Consent that never reaches the buyer monetises exactly like a refusal
The consent rate has become a metric tracked like a revenue line. It answers one precise question, how many users accepted, and leaves untouched a second one that actually decides the number: how many of those answers arrived intact at the buyer.
Between the consent window and the auction, the user’s choice stops being a button and becomes a string of characters carried in parameters that specifications name. When that string is missing, arrives in a stale version or leaves one channel out, the industry applies a default rule, and it does not favour the publisher.
Here is that journey, what each break costs, what changed on 1 March 2026, and why, inside an app, the time it takes to fix is not the publisher’s alone.
What consent is actually worth, measured rather than assumed
Start with the figure the industry quotes without having read it. The reference most often invoked on the value of tracking to a publisher is a study by Veronica Marotta, Vibhanshu Abhishek and Alessandro Acquisti, presented at the WEIS conference in 2019. It draws on one week of advertising transactions in May 2016, across the sites of a single large media group, more than 70% of them concluded from US addresses.
Its result is sober: “when a user’s cookie is available publisher’s revenue increases by only about 4%”, which is “an average increase of $0.00008 per advertisement”. The authors stop short of concluding that tracking is worthless, and do the arithmetic at scale: for a site selling four million ads a day, giving up cookies would forfeit “about $320 in revenue per day, or almost $10,000 per month”.
Three cautions come with it, two of them set by the authors. The result “can be interpreted as the value generated for publishers by the presence of a cookie, but cannot be interpreted as the value generated by behavioral advertising”, and it “may not generalize to the entire universe of existing websites”. The third is about the document itself: it describes itself as a preliminary draft from May 2019, and it covers web display, where phones already account for 31% of the transactions but never through an app.
So the figure does not establish that consent is worthless. It establishes that its value is fractions of a cent multiplied by volume, which makes it fragile at both ends: a point of consent rate gained gets diluted, a lost signal wipes out the whole line. Transport, by contrast, is not a matter of percentages. It is all or nothing.
The default rule: no signal, no consent
This is not an interpretation. It is written into the technical specification that consent management platforms and their partners follow. The CMP API specification of IAB Europe’s Transparency and Consent Framework puts it this way: “If a CMP is not present, or if the CMP fails to respond, vendors should assume ‘no consent’ and ‘no legitimate interest transparency established’ in contexts where GDPR applies.”
One honest caveat about that sentence: it sits in the passage explaining how a script detects a CMP on a page, and the in-app part of the same specification carries no equivalent. It states the spirit of the framework, not a rule written for apps. What does apply to apps is written elsewhere, and far more bluntly.
On the buying side, Google Ad Manager’s documentation looks categorical at first: “Ad Manager won’t request ads until a valid TC string is received.” That sentence addresses publishers passing the string to their own tags, and you have to read the neighbouring page to learn what actually happens to the inventory.
What happens is not silence, it is a downgrade. Google writes that it “will also attempt to serve an eligible limited ad for requests from the EEA, the UK, or Switzerland that don’t include a TC string from a Google-certified CMP”. The impression still sells, but at the price of an unconsented impression, on traffic where the user may well have said yes.
A technical silence is not read as an open question. It is read as a no, and it is paid at the price of a no.
WHAT A COMPLETE REQUEST CARRIES gdpr=1 the European framework applies 0: it does not apply. absent: unknown gdpr_consent=<TC string> the choice, disclosed vendor segment included addtl_consent=2~1.10~dv.2.3.4 the Google partners outside the IAB global list WHAT EACH ABSENCE PRODUCES gdpr_consent empty the request is treated as unconsented, it falls back to limited ads string without the disclosed vendor segment the same fallback, although the user did answer addtl_consent missing those partners got no signal at all
1 March 2026 changed what a stale string is worth
Version 2.3 of the framework was released on 19 June 2025. It settles a long-standing ambiguity: under the previous version, a vendor declaring both purposes and special purposes under legitimate interest could not tell from the string whether the user had objected or whether it had simply never been disclosed in the interface. Version 2.3 makes a segment listing the disclosed vendors mandatory.
