Agent skill

Tcf V2 Implementation

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implementing the IAB Transparency and Consent Framework v2.2 for programmatic advertising consent management.

Apache-2.0Auto-check passedLegal & Compliance

Install Tcf V2 Implementation

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill tcf-v2-implementation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills tcf-v2-implementation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/tcf-v2-implementation .claude/skills/tcf-v2-implementation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tcf-v2-implementation
GitHub stars
295
Token cost
~2.7k tokens
SKILL.md length
1,014 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implementing the IAB Transparency and Consent Framework v2.2 for programmatic advertising consent management.

  • Works in 6 steps: CMP Registration → Global Vendor List Integration → TCF v2.2 Purposes → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, TCF v2.2 Architecture, TCF v2.2 Compliance Validation and Key Legal and Technical…
  • Runs Python scripts from its folder; reaches vendor-list.consensu.org and policies.google.com

What it does

Tcf V2 Implementation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implementing the IAB Transparency and Consent Framework v2.2 for programmatic advertising consent management. Covers CMP registration, Global Vendor List integration, TC String encoding, publisher restrictions, and compliance validation.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and E-commerce operations. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve E-commerce operations

Example prompts

  • “/tcf-v2-implementation”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. CMP Registration
  2. Global Vendor List Integration
  3. TCF v2.2 Purposes
  4. TC String Structure
  5. Publisher Restrictions
  6. CMP API Implementation

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • vendor-list.consensu.org
    • policies.google.com

    Also links to:

    • cmp.pinnacle-ecommerce.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tcf V2 Implementation loads about 2.7k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,014 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,014 words, ~2,675 tokens.

Download SKILL.mdSave it as .claude/skills/tcf-v2-implementation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
tcf-v2-implementation
description
Implementing the IAB Transparency and Consent Framework v2.2 for programmatic advertising consent management. Covers CMP registration, Global Vendor List integration, TC String encoding, publisher restrictions, and compliance validation.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
cookie-consent-compliance
metadata.tags
tcf, iab, consent-management-platform, tc-string, global-vendor-list

IAB TCF v2.2 Implementation

Overview

The IAB Europe Transparency and Consent Framework (TCF) v2.2, released in May 2023 as an update to v2.0, provides a standardized mechanism for collecting, encoding, and distributing user consent signals across the programmatic advertising supply chain. Publishers, advertisers, and ad technology vendors use TCF to communicate consent status through the TC String — a compact, base64url-encoded data structure. TCF v2.2 introduced key changes including the removal of legitimate interest as a legal basis for cross-device targeting (Purpose 2 in part) and restrictions on certain vendor practices.

TCF v2.2 Architecture

Core Components
  1. Consent Management Platform (CMP): The user-facing interface that collects consent. Must be registered with IAB Europe and assigned a CMP ID.
  2. Global Vendor List (GVL): A centralized registry of ad technology vendors, maintained by IAB Europe, listing each vendor's declared purposes and legal bases.
  3. TC String: The encoded consent signal transmitted through the ad supply chain.
  4. CMP API (__tcfapi): A JavaScript API that vendors call to read the current consent state.
Implementation for Pinnacle E-Commerce Ltd
Step 1: CMP Registration

Register Pinnacle E-Commerce Ltd's CMP with IAB Europe:

Registration FieldValue
CMP NamePinnacle Consent Manager
PublisherPinnacle E-Commerce Ltd
CMP IDAssigned by IAB Europe upon registration (e.g., 432)
Supported TCF version2.2
GVL versionLatest (auto-updated weekly)
CMP JavaScript URLhttps://cmp.pinnacle-ecommerce.com/tcf-v2.js

Registration requirements:

  • Demonstrate CMP compliance with IAB TCF Policies
  • Pass IAB Europe CMP validation testing
  • Agree to the CMP Terms and Conditions
  • Implement the __tcfapi stub before the full CMP loads
Step 2: Global Vendor List Integration

