IAB Transparency and Consent Framework (TCF) 2.4
The IAB Transparency and Consent Framework (TCF) 2.4 is a technical standard that allows publishers and advertisers to collect, manage, and share user consent signals for compliance with the General Data Protection Regulation (GDPR) and ePrivacy Directive in the European Union.
CookieHub is a registered CMP (Consent Management Platform) that supports TCF 2.4 out of the box.
What is the purpose of TCF 2.4?
The framework defines how websites collect and store user consent preferences and communicate those preferences to third-party vendors that process personal data, such as ad networks, analytics providers, and retargeting platforms.
It ensures that:
- Vendors can only access or process personal data with a valid legal basis (such as consent)
- Users are clearly informed about:
- Why their data is being used (purposes)
- Which vendors are involved
- What data is collected
- How long data is retained
- Consent choices are standardized, structured, and passed in a machine-readable format
How it works
When TCF 2.4 is enabled for a region, CookieHub:
- Displays a standardized consent dialog based on the IAB’s user interface requirements
- Retrieves the Global Vendor List (GVL) containing all vendors registered in the TCF
- Allows users to accept or reject:
- Purposes (e.g., personalized ads, content measurement)
- Special features (e.g., precise geolocation)
- Vendors that will process their data
- Generates a Transparency and Consent (TC) string, which contains the user’s choices
- Stores the consent string and shares it with participating vendors through JavaScript or via the CMP API
The TC string includes:
- Consent or objection to each purpose
- The selected legal basis (e.g., consent or legitimate interest)
- User preferences per vendor
CookieHub’s implementation
CookieHub fully manages TCF 2.4 on your behalf.
When you enable the TCF 2.4 framework for a region:
- The correct dialog is displayed automatically with no additional configuration needed
- CookieHub:
- Fetches the Global Vendor List (GVL)
- Shows the list of vendors and purposes to users
- Generates and updates the TC string in real time
- Makes the TC string available to vendors via the IAB API
- If Google is included in the vendor list, Google Consent Mode v2 and Additional Consent Mode are automatically enabled. See how TCF purposes map to Consent Mode parameters.
The consent dialog is generated automatically and follows IAB’s specifications. A few choices remain yours, and they are made in the IAB TCF settings section of the domain’s settings: which vendor list the dialog offers, how it treats vendors’ legitimate interest claims, and which purposes, special features and stacks it presents.
What changes in TCF 2.4
TCF 2.4 accompanies TCF Policy version 5.0.b. Web CMPs must comply by 23 October 2026. Everything below is handled automatically — there is nothing to configure.
A Features section in the preference centre
The consent dialog’s second layer now includes a Features section listing the three TCF Features, each with its description and the IAB’s plain-language illustration.
Features are not a choice. They are means of processing used only in pursuit of purposes you are asked about, so the section is read-only by design and carries the IAB’s standard explanation saying exactly that. It is deliberately kept apart from the purpose toggles above it: TCF 2.4 prohibits presenting a Feature next to a control that cannot be disabled, because that invites users to think they chose it.
Before 2.4, these three Features appeared only inside an individual vendor’s entry under Partners, so most visitors never saw them.
All three Special Purposes are now named
The dialog previously named two. “Save and communicate privacy choices”, added in TCF 2.2, is now disclosed alongside the other two.
Illustrations throughout
Every purpose, Feature and Special Feature shown inside a vendor’s entry now carries its IAB illustration, not just its name and description.
Special Feature 2 has a new name
“Identify devices based on information actively requested”, previously “Actively scan device characteristics for identification”. CookieHub reads these names from the Global Vendor List, so this appeared automatically when the IAB published it — no action was needed and none is needed now.
When to use TCF 2.4
Use the IAB TCF 2.4 framework if:
- You serve personalized ads in the EU or UK using platforms that require TCF (such as Google Ads, AdSense, or Meta Ads)
- You need to provide structured, vendor-level consent to a wide range of ad tech providers
- Your advertising partners or header bidding providers require a valid TC string
If you do not use advertising vendors that require the TCF, you can use CookieHub Choices instead for category-based consent.
How to enable TCF 2.4 in CookieHub
- Go to Dashboard → Domain list
- Click on the domain you want to configure
- Click Settings
- Under Regional settings:
- Set the framework to IAB TCF 2.4
- Set the consent type to Explicit consent / opt-in
- Open the IAB TCF section, which now appears in the left menu, to select your vendor list and review which purposes, special features and stacks the dialog presents
- Save your changes
The TCF interface will appear automatically for users in the selected region(s), and the consent string will be generated and shared with vendors.
See IAB TCF settings for what each setting in that section does.
Summary
| Feature | CookieHub Support |
|---|---|
| TCF 2.4 consent UI | ✅ Yes |
| Global Vendor List integration | ✅ Yes |
| Per-purpose and per-vendor control | ✅ Yes |
| Automatic TC string generation | ✅ Yes |
| Signals shared with vendors | ✅ Yes |
| Google Consent Mode + AC Mode support | ✅ Yes (if needed) |