Your legal team forwarded you a headline about IAB Europe "winning" against the Belgian data protection authority, and now someone in the room is asking whether you can stop worrying about the TCF. You can't. On January 7, 2026, the Belgian Market Court annulled the APD's 2023 validation of IAB Europe's TCF corrective action plan, not the underlying finding that the TCF's TC String processing broke GDPR. The case goes back to the regulator. Nothing about your own CMP configuration, vendor list, or consent logging obligations changed on that date.
Key Takeaways
- The Market Court's January 7, 2026 judgment annulled only the APD's January 2023 validation of IAB Europe's remedial action plan, not the 2022 finding that the TC String is personal data or that IAB Europe is a joint controller for it.
- The APD must now redo its validation with a narrower scope, limited to IAB Europe's responsibility for the TC String rather than participants' downstream processing, and must give IAB Europe a formal hearing first. As of this writing, the APD has not issued a new decision.
- Nothing in either the May 2025 or January 2026 rulings removes a publisher's or vendor's own GDPR accountability for its own processing, and Belgium has named adtech as a strategic enforcement target through 2028.
What the Market Court Actually Ruled on January 7, 2026
The Belgian Market Court, the Brussels Court of Appeal's competition and regulatory chamber, annulled the Belgian data protection authority's (APD) January 11, 2023 decision validating the remedial action plan IAB Europe had submitted after its 2022 sanction (ictrechtswijzer.be). That 2023 validation had started a six-month clock for IAB Europe to implement the approved measures. The court found the validation legally flawed because several of the required measures assumed IAB Europe was a joint controller not just for the TC String but for how individual TCF participants process data downstream, on OpenRTB and elsewhere. That broader assumption had already been rejected by the same court fourteen months earlier.
On May 14, 2025, the Market Court had ruled that IAB Europe is a joint controller only for the creation and storage of the TC String itself, and explicitly declined to extend that status to downstream OpenRTB processing, because no evidence was put before it establishing IAB Europe's control over what happens to data after the string is generated (Harbottle & Lewis). That same 2025 ruling confirmed the TC String is personal data and upheld the APD's €250,000 fine against IAB Europe, according to the Belgian data protection authority's own account of the case (dataprotectionauthority.be). The January 2026 judgment also ordered the APD to pay roughly €1,900 in IAB Europe's legal costs, a routine cost-shifting order that some trade coverage has cited as evidence of a broader win than the ruling actually delivered (ppc.land). Commenting on that earlier judgment, Peter Craddock, a partner at Keller and Heckman LLP, wrote that "nowhere does the [Market Court] say that the TCF is illegal, in fact it confirms the sanctions of the [APD's] decision," while advising TCF participants to tighten their own policy language rather than read the ruling as a clearance (IAB Europe guest post). The same caution applies with more force to the 2026 annulment, which is a procedural correction to a validation decision, not a fresh ruling on whether TCF processing itself is lawful.
Because the 2023 validation rested partly on the broader joint-controller theory the court had already thrown out, the court sent the matter back to the APD with instructions to reassess IAB Europe's action plan on the correct, narrower legal basis, and to give IAB Europe a proper hearing on the new circumstances before issuing any new decision (IAB Europe).
What This Does Not Mean
It is easy to read "the APD's decision was annulled" as "the TCF is fine now." That is not what happened. Three things survived the January 2026 judgment untouched:
- The 2022 finding stands. The APD's original February 2, 2022 decision, that the TC String is personal data and that IAB Europe is a joint controller for its creation, was not before the Market Court in this appeal and was not disturbed by it.
- The €250,000 fine stands. That penalty was upheld in the May 2025 ruling and was not part of what got annulled in January 2026.
- The CJEU's underlying framework stands. The Court of Justice of the EU had already confirmed, in its March 7, 2024 judgment in Case C-604/22, that a TC String qualifies as personal data and that an organization determining the purposes and means of a shared data structure can be a joint controller for it, even without full access to the data itself (Cleary Cybersecurity and Privacy Watch).
