What to ask before trusting a vendor's TCF compliance claim
Ask ten ad-tech vendors whether they are TCF compliant and all ten will say yes. Press for details and the yes means ten different things: registered with the framework, reading the consent string, writing to the consent string, passing it downstream, or just planning to do one of those eventually. For a publisher, the difference between those versions is the difference between compliant inventory and a liability. Here is how to interrogate the claim.
Start with registration, then move past it
Registration with the IAB Transparency and Consent Framework is the minimum claim, and it is the easiest to verify. Every registered vendor has a Global Vendor List ID, and the list is public. Ask for the ID and check it. If a vendor cannot give you one, the conversation is over: they are not in the framework, whatever their sales deck says.
But registration proves only that the vendor joined the program. It says nothing about what the vendor does with the consent string on your pages. Plenty of registered vendors read the TC string correctly and then pass the user's data to unregistered downstream partners, which breaks the chain the framework exists to protect. Registration is the ticket to the conversation, not the end of it.
The questions that actually matter
Once registration checks out, ask these in writing, and keep the answers on file:
- Do you read the TC string before every bid request, or cache it? A vendor that reads once per page and caches can act on a stale decision if the user changes consent mid-session. Fresh reads per request are the standard you want.
- Which purposes and legal bases do you claim, and under what conditions? A vendor registered for ten purposes that your banner only offers five of will quietly fall back to whatever it can claim. Know exactly which purposes their system needs and whether your banner configuration grants them.
- Do you pass the TC string and the addtl consent string to your downstream partners unmodified? Many vendors truncate or re-encode the string for their own systems and lose signal in the process. Ask whether the downstream partner receives the exact string your CMP generated.
- What happens on your side when the TC string is missing or malformed? The safe answer is that processing stops for anything requiring consent. The wrong answer is that the vendor treats a missing string as an implicit yes, which is both common and a direct violation.
- Are your subprocessors registered vendors too? The chain is only as compliant as its weakest link. A compliant vendor feeding data to an unregistered subprocessor hands you the exposure.
Test the claim yourself
Vendor answers are paperwork. Verification is a consent scan. Set up a test page with the vendor's tag, decline all optional purposes in the banner, and watch the network tab. If bid requests fire with the consent string intact and limited to the right purposes, the claim holds. If requests fire before consent resolves, or the vendor's calls ignore the decline, you have found the truth that the sales deck skipped.
Run the same test after the vendor ships an update. Vendor integrations drift: a new SDK version, a new endpoint, a "performance optimization" that reorders the tag sequence. Consent behavior is not a one-time audit. It is a regression test, and the vendors worth keeping are the ones who welcome being re-tested.
Write the answers into the contract
Whatever the vendor tells you in the evaluation, the contract should repeat. The insertion order or DPA addendum should name the GVL ID, the purposes the vendor may process, and the obligation to honor the TC string your CMP generates. A vendor that believes its own compliance claim will sign that language without flinching. A vendor that hesitates has just told you what the claim was worth.
Publishers own the consent surface, which means publishers own the consequence when a vendor misbehaves on it. Five questions in writing, one scan to verify, and the answers in the contract: that is the whole routine, and it takes less time than one compliance incident.