Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIsConsent management and Google Consent Mode · Lesson 3 of 14
Consent management: CMPs, IAB TCF 2.3 and GPP
Video lecture
Consent management: CMPs, IAB TCF 2.3 and GPP
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Consent management
Your consent banner is the most viewed piece of content on your website, and probably the least designed. It decides what you can measure, what you can show in ads, and whether a regulator ever knocks on your door. In this lecture you'll learn what a consent management platform must do, where IAB's TCF and GPP standards fit, how to design a banner that's lawful and still effective, and how to check consent state in the browser yourself.
0:34 Why it matters
Why does this matter? Because consent is the gate every other part of your measurement passes through. Here's an analogy. A consent platform is like the reception desk in an office building. It asks visitors who they're here to see, gives them the right badge, and every door in the building checks that badge. If reception hands out the wrong badges, or the doors don't check them, it doesn't matter how good your security policy looks on paper. Your tags are the doors. The consent state is the badge. And the CMP is reception.
1:15 Six jobs of a CMP
A consent management platform, or CMP, does six jobs. It presents clear choices. It blocks non-essential tags until consent, or passes consent state to tags that can adapt, like Google's consent mode. It stores proof of consent: what the user saw, when, and what they chose. It exposes that state through APIs. It applies different rules by region. And it lets people change their mind easily, with a persistent link or icon.
1:46 IAB TCF
Now the standards. The IAB Transparency and Consent Framework, TCF, is how consent travels across the advertising supply chain in Europe, packed into something called a TC string. The current version is two point three. IAB Europe set a transition deadline of the end of February twenty twenty-six, and the key change is proving which vendors were actually disclosed to the user. If your CMP supports TCF, make sure it's on version two point three.
2:19 Do you need it?
Do you need TCF? If you're a publisher earning from programmatic ads, usually yes. If you're an advertiser measuring your own site with Google, Meta and TikTok, it's optional. Many advertisers use a non-TCF CMP together with Google consent mode and tag-level blocking. For the United States, IAB Tech Lab's Global Privacy Platform, GPP, carries state-by-state signals in one string, and ad tech vendors increasingly expect it.
2:48 Simple example: Manchester gift shop (illustrative)
Here's a simple worked example. A Manchester gift shop uses a CMP with three first-layer buttons: accept all, reject all, and manage choices. A visitor clicks manage, turns on analytics, and leaves advertising off. What should happen? GA4 runs, according to their Consent Mode setup. The Meta and TikTok pixels stay silent. The server container doesn't forward anything to ad platforms for that visitor. And the CMP stores a record of what the visitor saw and chose, with a timestamp. If a month later the visitor clicks the privacy link in the footer and turns advertising on, the tags start working from that moment.
3:33 Lawful design
Let's talk design, because regulators across Europe and the UK have repeatedly acted against dark patterns. Where consent is required, make rejecting as easy as accepting on the first layer. No pre-ticked boxes. No hiding advertising cookies behind legitimate interest. Explain purposes in plain language and name key vendors. Don't block the whole site unless you offer a fair alternative the regulator accepts. And localize: Arabic and English for Gulf sites, Urdu where it helps Pakistani audiences.
4:06 Better consent rates, honestly
Can you improve consent rates without tricks? Yes. Be honest about the value exchange, for example, we use this to show you relevant offers and keep the site free of irrelevant ads. Keep the banner short and readable on mobile. Load the CMP early and fast, because a slow banner delays everything else. And don't nag people who said no. Test wording, not deception.
4:34 Example: UK retailer (illustrative)
Here's an illustrative setup for a UK retailer with EU and Gulf visitors. UK and EU visitors get an opt-in banner with Accept, Reject and Manage on the first layer. Advertising tags wait for consent. For UK analytics, they only use the new statistical exemption after legal review, with an easy objection link. Gulf visitors get an Arabic and English banner. US visitors get a privacy choices link, Global Privacy Control honored, and a GPP string generated.
