The IAB Europe Transparency and Consent Framework (TCF) continues to evolve as regulators, users, and digital advertising need more transparent data processing.
In 2026, IAB Europe introduced TCF Policy v5.0.b, followed by Technical Specifications v2.4. The update adds clarity in several areas: multi-device consent, requirements for CMP feature interfaces, Special Feature 2, and explains how to properly represent vendor disclosures.
Consent Management Platforms (CMPs) need to evaluate their implementation.
CookieScript CMP is currently implementing v5.0.b and v2.4 requirements and will support TCF v2.4 on time, before October 23, 2026.
Publishers need to review whether they display, store, synchronize, and communicate privacy preferences across websites, apps, and other digital interfaces properly.
IAB TCF Technical Specifications v2.4 are ultimately focused on a well-known privacy principle: users should understand what privacy choices they are making, how to change them, where those choices apply, and how their preferences are communicated. For CMPs, achieving that requires updated UI and signaling support. For publishers, it requires validating that the technology accurately reflects both their privacy practices and the experience presented to users.
This guide explains what IAB TCF Technical Specifications v2.4 means for CMPs and publishers, and how to get ready for the TCF v2.4 update.
What’s Changing in IAB TCF Policy v5.0.b and Technical Specifications v2.4
IAB TCF Policy v5.0.b introduced requirements and guidance around multi-device consent, sets rules on how to present Features in CMP interfaces, updates the name and guidance for Special Feature 2, and adds a new standardTexts field to the Global Vendor List (GVL) to properly represent vendor disclosures.
The IAB Transparency and Consent Framework 2026 introduces the following changes:
Multi-device consent
IAB TCF Policy v5.0.b introduced multi-device scope. It clarifies how publishers can persist and communicate user privacy choices across multiple devices and access points.
It is a common situation when users access the same content through different devices. Thus, users should be able to manage the same privacy preferences through business’ website and mobile application.
Previously, the TCF focused on service-specific and group-specific scope. The TCF v2.4 update now clarifies how to manage users’ privacy choices across different devices.
Multi-device scope rules:
- User notification
Consent Management Platforms (CMPs) must explicitly inform users via the UI whether their privacy choices apply to a single service, a group of services, or across multiple devices. - Choice persistence
Publishers can apply a user's consent choices across connected devices when authenticated or linked through a unified service environment. When users sign in to an account, they must be informed about the scope of those choices. - Special Feature 2 alignment
When using multiple connected devices, multi-device identification requires clear separate notice and user opt-in control for all connected devices. - Transparency requirements
The framework standardizes how to explain these cross-device consent choices without introducing a new set of data processing purposes.
Note that the update does not mean every publisher must synchronize consent across devices. Publisher can decide whether they want to synchronize consent or not. When publishers choose to persist privacy preferences across devices, users must receive appropriate information about the scope of those choices. The CMP must also clearly state whether consent applies on a service-specific, group-specific, and/or multi-device basis.
The update also addresses a common problem created by conflicting cross-device consent preferences. For example, a user may access the same content through a laptop and a mobile phone, and make different privacy choices before signing in. After authentication, the publisher could have a locally expressed preference and an account-level preference.
IAB Transparency and Consent Framework 2026 lets publishers decide how to resolve that situation. They may prioritize the most recent pre-login preference or restore the preference already associated with the authenticated account. However, it is important to keep choice persistence and clearly communicate to users which preference was ultimately applied.
Cross-device consent is not the same as cross-domain consent: multi-device scope primarily focuses on consent choices applied across devices or end-user agents. When businesses use a defined group of digital properties, they need separate cross-domain consent to share consent across domains. The privacy notice must describe both scopes.
Clearer explanations of features
The IAB TCF update clarifies how to explain features inside CMP interfaces.
Policy v5.0.b aims to distinguish between Purposes and Features, explained by IAB and CMP. In the TCF, a Purpose explains why information is processed, while a Feature inside CMP describes a method of processing that may be used to achieve one or more Purposes.
- The standard Feature text and translations will be provided through the Global Vendor List (GVL)
IAB Transparency and Consent Framework 2026 provides standardized explanatory text that CMPs can display alongside Features. Technical Specifications v2.4 therefore add a new standardTexts field to the Global Vendor List (GVL). The updated framework also includes illustrations intended to make individual Features easier for users to understand. - Features should not appear next to controls that cannot be disabled
CMPs should avoid presenting ordinary Features next to controls, so they could appear to be independent consent controls. IAB Europe's policy states that when users review Features, the interface should provide their standard names, user-friendly descriptions and illustrations, together with the standard Feature explanation, without associating those Features with controls that could mislead users. - Feature illustrations
The Privacy Policies should include illustrations for each Feature, helping users to better understand them.
Special Feature 2 name
Special Feature 2 was renamed to make the description clearer.
The previous user-facing name "Actively scan device characteristics for identification" has been replaced with "Identify devices based on information actively requested."
