The scoping question, first
If your ad stack requires a TCF string, you need a registered CMP
StrongPrivacy recognises and classifies an IAB TCF consent string (the euconsent-v2 cookie is in the catalogue), but it is not a registered TCF consent management platform and does not emit one. A publisher running real-time bidding that depends on a TCF string needs a registered CMP for that part of the site. Settle this before a migration, not during one.
Some publishing sites do not run real-time bidding. Direct-sold advertising, affiliate links, newsletters and analytics may involve a smaller set of named vendors, but category-level consent alone does not establish vendor-specific transparency, lawful basis or contract compliance. Inventory each recipient and purpose.
Where this fits a publisher well
- Editorial sites with direct-sold or affiliate advertising rather than programmatic auctions
- Verification: proving what actually loads on an article page, which is where header bidding surprises live
- Evidence: recording what a visitor was shown and when, against a versioned configuration
- Finding the tags nobody remembers: the catalogue names ad exchanges, verification vendors and paywall tooling as well as the obvious pixels
Scan article pages, not the front page
A publisher’s homepage is often the least representative page on the site. Ad slots, embedded social posts, video players and recommendation widgets live on article templates. Scans cover a set of pages (up to twenty pages on Growth and twenty-five on Agency), and choosing them well matters more here than anywhere else.
Common questions
Does StrongPrivacy support the IAB TCF?
It detects and classifies a TCF consent string so a scan reports it accurately. It is not a registered CMP and does not emit one. If your demand partners require a TCF string, that requirement is not met here.
What about header bidding wrappers?
Prebid and programmatic exchanges are in the classification catalogue, so a scan will name them. Controlling them is a matter of gating the wrapper and configuring the wrapper’s own consent handling.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- StrongPrivacy product capabilities
Product documentation
Checked
- IAB Europe: Transparency and Consent Framework
Official documentation
Checked
- ICO: guidance on storage and access technologies
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.