TCF v2.3 Is Out: What Publishers With EU Traffic Must Do by February 2026
IAB Europe released TCF v2.3 on June 19, making the disclosedVendors segment mandatory. Strings without it will be non-compliant after February 28, 2026. Here is the publisher checklist.
If you earn revenue from readers in the European Economic Area or the UK, a change to the consent framework that underpins most of programmatic advertising there just started its clock. On June 19, IAB Europe announced the release of TCF v2.3. The central change is that the “Disclosed Vendors” segment of the TC String, previously optional, becomes mandatory. All participants must fully support writing, reading and processing it by February 28, 2026, after which a TC String without the segment will be considered non-compliant with the framework.
That sounds like a technical footnote. For publishers, it is worth understanding, because if your consent management platform does not make the transition cleanly, the consequence is ad requests that vendors cannot legally act on.
What changed and why
The Transparency and Consent Framework (TCF) is how publishers, through their CMP, record what a user agreed to and pass that record, the TC String, to ad tech vendors. The string encodes consent and legitimate interest signals for each vendor and purpose.
The problem TCF v2.3 addresses is ambiguity. In some situations, a vendor could not tell from the existing signals whether it had actually been disclosed to the user in the CMP interface. That matters most for vendors that rely on legitimate interest for Special Purposes, such as security and fraud prevention, where no consent bit exists to confirm disclosure. The Disclosed Vendors segment settles it: a bit per vendor that says whether the vendor was shown to the user. IAB Europe said the updated technical specifications and JavaScript library would be published on July 3.
The legal backdrop
The update arrives shortly after a significant ruling. On May 14, the Brussels Market Court issued its judgment in the long-running case over the TCF. According to IAB Europe's summary, the court found that IAB Europe is a joint controller with TCF participants only in relation to the creation and use of TC Strings, not for participants' subsequent advertising processing. Whatever one's reading of the case, the practical message for publishers is unchanged: the accuracy of your consent signals is your responsibility, and regulators take them seriously.
What publishers need to do
If you use a commercial CMP
Most publishers do, and for them the heavy lifting falls on the CMP vendor. Your job is to verify it:
- Ask your CMP for its v2.3 timeline. Get a date for when it will include the Disclosed Vendors segment in every new TC String.
- Confirm how the vendor list is handled. The segment should reflect the vendors you actually show in your consent interface. If your vendor list is bloated with partners you no longer use, now is the time to trim it.
- Test the output. Once your CMP ships the update, decode sample TC Strings from your site with a TC String decoder and confirm the segment is present and matches the vendors you disclose.
If you run your own CMP
Plan engineering time. You will need to implement the updated specification, write the segment into every new string, and test that downstream partners read it correctly. Do this well before February, because vendors will begin acting on the segment as soon as they receive it.
Check your ad stack, not just your CMP
The consent string flows through your whole stack. Once the update is live, check each layer:
- Prebid.js. The consent management module reads the TC String from your CMP and passes it to bidders. Make sure you are on a Prebid version that handles the updated string and that your GDPR enforcement settings are configured deliberately, not left at whatever was set years ago.
- Google Ad Manager. Google works with TCF strings from certified CMPs. Confirm your CMP remains certified and that consent is resolved before ad requests are made.
- Server-side bidding. Check that Prebid Server and any server-to-server integrations pass the full string through unaltered.
- Analytics and non-ad vendors. Anything that reads the TC String to decide whether to fire should be tested too.
Watch the revenue signals
Consent changes have a way of showing up first in revenue reports. Before and after your CMP rolls out v2.3, monitor:
- Bid rates and CPMs from EEA and UK traffic, by SSP.
- The share of EEA ad requests arriving with a valid TC String.
- Error or warning logs from your CMP and Prebid consent module.
A sudden drop in EEA bid rates after a CMP update is often a sign that vendors are rejecting or misreading strings.
Use the transition to clean house
Every TCF update is an opportunity to fix accumulated problems. While your team is looking at consent anyway:
- Remove vendors from your CMP that you no longer work with. A shorter, accurate vendor list is easier for users to understand and easier to defend.
- Review the purposes and legal bases you request, and make sure they match what your partners actually need.
- Document your consent setup, including which CMP version, which vendors and which purposes, so you can answer regulator or partner questions quickly.
Timeline
- June 19, 2025: TCF v2.3 announced.
- July 3, 2025: updated technical specifications and JS library expected.
- Now through early 2026: CMPs add the segment; vendors begin reading it.
- February 28, 2026: deadline for full support. Strings without the segment are non-compliant after this date.
Eight months is plenty of time, as long as it does not become two weeks in February. Put a check on the calendar now. A managed partner like HBDR can audit consent flow through the ad stack, but the first step is simply asking your CMP when it ships.
Related Articles
July's Privacy Law Changes: A Checklist for Health and Finance Publishers
Connecticut, Arkansas and Virginia changes took effect July 1, and IAB Tech Lab just proposed GPP updates. What health, finance and other sensitive-content publishers should check.
Privacy Sandbox Is Winding Down in Chrome. Time to Clean Up Your Wrapper
Chrome 150 is now rejecting Protected Audience calls as Google retires most Privacy Sandbox APIs. Here is what to remove from your ad stack and what stays the same.
July 1 Privacy Deadlines: Connecticut and Arkansas Tighten Teen Ad Rules
On July 1, Connecticut's amended privacy law and Arkansas's children's and teens' privacy law take effect, both restricting targeted ads to minors. What publishers should change first.