5:07 Check it yourself
You can check consent state yourself in the browser console, and the lesson has the code. If your CMP supports TCF, call the TCF API and read the TC string, whether purpose one, storing and accessing information on the device, was consented, and whether a specific vendor has consent. Check the navigator's global privacy control flag. And look for consent commands in the data layer to see what Google's tags received.
5:38 Common failures
Common failures. A beautiful banner that doesn't actually block anything. Consent that's stored but never passed to server-side events. One global banner for every region. And forgetting to ask again when you add new vendors or purposes. Measure success with consent rates by region and device, zero pre-consent firing where consent is required, and proof-of-consent records you can retrieve on request.
6:05 Mistakes + try this now
Common consent mistakes. A banner that looks right but doesn't block anything. Consent that's recorded but never passed to server-side events. A reject option hidden on the second layer where regulators expect it on the first. No Arabic version for Gulf visitors. And forgetting to ask again after adding new vendors. Try this now: open your site in two fresh browser profiles. In one, accept all. In the other, reject all. Compare the cookies and network requests in each. If they look almost the same, your banner isn't doing its job.
6:45 Watch me do it: CMP setup (illustrative)
Watch me do it. Let's configure an illustrative CMP for a Karachi fashion brand that ships to the UK, the UAE and the US. Step one, geolocation rules: UK and EU visitors get opt-in with accept all, reject all and manage choices on the first layer. Gulf visitors get an Arabic and English banner with marketing consent. US visitors get a your privacy choices link, and Global Privacy Control is honored automatically. Step two, purposes: necessary, analytics, advertising and personalization, each described in one plain sentence. Step three, vendors: Google, Meta, TikTok and the email platform, each mapped to a purpose. Step four, Google Consent Mode integration: the CMP's template sets defaults and updates. Step five, tag blocking: in Tag Manager, Meta and TikTok tags require advertising consent. Step six, proof: consent records exported monthly. Step seven, testing: I open the site through a UK VPN location, reject all, and confirm no advertising cookies; then a Dubai location, check the Arabic layout reads right to left properly; then a US browser with GPC enabled. Only after all three pass do we publish. TCF isn't needed here because the brand doesn't sell ad inventory.
8:09 Recap and next step
Recap. A CMP presents choices, controls tags, stores proof and exposes consent to everything downstream. TCF version two point three is the current European standard, mostly for publishers, and GPP covers US states. Design without dark patterns. Your next step: audit your banner. Record the first-layer choices, whether reject is as easy as accept, which tags fire before and after each choice, and whether Global Privacy Control is honored.
What a consent management platform does
A consent management platform (CMP) presents choices to users, records their decisions, and makes those decisions available to your tags and vendors. A good CMP:
- Shows a banner/dialog with clear purposes and equally prominent "Accept" and "Reject" options where required.
- Blocks non-essential tags until consent (or passes consent state to tags designed to adapt, like Google Consent Mode).
- Stores proof of consent (what text the user saw, when, which choices).
- Exposes consent state via APIs: Google Consent Mode signals, the IAB TCF
__tcfapi, the IAB GPP__gpp, and its own JavaScript events. - Supports region rules (opt-in in the EU/UK, opt-out in US states, honoring GPC).
- Lets users change their mind easily (a persistent link or icon).
Google requires publishers and advertisers using certain Google products with EEA/UK traffic to use a Google-certified CMP in some contexts (for example, for AdSense/Ad Manager/AdMob publishers). Check Google's current requirements for your use case.
IAB Transparency & Consent Framework (TCF)
The TCF is a standard from IAB Europe for communicating consent across the ad-tech supply chain using a TC string. It defines purposes (e.g., store/access information on a device, use limited data to select ads, measure ad performance) and a Global Vendor List. The current version is TCF v2.3; IAB Europe set a transition deadline of 28 February 2026, after which new TC strings must follow v2.3 (the main change is a mandatory signal proving which vendors were disclosed to the user). If you run a CMP that supports TCF, confirm it is on v2.3.