IAB Europe set the end of the transition period at 28 February 2026, and its wording is blunt: “TC Strings created after 28 February 2026 without this segment will be considered invalid.” Strings created before remain valid, but only until they are replaced as users renew or change their choices.
Google announces the same deadline on the buying side, with the commercial consequence attached: “TCF v2.3 is mandatory for all TC strings generated on or after March 1, 2026. Failure to meet this requirement may cause the associated ad request to be defaulted to Limited Ads, which may impact revenue.”
A compliance fix becomes, directly, a revenue variable. That is rare enough to be worth noting: the two subjects do not often meet this closely.
Fixing a CMP inside an app: what changes remotely, and what does not
On a website, a fix to a consent window is live on the next load. In an app the answer is more nuanced than the usual shortcut suggests, and it is worth checking before either panicking or relaxing.
What is driven remotely is the message: with Google, the window is composed and published from the console, first-layer refuse button included. What is compiled into the binary is the library that writes the string. On the move to version 2.3, Google says the question does not even arise for its own solution: “The Google UMP SDK is IAB-certified for TCF v2.3 across all SDK versions”, and “no action is required if you are using the Google CMP for your web or app properties”.
For a third-party CMP the tone changes: “We urge you to contact your Consent Management Platform (CMP) immediately to confirm their plan and timeline for migrating your properties to their TCF v2.3-compliant solution.” This is where mobile parts company with the web. If that migration needs a new version of the library, it needs a release, then an install, and that delay does not belong to the publisher.
An installed version, for its part, cannot be recalled. In the 2026 Spanish file, the publisher wrote that it could not correct an already published version, only publish a new one, while stating in the same document that it had a feature able to force an update away from an obsolete version. Both claims sit side by side, and they frame the right question to ask at home: is the update forced, or merely hoped for?
One last point widens the problem. Google specifies that “the IAB TC string is available in device local storage (NSUserDefaults for iOS or SharedPreferences for Android) and accessible to all mediation partners to obtain, parse, and respect when called in a mediation waterfall request”. A stale string is therefore not a local incident: it is the value the whole waterfall reads back. Where that storage lives and what it holds is fully described by the specification.
What limited ads take out of the inventory
The fallback is not a failure, it is a documented serving mode. Google describes it this way: “Limited ads (LTD) allow you to serve ads without using personal data for personalization.” The qualifier matters: personalisation stops, processing does not. The same page notes that IP addresses are still used to deliver the ad, and that fraud-detection cookies are still set. Google also names the most common trigger, which has nothing to do with a stale string: “Limited ads serving applies if there is no consent for IAB TCF Purpose 1.”
What disappears touches the product being sold as much as the targeting. Google lists the disabled features, starting with every feature that relies on a local identifier: frequency capping, save for one closed beta, reporting on cookie reach and unique reach, and in-app conversions. It adds that unless programmatic limited ads are turned on, “fraud-detection capabilities may be reduced”, and recommends publishers inform advertisers.
The inventory stays sellable, but it loses the attributes that set its price. That loss shows up on no consent dashboard, because it happens after the window, inside the request.
The second channel nobody checks
A user’s choice is single; its transport is not. Alongside the TC string, Google maintains a second one, called additional consent. Its specification gives the reason: it allows transparency and consent signals to be sent to vendors “who are not yet registered with the IAB Europe Global Vendor List”, provided they appear on Google’s Ad Technology Providers list.
It travels in its own parameter and carries its own format, of the form 2~1.10~dv.2.3.4: the specification version number, the list of consented identifiers, then the list of vendors merely disclosed. Google specifies that only a CMP registered with IAB Europe’s framework may create it, and that vendors must not build one themselves.
