Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIsConsent management and Google Consent Mode · Lesson 3 of 14

Consent management: CMPs, IAB TCF 2.3 and GPP

Article · 8 min · 9 min lecture

Video lecture

Consent management: CMPs, IAB TCF 2.3 and GPP

14 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 14

Consent management

  • What a CMP must do
  • IAB TCF 2.3 and GPP
  • Lawful, effective design
  • Checking consent state

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

A consent management platform (CMP) presents choices to users, records their decisions, and makes those decisions available to your tags and vendors. A good CMP:

  • Shows a banner/dialog with clear purposes and equally prominent "Accept" and "Reject" options where required.
  • Blocks non-essential tags until consent (or passes consent state to tags designed to adapt, like Google Consent Mode).
  • Stores proof of consent (what text the user saw, when, which choices).
  • Exposes consent state via APIs: Google Consent Mode signals, the IAB TCF __tcfapi, the IAB GPP __gpp, and its own JavaScript events.
  • Supports region rules (opt-in in the EU/UK, opt-out in US states, honoring GPC).
  • Lets users change their mind easily (a persistent link or icon).

Google requires publishers and advertisers using certain Google products with EEA/UK traffic to use a Google-certified CMP in some contexts (for example, for AdSense/Ad Manager/AdMob publishers). Check Google's current requirements for your use case.

The TCF is a standard from IAB Europe for communicating consent across the ad-tech supply chain using a TC string. It defines purposes (e.g., store/access information on a device, use limited data to select ads, measure ad performance) and a Global Vendor List. The current version is TCF v2.3; IAB Europe set a transition deadline of 28 February 2026, after which new TC strings must follow v2.3 (the main change is a mandatory signal proving which vendors were disclosed to the user). If you run a CMP that supports TCF, confirm it is on v2.3.

Do you need TCF? If you are a publisher monetizing with programmatic ads, usually yes. If you are an advertiser measuring your own site with Google, Meta and TikTok, TCF is optional; many advertisers use a non-TCF CMP with Google Consent Mode and tag-level blocking.

IAB Global Privacy Platform (GPP)

For the US state patchwork, IAB Tech Lab's GPP carries multiple jurisdictions' signals in one string (including US national and state sections). Ad-tech vendors increasingly expect GPP strings for US traffic.

Designing a lawful, effective banner

Regulators (for example, the ICO, the French CNIL and the EDPB) have repeatedly acted against "dark patterns". Design principles:

  • Equal choice: Reject as easy as Accept on the first layer (where required).
  • No pre-ticked boxes, no "legitimate interest" tricks for advertising cookies.
  • Clear purposes in plain language; name key vendors.
  • No cookie walls that block the site unless the regulator allows a fair alternative.
  • Localization: Arabic and English for Gulf sites; Urdu where appropriate for Pakistani audiences.
  • Performance: load the CMP early and fast; a slow banner delays everything.

Improving consent rates legitimately: explain the value exchange honestly, keep the banner short, make it readable on mobile, and do not nag. Test wording, not deception.

Worked example: a UK retailer with EU and Gulf traffic

The retailer configures:

  • UK/EU visitors: opt-in banner, Accept/Reject/Manage on layer one; analytics under the UK DUAA exemption only after legal review for UK traffic, with an objection link; ads tags wait for consent.
  • UAE/KSA visitors: Arabic/English banner, consent for marketing tags, links to privacy notice.
  • US visitors: "Your Privacy Choices" link, GPC honored, GPP string generated.
// Check TCF v2 consent (if your CMP supports TCF)
if (typeof window.__tcfapi === 'function') {
  window.__tcfapi('addEventListener', 2, function (tcData, success) {
    if (success && (tcData.eventStatus === 'tcloaded' || tcData.eventStatus === 'useractioncomplete')) {
      console.log('TC string:', tcData.tcString);
      console.log('Purpose 1 (store/access device):', tcData.purpose.consents[1]);
      console.log('Google vendor (755) consent:', tcData.vendor.consents[755]);
    }
  });
}

// Check Global Privacy Control
console.log('GPC signal:', navigator.globalPrivacyControl === true);

// Inspect Google consent state (Google tag)
console.log(window.dataLayer && window.dataLayer.filter(e => e && e[0] === 'consent'));

Choosing a CMP

Compare CMPs on: supported frameworks (TCF v2.3, GPP, Google Consent Mode v2, Google certification if you need it), region rules and geolocation, tag-blocking method (GTM template, script rewriting, or both), server-side consent forwarding, languages including Arabic right-to-left layout, proof-of-consent export, performance impact, and data residency of consent logs. Run a two-week trial on a staging site and test every region's behavior before switching.

Pitfalls

  • A beautiful banner that does not actually block anything.
  • Consent stored but not passed to server-side events.
  • One global banner for every region.
  • Forgetting to re-prompt after adding new purposes or vendors.

How to measure success

Consent rate by region and device (tracked without personal data), zero pre-consent firing for non-essential tags where consent is required, and proof-of-consent records retrievable on request.

Key takeaways

  • A CMP presents choices, blocks or adapts tags, stores proof, exposes consent via APIs and supports regional rules.
  • IAB TCF v2.3 is the current standard (transition deadline 28 Feb 2026); publishers usually need it, advertisers may not.
  • IAB GPP carries US state signals; honor Global Privacy Control.
  • Avoid dark patterns: equal Accept/Reject where required, no pre-ticked boxes, clear purposes.
  • Verify that consent actually controls what fires, client-side and server-side.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. What is the current version of the IAB Transparency & Consent Framework as of 2026?
  2. Which banner design is most likely to be challenged by EU/UK regulators?
  3. Which IAB standard is designed to carry US state privacy signals?

Put it into practice

Audit your consent banner: record the first-layer choices, whether Reject is as easy as Accept, which tags fire before and after each choice, and whether GPC is honored.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.