What actually got annulled was narrower: the APD's approval of a specific set of remedial measures, built on legal reasoning the courts had since narrowed. That is a procedural reset for IAB Europe's compliance file, not a substantive ruling that TCF processing is lawful. Some coverage of the January 2026 judgment has gone further, framing it as confirming the "full legality" of the TCF outright. That framing conflates two separate questions: whether IAB Europe can be held jointly liable for what participants do with a TC String (narrowed, in IAB Europe's favor) and whether TCF processing itself complies with GDPR (not decided in this judgment either way, and still resting on the unresolved APD file). If you are relying on the January 2026 headline as evidence the regulatory risk around the TCF has gone away, you are reading a procedural win as a substantive one.
What Stays Yours to Own, Regardless of How Joint Controllership Resolves
This is the part the legal-analysis coverage tends to skip, because it is not really about IAB Europe. However the APD ultimately re-scopes IAB Europe's responsibility, your own GDPR accountability for your own processing does not move.
A publisher whose CMP misreports which vendors were actually disclosed to a visitor is exposed on that fact alone, independent of anything IAB Europe is or is not responsible for. A vendor that processes personal data on the strength of a TC String it never verified is exposed on its own account, because GDPR's accountability principle attaches to the controller that actually processes the data, not just to the framework operator. IAB Europe's joint-controller status covers the TC String's creation and storage; it was never a shield for what a participant does with that string afterward.
Concretely, that means:
- If you operate a CMP, you remain responsible for the accuracy of what your banner discloses and for correctly populating the Disclosed Vendors bitfield in the TC String, the mechanism TCF 2.3 introduced specifically to close this gap. Secure Privacy's detailed walkthrough of TCF 2.3 covers how that bitfield works and what it changed for CMP configuration; this article does not restate that mechanic.
- If you are a vendor receiving TC Strings, you remain responsible for verifying your own bit is set before processing under a legal basis that depends on disclosure, not for assuming the string is clean because IAB Europe operates the standard.
- If you migrated to TCF 2.3 ahead of the February 28, 2026 enforcement deadline, that migration work is unaffected by the January 2026 annulment. It was never contingent on how the APD's case against IAB Europe resolved. Secure Privacy's TCF v2.3 migration checklist remains the operational reference if that work is still in progress.
Where Things Actually Stand as of Late July 2026
Six and a half months after the annulment, the APD has not issued a new validation decision. IAB Europe's own public statements after the January ruling said only that it would "continue to keep the market updated on the case as the matter returns to the APD for further proceedings," without committing to a timeline (IAB Europe). A search of IAB Europe's own news archive through late July 2026 turns up governance and market-benchmark announcements, but no update on the re-scoped action plan review. That silence is itself informative: the file is open, not closed, and there is no fixed date by which participants can expect resolution. Treat any claim that the APD has already re-validated a new plan as unverified until the regulator or IAB Europe publishes it directly.
Why Belgium Isn't Going Quiet on Adtech
Separately from the IAB Europe case, the APD published its 2026-2028 strategic enforcement plan on December 23, 2025, naming large-scale, high-risk data processing and all processing involving minors as its two top enforcement priorities, and explicitly listing "advertising technology processing, cross-border data sharing among data brokers, and large-scale profiling systems" within that scope (ppc.land). The authority is working with roughly 90 staff and 18 external specialists against caseloads that grew across every measured category between 2023 and 2024: complaints up 20%, inspection cases more than doubled, and breach notifications up as well. That combination, a named adtech priority plus a resource-constrained regulator shifting toward proactive, fact-focused investigations rather than reactive complaint handling, is the reason this file is unlikely to go quiet through 2028, independent of how the IAB Europe remand resolves.
