IAB TCF 2.4 compliance, handled
TCF v2.4 shipped to CookieHub domains almost a month ahead of the IAB's 23 October 2026 deadline for web environments. If your widget updates automatically, you are already running TCF v2.4 - the new disclosures appear on your site with nothing to configure and nothing to migrate.
Trusted and used by 30.000+ websites and companies worldwide.
What's new in your consent dialog
Features, clearly disclosed
The second layer of the consent dialog now includes a Features section: the IAB's standard explanation and all three TCF Features with their official illustrations, each one expandable. Features carry no consent choice under the framework, and the dialog now presents them that way.
Complete disclosure
CookieHub now also discloses Special Purpose 3 alongside the other special purposes, and every purpose, feature and stack name comes straight from the current Global Vendor List - including the updated name for Special Feature 2, "Identify devices based on information actively requested".
Your existing choices stay where they are
Existing dialogs keep the same purposes and controls in the same order. The new TCF disclosures are added without reshuffling the choices visitors already know.
You decide what your dialog presents
The Dashboard has a new TCF settings section. Choose which purposes, special features and stacks your dialog presents - individually or bundled as IAB stacks - and manage your vendor list and legitimate-interest settings in the same place.
Your set is yours:
Existing domains keep exactly the set of purposes, special features and stacks they present today.
Personalised advertising, when you want it:
Select purposes 3 and 4, or Stack 10, and the ad_personalization Consent Mode signal becomes grantable.
Purpose 1 stays required:
CookieHub keeps Purpose 1 required, because removing it would deny several Consent Mode signals at once.
Consent signals you can defend
The TC string reflects the purposes and vendors your dialog disclosed and the choices your visitors made. Purposes your configuration does not present are never signalled as consented, the disclosed-vendors segment records which vendors were shown, and every change in this release was verified by decoding real consent strings against the live Global Vendor List.
Consent Mode, documented
How CookieHub derives each Google Consent Mode signal is now published, both for category-based setups and for TCF: Google Consent Mode v2 mapping. The tables describe what each signal requires and apply to widget version 2.9.1 and later.
Compliance Checker
Use our free TCF compliance scanner to analyze how your website interacts with publishers, vendors, and consent signals under the IAB Transparency and Consent Framework. Receive a detailed report on all active services, their declared purposes, and legal bases to ensure your consent management aligns with IAB standards.
Do you need to do anything?
If your domain runs the latest widget generation with automatic updates enabled: no. You are already on TCF v2.4.
If automatic updates are disabled, or your domain runs an earlier widget generation: update to the 2.4 release before the IAB's 23 October 2026 web deadline. CookieHub no longer supports TCF 2.3, so every TCF domain needs to move by then.
FAQ about IAB TCF v2.4
The IAB Transparency and Consent Framework (TCF) is a technical standard that allows publishers and advertisers to collect, manage, and share user consent signals for compliance with the General Data Protection Regulation (GDPR) and ePrivacy Directive in the European Union.
The v2.4 Technical Specifications were published on 23 July 2026, following the release of TCF Policies v5.0.b in May. It primarily improves how the framework's Features are explained to users - with standard texts and illustrations from the Global Vendor List - and introduces policy changes such as multi-device consent provisions and the renaming of Special Feature 2. Web CMPs must implement the new disclosures by 23 October 2026.
Not if your widget updates automatically on the latest generation. If updates are disabled or you run an earlier generation, update to the 2.4 release before the 23 October 2026 web deadline - CookieHub no longer supports TCF 2.3.
TCF v2.4 requires CMPs to disclose the framework's three Features with the IAB's standard explanation and illustrations. Features carry no consent choice under the framework, so there is nothing to toggle.
They moved from the Customize dialog to the new TCF settings section in the Dashboard, with their values unchanged.
In TCF settings, present purposes 3 and 4 - individually or via Stack 10. Visitors are asked again, and the ad_personalization signal becomes grantable once they consent.
Nothing. Stored consent is never altered by a configuration change; newly added purposes read as denied until the visitor is asked again.
CookieHub keeps Purpose 1 required by design: several Consent Mode signals depend on it, so removing it would deny them all at once.
In preparing for the launch of the GDPR, IAB Europe launched a collaborative effort to deliver, maintain and iterate an industry standard, the TCF, in an attempt to meet the needs of users, industry and regulators. Since 2018, it has gone through several iterations to ensure that it meets the needs of the industry while still complying with the regulation. The most recent version, TCF v2.4, was published in July 2026.
The framework defines how websites collect and store user consent preferences and communicate those preferences to third-party vendors that process personal data, such as ad networks, analytics providers, and retargeting platforms.
It ensures that vendors can only access or process personal data with a valid legal basis (such as consent). It also ensures that users are clearly informed about:
- Why their data is being used (purposes)
- Which vendors are involved
- What data is collected
- How long data is retained
Consent choices are standardized, structured, and passed in a machine-readable format.
IAB TCF is not itself a law, and GDPR does not require websites to use it. However, some advertising platforms and publishers require it as part of their consent infrastructure. For example, Google requires publishers using AdSense, Ad Manager or AdMob to use a Google-certified CMP integrated with TCF when serving personalized ads to users in the EEA, UK and Switzerland.
You might also want to use TCF if you need to provide structured, vendor-level consent to a wide range of ad tech providers, or if your advertising partners or header bidding providers require a valid TC string.
- Go to Dashboard → Domain list
- Click on the domain you want to configure
- Click Settings
Under Regional settings:
- Set the framework to IAB TCF 2.4
- Set the consent type to Explicit consent / opt-in
- Save your changes
The TCF interface will appear automatically for users in the selected region(s), and the consent string will be generated and shared with vendors. To manage your vendor list and the purposes, special features and stacks your dialog presents, open the IAB TCF section in the Dashboard menu.
Using IAB TCF v2.4 with CookieHub supports GDPR compliance, but it does not guarantee full compliance on its own.
The framework standardizes how consent is collected, stored, and shared with vendors. However, full GDPR compliance requires a broader privacy strategy that includes:
- Clear user notices and privacy disclosures
- Data minimization and purpose limitation
- Honoring user withdrawal of consent
- Maintaining up-to-date records in your CookieHub CMP
CookieHub's TCF v2.4 implementation ensures that your consent signals are correctly formatted and transmitted to vendors, a key step toward compliance and ethical data use in digital advertising.

