Skip to main content

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

IAB TCF 2.4: Preparing for Compliance

Prepare for updated requirements on multi-device consent, Feature transparency, and Special Feature 2.

Shay Olupona
Senior Product Manager 
August 31, 2026

Reflective glass building beside the OneTrust logo on a white background.

The IAB Transparency and Consent Framework (TCF) provides policies and technical specifications intended to help publishers, advertisers, vendors, and Consent Management Platforms support compliance with certain requirements of the GDPR and ePrivacy Directive. IAB Europe’s May 2026 policy update introduces targeted changes addressing multi-device consent, the presentation of Features, and Special Feature 2.

The changes do not introduce a new set of Purposes or require a separate TCF template. Instead, they update how existing TCF information should be explained and displayed, while clarifying how publishers may persist privacy choices across devices.

 

The update focuses on four areas: informing users when choices apply across devices, improving the explanation and placement of Features, renaming and clarifying Special Feature 2, and correcting the advertiser example stack. IAB Europe incremented the Policies from v5.0.a to v5.0.b.

 

Key Takeaways

  • TCF 2.4 updates existing TCF content and user experiences rather than introducing new Purposes or a separate template.
  • Organizations that persist TCF choices across devices or end-user agents need to explain that scope clearly and define how conflicting choices are handled.
  • Updated Feature explanations, illustrations, and Special Feature 2 terminology require review across supported interfaces and languages.
  • Web and native experiences have separate compliance timelines, making early validation of GVL content, translations, and UI behavior an important preparation step.

 

What Is Changing in TCF 2.4?

Greater Transparency for Multi-Device Consent

Publishers may persist a user’s privacy choices across multiple devices or end-user agents, such as when the user signs in to an account. When they do, users must be informed about the scope of those choices.

The updated Policies also provide flexibility where signals conflict. For example, a choice made on a device before login may differ from the preference already associated with the user’s account. The IAB Europe communication does not prescribe one conflict-resolution method.

For example, a user might make one privacy choice on a mobile device while signed out, then sign in to an account that already holds a different preference. The organization needs a defined approach for resolving that conflict and clear wording that explains the scope of the resulting choice.

What this means for organizations: Organizations that do not persist TCF choices across devices are not affected by this specific disclosure requirement. Organizations that do must clearly explain that scope and define how conflicting choices are handled.

What this means for customers: Customers using standard locked TCF content can rely on updated default wording when provided. Customers using custom TCF text should review and update their disclosure if they use multi-device consent. 

 

Cross-device is not automatically cross-domain

Multi-device scope concerns choices applied across devices or end-user agents. If a customer also applies choices across a defined group of digital properties, the notice should describe both scopes. The terms should not be treated as interchangeable.

 

Clearer Explanations of Features

CMPs will be required to display standard explanatory text alongside Features. The text clarifies that Features are means of processing used in pursuit of one or more Purposes for which the user is given a choice.

  • Features should not appear next to controls that cannot be disabled, avoiding a presentation that could mislead users.
  • The Policies will include illustrations for each Feature to support user understanding.
  • The standard Feature text and translations will be provided through the Global Vendor List (GVL).

Product impact: This is an update to GVL ingestion and the existing TCF UI. It is not a new template and does not add new Purposes, Special Purposes, Features, or Special Features.

 

Special Feature 2 Name and Guidance Update

Special Feature 2 is being renamed to make the user-facing description clearer. The vendor guidance is also updated to reflect the active request of Client Hints for the purpose of creating a fingerprint.

Previous nameActively scan device characteristics for identification
Updated nameIdentify devices based on information actively requested
Implementation impactUpdate GVL-backed labels, translations, guidance mappings, and UI text.

Template impact: This is primarily a metadata, translation, and display-text change. It does not create a new consent signal category or require a new TCF template.

 

Updated Advertiser Example Stack 

IAB Europe also updated Example Stack Combination 3 for advertisers. Purposes 2, 3, and 4 were removed because advertisers typically do not sell advertising placements on their own properties. This changes the example, not the availability of those Purposes within the TCF.