The GVL is published at https://vendor-list.consensu.org/v3/vendor-list.json and contains:

json
{
  "gvlSpecificationVersion": 3,
  "vendorListVersion": 287,
  "tcfPolicyVersion": 4,
  "lastUpdated": "2026-03-01T12:00:00Z",
  "purposes": {
    "1": {
      "id": 1,
      "name": "Store and/or access information on a device",
      "description": "Cookies, device or similar online identifiers...",
      "illustrations": ["..."]
    }
  },
  "vendors": {
    "755": {
      "id": 755,
      "name": "Google Advertising Products",
      "purposes": [1, 3, 4],
      "legIntPurposes": [2, 7, 9, 10],
      "flexiblePurposes": [2, 7, 9, 10],
      "specialPurposes": [1, 2],
      "features": [1, 2],
      "specialFeatures": [],
      "policyUrl": "https://policies.google.com/privacy",
      "cookieMaxAgeSeconds": 63072000,
      "usesCookies": true,
      "usesNonCookieAccess": true
    }
  }
}

GVL Management for Pinnacle E-Commerce Ltd:

  1. Cache the GVL locally with a maximum staleness of 24 hours
  2. Display only vendors that Pinnacle E-Commerce Ltd actually uses (vendor subset)
  3. Show vendor count in the consent banner: "We work with 47 advertising partners"
  4. Provide a searchable vendor list in the detailed consent layer

Pinnacle E-Commerce Ltd Vendor Subset:

Vendor IDVendor NamePurposesLegal Basis
755Google Advertising Products1, 3, 4Consent
91Criteo SA1, 2, 3, 4, 7Consent
42Taboola Inc.1, 2, 3, 4, 5, 7Consent
69OpenX Technologies1, 2, 3, 4, 7Consent
253Meta Platforms, Inc.1, 2, 3, 4, 7, 10Consent
Step 3: TCF v2.2 Purposes

The 11 TCF purposes and their mapping for Pinnacle E-Commerce Ltd:

TCF PurposeNameLegal Basis at Pinnacle
1Store and/or access information on a deviceConsent only
2Select basic adsConsent only
3Create profiles for personalised advertisingConsent only
4Use profiles to select personalised adsConsent only
5Create profiles to personalise contentConsent only
6Use profiles to select personalised contentConsent only
7Measure ad performanceConsent only
8Measure content performanceConsent only
9Understand audiences through statistics or combinations of data from different sourcesConsent only
10Develop and improve servicesConsent only
11Use limited data to select contentConsent only

Special Purposes (always allowed, no consent required):

  • SP1: Ensure security, prevent and detect fraud, and fix errors
  • SP2: Deliver and present advertising and content

Features (declared, not consented to individually):

  • F1: Match and combine data from other data sources
  • F2: Link different devices
  • F3: Receive and use automatically-sent device characteristics for identification

Special Features (require explicit consent):

  • SF1: Use precise geolocation data
  • SF2: Actively scan device characteristics for identification
Show full SKILL.md (449 more words)Show less
Step 4: TC String Structure

The TC String is a base64url-encoded binary string containing:

Core String Segments:

FieldBitsDescription
Version6TCF version (value: 2)
Created36Deciseconds since 01/01/2020 00:00:00 UTC
LastUpdated36Deciseconds since 01/01/2020 00:00:00 UTC
CmpId12CMP ID (Pinnacle: 432)
CmpVersion12CMP version number
ConsentScreen6Screen number in CMP where consent was given
ConsentLanguage12ISO 639-1 language code
VendorListVersion12GVL version used
TcfPolicyVersion6TCF Policy version (value: 4)
IsServiceSpecific11 = publisher-specific TC String
UseNonStandardStacks1Whether non-IAB standard stacks are used
PurposeConsents24Bitfield for purpose consent (purposes 1-24)
PurposeLegitimateInterests24Bitfield for purpose LI
PurposeOneTreatment10 = purpose 1 was disclosed; 1 = not
PublisherCC12ISO 3166-1 alpha-2 publisher country code

Vendor Consent Section: Variable-length encoding of per-vendor consent using either a bitfield or range encoding, depending on which is more compact.

Publisher Restrictions Section: Overrides vendor-declared legal bases at the publisher level.

