CookieCitadel is a consent management platform for publishers and media sites. It runs a TCF v2.2 certified consent banner, passes consent strings to your ad stack correctly, and keeps programmatic revenue flowing in the EU and UK. It handles the vendor list, legitimate interest disclosures, and per-vendor toggles that ad-funded sites are required to show.
Get your free consent auditThe Transparency and Consent Framework is the ad industry's standard for passing consent decisions between publishers and ad tech vendors. If you run programmatic ads in the EU or UK, your SSPs and ad servers expect a TC string from a certified CMP. Without one, demand partners bid less or not at all, which shows up directly as lost revenue.
The platform syncs the IAB's Global Vendor List automatically as it updates each week. Your banner discloses the vendors you actually work with, their purposes, and their legitimate interest claims. When Google or another major vendor updates its requirements, your configuration updates without a banner redeploy.
Ad requests still fire but carry a consent string showing no consent, so demand partners serve non-personalized ads where they support it. You keep impressions; targeting is what changes. CookieCitadel also supports limited ads mode for declined traffic, which recovers part of the revenue gap compliantly.
| Capability | CookieCitadel | Basic alternative |
|---|---|---|
| IAB TCF v2.2 certified | Yes | No |
| Automatic Global Vendor List sync | Yes | No |
| Per-vendor consent toggles | Yes | No |
| Non-personalized and limited ads fallback | Yes | No |
| Consent string validation tools | Yes | No |
| Publisher ad-stack integrations | Yes | No |
Yes, in the EU and UK. Google Ad Manager and most SSPs require a valid TC string from a certified CMP for personalized ads. Traffic without one gets limited or no personalized demand, and publishers typically see a meaningful CPM drop on that inventory. The requirement is enforced by the ad platforms, not just regulators.
Version 2.2 tightened the rules: legitimate interest was removed as a legal basis for advertising and content personalization, vendor disclosure requirements got stricter, and consent must be as easy to withdraw as to give. Google certified under 2.2 and expects publishers to have migrated. CookieCitadel is built natively on 2.2, not patched from v2.0.
They must be able to, under both GDPR and the TCF. CookieCitadel adds a persistent privacy trigger, a small icon or footer link, that reopens the full preference center on any page. Every change regenerates the consent string and propagates to your ad stack on the next request.
The dashboard includes a TC string decoder and validator. Load any page, and it shows the exact string being sent, which vendors and purposes it covers, and whether it would pass IAB validation. This is the fastest way to debug revenue drops caused by malformed consent.
Yes. There are tested integrations for Google Ad Manager, Prebid.js, Amazon TAM, and the major SSPs, with setup guides for each. The consent string is exposed through the standard __tcfapi interface that every certified vendor reads, so anything TCF-compliant in your stack works out of the box without custom code.
Start with the free consent audit: we validate the consent string your ad stack actually receives and show you which demand partners see malformed or missing consent. Plans scale with monthly sessions after that. The audit carries no charge and no card.