
Vendor Due Diligence
Part of AdTech privacy and permission signals
Checking how vendors handle missing consent signals
A missing permission signal is not a blank cheque.
A missing permission signal is not a blank cheque. It may mean the person was never asked, the integration failed or the vendor cannot parse the format. For each data use, document the default the vendor says it applies.
For Australian direct marketing, the OAIC says APP 7 generally prohibits an organisation from using or disclosing personal information it holds for direct marketing unless an exception applies. Where an exception permits that use or disclosure, the individual must be able to opt out and the organisation must comply with the request.
Review vendors one at a time. Ask what each does when the signal is absent, malformed, delayed or withdrawn, and whether it suppresses advertising identifiers, pauses tags, uses a limited mode or keeps processing. Ask for the answer for the market and software version actually deployed.
Do not treat framework support as the vendor’s answer. IAB Tech Lab describes the Global Privacy Protocol (GPP) as a protocol for transmitting privacy, consent and consumer choice signals; it supports IAB Europe TCF and other privacy strings. A vendor may support GPP or TCF yet apply different rules to different fields.
Name the framework and version in the review record. IAB Europe lists TCF v2.3 implementation resources and TCF v5.0 Policies, updated May 2026; IAB Tech Lab’s GPP page was last updated 12 August 2026 and says its implementation guidelines were finalised in February 2025. Ask the vendor which applicable policy, specification and implementation version it follows.
For each vendor, record its name, the relevant registered-vendor listing where applicable, the signal format and the vendor’s stated response for every test case. IAB Europe provides a List of registered TCF Vendors and a TCF CMP Validator; neither, by itself, establishes what a particular vendor does when a signal is missing.
Run cases for an absent signal, a malformed TC String or GPP string, a delayed signal, a denied state and a withdrawal. Configure the consent management platform to produce the cases, then compare the vendor’s stated response with observed calls and stored data.
IAB Tech Lab lists TypeScript and Java libraries for GPP string encoding and decoding. Use an available library to prepare or inspect a GPP string; treat that as a format check, not proof of the vendor’s runtime behaviour.
Ask the vendor to state what it considers missing, what processing it allows in each case, and what action it takes if the signal cannot be parsed or arrives late. Ask it to distinguish an absent signal from a valid denied signal, and to explain how withdrawal changes the behaviour.
Pass a case only when observed calls and stored data match the vendor’s documented answer for that signal state, market and deployed version. Fail it when processing continues contrary to that answer; if the answer or result is unclear, hold the relevant data flow until privacy and technical owners resolve it.
Record the test date, signal format and state, vendor name and version, market, owner, stated response and observed result. Recheck after changes to the site, consent tool or vendor integration, because a previously safe default can change in deployment.
Vendor Responses to Missing or Malformed Consent Signals
- Absent SignalVendor suppresses advertising identifiers and pauses tags; no processing without consent.
- Malformed TC String / GPP StringVendor treats as invalid, applies default privacy mode; may log error but does not process data.
- Denied StateVendor respects opt-out; stops all data processing and discards existing identifiers.
Consent Signal Lifecycle and Vendor Response Timeline
- Signal Not Received (Absent)
- Immediate suppression of tracking; no data sent to vendor
- Signal Arrives Late (>10s)
- Vendor holds request; processes only if signal received before timeout
- Signal Malformed
- Treated as invalid; default privacy mode applied
- Consent Denied
- All tracking stopped; identifiers suppressed
Privacy Compliance Metrics for Vendor Consent Handling
- 12Vendors Tested
- 11Supports TCF v2.3


