What it does
`euconsent-v2` holds a Transparency and Consent Framework string. Depending on the framework version and configuration, it can encode CMP metadata, purpose-level consent and legitimate-interest signals, vendor-level signals and policy-version information. `addtl_consent` is Google’s Additional Consent string for vendors outside the TCF Global Vendor List; neither string should be paraphrased as blanket consent.
The string is used when an advertising stack, publisher, demand partner or platform such as Google Ad Manager requires the IAB Transparency and Consent Framework. Real-time bidding is a common case, not the only possible reason.
What to write in a cookie declaration
List it under necessary as a consent management cookie, and name TCF specifically: the string is meaningful to people auditing your ad stack.
| Field | Value |
|---|---|
| Name | euconsent-v2 |
| Provider | IAB TCF |
| Purpose category | functional |
| Consent category | Necessary |
| Expiry | Up to 13 months under TCF policy (vendor default) |
| Storage | First-party |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Do not gate a string that is genuinely used to communicate the visitor’s choice. Whether you need TCF at all depends on your advertising partners and contractual stack, not merely whether you call the site a publisher.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Do I need a TCF consent string?
Only if your advertising stack or partners require TCF. Real-time bidding is a common reason, but demand partners, publisher tooling, Google Ad Manager or contractual requirements can also make it relevant. Named vendors and category controls do not by themselves answer that integration question.
Does StrongPrivacy emit a TCF string?
No. It recognises and classifies one so a scan reports it accurately, but it is not a registered TCF CMP and does not produce the string.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- IAB Europe: Transparency and Consent Framework
Official documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.