In June 2024, IAB Europe introduced an important set of amendments to the Transparency & Consent Framework, then operating as TCF v2.2.
A central change was the introduction of Special Purpose 3, “Save and communicate privacy choices”, which was intended to address the processing of users’ privacy-choice signals recorded through the Framework.
The update followed an important legal development earlier that year.
On 7 March 2024, the Court of Justice of the European Union delivered its judgment in Case C-604/22, arising from proceedings concerning IAB Europe and the Belgian Data Protection Authority.
The Court confirmed that a TC String can constitute personal data where the information contained in it can be associated with an identifier such as an IP address or other information that makes the user identifiable by reasonable means.
The 2024 TCF amendments responded to that environment by providing a more explicit framework for the processing, storage and communication of privacy-choice signals.
Those changes were important at the time.
But the TCF has continued to evolve since then.
TCF v2.3, subsequent policy and technical-specification updates, and later Belgian court decisions have further developed the compliance environment surrounding the Framework.
This updated Insight therefore looks at both:
- what changed in 2024; and
- what publishers, CMPs and vendors need to understand about the Framework now.
What is the IAB Europe Transparency & Consent Framework?
IAB Europe is the European-level association for the digital marketing and advertising ecosystem.
The Transparency & Consent Framework, commonly referred to as the TCF, is an industry framework developed to support participants in the online advertising ecosystem in managing transparency and user-choice signals in connection with requirements arising from the GDPR and the ePrivacy Directive.
Participation in the TCF is voluntary.
The Framework combines technical specifications and policies used by participants such as:
- publishers;
- consent management platforms;
- vendors;
- advertisers;
- technology providers; and
- other participants in the digital advertising ecosystem.
The Framework provides a standardised mechanism through which information can be disclosed to users and privacy choices can be recorded and communicated between participating organisations.
That standardisation is important because digital advertising can involve multiple participants.
Without a common technical structure, transparency information, user choices and downstream signals could be implemented inconsistently across the ecosystem.
The TCF therefore seeks to provide common rules for matters including:
- information shown to users;
- purposes and special purposes;
- vendor disclosures;
- consent and legitimate-interest signals;
- storage and communication of user choices; and
- technical signalling through the TC String.
Why Special Purpose 3 was introduced in 2024
On 3 June 2024, IAB Europe announced amendments to the TCF v2.2 Policies introducing:
Special Purpose 3: “Save and communicate privacy choices”
The change addressed the processing of users’ privacy choices recorded and communicated through the TC String.
Special Purpose 3 was intended to cover processing carried out for the purpose of determining and respecting a user’s consent or objection status for a vendor or purpose.
Where a vendor relied on legitimate interests for processing connected with Special Purpose 3, the TCF Policies required the vendor to have conducted and documented an appropriate legitimate-interest assessment.
The change therefore sought to provide an explicit policy basis within the Framework for processing necessary to record, store and communicate privacy choices.
The 2024 amendments also changed CMP transparency requirements
The June 2024 amendments also introduced a secondary-layer transparency requirement for Consent Management Platforms.
Where the relevant information was provided in connection with legitimate-interest processing, the CMP interface needed to enable users to review information concerning the storage and access associated with recording privacy signals.
This included information about the maximum duration for which those choices could be stored on the user’s device.
The objective was to improve transparency around a part of the consent-management process that might otherwise remain largely invisible to the user.
The policy version was also increased from version 4.0.a to version 5.0.
The original 2024 implementation timetable
When the original Privacy Minders article was published in July 2024, the changes were subject to short implementation deadlines.
Vendors had been required to update relevant Global Vendor List registrations by 3 July 2024.
CMPs were required to implement the policy amendments by 4 October 2024.
Those deadlines have now passed and should be understood as historical milestones in the development of the Framework.
The 2024 changes nevertheless remain important because they illustrate how the TCF began responding operationally to the legal issues surrounding privacy-choice signalling and TC Strings.
The legal background: the CJEU and the TC String
The 2024 changes followed the CJEU judgment in Case C-604/22.
The case arose from proceedings between IAB Europe and the Belgian Data Protection Authority concerning the operation of the Transparency & Consent Framework.
One of the central questions concerned the TC String.
A TC String records user preferences through a structured sequence of characters and allows those preferences to be communicated within the TCF ecosystem.
The Court held that a TC String can constitute personal data where the information can be associated with an identifier or other information enabling the individual concerned to be identified by reasonable means.