The consequence is concrete: a publisher can post a flattering rate, forward its TC string correctly, and forward nothing at all to that family of partners. From their point of view the user never answered.
At the other end, revenue taken before the choice
Monetisation is not lost only through failed transport. It is also taken too early, and that failure has a price tag.
On 1 September 2025 the CNIL’s enforcement committee fined the Irish company operating SHEIN’s site for Europe 150 million euros under article 82 of the French Data Protection Act. The findings are the kind a traffic capture surfaces: cookies “particularly with advertising purposes”, placed “as soon as they arrived on the site, even before they interacted with the information banner to express a choice”. And after refusal: “when a user [...] clicked on the ‘Refuse all’ button in the banner [...] new cookies were still placed and others, already present, continued to be read.”
The same day, two fines totalling 325 million euros were issued against Google, 200 million against GOOGLE LLC and 125 million against GOOGLE IRELAND LIMITED. They cover two separate breaches, one of them the display of advertisements between Gmail messages. On the tracker count alone, the CNIL found that “until October 2023, the consent of users creating a Google account was not freely given, as it was more difficult to refuse cookies linked to personalised advertising than to accept them”. That breach concerned more than 74 million accounts.
Both cases concern websites, which has to be said in an article about mobile. They still apply here, because article 82 of the French Data Protection Act draws no line between a browser and a phone, and the CNIL built its mobile app recommendation on that same provision. What these decisions punish is no interface detail, it is monetisation mechanics: taking revenue before the choice, and making refusal costlier than agreement. In an app, the same mechanics are measured on the traffic, and an SDK can produce them without its provider seeing it.
Monetising refusal: consent or pay
That leaves the route some publishers take when refusal costs too much: charging for it. The CNIL states the intent plainly: publishers are seeking to “offset the loss of advertising revenue resulting from the absence of trackers with another form of remuneration”.
The framework rests on a Conseil d’État ruling of 19 June 2020, narrower than it is usually made out to be. The court did not bless tracking walls: it struck down the position in which the CNIL banned them outright. By “inferring such a general and absolute prohibition from the mere requirement of freely given consent [...], the CNIL exceeded what it may lawfully do within a soft-law instrument.” Neither “case by case” nor “alternative” appears anywhere in the ruling.
The test everyone quotes next, the case-by-case assessment and the “real and satisfactory alternative offered where cookies are refused”, is the CNIL’s own reading of that ruling, set out in the first assessment criteria it published on 16 May 2022. It starts there from the observation that websites and mobile apps alike use such walls, even if the rest of the document only ever speaks of sites.
The EDPB tightened the frame for large platforms in Opinion 08/2024, adopted on 17 April 2024. It is an opinion rather than binding law, and it is written as recommendations: “In most cases, it will not be possible for large online platforms to comply with the requirements for valid consent if they confront users only with a binary choice between consenting to processing of personal data for behavioural advertising purposes and paying a fee.” The opinion first asks controllers to consider an “equivalent alternative” that does not entail the payment of a fee. And if they do charge for that equivalent alternative, they should consider offering “a further alternative, free of charge, without behavioural advertising, e.g. with a form of advertising involving the processing of less (or no) personal data”.
Its scope is expressly limited to large online platforms. It nonetheless sets the direction of the reasoning, and the CNIL already applies the same real-alternative test to everyone else.
The questions only execution answers
A consent dashboard answers one question, what the user clicked. The rest are asked afterwards, on the wire, and no interface displays them.
Which requests leave before the window appears? Which keep going after a refusal? Which consent parameters does the request actually carry when it leaves the phone, and which are empty? Is the string written into local storage the one today’s installed version produces, or the one from a release shipped a year ago and never updated?
You answer by running the app on a real phone, marking the moment you accept and the moment you refuse, then reading the traffic. Skanopy places each exchange relative to those moments and names the third parties contacted: the map of third-party actors and what the banner actually triggers, replayed at every released version. The report establishes dated facts, it does not rule on compliance: the qualification stays with the data protection officer. That is the material behind a GDPR audit of a mobile app.
