Solutions

Consent for a publisher, where the ad stack is the site.

A publisher’s consent problem is not a list of vendors. It is an auction involving parties nobody enumerated in advance. Read this before assuming any consent platform covers it.

Typical plan
Growth or Agency
Hard part
Programmatic supply chain
TCF
Detected, not emitted
Decide first
Whether you need a registered CMP

The scoping question, first

If your ad stack requires a TCF string, you need a registered CMP

StrongPrivacy recognises and classifies an IAB TCF consent string (the euconsent-v2 cookie is in the catalogue), but it is not a registered TCF consent management platform and does not emit one. A publisher running real-time bidding that depends on a TCF string needs a registered CMP for that part of the site. Settle this before a migration, not during one.

Some publishing sites do not run real-time bidding. Direct-sold advertising, affiliate links, newsletters and analytics may involve a smaller set of named vendors, but category-level consent alone does not establish vendor-specific transparency, lawful basis or contract compliance. Inventory each recipient and purpose.

Where this fits a publisher well

  • Editorial sites with direct-sold or affiliate advertising rather than programmatic auctions
  • Verification: proving what actually loads on an article page, which is where header bidding surprises live
  • Evidence: recording what a visitor was shown and when, against a versioned configuration
  • Finding the tags nobody remembers: the catalogue names ad exchanges, verification vendors and paywall tooling as well as the obvious pixels

Scan article pages, not the front page

A publisher’s homepage is often the least representative page on the site. Ad slots, embedded social posts, video players and recommendation widgets live on article templates. Scans cover a set of pages (up to twenty pages on Growth and twenty-five on Agency), and choosing them well matters more here than anywhere else.

Common questions

Does StrongPrivacy support the IAB TCF?

It detects and classifies a TCF consent string so a scan reports it accurately. It is not a registered CMP and does not emit one. If your demand partners require a TCF string, that requirement is not met here.

What about header bidding wrappers?

Prebid and programmatic exchanges are in the classification catalogue, so a scan will name them. Controlling them is a matter of gating the wrapper and configuring the wrapper’s own consent handling.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.