IAB EU Vendors interpret a 'false' value to mean that the CMP script has not loaded and therefore none of the usual checks on the user has been done (geo-ip detection, expressed/implied consent, etc). For as long as the value remains 'false', IAB EU Vendors will consider this as no consent and will not drop any cookies or check for consent. TrustArc's version of the IAB EU stub sets this variable to 'true' as long as our CMP script runs.
NOTE: For consumers in a non-provisioned country 'cmpLoaded' will always have the value of 'false'.
gdprApplies
'True/False'. Indicates if the user is within the scope of GDPR, based on the observed IP address of the user's device and the desired behavior configuration your technical account manager has set on our system back-end. For example, having your CMP set to detect UK will return a 'gdprApplies' value to 'true' while anon-provisioned country (US) sets the value to 'false'. IAB EU vendors interpret a 'true' value to mean they need to wait for consent to be set before cookies can be dropped and/or data be collected.
Once the stub script and CMP scripts are in place, you can ping for the above values with the following command in the browser console:
__tcfapi("ping", 2, function(e) {
console.log(e)
});
For example:
The IAB EU TCF consent string is recorded in cookie 'euconsent-v2'. The expiration is set to the same time as the TrustArc cookies (13 months). This is the alpha-numeric value that IAB EU Vendors will observe to determine whether consent has been given for them to collect and process data.
Your TAM will perform a final check of your implementation prior to it going live in your production environment. A portion of the review will be technical (ensuring stub and CMP scripts are performing correctly, gdprApplies values are accurate, etc.) and some of the review will be to verify that TCF policies are being followed. As a registered CMP, TrustArc must ensure that all deployments are compliant before going live.
The IAB has released an extension that allows for validating an IAB implementation. The TAM team and the client can review the checklist to ensure that the implementation meets all the requirements. Some tasks are automated, while others need manual checking. For further details on the CMP Validator, please follow the CMP Validator User Guide. This other link lets you find the CMP Validator directly on the Chrome Web Store.
With a CMP/TMS integration you should not have to add the firing/experience rules to tags belonging to IAB EU Vendors, as vendors should already be checking for the consent string in the 'euconsent-v2' cookie to determine whether they are allowed to execute and collect data. Adding or leaving the firing/experience rules attached to the IAB EU vendor tags in the TMS is also acceptable as the end result is the same – the user's consent preference is respected.
The CMP will automatically translate based on the detected language setting of the end-user's browser. The IAB EU provides translations for their content automatically in the following languages:
| Bulgarian | Estonian | Latvia | Russian |
| Catalan | Finnish | Maltese | Slovak |
| Czech | French | Dutch | Slovenian |
| Danish | Croatian | Norwegian | Swedish |
| German | Hungarian | Polish | Turkish |
| Greek | Italian | Portuguese | Chinese |
| Spanish | Lithuanian | Romanian |
Due to certain content being provided directly by the IAB EU's GVL, we are unable to support languages outside of this list. If more languages are added to the GVL, we will add support for those.
Per the TCF Policy:
A Publisher must make a public attestation of compliance with the Policies in a prominent disclosure, such as in a privacy policy. This language must at a minimum include: (i) an affirmation of its participation in the IAB Europe Transparency & Consent Framework; (ii) an affirmation of its compliance with the Policies and Specifications with the Transparency & Consent Framework; (ii) the IAB Europe assigned ID of the CMP that the publisher uses. Example:
“<Organisation> participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. [operates|uses] the Consent Management Platform with the identification number <CMP ID>.”
TrustArc CCM simplifies the stub management by allowing the system to load the stub from our end. Clients no longer need to add the stub code on their websites. The stub will only load for locations that have IAB enabled. In addition, if clients already have an IAB stub implemented on their sites, the new setting will not override the existing stub code.
Your Technical Account Manager is responsible for enabling this setting. Once enabled, the following stub script needs to be added to the client's site before the notice script:
<script src="https://consent.trustarc.com/iabasset/iabTcfStubV22.js?domain={domain}"></script>
Sample Script
<html>
<head>
<script src="https://consent.trustarc.com/iabasset/iabTcfStubV22.js?domain={domain}"></script>
<script async="async" src="https://consent.trustarc.com/notice?domain={domain}&iab=true"></script>
</head>
<body>
<div id="consent_blackbar"></div>
<div id="teconsent"></div>
</body>
</html>
For more information, see the stub script in the link below:
https://github.com/InteractiveAdvertisingBureau/iabtcf-es/blob/master/modules/stub/src/stub.js
IAB TCF v2.2 support ensures that your Consent Management Platform (CMP) aligns with the latest IAB TCF standards.
IAB TCF v2.2 improvements are as follows:
If you are a publisher serving Ads in the EEA and UK and you use Google AdSense, Ad Manager, or Admob, you are required to use a CMP that is certified with Google (such as TrustArc) and have integrated with IAB TCF by January 16, 2024. Otherwise, only limited ads will be eligible to serve on EEA or UK traffic.
IAB TCF v2.2 support facilitates improved privacy compliance, transparency, and standardization in the digital advertising ecosystem while giving users more control over their data. Not adhering to IAB policies carries significant repercussions (losing customer trust and compliance), as it can lead to expulsion of the CMP from the list of IAB TCF v2.2 compliant CMPs.
After 4 October 2024, new TC Strings must be created under the policies version 5. TC Strings created before 4 October 2024 under the policies version 4 will remain valid. CMP Framework UIs will not need to apply for re-validation. The new Policies do not require CMPs to resurface the Framework UIs. The iteration comprises the introduction of a new “Special Purpose 3” (“Save and communicate privacy choices”), which has been added to the TCF purposes taxonomy and intends to facilitate how TCF participants establish a legal basis for processing users' privacy choices recorded in the form of a TC String- when participants consider the latter to be personal data from their perspective. Please check this link for more information.
How can you be TCF v2.2 compliant?
If you are a publisher and target users in the EEA or UK using our IAB TCF solution, we strongly recommend you begin testing IAB TCF v2.2. Last November 20, 2023, TrustArc and other CMPs were obligated to update customers using our IAB TCF solution to TCF v2.2. This is a requirement for all CMPs registered with the IAB.
For publishers working with Google Ads and partners, the following page provides some scenarios that can help when investigating issues. For more information, visit the Troubleshooting TCF v2.0 implementation website.
If a website intermittently displays Google Ads, please make sure that Google Advertising Products is listed as an IAB Vendor. Also, ask your client to confirm the list of Ad Partners that need to be added. The piggybacking vendors could dynamically change according to the Ads Network's bidding process, and thus, Ads might fail to load.
For EU users, Google has the option to serve personalized and non-personalized ads. The legitimate interest setting will define the behavior for Ads publishing when the user launches the website and consent has not been given. For more details about the requirements, please see Publisher integration with the IAB TCF v2.0.
Google also offers a console to check how ads are being delivered. For more information, please see Google Publisher Console.