IAB Europe has released version 2.4 of the Transparency and Consent Framework (TCF), the standard most publishers in Europe use to collect consent for advertising and pass it on to their ad tech partners. If you run ads or measurement on a website or app with EU or UK traffic, it applies to you.
Your visitors won't be asked to consent again, and the consent you have already collected stays valid. One change can affect a small group of ad tech vendors though, so it's worth a quick check before the deadline.
IAB TCF 2.4 Deadline and How to Check Your Vendors
| Where | Deadline |
|---|---|
| Websites | October 23, 2026 |
| Mobile apps and CTV | February 23, 2027 |
The new rules were published on July 23, 2026, together with IAB Europe's updated TCF Policies (version 5.0.b).
Most of TCF 2.4 is about making the consent screen easier for your visitors to understand. The second layer, where visitors see the detail behind each choice, now explains more clearly what "Features" are: ways that data is processed, only ever used for purposes the visitor already has a choice over. One item has also been renamed, to "Identify devices based on information actively requested".
None of this needs any action from you if your consent platform keeps its texts up to date.
The change that matters for your revenue and reporting is about a small group of vendors. Some ad tech companies only process data for reasons users can't refuse, such as keeping ads safe from malware, preventing ad fraud, fixing errors and delivering ads. The IAB calls these Special Purposes.
Until now, the consent signal marked these vendors with a "legitimate interest" flag so they knew they had been shown to your visitors. TCF 2.4 removes that flag for them. Instead, they rely on the list of vendors shown to the visitor, which has been part of every consent signal since TCF 2.3.
Vendors that have updated their technology won't notice a thing. A vendor that still looks for the old flag may think it isn't allowed to run. If that happens, you could lose ad security scanning, fraud protection or reporting from that vendor, most likely for visitors who reject consent or haven't made a choice yet.
For all other vendors, the ones that ask your visitors for consent, nothing changes.
These are the 22 vendors on the IAB's vendor list (September 2026) that only use Special Purposes. Being on this list doesn't mean a vendor will stop working. It means they are the ones to check with.
| Vendor ID | Vendor | What they do it for |
|---|---|---|
| 56 | Confiant Inc. | Security and fraud prevention, Ad and content delivery |
| 205 | Adssets AB | Ad and content delivery |
| 415 | Seenthis AB | Ad and content delivery |
| 572 | CHEQ AI TECHNOLOGIES | Security and fraud prevention, Ad and content delivery |
| 597 | Adjust Digital A/S | Ad and content delivery |
| 950 | Stream Eye OOD | Ad and content delivery |
| 1044 | TMT Digital Inc | Security and fraud prevention |
| 1129 | Brandhouse/Subsero A/S | Security and fraud prevention, Ad and content delivery |
| 1160 | streaMonkey GmbH | Security and fraud prevention, Ad and content delivery |
| 1187 | AccountInsight Ltd | Security and fraud prevention, Ad and content delivery, Saving privacy choices |
| 1225 | Dando online LTD | Security and fraud prevention, Ad and content delivery |
| 1362 | 9 Dots Media Ltd | Security and fraud prevention, Ad and content delivery, Saving privacy choices |
| 1376 | Carbonatix LTD | Ad and content delivery |
| 1395 | Marketing Science Consulting Group, Inc. | Security and fraud prevention |
| 1404 | Sahar Media FZE | Ad and content delivery |
| 1451 | Accenture Song Brand Germany GmbH | Ad and content delivery |
| 1468 | OnCore Digital Media | Ad and content delivery |
| 1516 | Peer39 | Security and fraud prevention |
| 1538 | Coresibo LTD (DBA Tredio) | Security and fraud prevention, Ad and content delivery, Saving privacy choices |
| 1568 | Bannerwise | Ad and content delivery |
| 1584 | DSR Agency GmbH | Security and fraud prevention, Ad and content delivery |
| 1614 | Ad Insertion platform Sarl | Security and fraud prevention, Ad and content delivery, Saving privacy choices |
The IAB list changes every week, so also check the vendors selected in your UniConsent dashboard.
On websites, UniConsent is updated automatically for IAB TCF 2.4, as it was for TCF 2.3. There is nothing to reinstall, no settings to change, and your visitors won't be asked to consent again. The consent signal your ad partners receive follows the new rules, and the consent screen shows the new wording in every language it supports.
In mobile apps, the UniConsent consent screen is updated in the same way. If your developers built their own first consent screen and use the UniConsent SDK only to save the choice, ask them to update to SDK version 26.9.0 (iOS, Android, Flutter or React Native) before February 23, 2027.
Do these checks once the update is live, and again a week later.
Then ask your account manager at each of these vendors one question: "Does your technology use the Vendors Disclosed list in the TCF consent string for Special Purpose processing?" If the answer is no, ask when they will update.
Finally, watch the vendor's own dashboard for the first week after the deadline and compare it with the week before. That means blocked ads for an ad security vendor, fraud rates for a fraud prevention vendor, or impressions for an ad delivery vendor. A sudden drop, especially among visitors who rejected consent, is the sign to follow up.
If you're not sure about a vendor on your site or in your app, email us at hello@uniconsent.com and we'll check it with you.
UniConsent is a part of Transfon's privacy-first User Experience Platform serves tens of millions of users per day to provide a seamless privacy experience for both users and publishers in the age of post GDPR. Contact us to know more: hello@uniconsent.com
Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
Activate Google Consent Mode UniConsent to enhance the accuracy of your Google Analytics and Google Ads conversion data.
Set up Google Consent Mode →Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up
IAB TCF 2.4 Deadline and How to Check Your Vendors
NFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking — How to Make Opt-Outs Actually Work

First-Party CMP Domain: Serve Your Consent Banner from Your Own Domain
UniConsent Is a Certified Microsoft UET CMP and Microsoft Clarity CMP

UK GDPR Right to Complain: Changes on June 19, 2026 and What Organisations Must Do

Prebid.js CMP Setup: Passing TCF, GPP, and CCPA Consent to Your Header Bidding Stack
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up