Skip to content
Biscotti CMP
PricingDownloadsDocsMCP ServerBlog
LoginStart for free
Home›Blog
Consent & Banners

Implementing IAB TCF 2.4: A Practical Guide for Publishers and Advertisers

July 7, 2026 · 6 min read

Quick answer: IAB Europe published TCF 2.4 on 23 July 2026. Web implementations must migrate by 23 October 2026; the deadline for mobile apps and CTV is 23 February 2027. The TC string format version remains 2 and the TCF policy version remains 5. TCF 2.4 therefore does not introduce a blanket new string format. The key work is applying the updated policies, especially the stricter vendor legitimate-interest rule.


Key takeaways

  • TCF 2.4 is the current specification, with separate migration deadlines by environment.
  • Web: 23 October 2026. Mobile app and CTV: 23 February 2027.
  • The binary TC string version stays at 2; tcfPolicyVersion stays at 5.
  • Existing valid choices do not require blanket reconsent merely because the framework label changed. Other material changes can still require a new prompt.
  • The DisclosedVendors segment became mandatory in TCF 2.3 and continues under 2.4; it is not a new 2.4 feature.
  • Vendors may not signal legitimate interest based only on Special Purposes. This 2.4 rule has applied since April 2026.
  • Registration and certification are different claims, and a CMP registration must be checked per environment.

What changes with IAB TCF 2.4?

TCF 2.4 updates the policies and technical specifications of the Transparency and Consent Framework. Implementers must not confuse the framework label with fields encoded in the TC string. The Core segment still uses format version 2, and the policy version remains 5. Integrations must neither encode an invented string version “2.4” nor discard every existing signal solely because the framework version changed.

The most important implementation change concerns vendor legitimate interest. A vendor may set an LI bit only where at least one permitted processing purpose supports it. Special Purposes alone are insufficient. CMPs must enforce this invariant while generating, restoring and withdrawing signals.

Disclosed Vendors: introduced in 2.3, still required in 2.4

The DisclosedVendors segment records which vendors were actually presented to the person. It became mandatory with TCF 2.3 and remains part of a correct 2.4 implementation. A migration should validate it against the visible vendor list:

  • Every vendor in the segment must have been disclosed in the consent UI.
  • Vendors that were not shown, are deleted or are inactive must not be signalled as disclosed.
  • Vendor sets in configuration, UI, DisclosedVendors and TCData must be traceably consistent.

Deadlines by environment

Environment TCF 2.4 migration deadline
Web 23 October 2026
Mobile app 23 February 2027
CTV 23 February 2027

A Web registration does not automatically cover mobile apps or CTV. Check the CMP's entry in the official CMP list and its registered environments. Biscotti CMP is operated by Campcruisers GmbH and is registered for Web under CMP ID 497. This does not claim a mobile-app or CTV registration.

Step-by-step migration to TCF 2.4

1. Verify registration and environment

Compare the CMP ID, legal entity and registered environments with the official CMP list. Do not rely on a logo or a broad “IAB compliant” statement.

2. Bind the current GVL and vendor selection

Load a current Global Vendor List and determine which vendors are actually used for the specific site or app. The interface and consent state must derive from the same vendor set.

3. Enforce vendor LI fail-closed

Do not produce a vendor-LI signal when the vendor declares only Special Purposes or no permitted LI purpose remains. Re-check this after rejection, withdrawal, GVL changes and restoring stored state.

4. Preserve TC string semantics

Continue to encode TC string format version 2 and policy version 5. Keep the mandatory DisclosedVendors segment. Do not change API version fields merely because the framework specification is named 2.4.

5. Make a targeted reconsent decision

A version change alone is not a blanket reason for reconsent. Instead, assess material changes to purposes, vendors, legal bases, publisher restrictions and the information shown to the person. Record the decision.

6. Test complete state transitions

At minimum, test Accept All, Reject All, granular choices, legitimate interest, withdrawal, reopening, browser restart and a GVL update. Decode generated strings independently and compare vendor and purpose sets.

