IAB TCF (Transparency and Consent Framework)
Что такое IAB TCF (Transparency and Consent Framework)?
IAB TCF (Transparency and Consent Framework)The Interactive Advertising Bureau Europe's framework for capturing, encoding, and propagating user consent for advertising and analytics data uses under GDPR — controversial, partly invalidated by Belgian DPA in 2022, then revised as TCF v2.2.
The Transparency and Consent Framework (TCF) is IAB Europe's industry-wide framework for representing GDPR-compliant consent for advertising and analytics in the open-web ad-tech ecosystem. A Consent Management Platform (CMP) presents the user with the standardized consent UI listing purposes (e.g. 'create profiles to personalise content', 'measure ad performance'), vendor counts, and legitimate-interest claims; the resulting consent string — a base64-encoded structure conforming to the TCF v2.x specification — is passed via the IAB OpenRTB bid request to every SSP, DSP, and ad-tech vendor in the chain, who are expected to honour the encoded purposes and vendor opt-ins. The Belgian Data Protection Authority ruled in February 2022 that the original TCF v2.0 was itself a GDPR violation (insufficient transparency, IAB Europe acting as joint controller for the consent string), kicking off a multi-year remediation that produced TCF v2.2 (May 2023) with cleaner purpose text, mandatory vendor counts, and explicit information sources. A separate IAB Tech Lab US Privacy String (`USP_v1`) handles U.S. state-law signals. From a security/AppSec perspective, the TCF string is a critical input that should be validated and not blindly trusted as user identity.
● Примеры
- 01
A publisher's CMP shows the TCF v2.2 consent UI to EU visitors, encodes the resulting choice into a TC string, and propagates it via OpenRTB to bidders.
- 02
An ad-tech vendor checks the TCF string on each request and refuses to process the bid request for purposes that the user has not opted into for that vendor.
● Частые вопросы
Что такое IAB TCF (Transparency and Consent Framework)?
The Interactive Advertising Bureau Europe's framework for capturing, encoding, and propagating user consent for advertising and analytics data uses under GDPR — controversial, partly invalidated by Belgian DPA in 2022, then revised as TCF v2.2. Относится к категории Приватность и защита данных в кибербезопасности.
Что означает IAB TCF (Transparency and Consent Framework)?
The Interactive Advertising Bureau Europe's framework for capturing, encoding, and propagating user consent for advertising and analytics data uses under GDPR — controversial, partly invalidated by Belgian DPA in 2022, then revised as TCF v2.2.
Как работает IAB TCF (Transparency and Consent Framework)?
The Transparency and Consent Framework (TCF) is IAB Europe's industry-wide framework for representing GDPR-compliant consent for advertising and analytics in the open-web ad-tech ecosystem. A Consent Management Platform (CMP) presents the user with the standardized consent UI listing purposes (e.g. 'create profiles to personalise content', 'measure ad performance'), vendor counts, and legitimate-interest claims; the resulting consent string — a base64-encoded structure conforming to the TCF v2.x specification — is passed via the IAB OpenRTB bid request to every SSP, DSP, and ad-tech vendor in the chain, who are expected to honour the encoded purposes and vendor opt-ins. The Belgian Data Protection Authority ruled in February 2022 that the original TCF v2.0 was itself a GDPR violation (insufficient transparency, IAB Europe acting as joint controller for the consent string), kicking off a multi-year remediation that produced TCF v2.2 (May 2023) with cleaner purpose text, mandatory vendor counts, and explicit information sources. A separate IAB Tech Lab US Privacy String (`USP_v1`) handles U.S. state-law signals. From a security/AppSec perspective, the TCF string is a critical input that should be validated and not blindly trusted as user identity.
Как защититься от IAB TCF (Transparency and Consent Framework)?
Защита от IAB TCF (Transparency and Consent Framework) обычно сочетает технические меры и операционные практики, как описано в определении выше.
Какие есть другие названия IAB TCF (Transparency and Consent Framework)?
Распространённые альтернативные названия: TCF, Transparency and Consent Framework, IAB TCF v2.2.
● Связанные термины
- privacy№ 233
Управление согласиями
Процессы и инструменты сбора, фиксации, обновления и применения разрешений пользователей на обработку персональных данных и установку cookies в соответствии с законодательством о приватности.
- privacy№ 494
Global Privacy Control (GPC)
A browser-level signal — an HTTP header and a JavaScript property — by which a user expresses a 'do not sell or share' opt-out, given binding legal force in California (CCPA/CPRA) and Colorado (CPA) regulations.
- compliance№ 488
GDPR
Общий регламент по защите данных Европейского союза, регулирующий обработку персональных данных лиц, находящихся в ЕС и ЕЭЗ.
- privacy№ 1263
Сторонний cookie
Cookie, установленный доменом, отличным от того, что в адресной строке браузера; исторически использовался для отслеживания пользователей между сайтами.
- privacy№ 914
Персонально идентифицируемая информация (PII)
Любые данные, позволяющие идентифицировать конкретного человека самостоятельно или в сочетании с другими сведениями: имена, идентификаторы, биометрия.
- compliance№ 167
CCPA
Закон о защите частной жизни потребителей Калифорнии — закон штата США, наделяющий жителей Калифорнии правами в отношении их персональных данных, хранимых бизнесом.
● См. также
- № 299Dark Patterns