The judgment also addressed the circumstances in which a sectoral organisation such as IAB Europe can be considered a joint controller in relation to the processing involved in establishing and using the Framework.
The significance of the judgment went beyond the technical format of the TC String.
It reinforced the principle that preference and consent signals cannot automatically be treated as anonymous technical metadata merely because they are encoded or represented through a technical string.
What has changed since the 2024 update?
The TCF has continued to evolve materially since the original article was published.
Three developments are particularly relevant:
- the introduction of TCF v2.3;
- further TCF policy and technical-specification changes in 2026; and
- subsequent Belgian court decisions concerning IAB Europe’s role within the Framework.
These developments mean that organisations should no longer treat compliance with the June 2024 v2.2 amendments as the current endpoint of TCF implementation.
TCF v2.3 and the disclosed vendors requirement
IAB Europe released TCF v2.3 in June 2025.
A key objective of v2.3 was to address ambiguity concerning whether a particular vendor had actually been disclosed to the user in the CMP interface.
Under the previous implementation, certain vendors relying on legitimate interests in connection with Special Purposes could encounter uncertainty when interpreting TC String signals.
TCF v2.3 addressed that problem by making the previously optional disclosedVendors segment mandatory for newly created TC Strings.
That segment enables vendors to determine whether they were presented to the user within the CMP interface.
The transition period concluded on 28 February 2026.
From 1 March 2026, newly created TC Strings that do not contain the required disclosedVendors segment are treated as invalid under the v2.3 framework.
TC Strings created before the transition deadline without the segment may remain valid until they are replaced as users renew or change their choices.
The Framework continued to evolve in 2026
TCF development did not stop with v2.3.
During 2026, IAB Europe announced further policy and technical changes concerning matters such as:
- multi-device consent;
- improvements to TCF user-interface requirements;
- clarification concerning Special Feature 2; and
- additional technical-specification development.
IAB Europe’s current participant-notification materials include TCF Policies v5.0.b and Specifications v2.4.
For publishers, CMPs and vendors, this illustrates an important compliance point:
TCF implementation is not a one-time technical project.
Participants need processes for monitoring policy, specification and compliance-programme changes and determining whether those changes require modifications to:
- CMP interfaces;
- vendor integrations;
- TC String handling;
- consent signalling;
- privacy disclosures; or
- internal compliance documentation.
The Belgian Market Court further clarified IAB Europe’s role
In May 2025, the Belgian Market Court ruled on IAB Europe’s appeal against the Belgian Data Protection Authority’s earlier decision.
Exercising its full jurisdiction, the Court annulled Decision 21/2022 on procedural grounds while confirming the infringements identified by the Belgian DPA and the €250,000 fine.
The Court also confirmed that the TC String constitutes personal data within the meaning of the GDPR and that IAB Europe acts as a joint controller in relation to the processing of users’ preferences within the TCF.
At the same time, the Court rejected the broader conclusion that IAB Europe acts as a joint controller for processing operations taking place entirely within the OpenRTB protocol.
That distinction matters.
The litigation therefore did not establish that IAB Europe controls all downstream advertising processing simply because that processing takes place in an ecosystem using the TCF.
The analysis depends on the particular processing operation and the role the relevant participant actually plays in determining its purposes and means.
The corrective-measures proceedings also changed in 2026
The procedural position evolved again in January 2026.
According to IAB Europe’s account of the proceedings, the Belgian Market Court annulled the Belgian Data Protection Authority’s January 2023 decision validating IAB Europe’s corrective action plan.
The issue was linked in part to the fact that elements of that earlier action plan had been based on a broader understanding of IAB Europe’s controllership than the scope later confirmed by the courts.
The matter was therefore returned to the Belgian authority for further consideration.
For market participants, the practical lesson is not that the TCF litigation is irrelevant or resolved in every respect.
It is that the legal position has become more precise.
The scope of responsibility needs to be assessed by reference to the actual processing operation rather than by treating every activity within the TCF and OpenRTB ecosystem as a single joint-controlled process.
Using the TCF does not automatically establish GDPR compliance
One point should remain clear throughout these developments.
Participation in the TCF does not, by itself, establish that an organisation complies with the GDPR or the ePrivacy Directive.
The Framework provides standardised mechanisms and policies intended to assist participants with transparency and choice signalling.
Each participant remains responsible for assessing the legal basis and compliance requirements applicable to its own processing.