Sources
Every finding in this article traces back to one of these documents.
- IAB ’26All You Need to Know About the Transition to TCF v2.3: released 19 June 2025, transition ends 28 February 2026, disclosed vendor segment mandatoryIAB Europe
- IAB Tech LabCMP API v2: the ${GDPR} and ${GDPR_CONSENT_XXXX} macros, and the default rule when no CMP respondsIAB Tech Lab, Transparency and Consent Framework v2
- GooglePublisher integration with the IAB Europe TCF: the 1 March 2026 deadline, the limited ads fallback, and the string read from local storage by mediation partnersGoogle Ad Manager Help
- GoogleLimited ads: what the mode disables, from local-identifier features to reportingGoogle Ad Manager Help
- GoogleEuropean regulations message: the UMP SDK certified for TCF v2.3 across all SDK versions, and the limited ads fallback without consent for Purpose 1Google AdMob Help
- GoogleGoogle Additional Consent technical specification: the AC string format and vendors outside the Global Vendor ListGoogle Ad Manager Help
- WEIS ’19Online Tracking and Publishers’ Revenues: An Empirical AnalysisVeronica Marotta, Vibhanshu Abhishek, Alessandro Acquisti, Workshop on the Economics of Information Security, preliminary draft of May 2019
- CNIL ’25Trackers dropped without consent: 150 million euro fine, decision SAN-2025-005 of 1 September 2025CNIL, press release of 3 September 2025
- CNIL ’25Cookies and advertisements inserted between emails: GOOGLE fined 325 million eurosCNIL, press release of 3 September 2025
- CNIL ’22Cookie walls: first assessment criteriaCNIL, 16 May 2022
- CE ’20Ruling no. 434684: the CNIL could not infer a general and absolute ban on tracking walls from the mere requirement of freely given consentConseil d’État, 19 June 2020
- EDPB ’24Opinion 08/2024 on valid consent in the context of consent or pay models implemented by large online platformsEuropean Data Protection Board, adopted on 17 April 2024
- CNIL ’25Recommendation on mobile applications, amended versionCNIL, deliberation no. 2025-024 of 27 March 2025
Common questions
- Does a high consent rate guarantee an app’s advertising revenue?
- No. The rate measures what the user answered in the window, not what the ad request carries afterwards. IAB Europe’s CMP API specification states that where no CMP is present or it fails to respond, vendors should assume no consent, and Google states that it will serve a limited ad to European requests carrying no TC string from a CMP it certifies. The impression still sells, but at the price of an unconsented one: an agreement that does not arrive produces the same commercial result as a refusal.
- What changed on 1 March 2026 for TCF consent strings?
- Version 2.3 of IAB Europe’s framework, released on 19 June 2025, makes a segment listing the vendors disclosed to the user mandatory. IAB Europe set the end of the transition period at 28 February 2026 and states that strings created after that date without the segment will be considered invalid. Google specifies that version 2.3 is mandatory for any string generated on or after 1 March 2026, and that failing this the ad request may default to limited ads.
- What is Google’s additional consent string for?
- It carries consent to Google Ad Technology Providers that are not yet on IAB Europe’s Global Vendor List. It is a second channel, separate from the TC string, with its own parameter and its own format. Only a CMP registered with IAB Europe’s framework may create one. If it does not travel, those partners receive nothing even when the user accepted.
- Does fixing a consent window inside an app require shipping a new version?
- It depends on the CMP. The message itself is composed and published remotely; what is compiled into the app is the library that writes the consent string. Google states that its own UMP SDK is IAB-certified for TCF v2.3 across all SDK versions, and that no action is required for publishers using its CMP. For a third-party CMP it points publishers to their provider’s migration plan: if that plan needs a new version of the library, it needs a release and then an install, and versions already installed keep emitting in the meantime.