Audience Manager Plug-in for IAB TCF
An important aspect in the privacy obligations you have towards your users is the acquisition and conveyance of user choices over how their personal data may be used (i.e., “purposes”) and by whom (i.e., “companies”).
Adobe provides you with the means to manage and communicate your users' privacy choices through the Opt-in functionality and through IAB Transparency and Consent Framework (TCF) support.
This article describes the Audience Manager use cases that support the IAB TCF and how to implement IAB TCF support in Audience Manager. Audience Manager is registered in the IAB TCF with the vendor ID 565.
Scope and Limitations
As a Publisher or Advertiser working with Audience Manager, you are able to convey user choices to Audience Manager as per IAB TCF. This provides you with an easy and consistent way of communicating user choices to all partners you work with and Audience Manager can help you respect your users' privacy choices.
The IAB TCF support described in this article represents the first phase in Audience Manager's planned support for the IAB framework. Currently, Audience Manager does not support:
- Mobile device workflows;
- Cross-device consent management;
- Appending consent to URLs sent to URL destinations ;
- Appending consent to segments.
You must meet the following prerequisites to use the IAB TCF with Audience Manager:
- You must be using Experience Cloud ID Service (ECID) version 4.1 or newer. Download our latest ECID release.
- Alternatively, if you use Server-Side Forwarding (SSF) to import data into Audience Manager, you must upgrade to the latest version of AppMeasurement. Download AppMeasurement using the Analytics Code Manager .
- You must be using a Consent Management Platform (CMP), either commercial or your own, that supports IAB, and is registered with the IAB TCF. See the list of CMPs registered within the IAB framework .
Recommendations and how to implement
To enable the IAB TCF support in Audience Manager, read our documentation on how to set up IAB with Opt-in .
User choice workflow when using the IAB framework
When visiting a web property, your users can provide their choices regarding how their data is to be used by the publisher and by the third-party vendors that the publisher works with. Users provide their choices in the form of standard purposes and permissions to third-party vendors registered in the global vendor list. The image below represents an example of a CMP dialogue, displayed to a first-time visitor of a website. Keep in mind that this dialogue can look very different, based on customer implementation.
The standard purposes in the IAB framework are:
- Information storage and access
- Ad selection, delivery, and reporting
- Content selection, delivery, and reporting
Refer to the IAB framework specification page for a description of the five standard purposes.
Users may grant their consent for a combination of standard purposes and vendors. For example, users could grant their consent for storage, personalization, and measurement and grant their consent to all third-party vendors displayed by the CMP. Or, in another example, they could grant their consent for all five standard purposes but only grant consent to a few of the vendors displayed by the CMP.
Once the user selects their privacy choices, the user choice(s) are recorded in the IAB TCF consent string. The IAB TCF consent string stores the combination of approved purposes and vendors, along with other metadata information (see the IAB page for more information). Every vendor registered in the IAB TCF evaluates the IAB TCF consent string and makes decisions based on the users' privacy choices. Keep in mind that the users' privacy choices are valid across all approved vendors.
Standard purposes needed by Audience Manager
Audience Manager evaluates the users' choices stored in the IAB TFC consent string for:
- Information storage and access (purpose ID 1 in the global vendor list )
- Personalization (purpose ID 2)
- Measurement (purpose ID 5)
- Audience Manager vendor consent to store, process, or activate on data for a publisher.
Audience Manager needs consent for all three purposes, plus vendor consent in order to deploy cookies and initiate or honor ID syncs.
Audience Manager behavior depends on whether the user grants consent
Audience Manager works differently depending on whether Audience Manager detects in the IAB TCF consent string that the user has provided consent for the three purposes (storage, personalization, measurement) or not.
When your user provides consent , Audience Manager:
When your user declines consent, Audience Manager:
Publisher Use Case
By implementing the IAB TCF, you are not required to maintain custom code for consent management on your web properties via a different mechanism with Adobe or other third-party vendors. The use case is described in the image and in the steps below. Start from the left of the image:
- A user visits one of your web properties. As long as you are using the latest versions of the ECID and DIL libraries (see Prerequisites ), the opt-in flow is triggered.
- Audience Manager checks whether the IAB flow applies ( isIabContext=true ). See Recommendations and how to implement .
- Audience Manager checks whether GDPR applies ( gdpr = 1 ) and whether there is a CMP, registered with IAB, on your web property. For example, this would apply to users visiting from the European Union area. Note that it is your responsibility as publisher to set the GDPR flag.
- If GDPR applies, Audience Manager checks the IAB TCF consent string, passed in the parameter gdpr_consent , for the needed permissions. Audience Manager needs permissions for storage, personalization, measurement, plus Audience Manager vendor consent, to store, process or activate data.
- If the IAB TCF consent string is present and it contains the required permissions, Audience Manager passes the IAB TCF consent string on to our data collection servers (DCS).
- Audience Manager responds by setting a demdex cookie on the browser. Audience Manager also initiates and honors 3rd party ID syncs.
- Alternatively, if the IAB TCF consent string passed in step 5 does not contain all the needed permissions, Audience Manager does not collect, process, or activate data and does not honor or initiate ID syncs.
Advertiser Use Case
Audience Manager evaluates and honors consent passed in pixel calls , in accordance with the IAB TCF.
Pixels are generally placed by Audience Manager customers on their partner pages or they are placed in ad servers to include in the ad response. In the first case, your partner must programmatically retrieve the consent parameter and add it to the pixel before firing. In the second case, which is more common and is described in detail below, ad servers append the consent parameters they receive from the Supply-Side Platform (SSP) or publisher ad servers to all pixels.
Audience Manager uses two parameters to pass user consent in pixel calls:
- gdpr can be 0 (GDPR does not apply) or 1 (GDPR applies);
- gdpr_consent is the URL-safe base64-encoded GDPR consent string (see specification ). A sample call for an impression pixel, with the two parameters could look like below:
The use case is described in the image and in the steps below. Start from the left of the image:
- Your user is served an impression via an ad server. This translates into a pixel call to our Data Collection Servers (DCS).
- Audience Manager checks whether the GDPR flag applies. If it doesn't, Audience Manager stores the data passed in macro variables in pixel calls.
- If the consent string is present and it contains the required permissions, Audience Manager stores the data passed in macro variables in pixel calls.
- If the consent string is missing or lacks the required permissions, Audience Manager drops the data passed in macro variables in pixel calls.
Activation partners that support IAB TCF
The Audience Manager Plug-in for IAB TCF enables you to forward the IAB TCF consent string to activation partners while respecting users’ privacy choices. For information on which activation partners support IAB TCF (accurate as of July 7th, 2019), refer to our Partner Excel sheet .
Test your IAB implementation
To test that you have correctly implemented the Audience Manager Plug-in for IAB TCF, read Use Case 4 in Validation Methods for Opt-in and IAB implementation .
IAB and Opt-out in Audience Manager. Order of precedence.
Another privacy option at your users' disposal is the ability to opt out of all data collection. Adobe provides users with the means to do so within the Your Privacy Choices page.
Audience Manager addresses opt-out management in a separate article in our documentation .
Order of Precedence - If your user opts out of data collection using a global opt-out tool, as described in the link above, this takes precedence over the opt-in and IAB verifications.