The related vendor guidance has also been clarified to cover techniques in which device information is actively requested, including using User-Agent Client Hints to create identifiers or fingerprints. Users must still opt in before vendors can use Special Feature 2 where the TCF requires that Special Feature.
Mandatory disclosed vendors segment
Technical Specifications v2.4 simplify a rule about vendor disclosure.
TCF v2.3 made the Disclosed Vendors segment mandatory, removing uncertainty over whether Special-Purpose-only vendors had been presented to a user. As a result, IAB TCF Policy v5.0.b removes the previous workaround that required those vendors to be represented through the Vendor legitimate interest declaration.
IAB TCF Policy v5.0.b Implementation Timeline
IAB TCF Policy v5.0.b implementation is a multistep process, that includes the following timelines. However, exact CMP compliance deadline is still to be confirmed.
- May 29, 2026: IAB Europe TCF update published the updated TCF policies (v.2026-05-29.5.0.b), introducing changes for multi-device consent, feature presentations, and Special Feature 2.
- June 29, 2026: The public comment period hosted by the IAB Tech Lab officially closed.
- July 16, 2026: Official notification and release for TCF 5.0.b integration details were distributed to vendors and CMPs.
- October 23, 2026: CMP compliance deadline for web environments.
- February 23, 2027: CMP compliance deadline for native app environments, including mobile devices and CTV.
Key Compliance and Technical Implications for CMPs
TCF v2.4 sets rules for what information should be supplied by the Global Vendor List (GVL), how to provide that information in consent notices, how to achieve multi-device choice transparency, requires renaming and clarification of special Feature 2, supporting the new GVL standardTexts field, and ensuring multi-device consent implementations correctly communicate the scope of a user's choices.
TCF requirements for publishers include:
- Global Vendor List (GVL) requirements
CMPs that utilize the GVL should ensure their integrations recognize the new standardTexts information and can correctly render the required Feature explanations and illustrations. - Multi-device choice transparency
CMPs must explicitly inform users whether their privacy selections apply only for the current device or across multiple devices or platforms. If publishers intend to use privacy choices across devices, they must clearly notify users how this cross-device mapping operates. - Standard features explanations requirement
In the TCF, a Purpose explains why information is processed and allows user controls. In contrast, a Feature describes a method of data processing and does not provide opt-outs. Users often confuse Purposes and Features. To address this, CMPs must now present standard text explanations alongside the Feature name and a user-friendly description directly in the UI. - Renaming and clarification of Special Feature 2
The IAB TCF 2026 update refines and clarifies the scope of Special Feature 2, which relates to tracking and using precise geo-location data. CMP providers should use the updated name and associated user-facing information, while vendors and publishers should review whether technologies in their stack that actively request device characteristics fall within the clarified guidance. The updated wording is particularly relevant to fingerprinting-related techniques and Client Hints.
After updating the scope of Special Feature 2, CMPs should test how Feature information appears across desktop, mobile web, native apps, and CTV interfaces. The goal is not simply to fit additional text onto a screen. IAB TCF for CMPs requires to explain to users the differences between a Purpose and a Feature. Users shouldn’t believe that an ordinary Feature has an independent toggle when it does not.
Multi-device implementations may involve a larger architectural change. A CMP and publisher need to establish where to store privacy preferences, how to retrieve account-level choices after authentication, and how to solve conflicts between device-level and account-level signals. Whatever conflict-resolution method is chosen should produce a consistent result and it should be clear to users.
IAB TCF sets deadlines for CMPs to implement the IAB TCF updates. The deadline for the implementation in web environments is 23 October 2026, while the deadline for the implementation in mobile app and connected TV environments is 23 February 2027.
How Publishers Can Prepare for the 2026 TCF Update
IAB TCF for publishers sets requirements to confirm their CMP's v2.4 roadmap, review consent scope, document cross-device conflict rules, audit vendor configuration, test the full consent journey, include multiple environments in QA, and keep implementation records.
Publishers may rely on their CMP provider for much of the technical implementation but shouldn’t rely entirely on it. TCF says each participant is responsible for complying with the framework's applicable privacy and data protection requirements.
Publishers should therefore understand how their chosen CMP plans to implement v5.0.b and v2.4 and review the privacy experience from the perspective of their own users.
TCF requirements for publishers include:
- Confirm your CMP's v2.4 roadmap
Contact your CMP to know when it is planning to update GVL fields, Feature explanations, illustrations, and Special Feature 2 wording. - Review consent scope
Determine whether privacy choices are service-specific, group-specific or synchronized across multiple devices, and ensure the CMP communicates that scope correctly. - Document cross-device conflict rules
If choices are linked to user accounts, decide what happens when a local preference conflicts with a preference previously stored against the authenticated account. - Audit your vendor configuration
Check the vendors, Purposes, Special Purposes, Features, and Special Features that your advertising and analytics stack uses. - Test the full user journey for consent
Check what happens when users accept or reject tracking, change preference, and withdraw consent. - Include multiple environments in QA
Publishers operating websites, apps or CTV services should verify that each implementation receives the appropriate update before its respective deadline. - Keep implementation records
Record CMP versions, configuration changes, test results and relevant deployment dates so you can demonstrate for regulators how your TCF implementation was reviewed.
