Consent String
A consent string is a compact, machine-readable code that captures the privacy and consent choices a user has made, so that those choices can be passed between different systems. In online advertising, it commonly travels alongside an ad request to indicate whether a user has agreed to particular uses of their data. It is a technical carrier of a consent signal rather than proof that valid consent was obtained.
A consent string is an encoded, machine-readable data structure that represents a user's privacy choices, including consent status and, in some frameworks, publisher transparency information, and is exchanged between participating systems (for example, added to an ad bid request). The most widely referenced example is the string defined under IAB Europe's Transparency & Consent Framework (TCF), which IAB Europe describes as an accountability tool built on standardisation to facilitate compliance with certain provisions of the ePrivacy Directive and the EU GDPR. A consent string encodes the recorded outcome of a consent interaction; it does not by itself establish that consent met the validity conditions of any applicable law, nor does it determine the lawful basis for processing, which may or may not be consent. Treatment and applicability differ across jurisdictions and regimes; this entry does not cover the mechanics of consent capture, the technical encoding format and version specifics, string length or URL constraints, storage and retention, or enforcement. Practitioners should validate any specific claims against the relevant framework specification and applicable law.
Why it matters
A consent string matters because modern digital advertising and content delivery involve many participating systems that never interact directly with the user. The consent string provides a compact, machine-readable way to carry a user's recorded privacy choices between these systems, so that a signal reflecting those choices can travel alongside an ad bid request or similar transaction. Without such a standardised carrier, downstream parties would have no consistent means of learning what a user was told or what they indicated.
The critical point for practitioners is that a consent string is a technical carrier of a signal, not proof that valid consent was obtained. It encodes the recorded outcome of a consent interaction, but it does not by itself establish that the consent met the validity conditions of any applicable law, and it does not determine the lawful basis for processing, which may or may not be consent. Under the EU GDPR and the ePrivacy Directive, consent is only one of several possible lawful bases, and treating the presence of a consent string as equivalent to demonstrable, valid consent is a common and consequential error. IAB Europe describes its Transparency & Consent Framework (TCF), which defines the most widely referenced consent string, as an accountability tool built on standardisation to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR, framing it as an aid to compliance rather than a guarantee of it.
Accountability under governance and data protection frameworks generally requires demonstrable evidence that consent was validly captured, not merely the existence of an encoded string asserting a status. Organisations relying on consent strings should therefore treat them as one component within a broader consent capture and record-keeping process, and validate any specific claims against the relevant framework specification and applicable law.
Who it's relevant to
Inside Consent String
Common questions
Answers to the questions practitioners most commonly ask about Consent String.