Consented data is personal data collected, stored or used on the strength of a person's explicit agreement, as opposed to another legal ground such as legitimate interest or contract. The idea exists because European law makes agreement the gate for most advertising uses of personal information. Article 4(11) of the GDPR defines consent as an indication of wishes that is freely given, specific, informed and unambiguous, expressed by a statement or a clear affirmative act. Article 7 adds that the controller must be able to demonstrate the agreement, and that withdrawal must be as easy as giving it.

The trade uses the label loosely. Platforms and data sellers attach it to audiences, identifier graphs and event streams to signal that records can be activated lawfully. Legally there is no certificate. Agreement covers the purposes a person saw, the vendors disclosed and the period before withdrawal, so the status travels as a signal beside the records rather than as a property of them.

How agreement becomes a signal

Two EU instruments create the demand. Article 5(3) of the ePrivacy Directive, amended in 2009, requires agreement before information is stored on or read from a device, which covers cookies and most device identifiers. The GDPR then decides whether the processing that follows is lawful. Legitimate interest cannot cover the cookie itself, only what happens to the data afterwards.

On the sell side, a consent management platform (CMP) holds tags until a visitor chooses, then records the outcome. Under IAB Europe's Transparency and Consent Framework (TCF), the record is a TC String: base64 text carrying consent and legitimate-interest bits for each purpose, vendor bits and publisher restrictions. It enters the OpenRTB bid request in user.consent, with regs.gdpr flagging that the GDPR applies, while the IAB Tech Lab's Global Privacy Platform (GPP) carries equivalent signals in regs.gpp and regs.gpp_sid. A demand-side platform reads the string before bidding. Google, for one, treats consent for Purpose 1 and either consent or legitimate interest for Purpose 2 as the minimum for non-personalised ad requests.

Buy-side tags use other channels. Google's Consent Mode relays four parameters - ad_storage, analytics_storage, ad_user_data and ad_personalization - and runs in a basic form, in which tags stay blocked until a choice, or an advanced form, in which tags load with a denied default and send limited measurement signals, according to Google's developer documentation. Amazon Ads has required, since June 30, 2026, a valid TCF, GPP or Amazon consent signal plus a country code for UK and EEA data sent through its ad tag and its Conversions and Events APIs.

Retention is a configuration matter. France's CNIL treats silence as refusal and, according to Bird & Bird's summary of its October 2020 guidance, regards six months as good practice before asking again, whichever answer was given.

Origin and evolution

The ePrivacy Directive of 2002 protected device privacy, but only its 2009 amendment made agreement the rule. The GDPR became applicable on May 25, 2018. IAB Europe launched the TCF a month earlier, on April 25, 2018, after work with more than 70 companies that began in February 2017. On October 1, 2019 the Court of Justice ruled in Planet49 that pre-ticked boxes are not valid consent, and TCF v2.1 followed in August 2020 to align. The European Data Protection Board's Guidelines 05/2020, adopted on May 4, 2020, went further: cookie walls and scrolling do not amount to valid agreement.

Google introduced Consent Mode as a beta for European advertisers in September 2020 and added ad_user_data and ad_personalization in December 2023. TCF v2.2, released on May 16, 2023, withdrew legitimate interest for purposes 3 to 6, the profiling and personalisation purposes, leaving consent as the only route. Two Court of Justice rulings then reshaped the field. In Meta v Bundeskartellamt, on July 4, 2023, it held that a dominant platform's position does not by itself prevent valid consent but weighs on whether consent was freely given. On March 7, 2024 it found, in the IAB Europe case, that a TC String is personal data. The EDPB's Opinion 08/2024, adopted April 17, 2024, concluded that most "consent or pay" models fail the freely given test.

TCF v2.3 followed on June 19, 2025, according to IAB Europe, making the Disclosed Vendors segment mandatory so that vendors relying on legitimate interest for special purposes can tell whether they were shown to the user. Strings created after February 28, 2026 without it are invalid. Mobile took a separate path: Apple's App Tracking Transparency prompt, introduced with iOS 14.5 in April 2021, produced reported opt-in rates of 11 to 15 per cent after launch.

