Skip to main content
Praxikon

Ruling

IAB Europe: the TC String is personal data and the industry body is a joint controller

Date
Status
final
Body
Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
Reference
C-604/22, ECLI:EU:C:2024:214

What it is about

Question: is the encoded consent string (TC String) from the Transparency and Consent Framework for online ad auctions personal data, and is IAB Europe as author of that framework a (joint) controller? Ruling: the TC String is personal data once it can, by reasonable means, be linked to an identifier such as an IP address, even if IAB Europe itself cannot access that link. IAB Europe is a joint controller for recording and disseminating the preferences because the framework co-determines purposes and means; that responsibility does not automatically extend to later processing by websites and advertisers.

What this means in practice

Anyone who sets up a standard, protocol or platform for data exchange and sets its rules can be a joint controller without seeing the data itself. That requires an Article 26 arrangement with participants and your own accountability. For websites and advertisers using the TCF, consent signals themselves are personal data and thus subject to all GDPR principles, including security and transparency.

The GDPR articles concerned

Source: EUR-Lex, arrest C-604/22checked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines8 of 9

Enforcement and fines

Legislation in motion6 of 8