Technical checklist

  • __tcfapi('ping', 2, ...) reports consistent CMP and policy data.
  • TC string format version is 2 and tcfPolicyVersion is 5.
  • DisclosedVendors matches the vendors actually shown.
  • Vendor LI is never set without a permitted LI purpose.
  • Reject and withdrawal remove impermissible consent and LI signals.
  • Stored state is restored only when compatible with the current configuration.
  • CMP ID and registered environment match the public CMP list.
  • Web, mobile-app and CTV releases are approved separately.

Must existing users be asked again?

Not automatically. The TCF 2.4 label alone changes neither the TC string format nor the policy-version number. A new choice is required when the previous decision no longer describes current processing or the person must receive material new information. Base the decision on actual configuration changes and obtain legal advice where appropriate.

Common mistakes

  • Encoding TCF 2.4 as a new TC string format version.
  • Increasing tcfPolicyVersion without a normative basis.
  • Describing Disclosed Vendors as a new TCF 2.4 change.
  • Treating Special Purposes as sufficient for vendor LI.
  • Presenting a Web registration as a mobile-app or CTV registration.
  • Using “registered”, “validated” and “certified” as synonyms.
  • Testing only Accept All while omitting reject, withdrawal or restart.

Conclusion

Migrating to TCF 2.4 is not a text-only update. It requires an environment-specific release plan, correct vendor-LI signals and evidence that the visible vendor set, stored state and TC string agree. Keeping format version 2, policy version 5 and the history of Disclosed Vendors distinct avoids the most common migration errors.

FAQ

Is TCF 2.4 a new TC string format version?
No. The TC string version field remains 2; the framework label 2.4 must not be written into it.

Does the TCF policy version change?
No. tcfPolicyVersion remains 5 for TCF 2.4.

Are Disclosed Vendors new in TCF 2.4?
No. The segment became mandatory in TCF 2.3 and continues in 2.4.

Does TCF 2.4 always require reconsent?
No. The actual changes to processing and user information matter, not the version number alone.

Is Biscotti CMP registered for mobile apps or CTV?
The current entry for Campcruisers GmbH, CMP ID 497, covers Web. It does not establish registration for mobile apps or CTV.

Sources

  • IAB Europe, TCF Policies v5.0.b and Specifications v2.4: https://iabeurope.eu/transparency-consent-framework/
  • IAB Europe CMP list: https://cmplist.consensu.org/v2/cmp-list.json
  • IAB Tech Lab, Consent String and Vendor List Formats: https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework

This article explains technical and operational considerations and is not legal advice.

Related Articles

Consent & Banners

Adapting Your Website for 2026: The Future of Global Privacy Compliance

Learn how to adapt your website for 2026 privacy compliance. Covers GDPR, CCPA, new U.S. state laws, consent design, tools, and enforcement risks in one practical guide.

Consent & Banners

AVV vs. DPA: Navigating the Nuances of Data Processing Agreements

AVV and DPA are the same GDPR-required contract, one in German, one in English. Learn what each must include, who needs one, and the cost of getting it wrong.

Consent & Banners

Data Minimization: The Golden Rule Across Global Privacy Frameworks

Learn what data minimization means across GDPR, CCPA, PIPEDA, and APEC frameworks, how to implement it, and what happens if your business fails to comply in 2026.

Deepen Your Knowledge

Find comprehensive articles on all topics in our knowledge base.

Go to Knowledge Base

GDPR · CCPA · TCF 2.4 Ready

Start for free
← Back to blog
Biscotti CMP

Built by Campcruisers GmbH in Falkensee, Germany.

Product

About UsFeaturesPricingDocumentationMCP ServerCookie CheckAccessibilityDownloadsLegal WatchdogAssessment EngineTrust PortalEnterprisePrivacy & Consent Knowledge BaseBlogCookie Consent & Privacy GlossaryJurisdictionsAccessibility as a design principle

Legal

ImprintPrivacy PolicyTerms of ServiceRight of WithdrawalDPACookie Policy

Contact

Contact
© 2026 Biscotti – A service of Campcruisers GmbH