Why it matters to marketers

Agreement decides what exists in the bid stream. When ad_storage is denied, Google's advertising systems operate without identifiers. Consent Mode modelling estimates conversions for non-consenting traffic from the behaviour of consenting users, but accuracy degrades as the share of refusals rises. Since June 15, 2026, ad_storage has been the single control over advertising data for linked Analytics and Ads accounts, which raises the cost of faulty implementation. One account saw its Google Ads conversions fall 90 per cent overnight after Google began enforcing its EU User Consent Policy on July 21, 2025, because the banner recorded choices but never passed them to the tags.

Liability follows the signal as well. France's Conseil d'Etat upheld a EUR 40 million fine against Criteo on March 4, 2026, after the company relied on partner websites to collect consent and could not prove it when asked. In May 2026 Andreea Mandeal, chief marketing officer at iubenda, argued in a position piece on the IAB Tech Lab website that consent management is foundational infrastructure for first-party data strategies, not a downstream compliance task.

Where it fails and who disputes it

The first dispute concerns what consent rates mean. Privacy group noyb reported on July 24, 2025 that pay-or-okay systems on European websites reach consent rates near 99.9 per cent, against research putting genuine preference for personalised advertising between 0.16 and 7 per cent. Elsewhere noyb has put the figure at 3 to 10 per cent, against consent rates of up to 90 per cent on banners with dark patterns. Regulators differ. EDPB chair Anu Talus said, "Online platforms should give users a real choice when employing 'consent or pay' models", whereas the UK Information Commissioner's Office allowed such models in January 2025 on strict conditions.

The second problem is auditability. BCN, a German publisher network, describes more than 80 million consented profiles from over 50 domains, a pool unlikely to equal 80 million distinct individuals. On July 13, 2026 a US judge let an investor suit against Zeta Global proceed. The plaintiffs allege that the true opt-in figure was less than half of the 240 million the company claimed; Zeta denies operating consent farms.

Third, signals are fragile. Choices collected but not passed downstream have the same effect as no choice at all.

Finally, the rules themselves are unsettled. The European Commission's Digital Omnibus proposal of November 19, 2025 included an Article 88b requiring controllers to honour automated consent signals from browsers. The Council removed it on June 18, 2026. An Implement Consulting Group estimate put annual advertiser losses from a 60 to 65 per cent fall in consent rates at EUR 40-50 billion; noyb contends that the estimate rests on a false assumption about overrides. A Council text dated September 3, 2026 returns cookie rules to Article 5(3) of the ePrivacy Directive and adds an exemption for measuring contextual advertising. No final text had been adopted by late September 2026, Tech Times reported.

Not the same as

First-party data describes where information came from, namely a direct relationship with the person. It says nothing about the legal basis, so records gathered without valid agreement stay unusable for purposes that need it.

Legitimate interest is the alternative GDPR ground, resting on a documented balancing test rather than agreement. Vendors can register some TCF purposes as flexible, and Google has registered purposes 2, 7, 9 and 10 as flexible, defaulting to legitimate interest.

Opt-out signals such as Global Privacy Control send a refusal, a header named Sec-GPC with the value 1, and belong to the United States model. Most state laws require opt-in for sensitive data but opt-out for ordinary targeted advertising, with California treating sensitive data on an opt-out basis. An audit of 7,634 sites found 55 per cent set advertising cookies despite an active signal.

Consent tooling is plumbing. A CMP, a TC String and Consent Mode record and relay a choice; none is the agreement. A site can run a CMP without Consent Mode, in which case the signals never reach Google's tags.

Recent developments

Policy 5.0.b of the TCF adds multi-device consent persistence, interface requirements and a renamed special feature on fingerprinting. The web compliance deadline falls in mid-October 2026, with native apps and connected TV following in mid-February 2027. Where an ad request from the EEA, UK or Switzerland arrives without a TC String, Google's CMP can serve a fallback message; the control managing that behaviour can activate from October 9, 2026.

