Home / Blog / What to ask before trusting a vendor's TCF compliance claim

What to ask before trusting a vendor's TCF compliance claim

Ask ten ad-tech vendors whether they are TCF compliant and all ten will say yes. Press for details and the yes means ten different things: registered with the framework, reading the consent string, writing to the consent string, passing it downstream, or just planning to do one of those eventually. For a publisher, the difference between those versions is the difference between compliant inventory and a liability. Here is how to interrogate the claim.

Start with registration, then move past it

Registration with the IAB Transparency and Consent Framework is the minimum claim, and it is the easiest to verify. Every registered vendor has a Global Vendor List ID, and the list is public. Ask for the ID and check it. If a vendor cannot give you one, the conversation is over: they are not in the framework, whatever their sales deck says.

But registration proves only that the vendor joined the program. It says nothing about what the vendor does with the consent string on your pages. Plenty of registered vendors read the TC string correctly and then pass the user's data to unregistered downstream partners, which breaks the chain the framework exists to protect. Registration is the ticket to the conversation, not the end of it.

The questions that actually matter

Once registration checks out, ask these in writing, and keep the answers on file:

Test the claim yourself

Vendor answers are paperwork. Verification is a consent scan. Set up a test page with the vendor's tag, decline all optional purposes in the banner, and watch the network tab. If bid requests fire with the consent string intact and limited to the right purposes, the claim holds. If requests fire before consent resolves, or the vendor's calls ignore the decline, you have found the truth that the sales deck skipped.

Run the same test after the vendor ships an update. Vendor integrations drift: a new SDK version, a new endpoint, a "performance optimization" that reorders the tag sequence. Consent behavior is not a one-time audit. It is a regression test, and the vendors worth keeping are the ones who welcome being re-tested.

Write the answers into the contract

Whatever the vendor tells you in the evaluation, the contract should repeat. The insertion order or DPA addendum should name the GVL ID, the purposes the vendor may process, and the obligation to honor the TC string your CMP generates. A vendor that believes its own compliance claim will sign that language without flinching. A vendor that hesitates has just told you what the claim was worth.

Publishers own the consent surface, which means publishers own the consequence when a vendor misbehaves on it. Five questions in writing, one scan to verify, and the answers in the contract: that is the whole routine, and it takes less time than one compliance incident.

Get a free consent audit of your website

Free consent audit