Step 5: Publisher Restrictions

Pinnacle E-Commerce Ltd applies publisher restrictions to enforce consent-only for all purposes:

json
{
  "publisherRestrictions": [
    {
      "purposeId": 2,
      "restrictionType": 1,
      "vendorIds": [91, 42, 69]
    },
    {
      "purposeId": 7,
      "restrictionType": 1,
      "vendorIds": [91, 42, 69, 253]
    },
    {
      "purposeId": 9,
      "restrictionType": 1,
      "vendorIds": [91, 42, 69]
    },
    {
      "purposeId": 10,
      "restrictionType": 1,
      "vendorIds": [91, 42, 69, 253]
    }
  ]
}

Restriction types:

  • 0 = Purpose flatly not allowed by publisher
  • 1 = Require consent (override legitimate interest)
  • 2 = Require legitimate interest (override consent)
  • 3 = Vendor requires both consent and LI to process
Step 6: CMP API Implementation

The __tcfapi must be available before any vendor scripts load:

Stub Implementation (loads first):

javascript
(function() {
  var queue = [];
  var tcfapi = function(command, version, callback, parameter) {
    if (command === 'addEventListener') {
      queue.push({ command: command, callback: callback });
    } else {
      queue.push({ command: command, version: version, callback: callback, parameter: parameter });
    }
  };
  tcfapi.queue = queue;
  window.__tcfapi = tcfapi;
})();

Supported Commands:

CommandDescription
getTCDataReturns the TC String and parsed consent data
pingReturns CMP status and loading state
addEventListenerRegisters a callback for consent changes
removeEventListenerRemoves a registered callback
getInAppTCDataReturns TC data for in-app (mobile) contexts

getTCData Response:

json
{
  "tcString": "CPyXXYAPyXXYAAGABCENB4CgAP_AAH_AAAAAHfoBpDxkBSFCAGJoYtkgAAAGxwAAICACABAAoAAAABoAIAQAAAAQAAAgBAAAABIAIAIAAABAGEAAAAAAQAAAAQAAAEAAAAAAIQIAAAAAAiBAAAAAAAAAAAAAAABAAAAAAAAAAgAAAAAAAQAA",
  "tcfPolicyVersion": 4,
  "cmpId": 432,
  "cmpVersion": 1,
  "gdprApplies": true,
  "eventStatus": "useractioncomplete",
  "purpose": {
    "consents": { "1": true, "2": false, "3": false, "4": false, "7": true },
    "legitimateInterests": {}
  },
  "vendor": {
    "consents": { "755": true, "91": false, "42": false },
    "legitimateInterests": {}
  },
  "publisher": {
    "restrictions": { "2": { "91": 1, "42": 1, "69": 1 } }
  }
}

TCF v2.2 Compliance Validation

Validation Checklist
RequirementVerification Method
CMP registered with IAB EuropeCheck CMP ID in IAB registry
GVL version current (within 7 days)Parse TC String VendorListVersion field
TC String decodes correctlyUse IAB reference decoder
Purpose 1 consent collected before device storageVerify no cookies set pre-consent
Publisher restrictions encodedDecode TC String restrictions segment
__tcfapi responds to pingCall __tcfapi('ping', 2, callback)
Consent UI shows all declared purposesCompare UI with GVL purposes
Vendor list matches GVL subsetCompare displayed vendors with GVL
TC String transmitted in bid requestsInspect OpenRTB consent field
  • IAB Europe TCF v2.2 Technical Specification (May 2023) — TC String format, CMP API, GVL structure
  • IAB Europe TCF Policies v4 — Rules governing CMPs and vendors
  • IAB Europe CMP Validator Tool — Automated TC String validation
  • ePrivacy Directive 2002/58/EC, Article 5(3) — Legal basis for TCF Purpose 1
  • CJEU Case C-673/17 (Planet49) — Active consent requirements
  • Belgian DPA Decision 21/2022 (IAB Europe) — Found IAB Europe a data controller for TC String; TCF must ensure valid GDPR consent
  • GDPR Article 4(11) — Consent definition applicable to TCF consent signals

