Home / Blog / Consent on infinite scroll: the signal decay your ad refresh does not handle

Consent on infinite scroll: the signal decay your ad refresh does not handle

Published 2026-10-04

Your consent signals are clean on page load. The TCF string is present, vendors read it, and the audit passes. Then the reader scrolls, the ad slots refresh, and somewhere around the fourth refresh the consent signal quietly stops traveling with the request. Infinite scroll and auto-refreshing ad slots are where consent signals decay, and almost nobody is checking.

Why refresh breaks what load got right

On page load, the consent framework runs once, builds the signal, and hands it to every vendor in the auction. On refresh, the responsibility moves to the ad code: each refresh is supposed to re-attach the current consent signal to the new bid requests. The failure modes are all in that handoff. The refresh fires before the consent framework has re-initialized on the scrolled view. The refresh reuses a cached TCF string from page load even though the visitor changed their choice mid-session. Or the refresh path was built by a different team than the load path, and it never attached the signal at all.

Infinite scroll makes every one of these worse, because new slots are created dynamically. A slot injected after the initial auction often misses the consent setup entirely: it bids, wins, and renders with no signal, or with a stale one. From the vendor's perspective the request looks legitimate. From the regulator's perspective the publisher served personalized ads without valid consent.

Where the signal gets dropped

Three checkpoints catch most of it. First, the refresh trigger itself: check whether your refresh logic waits for the consent framework's ready state before firing, or whether it races it. A refresh on a timer does not wait for anything, and timers do not know what consent is. Second, the signal source at refresh time: verify the refresh reads the current consent state, not a variable captured at page load. Visitors do change their minds, and the mid-session change is exactly when the stale cache hurts you. Third, dynamically injected slots: every slot created after initial load needs the same consent wiring as the first paint slots, including the TCF string in the bid request and the same vendor allowlist.

How to test it

Manual testing is straightforward. Load a page, accept or reject through the banner, then scroll and trigger several refreshes while watching the bid requests in the network tab. Check each refresh for the TCF string and compare it to the current consent choice. Then change the choice mid-session and refresh again: does the signal update, or does the old one persist? Automate the core case: a script that sets consent to rejected, triggers N refreshes, and asserts every bid request carries the rejected signal or no personalization request at all.

Test the reject path hardest. Most publishers test the accept path because it is the one that makes money, but the reject path is the one regulators test. A refresh that keeps personalizing after a reject is the finding.

The fix: refresh as a consent event, not a timer event

Treat every ad refresh like a mini page load for consent purposes. The refresh should read the live consent state, attach the current signal, and only then bid. Centralize the signal in one place the refresh code reads from, rather than letting each slot or wrapper capture its own copy. If the consent framework is not ready, the refresh should wait or fall back to the non-personalized path, never to a guessed signal.

For infinite scroll, wire consent into the slot creation path. A new slot should not exist until the consent setup for it exists. That usually means hooking slot injection into the same consent-ready callback the initial auction uses, and re-checking on every refresh rather than once per session.

The bottom line

Consent that only survives page load is consent that decays with every scroll. The refresh path is a separate implementation with its own failure modes, and it needs its own tests. Publishers who treat refresh as a consent event, with the current signal attached every time, keep the audit clean on the hundredth impression, not just the first.

Get a free consent audit of your website

Free consent audit