Since late afternoon on Thursday, September 3, 2026, TCF Purpose 2 may be missing from the consent vector of visitors who nevertheless clicked "Accept All." This is not a malfunction of your CMP: it is the result of a change made by Microsoft Advertising in its TCF registration.
Here is what changed, what it produces, and how to act if your statistics have shifted.
What Changed
On September 3, 2026, IAB Europe published version 175 of the Global Vendor List (GVL), the registry of Transparency & Consent Framework (TCF) partners. In this version, Microsoft Advertising (TCF Vendor #1126) updated its declared legal basis for Purpose 2, "Use limited data to select advertising." Previously declared under Consent, it is now declared under Legitimate Interest. Microsoft continues to declare this purpose as "flexible," meaning publishers can force the alternative legal basis.
This change was made directly by Microsoft within its TCF registration, without prior notice to publishers or CMPs. All TCF-compliant CMPs read the GVL: the update was applied automatically across Sirdata and all other CMPs as soon as the new version became available.
What This Produces in Signals
A TCF CMP only requests consent for a purpose if at least one vendor in the configuration requires it. On sites where Microsoft Advertising was the only vendor requesting consent for Purpose 2, this purpose no longer appears in the consented purposes vector after an "Accept All" click. It remains present under Legitimate Interest, in accordance with Microsoft's new declaration.
This behavior is correct under the standard and does not compromise the compliance of your data collection. Purpose 2 covers advertising selection based on limited data—in other words, contextual advertising—which logically relies on legitimate interest. The consent required by the ePrivacy Directive for cookies is handled by the Purpose 1 signal (store and/or access information on a device).
Potential Impact on Your Statistics
Some implementations test for the presence of Purpose 2 consent in the consent vector as a firing trigger, alongside Purpose 1 consent. Since September 3, these conditions may no longer be met: ad tags, server-side requests, or measurement scripts may stop firing, leading to a drop in statistics. This affects potentially all websites running a TCF CMP, regardless of the vendor.
If you have observed a drop since late Thursday, September 3, prioritize checking implementations that use Purpose 2 consent as a technical condition.
Two Ways to Act
- Update your triggering logic to stop testing Purpose 2 consent. Consent for Purpose 1 and the relevant vendor is sufficient to set and read cookies; Purpose 2 can be accepted via Consent or Legitimate Interest.
- Enable a TCF Publisher Restriction on Microsoft Advertising for Purpose 2, forcing Consent as the legal basis. The TCF standard includes this mechanism for flexible purposes and mandates CMPs to support it. Since Microsoft declares Purpose 2 as flexible, the restriction applies: Purpose 2 becomes available again in the consent vector when accepted by the user. On Sirdata, activation takes just a few clicks in the portal (see the documentation on Publisher Restrictions). Clients using other CMPs can request the same setup from their provider.
A Setting to Monitor
The restriction remains effective as long as Microsoft maintains a flexible legal basis for Purpose 2. While this declaration may remain unchanged long-term, Microsoft could update it again without notice in a future GVL version. Removing dependency on Purpose 2 consent in your firing rules remains the most robust long-term solution.