Back to Blog
Education June 30, 2025 4 min read

TCF v2.3 Is Out: What Publishers With EU Traffic Must Do by February 2026

IAB Europe released TCF v2.3 on June 19, making the disclosedVendors segment mandatory. Strings without it will be non-compliant after February 28, 2026. Here is the publisher checklist.

HR
HBDR Research
June 30, 2025

If you earn revenue from readers in the European Economic Area or the UK, a change to the consent framework that underpins most of programmatic advertising there just started its clock. On June 19, IAB Europe announced the release of TCF v2.3. The central change is that the “Disclosed Vendors” segment of the TC String, previously optional, becomes mandatory. All participants must fully support writing, reading and processing it by February 28, 2026, after which a TC String without the segment will be considered non-compliant with the framework.

That sounds like a technical footnote. For publishers, it is worth understanding, because if your consent management platform does not make the transition cleanly, the consequence is ad requests that vendors cannot legally act on.

What changed and why

The Transparency and Consent Framework (TCF) is how publishers, through their CMP, record what a user agreed to and pass that record, the TC String, to ad tech vendors. The string encodes consent and legitimate interest signals for each vendor and purpose.

The problem TCF v2.3 addresses is ambiguity. In some situations, a vendor could not tell from the existing signals whether it had actually been disclosed to the user in the CMP interface. That matters most for vendors that rely on legitimate interest for Special Purposes, such as security and fraud prevention, where no consent bit exists to confirm disclosure. The Disclosed Vendors segment settles it: a bit per vendor that says whether the vendor was shown to the user. IAB Europe said the updated technical specifications and JavaScript library would be published on July 3.

The legal backdrop

The update arrives shortly after a significant ruling. On May 14, the Brussels Market Court issued its judgment in the long-running case over the TCF. According to IAB Europe's summary, the court found that IAB Europe is a joint controller with TCF participants only in relation to the creation and use of TC Strings, not for participants' subsequent advertising processing. Whatever one's reading of the case, the practical message for publishers is unchanged: the accuracy of your consent signals is your responsibility, and regulators take them seriously.

What publishers need to do

If you use a commercial CMP

Most publishers do, and for them the heavy lifting falls on the CMP vendor. Your job is to verify it:

  • Ask your CMP for its v2.3 timeline. Get a date for when it will include the Disclosed Vendors segment in every new TC String.
  • Confirm how the vendor list is handled. The segment should reflect the vendors you actually show in your consent interface. If your vendor list is bloated with partners you no longer use, now is the time to trim it.
  • Test the output. Once your CMP ships the update, decode sample TC Strings from your site with a TC String decoder and confirm the segment is present and matches the vendors you disclose.

If you run your own CMP

Plan engineering time. You will need to implement the updated specification, write the segment into every new string, and test that downstream partners read it correctly. Do this well before February, because vendors will begin acting on the segment as soon as they receive it.

Check your ad stack, not just your CMP

The consent string flows through your whole stack. Once the update is live, check each layer:

  • Prebid.js. The consent management module reads the TC String from your CMP and passes it to bidders. Make sure you are on a Prebid version that handles the updated string and that your GDPR enforcement settings are configured deliberately, not left at whatever was set years ago.
  • Google Ad Manager. Google works with TCF strings from certified CMPs. Confirm your CMP remains certified and that consent is resolved before ad requests are made.
  • Server-side bidding. Check that Prebid Server and any server-to-server integrations pass the full string through unaltered.
  • Analytics and non-ad vendors. Anything that reads the TC String to decide whether to fire should be tested too.

Watch the revenue signals

Consent changes have a way of showing up first in revenue reports. Before and after your CMP rolls out v2.3, monitor:

  • Bid rates and CPMs from EEA and UK traffic, by SSP.
  • The share of EEA ad requests arriving with a valid TC String.
  • Error or warning logs from your CMP and Prebid consent module.

A sudden drop in EEA bid rates after a CMP update is often a sign that vendors are rejecting or misreading strings.

Use the transition to clean house

Every TCF update is an opportunity to fix accumulated problems. While your team is looking at consent anyway:

  1. Remove vendors from your CMP that you no longer work with. A shorter, accurate vendor list is easier for users to understand and easier to defend.
  2. Review the purposes and legal bases you request, and make sure they match what your partners actually need.
  3. Document your consent setup, including which CMP version, which vendors and which purposes, so you can answer regulator or partner questions quickly.

Timeline

  • June 19, 2025: TCF v2.3 announced.
  • July 3, 2025: updated technical specifications and JS library expected.
  • Now through early 2026: CMPs add the segment; vendors begin reading it.
  • February 28, 2026: deadline for full support. Strings without the segment are non-compliant after this date.

Eight months is plenty of time, as long as it does not become two weeks in February. Put a check on the calendar now. A managed partner like HBDR can audit consent flow through the ad stack, but the first step is simply asking your CMP when it ships.

Tags: tcf gdpr consent management iab europe prebid

Ready to maximize your ad revenue?

Get Started