Do you need TCF? If you are a publisher monetizing with programmatic ads, usually yes. If you are an advertiser measuring your own site with Google, Meta and TikTok, TCF is optional; many advertisers use a non-TCF CMP with Google Consent Mode and tag-level blocking.
IAB Global Privacy Platform (GPP)
For the US state patchwork, IAB Tech Lab's GPP carries multiple jurisdictions' signals in one string (including US national and state sections). Ad-tech vendors increasingly expect GPP strings for US traffic.
Designing a lawful, effective banner
Regulators (for example, the ICO, the French CNIL and the EDPB) have repeatedly acted against "dark patterns". Design principles:
- Equal choice: Reject as easy as Accept on the first layer (where required).
- No pre-ticked boxes, no "legitimate interest" tricks for advertising cookies.
- Clear purposes in plain language; name key vendors.
- No cookie walls that block the site unless the regulator allows a fair alternative.
- Localization: Arabic and English for Gulf sites; Urdu where appropriate for Pakistani audiences.
- Performance: load the CMP early and fast; a slow banner delays everything.
Improving consent rates legitimately: explain the value exchange honestly, keep the banner short, make it readable on mobile, and do not nag. Test wording, not deception.
Worked example: a UK retailer with EU and Gulf traffic
The retailer configures:
- UK/EU visitors: opt-in banner, Accept/Reject/Manage on layer one; analytics under the UK DUAA exemption only after legal review for UK traffic, with an objection link; ads tags wait for consent.
- UAE/KSA visitors: Arabic/English banner, consent for marketing tags, links to privacy notice.
- US visitors: "Your Privacy Choices" link, GPC honored, GPP string generated.
Hands-on: reading TCF and consent state in the browser console
// Check TCF v2 consent (if your CMP supports TCF)
if (typeof window.__tcfapi === 'function') {
window.__tcfapi('addEventListener', 2, function (tcData, success) {
if (success && (tcData.eventStatus === 'tcloaded' || tcData.eventStatus === 'useractioncomplete')) {
console.log('TC string:', tcData.tcString);
console.log('Purpose 1 (store/access device):', tcData.purpose.consents[1]);
console.log('Google vendor (755) consent:', tcData.vendor.consents[755]);
}
});
}
// Check Global Privacy Control
console.log('GPC signal:', navigator.globalPrivacyControl === true);
// Inspect Google consent state (Google tag)
console.log(window.dataLayer && window.dataLayer.filter(e => e && e[0] === 'consent'));Choosing a CMP
Compare CMPs on: supported frameworks (TCF v2.3, GPP, Google Consent Mode v2, Google certification if you need it), region rules and geolocation, tag-blocking method (GTM template, script rewriting, or both), server-side consent forwarding, languages including Arabic right-to-left layout, proof-of-consent export, performance impact, and data residency of consent logs. Run a two-week trial on a staging site and test every region's behavior before switching.
Pitfalls
- A beautiful banner that does not actually block anything.
- Consent stored but not passed to server-side events.
- One global banner for every region.
- Forgetting to re-prompt after adding new purposes or vendors.
How to measure success
Consent rate by region and device (tracked without personal data), zero pre-consent firing for non-essential tags where consent is required, and proof-of-consent records retrievable on request.
Key takeaways
- A CMP presents choices, blocks or adapts tags, stores proof, exposes consent via APIs and supports regional rules.
- IAB TCF v2.3 is the current standard (transition deadline 28 Feb 2026); publishers usually need it, advertisers may not.
- IAB GPP carries US state signals; honor Global Privacy Control.
- Avoid dark patterns: equal Accept/Reject where required, no pre-ticked boxes, clear purposes.
- Verify that consent actually controls what fires, client-side and server-side.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Audit your consent banner: record the first-layer choices, whether Reject is as easy as Accept, which tags fire before and after each choice, and whether GPC is honored.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.