That may include questions concerning:
- whether consent is required;
- whether legitimate interests can be relied upon;
- whether transparency information is sufficient;
- whether data minimisation requirements are met;
- whether storage and access to terminal equipment complies with applicable ePrivacy rules;
- how vendors and processors are governed;
- how user choices are respected downstream; and
- whether the organisation’s technical implementation matches its legal analysis.
The TCF can support compliance architecture.
It does not replace the underlying legal assessment.
A compliant TCF implementation depends on more than generating a valid TC String. The legal, technical and operational layers must align.
What publishers should review now
Publishers participating in the TCF should ensure that their implementation remains aligned with the current Framework rather than the version that was in place when their CMP was first deployed.
Relevant questions include:
- Is the CMP currently certified and operating against the appropriate TCF requirements?
- Are current vendor disclosures accurate?
- Are privacy-choice signals being communicated correctly?
- Are the purposes, special purposes and legal bases reflected accurately in the interface?
- Are vendor and storage disclosures current?
- Are internal governance arrangements in place to monitor future TCF changes?
- Does the publisher’s own legal analysis support the processing carried out through its advertising stack?
Publishers using commercial CMPs may rely on the CMP provider for parts of the technical implementation.
That does not remove the publisher’s need to understand whether its own use of the advertising ecosystem is legally and operationally consistent with the privacy choices presented to users.
What CMPs should review now
CMPs occupy a central operational position in the Framework because they present transparency information, capture user choices and generate or update the signals relied upon by other TCF participants.
CMPs should therefore monitor:
- current TCF policy requirements;
- technical-specification changes;
- UI requirements;
- TC String structure;
- vendor-disclosure rules;
- storage and access disclosures;
- certification requirements; and
- compliance-monitoring expectations.
The move to v2.3 demonstrates why technical signalling cannot be treated as static.
A change to the information encoded within the TC String can materially affect the ability of downstream vendors to understand whether transparency has been provided and whether particular processing may proceed.
What vendors should review now
Vendors should ensure that their TCF registrations, technical integrations and legal-basis declarations reflect their actual processing.
That includes reviewing:
- purposes and special purposes;
- legitimate-interest declarations;
- Special Purpose 3 where relevant;
- vendor disclosure;
- disclosedVendors signalling;
- storage and access practices;
- technical handling of TC Strings; and
- the organisation’s underlying legitimate-interest or consent analysis.
For vendors affected by the disclosure ambiguity addressed by v2.3, the disclosedVendors segment now forms an important part of the technical signal used to determine whether the vendor was presented to the user.
Technical implementation and legal analysis therefore need to be reviewed together.
A practical TCF compliance review
A useful review can be organised across four layers.
01 · FRAMEWORK STATUS
Confirm which TCF Policies, technical specifications and implementation requirements currently apply.
02 · USER INTERFACE
Review the transparency information, consent and objection choices, vendor information and storage disclosures shown to users.
03 · TECHNICAL SIGNALLING
Verify how TC Strings are created, stored, updated and communicated and whether the implementation reflects current requirements, including vendor-disclosure signalling.
04 · LEGAL GOVERNANCE
Confirm that the underlying legal bases, legitimate-interest assessments, data-protection analysis and ePrivacy requirements support the processing represented through the Framework.
The review should also identify who within the organisation is responsible for monitoring future TCF changes.
A technically valid implementation can become outdated if policy and specification changes are not incorporated into the organisation’s change-management process.
From TCF v2.2 to continuous compliance
The June 2024 introduction of Special Purpose 3 was an important development in the evolution of the Transparency & Consent Framework.
It responded to a specific legal and technical issue concerning the processing of users’ privacy choices and the significance of the TC String.
But the changes that followed demonstrate why TCF compliance cannot be viewed through a single historical version.
Since the original article was published:
- TCF v2.3 has changed vendor-disclosure signalling;
- policy and technical specifications have continued to evolve;
- the Belgian courts have further clarified the scope of IAB Europe’s responsibility; and
- compliance expectations across publishers, CMPs and vendors have continued to develop.
For organisations participating in the TCF, the practical objective should therefore be continuous alignment between:
- current Framework requirements;
- technical implementation;
- user-facing transparency;
- consent and privacy-choice signals; and
- the legal analysis supporting the underlying processing.
The TCF can provide important common infrastructure for digital advertising privacy.
Its value depends on participants keeping that infrastructure, and the legal governance around it, current.