Germany's Bundeskartellamt has made binding commitments under which Apple will redesign its tracking prompt, with Adjust reporting an average opt-in rate of 38 per cent in the first quarter of 2026, up from 35 per cent a year earlier. On the sell side, sales of segments built on consented profiles are moving to software agents, as BCN's Signals Agent shows, and the question of who verifies the underlying consent moves with them.

Timeline

  • July 12, 2002: The EU adopts the ePrivacy Directive.
  • November 25, 2009: Directive 2009/136/EC amends the ePrivacy Directive to require consent for storing or accessing information on a device.
  • February 2017: IAB Europe begins work on the Transparency and Consent Framework with more than 70 companies.
  • April 25, 2018: IAB Europe launches the TCF.
  • May 25, 2018: The GDPR becomes applicable.
  • August 21, 2019: IAB Europe announces TCF v2.0.
  • October 1, 2019: The Court of Justice rules in Planet49 that pre-ticked boxes are not valid consent.
  • May 4, 2020: The EDPB adopts Guidelines 05/2020 on consent.
  • August 19, 2020: TCF v2.1 launches.
  • September 2020: Google launches Consent Mode as a beta for European advertisers.
  • October 1, 2020: The CNIL publishes final cookie guidelines.
  • April 2021: Apple's App Tracking Transparency arrives with iOS 14.5.
  • May 16, 2023: TCF v2.2 is released and withdraws legitimate interest for purposes 3 to 6.
  • July 4, 2023: The Court of Justice decides Meta v Bundeskartellamt.
  • December 2023: Google adds ad_user_data and ad_personalization to Consent Mode.
  • March 7, 2024: The Court of Justice rules that a TC String is personal data.
  • April 17, 2024: The EDPB adopts Opinion 08/2024 on consent or pay models.
  • June 19, 2025: IAB Europe releases TCF v2.3.
  • July 21, 2025: Google enforces its EU User Consent Policy more strictly for UK and EEA traffic.
  • November 19, 2025: The European Commission publishes the Digital Omnibus proposal.
  • February 28, 2026: The TCF v2.3 transition ends.
  • March 4, 2026: France's Conseil d'Etat upholds the Criteo fine.
  • June 15, 2026: Consent Mode becomes the single control for advertising data in linked Analytics accounts.
  • June 18, 2026: The EU Council removes Article 88b from its Digital Omnibus text.
  • June 30, 2026: Amazon Ads' consent signal requirement takes effect for UK and EEA data.
  • July 13, 2026: A US judge allows the investor suit against Zeta Global to proceed.
  • September 3, 2026: A Council compromise text returns cookie rules to the ePrivacy Directive.
  • Mid-October 2026: Web compliance deadline for TCF Policy 5.0.b.

Summary

Who: Controllers that collect or use personal data for advertising, including publishers, advertisers, platforms and data sellers; the people whose agreement is sought; regulators such as the EDPB and the CNIL; and standard setters including IAB Europe and the IAB Tech Lab.

What: Personal data processed on the basis of a person's freely given, specific, informed and unambiguous agreement, recorded by a CMP and carried to vendors as a TC String, a GPP string or a platform signal such as Consent Mode.

When: Agreement became the rule for device access in 2009 and for the processing that follows from May 25, 2018. The signalling standards have been revised repeatedly since April 2018, and rules for 2026 and beyond are still being negotiated.

Where: Chiefly the EU, the EEA, the UK and Switzerland, with opt-in elements in United States state laws for sensitive data and in platform rules such as Apple's prompt.

Why: Law ties many advertising uses of personal data to agreement, and platforms now restrict conversion tracking, audiences and bidding where a valid signal is missing. The cost of unproven or poorly transmitted consent is lost measurement, regulatory fines and contested audience claims.