What Changed vs. What Didn't
| Element | Status after January 7, 2026 | What it means for you |
|---|---|---|
| APD's 2023 action-plan validation | Annulled, sent back to APD for a fresh decision | No currently-approved IAB Europe remedial plan exists; do not cite the old validation as current |
| 2022 finding: TC String is personal data | Untouched, not part of this appeal | Your own processing of TC Strings still falls under GDPR |
| IAB Europe as joint controller for TC String creation | Confirmed (May 2025 ruling), untouched by the annulment | IAB Europe's TCF governance obligations continue |
| IAB Europe as joint controller for downstream processing | Rejected (May 2025 ruling) | You cannot point to IAB Europe's controllership to explain away your own downstream processing |
| €250,000 fine against IAB Europe | Upheld, not part of this appeal | Demonstrates the APD's willingness to sanction on these facts |
| Your CMP's Disclosed Vendors accuracy | Unaffected by any of the above | Still your obligation, still checked at audit |
| Belgium's 2026-2028 adtech enforcement priority | Published separately, independent of this case | Expect continued scrutiny regardless of how the APD remand ends |
A Status Checklist for Publishers and Vendors
- Confirm your CMP is running TCF 2.3 and that the Disclosed Vendors segment reflects exactly the vendors shown in your consent interface, not a superset carried over from an older configuration.
- Do not update any internal compliance documentation to state that "the TCF was cleared" by the January 2026 ruling. Document it accurately as a remand, with the 2022 findings and 2025 fine still standing.
- If you are a vendor, confirm your own process for checking the Disclosed Vendors bit before processing under a TCF-dependent legal basis; do not rely on IAB Europe's compliance status as a substitute.
- Keep a record of the actual APD decision (once issued) rather than any single news summary, since law-firm and trade-press coverage of these rulings has already diverged on details like the exact date of the CJEU's original judgment.
- If your organization operates in Belgium or processes EU personal data at scale through adtech channels, factor the APD's 2026-2028 enforcement priorities into your risk assessment independently of the IAB Europe case.
A CMP that can show, on demand, exactly which vendors were disclosed to a given visitor and exactly when consent was logged is the practical answer to most of what a regulator asks for in this space. Secure Privacy's cookie and consent management platform builds that evidentiary record automatically, with consent logs that stay audit-ready and continuous domain monitoring that flags configuration drift before an auditor finds it.
FAQ
Did the Belgian Market Court rule that the TCF is illegal?
No. The January 7, 2026 judgment annulled the APD's validation of IAB Europe's remedial action plan on procedural and scope grounds; it did not rule on whether TCF processing itself is lawful, and it left the 2022 finding that the TC String is personal data untouched.
Does the January 2026 ruling clear publishers and vendors of TCF-related compliance risk?
No. The ruling addresses IAB Europe's own regulatory file with the APD. It does not change a publisher's or vendor's independent GDPR obligations for their own processing, including accurate vendor disclosure and verification of the TC String before relying on it.
What did the May 14, 2025 ruling actually decide?
It confirmed IAB Europe is a joint controller for the creation and storage of the TC String, rejected the theory that IAB Europe is a joint controller for participants' downstream processing (such as OpenRTB), and upheld the APD's €250,000 fine against IAB Europe.
What happens next with the APD's case against IAB Europe?
The APD must reassess IAB Europe's action plan on the narrower legal basis the courts have set, giving IAB Europe a formal hearing on developments since the original submission. No new decision had been published as of late July 2026, and neither the APD nor IAB Europe has stated a timeline.
Is TCF 2.3 adoption still required if the APD's case is unresolved?
Yes. TCF 2.3's Disclosed Vendors requirement, with a February 28, 2026 enforcement deadline, is a technical standard change independent of the APD's case against IAB Europe. It remains the current version participants are expected to run.
Why is Belgium still considered a higher enforcement risk for adtech?
Separately from the IAB Europe litigation, the APD's published 2026-2028 strategic plan names advertising technology processing and large-scale profiling as enforcement priorities, backed by a caseload that grew across complaints, inspections, and breach notifications from 2023 to 2024.
What should a compliance team change in its internal documentation right now?
Replace any reference to "the APD approved IAB Europe's action plan" with an accurate description: that approval was annulled and the matter is back before the regulator. Continue documenting your own vendor disclosure accuracy and consent logging as the evidence that actually protects your organization.
If your team is still reconciling what this means for a live TCF integration, a scan of your current cookie and consent configuration will show whether your Disclosed Vendors bitfield, banner disclosures, and consent logs already match what regulators are asking for, regardless of how the IAB Europe case eventually resolves.




