How do ad tech companies prove they handle personal data responsibly? Every publisher and advertiser working within the European ad ecosystem needs a clear answer to this question. The IAB Transparency and Consent Framework (TCF) was built to solve exactly this problem. At the centre of this framework sit IAB TCF 2.0 vendors, the third-party companies that collect, process, and use personal data for advertising, analytics, and content personalisation.
Without a standardised system, every vendor would handle consent differently. That would create confusion for publishers, regulators, and users alike. The IAB TCF 2.0 vendor registration process brings structure and accountability to the entire programmatic supply chain. It gives publishers a verified list of vendors they can trust with their audience data.
This guide covers everything you need to know about IAB TCF 2.0 vendors. You will learn what vendors are, how the Global Vendor List operates, what purposes vendors declare, and how the consent signal travels from a user’s browser to every vendor in the chain. Whether you manage a publishing operation, run ad tech infrastructure, or oversee compliance, this guide gives you the clarity you need.
IAB TCF 2.0 vendors are third-party companies registered under the IAB Europe Transparency and Consent Framework. These vendors typically do not have a direct relationship with end users.
The TCF defines a vendor as any company that processes personal data but lacks direct access to end users. These companies operate behind the scenes of digital advertising. They rely on publishers and consent management platforms (CMPs) to collect and pass along consent signals on their behalf.
Vendors include demand-side platforms (DSPs), supply-side platforms (SSPs), ad exchanges, data management platforms, and measurement providers. Each vendor must register with IAB Europe and agree to follow TCF policies before they can receive consent signals from any CMP.
A wide range of ad tech and data companies register as IAB TCF 2.0 vendors. Ad servers like Google Ad Manager process ad requests for publishers globally. Analytics platforms such as Adobe Analytics track user behaviour across websites. Retargeting providers build audience segments for personalised ad delivery.
Attribution and measurement companies also participate in the vendor list. Social media advertising platforms, video ad networks, and identity resolution providers all hold vendor registrations. The common thread is that each of these companies processes personal data obtained through publisher websites.
Every registered vendor receives a unique numeric ID within the Global Vendor List (GVL). This ID serves as the universal identifier that CMPs, publishers, and other vendors use to reference a specific company. When a user grants or denies consent, the consent string stores decisions mapped to these vendor IDs.
The GVL currently includes over 1,000 registered vendors. It functions as a machine-readable registry that CMPs download automatically. This standardisation ensures that every participant in the ecosystem speaks the same language when it comes to user consent.
The Global Vendor List is the backbone of the entire TCF consent ecosystem. It provides the structured data that CMPs need to display vendor information to users.
The GVL stores detailed information about every registered vendor. This includes the vendor’s name, ID, privacy policy URL, and the specific purposes for which they process data. It also lists the legal bases each vendor relies on, whether consent or legitimate interest.
Beyond vendor details, the GVL defines the standard purposes, special purposes, features, and special features available under the framework. It also includes data categories and retention periods that vendors must declare. This level of detail gives publishers and CMPs everything they need to build transparent consent interfaces.
IAB Europe updates the Global Vendor List on a weekly basis. New vendors appear as they complete registration and pass the compliance review. Existing vendors can update their declared purposes or features at any time, and those changes reflect in the next GVL release.
CMPs automatically download the latest version of the GVL to stay current. This regular update cycle ensures that consent interfaces always reflect the most accurate vendor information. Publishers benefit because they never have to manually track changes to vendor declarations.
Consent management platforms rely on the GVL to populate their consent banners and preference centres. When a CMP loads on a publisher’s website, it reads the GVL to determine which vendors operate on that site. It then displays those vendors to the user along with their declared purposes.
The CMP generates a consent string based on the user’s choices. That string encodes which vendors received consent and for which purposes. This string then travels through the ad tech supply chain so every vendor can check whether it has permission to process that user’s data. The best consent management platforms make this process seamless for both publishers and users.
Every IAB TCF 2.0 vendor must declare the specific data processing purposes it requires. The framework provides a standardised list of purposes to keep things consistent.
The TCF defines 11 standard purposes that cover the full range of data processing activities in digital advertising. Each vendor selects the purposes relevant to its operations during registration. These purposes form the core of what users see in consent banners.
Purpose 11 was added later to address non-advertising content selection. It provides a specific legal pathway for content personalisation that does not involve ad targeting.
Beyond the standard 11 purposes, the TCF also defines special purposes and special features. Special purposes allow vendors to process data for security and fraud prevention. These cannot be objected to through the framework because they serve essential operational functions.
Special features, on the other hand, require separate opt-in vs opt-out choices from users. The two defined special features are precise geolocation data and device scanning. Vendors that rely on these features must collect explicit consent independently from standard purpose consent.
The TCF allows two legal bases for data processing: consent and legitimate interest. Under TCF 2.0, vendors could use legitimate interest for several advertising-related purposes. This gave vendors more flexibility but raised concerns from data protection authorities.