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/tcf-v2-implementation of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Tcf V2 Implementation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tcf V2 Implementation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tcf V2 Implementation this skillmukul975/Privacy-Data-Protection-Skills295—~2.7kAutomated safety check: PassApache-2.0
Morocco Ecommerce Compliance Audit Omar Laftouhlawve-ai/awesome-legal-skills836—~2.4kAutomated safety check: PassCustom licence
Webshop Search Formulatorzjunlp/SkillNet1.4k—~677Automated safety check: PassMIT
LinkfoxagentLeoYeAI/openclaw-master-skills2.2k—~3.8kAutomated safety check: PassMIT
Tech Contract Negotiation Patrick Munrolawve-ai/awesome-legal-skills836—~4.9kAutomated safety check: PassAGPL-3.0
Sealeap Chongming Amazon Seller Storefront Lead Miningxjli360/sealeap-amazon-skills240—~851Automated safety check: PassMIT

Similar skills

  • Performs a legal compliance audit for a Moroccan e-commerce website, focused on personal data protection (Law 09-08) and consumer contract disclosures/obligations (Law 31-08).

    836 GitHub stars~2.4k tokensUpdated 6 days ago
    Sales & SupportAuto-check passed
  • This skill generates effective search keywords based on parsed product criteria.

    1.4k GitHub stars~677 tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Linkfoxagent

    LeoYeAI/openclaw-master-skills

    Cross-border e-commerce AI Agent with 41 specialized tools for Amazon/TikTok/eBay/Walmart product research, competitor analysis, keyword tracking, review insights, patent detection, trend analysis…

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Tech Contract Negotiation Patrick Munro

    lawve-ai/awesome-legal-skills

    Systematic contract negotiation strategies for technology services agreements with German/EU law specificity.

    836 GitHub stars~4.9k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed
  • Mine product opportunities by tracing well-performing organic listings back to their sellers' storefronts, ranking storefront items by estimated revenue and review count, then validating each…

    240 GitHub stars~851 tokensUpdated 10 days ago
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Tcf V2 Implementation

What does Tcf V2 Implementation do?

Implementing the IAB Transparency and Consent Framework v2.2 for programmatic advertising consent management. Tcf V2 Implementation is an agent skill from mukul975/Privacy-Data-Protection-Skills.2 for programmatic advertising consent management.

When should I use Tcf V2 Implementation?

Tcf V2 Implementation fits situations like: tasks that involve Privacy and GDPR; tasks that involve E-commerce operations.

How do I install Tcf V2 Implementation in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill tcf-v2-implementation -a claude-code`. Or copy the skill folder (skills/privacy/tcf-v2-implementation in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/tcf-v2-implementation in your project. Claude Code loads it when a task matches its description.

How do I install Tcf V2 Implementation in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill tcf-v2-implementation -a codex`. Or copy the skill folder (skills/privacy/tcf-v2-implementation in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/tcf-v2-implementation in your project. Codex loads it when a task matches its description.

Can I use Tcf V2 Implementation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill tcf-v2-implementation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tcf-v2-implementation, .gemini/skills/tcf-v2-implementation, .github/skills/tcf-v2-implementation and .opencode/skills/tcf-v2-implementation in your project.

What does Tcf V2 Implementation need to run?

Going by SKILL.md and its folder, Tcf V2 Implementation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Tcf V2 Implementation access the network?

SKILL.md names 3 domains. In commands or code: vendor-list.consensu.org and policies.google.com; the agent is likely to contact these when it follows the instructions. As links in the text: cmp.pinnacle-ecommerce.com. This is read from the text; nothing was executed.

Is Tcf V2 Implementation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tcf V2 Implementation use?

Tcf V2 Implementation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tcf V2 Implementation use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 942 tokens, read only when the agent opens those files.

What are the alternatives to Tcf V2 Implementation?

Skills that share tags, products or a category with Tcf V2 Implementation: Morocco Ecommerce Compliance Audit Omar Laftouh (lawve-ai/awesome-legal-skills, 836 stars), Webshop Search Formulator (zjunlp/SkillNet, 1.4k stars), Linkfoxagent (LeoYeAI/openclaw-master-skills, 2.2k stars) and Tech Contract Negotiation Patrick Munro (lawve-ai/awesome-legal-skills, 836 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tcf V2 Implementation?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.