 

Compliance Timeline

DateIAB milestoneRecommended preparation
29 May 2026Updated Policies released and the 30-day public comment period for the Technical Specifications began.Assess content, GVL, UI, web, and native impacts.
29 June 2026Public comment period ended. CMPs could begin preparing to ingest the new GVL information.Finalize implementation planning against published specifications.
July 23, 2026GVL and translations were scheduled to be updated with standard Feature text and illustrations.Validate implementation against the released GVL content.
October 23, 2026CMP compliance deadline for web environments. Exact date to be confirmed.Complete web implementation and validation by the confirmed date.
February 23, 2027CMP compliance deadline for native app environments, including mobile and CTV. Exact date to be confirmed.Complete native implementation and validation by the confirmed date.

 

What Does TCF 2.4 Mean for Organizations?

  • Review whether privacy choices are persisted across devices or end-user agents and, if so, ensure users are informed of that scope.
  • Define how device-level and account-level preference conflicts are handled where authenticated consent is used.
  • Update CMP rendering to display the standard Feature explanation and illustrations supplied through the GVL.
  • Ensure Features are not presented next to controls that users cannot disable.
  • Adopt the updated Special Feature 2 name and guidance across supported languages and interfaces.
  • Review documentation or presets that reproduce the updated advertiser example stack.

 

3 Steps to Prepare for TCF 2.4

1. Confirm the scope of consent

Determine whether your organization applies TCF choices only within one device, across multiple devices, across a group of digital properties, or across both. Use disclosure wording that accurately describes the scope in use.

  • Use this light review to confirm the scope reflected in your implementation:
  • Identify whether TCF choices persist beyond the device or end-user agent where they were collected.
  • Confirm whether choices also apply across a defined group of digital properties.
  • Document how device-level and account-level conflicts are handled where authenticated consent is used.

 

2. Review content and configuration

If you use standard TCF content, adopt the CMP-provided update. If you use custom TCF text, review the multi-device disclosure and update it where applicable. Review the new Feature and Special Feature 2 content supplied through the GVL.

  • As part of that review:
  • Check custom TCF wording against the actual scope of multi-device consent in use.
  • Review standard Feature explanations, illustrations, and translations supplied through the GVL.
  • Confirm that the updated Special Feature 2 name and guidance appear consistently across supported interfaces and languages.

 

3. Validate web and native experiences

Verify GVL ingestion, translations, illustrations, Feature placement, and the updated Special Feature 2 label across supported web and native environments before the applicable confirmed deadline.

Before completing implementation:

  • Validate Feature placement and confirm Features do not appear next to controls that users cannot disable.
  • Test GVL-backed labels, translations, illustrations, and Special Feature 2 content across supported environments.
  • Complete web and native validation against their respective confirmed compliance dates.

 

Key takeaway

For most OneTrust customers, the update should be handled through changes to existing TCF content and UI rather than a new template. The main customer-specific action is for organizations using multi-device consent and custom TCF wording to confirm that their disclosures accurately explain the scope of the user’s choice.

 

Prepare Existing TCF Experiences for the Updated Requirements

TCF 2.4 is a targeted update to existing consent experiences, with the main operational work centered on transparency, content, configuration, and validation. Reviewing the scope of consent now gives teams time to address custom wording, updated GVL content, and differences between web and native implementations before the relevant compliance dates.

Learn how OneTrust Consent Management Platform supports TCF consent experiences across web, mobile, and CTV, and review your current implementation against the updated TCF 2.4 requirements. 

 

Key Questions About IAB TCF 2.4 Compliance

 

No. TCF 2.4 updates how existing TCF information is explained and displayed. It does not introduce new Purposes, Special Purposes, Features, or Special Features. For most OneTrust customers, preparation centers on updates to existing TCF content and UI rather than creating a separate template.

 

CMPs will display standard explanatory text alongside Features, with illustrations and translations supplied through the GVL. Special Feature 2 also receives an updated user-facing name and guidance. Organizations should review GVL ingestion, labels, translations, guidance mappings, and UI presentation across supported web and native environments.

 

The source guidance identifies a mid-October 2026 CMP compliance deadline for web environments and a mid-February 2027 deadline for native app environments, including mobile and CTV. Exact dates remain to be confirmed. Organizations should use the preceding implementation period to validate released GVL content and complete testing before the applicable deadline.