TCF 2.2 significantly changed this landscape. Vendors can now only use consent as the legal basis for advertising and content personalisation purposes. Legitimate interest remains available for limited operational purposes like security and fraud detection. This shift brought the framework closer to how regulators interpret GDPR requirements.
The consent flow under the TCF involves multiple participants working together in real time. Understanding this flow is essential for anyone managing vendor relationships.
When a user makes consent choices through a CMP banner, the CMP encodes those decisions into a TC string. This string is a compact, base64-encoded data structure. It records which vendors received consent, which purposes were approved, and whether legitimate interest applies.
The TC string gets stored in the user’s browser and made available through a standardised API. Ad tech vendors read this string before processing any personal data. If a vendor finds that it lacks consent for a specific purpose, it must refrain from that processing activity. This mechanism ensures that consent-driven ad personalisation respects every individual user’s choices.
CMPs act as the bridge between users and vendors. They present the consent interface, collect user preferences, and generate the TC string. A CMP must be registered with IAB Europe and hold a valid CMP ID to participate in the framework.
Publishers choose which CMP to use on their websites. The CMP then loads the GVL and identifies which vendors the publisher works with. It presents those vendors to users in a structured, readable format. The quality of the CMP directly affects consent rates and, by extension, how much data vendors can process.
If a user rejects consent for a specific vendor, that vendor’s ID gets flagged as denied in the TC string. The vendor must then exclude that user from any data processing that requires consent. This includes ad targeting, profile building, and personalised content delivery.
Some vendors may still process data under special purposes that do not require consent. However, these are limited to security and technical operations. For all advertising and measurement activities, a denial means a full stop. Managing consent fatigue is critical for publishers who want to maintain healthy consent rates across their vendor stack.
The registration process is straightforward but requires commitment to ongoing compliance. Any ad tech company that processes personal data through publisher websites should consider registering.
Vendors must apply through the GVL Portal managed by IAB Europe. The application includes basic company details, a valid privacy policy URL, and a declaration of processing purposes. The annual registration fee is EUR 1,575. This fee covers inclusion in the GVL and access to the TCF ecosystem.
Only companies that genuinely process personal data through publisher integrations should register. The TCF is not designed for companies that only handle first-party data or operate entirely outside the ad tech supply chain.
After submitting the application, vendors must complete a compliance questionnaire. This questionnaire verifies that the vendor understands TCF policies and agrees to follow them. It covers topics like data processing transparency, consent signal handling, and privacy policy requirements.
Once the questionnaire is approved, the vendor receives a unique ID and gets listed in the GVL. From that point forward, CMPs around the world can display the vendor in their consent interfaces. Publishers can also identify and manage the vendor through their CMP dashboards.
Registration is not a one-time event. Vendors must keep their GVL information current at all times. If a vendor adds new processing purposes or changes its legal basis, it must update its GVL entry promptly. Vendors must also ensure their scripts and tags respect TC strings in real time.
IAB Europe conducts compliance monitoring and can take enforcement action against non-compliant vendors. Penalties range from public disclosure of non-compliance to removal from the GVL. A removed vendor loses the ability to receive consent signals, effectively cutting it off from the European programmatic ecosystem.
Compliance with the TCF is not just about following rules. It directly affects business operations, revenue, and reputation across the ad tech supply chain.
Data protection authorities across Europe actively monitor how the ad tech industry handles consent. Non-compliant vendors risk enforcement action under the GDPR, which can result in fines of up to 4% of global annual turnover. The Belgian Data Protection Authority has already taken action against IAB Europe itself over TCF-related concerns.
Vendors that ignore TCF requirements also face the risk of being reported by IAB Europe to relevant authorities. This creates a dual layer of enforcement. Both the self-regulatory TCF system and government regulators can hold vendors accountable for mishandling consent data.
Publishers increasingly require their ad tech partners to maintain TCF compliance. A vendor that lacks GVL registration simply cannot participate in programmatic auctions on compliant publisher websites. This exclusion translates directly into lost revenue opportunities.
Understanding how IAB TCF v2 helps protect programmatic ad revenue is essential for any vendor operating in the European market. Compliance opens doors to premium publisher inventory and high-value audience segments that non-compliant vendors cannot access.
TCF compliance signals to the market that a vendor takes data privacy seriously. Publishers, agencies, and brands all prefer working with vendors that demonstrate clear, verifiable consent handling. This trust factor becomes a competitive advantage in vendor selection processes.
Transparency also matters for end users. When users see a well-structured consent interface listing verified vendors, they feel more confident about granting consent. This benefits the entire ecosystem by improving overall consent rates and maintaining the viability of consent-based marketing.
The framework has evolved significantly since TCF 2.0 launched in 2019. Vendors must understand these changes to stay compliant.
The biggest shift from TCF 2.0 to TCF 2.2 was the removal of legitimate interest as a legal basis for advertising purposes. Under TCF 2.0, vendors could claim legitimate interest for ad targeting and measurement. TCF 2.2 closed this option entirely for personalised advertising.