Publishers using cross-device consent should pay particular attention to authenticated experiences. Consent synchronization can reduce the need for users to repeat privacy choices on every device, but it also raises expectations around transparency. Users should clearly know whether changing a preference on one device changes it elsewhere and which preference applies after logging into an account.
Also, pay special attention to the revised Feature disclosures. Don’t treat the update as just additional CMP text. Provide clearer explanations that could help users better understand how vendors process information.
For CMPs, the deadline for publishers to implement the IAB TCF updates in web environments is 23 October 2026, and the deadline for implementation in mobile app and connected TV environments is 23 February 2027.
IAB TCF for publishers set requirements to use a CMP that is implementing the IAB TCF updates.
CookieScript CMP could be a good choice. It offers the following functionalities:
- IAB TCF support
CookieScript CMP currently supporst the latest version of the IAB TCF, and will support TCF Technical Specifications v2.4 before October 23, 2026. - Geo-targeting
geo-targeting identifies a visitor's exact location and applies the right Cookie Banner. It detects users from the EU and EEA, and automatically adapts for requirements, such as respecting IAB TCF, Google Consent Mode v2, GPC, and others. - GPC detection
CookieScript detects UOOM signals, such as GPC and other legally qualifying opt-out signals automatically, so you can pass the signal to third-party vendors and partners. - Google Tag Manager integration
for easier integration of Google Products. - Third-party cookie blocking
CookieScript CMP automatically blocks all non-essential scripts until consent is given. No cookies or other website trackers will be set on customers’ devices before consent. - Certification by Google
It allows the use of Google Ads, Google AdSense, Google Analytics, and other products. - Granular Cookie Banner
It lets users choose between different cookie types (e.g., strictly necessary, analytics, marketing, and security) rather than only allowing them to accept or reject all cookies. - Strong consent logging
CookieScript CMP lets you track banner versions, export consent logs, and keep them long-term. - Easy integration with your stack
CookieScript CMP is integrated with GTM, has many automatic CMS integration options, and allows custom scripts. - Google Consent Mode v2 integration
It enables privacy-safe marketing and analytics for businesses without exposing personal data. - Automatic cookie scanning
The CMP automatically scans your website for cookies, local storage, session storage, and other tracking technologies. - CookieScript API
CookieScript API to customize the behavior of cookie banners, manage Cookie Consent and scans, retrieve and update cookie declarations, and control individual cookies automatically. - 40+ language support
The CMP ensures consent banners display in each patient’s language, essential for international providers. - Cookie banner sharing to allow web agencies to share their banners with multiple users.
- Cross-domain cookie consent sharing to enable both sub-domain and cross-domain Cookie Consent sharing from a single user across multiple domains.

Frequently Asked Questions
What are the main changes in IAB TCF Policy v5.0.b and Technical Specifications v2.4?
IAB TCF Policy v5.0.b introduced requirements and guidance around multi-device consent, sets rules on how to present Features in CMP interfaces, updates the name and guidance for Special Feature 2, and adds a new standardTexts field to the Global Vendor List (GVL) to properly represent vendor disclosures. Use CookieScript CMP, which is implementing v5.0.b and v2.4 requirements and will support TCF v2.4 on time.
What does the TCF v2.4 update mean for CMPs?
CMPs need to provide information by the Global Vendor List (GVL) in consent notices, achieve multi-device choice transparency, rename and clarify special Feature 2, support the new GVL standardTexts field, and ensure multi-device consent implementations correctly communicate the scope of a user's choices. CMPs should also test how these disclosures work across web, mobile apps, and CTV environments. CookieScript CMP will support TCF v2.4 on time.
What are the compliance deadlines for TCF Technical Specifications v2.4?
IAB Europe published Technical Specifications v2.4 and the corresponding GVL update on July 23, 2026. CMPs must implement the new disclosures in web environments by October 23, 2026. For mobile apps and connected TV (CTV), the implementation deadline is February 23, 2027. Publishers should confirm how their CMP provider will meet the applicable deadline. CookieScript CMP is implementing v5.0.b and v2.4 requirements and will support TCF v2.4 on time.
How should publishers prepare for the IAB TCF 2026 update?
Publishers should confirm their CMP support a Policy v5.0.b and Technical Specifications v2.4. They should review their vendor configuration, Purposes, Features, Special Features, consent scope, and cross-device preference handling. Publishers should also test the consent choices across supported devices. CookieScript CMP is implementing v5.0.b and v2.4 requirements and will support TCF v2.4 on time.
Is multi-device consent mandatory under TCF Policy v5.0.b?
No. Publishers can decide whether to synchronize consent or not. When publishers choose to persist privacy preferences across devices, they must properly inform users. The CMP, such as CookieScript, should clearly communicate the scope of those choices. Publishers should also establish how to handle conflicting device-level and account-level preferences so users understand which privacy preference ultimately applies.