Mapping Ad Consent Signals Across Supply Chain: TC String in TCF must be mapped from CMP to each downstream platform; GPP string type must be recorded: IAB Europe, Canada, MSPA US or US State variant; Signal interpretation can change at each hand-off, even if format is shared
Image: AdTech Market Guide

Supply Chain

Part of AdTech privacy and permission signals

Mapping permission signals through the ad supply chain

A permission signal can change meaning as it passes from a site to an advertising platform and downstream partners.

A permission signal can change meaning as it passes from a site to an advertising platform and downstream partners. Draw the chain before assuming one consent tool controls every recipient.

Map each route as user choice and purpose in the notice → consent capture in a CMP → named signal and fields → API or tag reading it → each observed advertising platform and downstream partner → expected action. Mark each hand-off where the payload or its interpretation could change.

For TCF, map user choice → CMP → TC String (Transparency and Consent String with Global Vendor List format) → TCF CMP API or __tcfapi → Google Tag Manager, if present → tags and their observed endpoints. Record the signal and recipient at each hand-off; the TC String alone does not prove a downstream tag received or applied the choice.

For GPP, map site or app → Consent Management Platform API → GPP string → ad tech provider, and record the supported string carried: IAB Europe TCF, IAB Canada TCF, MSPA US National string or a US State string. IAB Tech Lab describes GPP as a transmission protocol, and IAB Europe publishes TCF specifications; a shared format does not guarantee every vendor follows the choice.

The TCF resources name the TC String with Global Vendor List format and a list of registered TCF Vendors. Use these to label the TCF route, then match each live endpoint to the vendor it actually calls rather than treating framework membership as proof of a call.

Google Tag Manager is a tag container; when installed, its script request contacts Google-controlled infrastructure to retrieve the container script. Map that request separately, then record which tags fire and the endpoint each calls; container loading does not establish that a consent signal reached a tag or partner.

Firefox implements Global Privacy Control (GPC), and OneTrust says its CMP supports the signal. Map GPC as a separate browser-originated input, then verify what value or API is passed onward instead of assuming it becomes a TC String or GPP string.

Include server-side events and measurement partners, not just browser tags. Add each as a node at the API or event hand-off where it receives a signal, and record the actual endpoint.

Test four states with authorised test devices: no choice yet, granted, denied and withdrawn. For each state, note which calls occur and which fields are passed at each named hand-off.

Check whether denial stops the relevant processing or merely changes a reporting label, and compare withdrawal separately with denial. Keep screenshots or logs in the internal review record, not in customer-facing copy.

Use the map to identify which partners belong in the chain at all. Record each partner's observed name and expected action, then document gaps and owners before expanding the integration.

Mapping Permission Signals Through the Ad Supply Chain

  1. User Choice in NoticeUser provides consent or denial via site notice
  2. Consent Capture in CMPConsent Management Platform (CMP) records user choice
  3. Named Signal and FieldsTC String (TCF) or GPP string generated with vendor-specific data
  4. API or Tag Reading SignalTag or API reads signal (e.g., `__tcfapi`, GPP header)
  5. Advertising Platform ReceptionPlatform receives signal—e.g., Google Tag Manager, ad server
  6. Downstream Partner ProcessingPartner processes signal based on observed endpoint and action
  7. Server-Side Event HandlingMeasurement or analytics partners receive signal via API event

TC String vs. GPP String: Key Differences in Consent Transmission

  • Standard FormatTC String (TCF Global Vendor List format)
  • Transmission ProtocolGPP is a transmission protocol, not a consent format
  • Supported StringsIAB Europe TCF, IAB Canada TCF, MSPA US National, US State strings
  • Vendor ComplianceFramework membership ≠ guaranteed signal receipt or processing
  • Browser-Originated SignalGPC from Firefox is separate; not automatically converted to TC String or GPP

Testing Permission Signal States with Authorised Devices

  • No Choice YetVerify no consent signals are passed; record initial state
  • Consent GrantedConfirm TC String or GPP string transmitted correctly; track endpoint calls
  • Consent DeniedCheck if processing stops or only reporting labels change
  • Consent WithdrawnCompare with denial: ensure revocation triggers updated actions

Key Data Points for Consent Signal Mapping

Primary Frameworks
TCF (IAB Europe), GPP (IAB Tech Lab)
Australian Privacy Regulator
OAIC – oversees tracking pixels and privacy obligations
Common Tools
OneTrust CMP, Google Tag Manager, Firefox GPC
Critical Step
Map actual endpoints—not just framework membership

More from Supply Chain

Supply Chain

Advertising clean rooms

Understand what advertising clean rooms can support, which controls to inspect and how to interpret matched campaign results.