This change aligned the framework with rulings from multiple European data protection authorities. These authorities consistently held that consent is the only appropriate legal basis for processing personal data for ad personalisation. Vendors that previously relied on legitimate interest had to restructure their consent flows.
TCF 2.2 also introduced clearer rules around how consent must be presented. CMPs can no longer pre-select vendor consent options. Users must actively grant consent through affirmative action. This raised the bar for what counts as valid consent under the framework.
For vendors, this meant lower initial consent rates but higher-quality consent signals. The data they now receive comes from users who made genuine, informed choices. This actually strengthens the legal standing of consent-based data processing and reduces the risk of regulatory challenges. Keeping up with Google Consent Mode v2 alongside TCF changes is equally important.
IAB Europe has released TCF 2.3, which introduces additional technical requirements. This version focuses on preventing consent string manipulation and improving signal integrity. It requires CMPs to implement new validation mechanisms that verify consent string authenticity.
For vendors, TCF 2.3 means greater confidence in the consent signals they receive. It also means stricter technical requirements for how they read and interpret TC strings. Vendors should review their integration code and ensure compatibility with the latest specification.
IAB TCF 2.0 vendors form the foundation of consent-based data processing in European digital advertising. The Global Vendor List, standardised purposes, and structured consent strings create a transparent system that benefits publishers, vendors, and users alike. As the framework continues evolving through TCF 2.2 and TCF 2.3, staying informed and compliant is the only path to sustainable growth in programmatic advertising.
Seers helps you stay compliant with IAB TCF requirements through an automated consent management platform. It handles vendor integration, consent collection, and TC string generation so you can focus on running your business.
START FREE TODAYAn IAB TCF 2.0 vendor is a third-party company registered with IAB Europe under the Transparency and Consent Framework. These companies process personal data for purposes like advertising, analytics, and content personalisation. They must declare their processing purposes and respect user consent decisions transmitted through the TC string generated by consent management platforms.
The Global Vendor List currently includes over 1,000 registered vendors. IAB Europe updates this list weekly as new vendors complete registration and existing vendors modify their declarations. The exact number fluctuates regularly. CMPs automatically download the latest version to ensure publisher consent interfaces always reflect current vendor information.
A vendor processes personal data for advertising, measurement, or personalisation purposes. A CMP collects and manages user consent preferences on behalf of publishers. Vendors receive consent signals through TC strings that CMPs generate. Both must register separately with IAB Europe, and each plays a distinct role within the consent supply chain.
A vendor cannot receive standardised consent signals through the TCF without GVL registration. Unregistered vendors are invisible to CMPs and cannot appear in consent interfaces. While a company can still process data outside the TCF framework, it must establish its own legal basis independently. Operating outside the GVL limits access to European programmatic inventory.
IAB Europe can publicly disclose the vendor’s non-compliance and report it to relevant data protection authorities. In serious cases, the vendor gets removed from the Global Vendor List entirely. Removal cuts off the vendor from receiving consent signals through any CMP. This effectively blocks the vendor from participating in compliant programmatic advertising across Europe.
TCF 2.2 removed legitimate interest as a legal basis for advertising and personalisation purposes. Under TCF 2.0, vendors could rely on legitimate interest for several processing activities. TCF 2.2 requires consent as the sole legal basis for these purposes. It also introduced stricter rules around how CMPs present consent choices to users.
Special purposes allow vendors to process data for essential operational functions like security and fraud prevention. These purposes cannot be objected to by users through the consent framework. There are three defined special purposes in the TCF. They exist because certain data processing activities are necessary for safe and functional website operations.
Vendors must pay an annual registration fee of EUR 1,575 to participate in the TCF. This fee covers inclusion in the Global Vendor List and access to the TCF ecosystem. The registration process also requires completing a compliance questionnaire and maintaining up-to-date vendor information throughout the membership period.
Publishers select vendors through their CMP configuration. They can choose to include all GVL vendors or create a curated list based on their ad tech stack. Many publishers audit vendors based on declared purposes, data retention policies, and reputation. A smaller, well-managed vendor list often leads to higher consent rates and cleaner data operations.
A TC string is a compact, base64-encoded data structure generated by a CMP after a user makes consent choices. It records vendor-level and purpose-level consent decisions. Vendors read this string through a standardised API before processing any personal data. If the string shows that a vendor lacks consent for a specific purpose, the vendor must not process data for that purpose.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.
Take our Free Cookie Audit and find out
Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.
United Kingdom
24 Holborn Viaduct
London, EC1A 2BN
Get our monthly newsletter with insightful blogs and industry news
By clicking “Subcribe” I agree Terms and Conditions
Seers Group © 2026 All Rights Reserved
Terms of use | Privacy policy | Cookie Policy | Sitemap | Do Not Sell or Share My Personal Information.