TC String
A TC String is a compact, encoded piece of data that records the consent and preference choices a user makes on a website that uses the IAB Europe Transparency and Consent Framework (TCF). It captures what a user was told and how they responded regarding the processing of their personal data by advertising vendors. In a case concerning the TCF, the Court of Justice of the European Union concluded that a TC String constitutes personal data within the meaning of Article 4(1) of the GDPR.
A TC String (Transparency and Consent String) is the standardized, encoded output of the IAB Europe Transparency and Consent Framework (TCF) that encapsulates the information disclosed to a user and the expression of their preferences regarding the processing of their personal data. Structurally, the TC String requires a mandatory Core String segment to precede all other segments, which may be followed by additional segments such as disclosedVendors and PublisherTC. The TCF is presented by IAB Europe as an accountability tool relying on standardization to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR; it does not by itself guarantee compliance, and the framework's status has been the subject of regulatory and judicial scrutiny. Notably, the Court of Justice of the European Union has held that a TC String constitutes personal data within the meaning of Article 4(1) of the GDPR, meaning its generation, storage, and transmission are subject to GDPR obligations independent of the underlying consent it records. The geographic and legal scope described here reflects the EU/EEA context; the treatment of TC Strings and the TCF may differ under the UK regime, US state privacy laws, and other frameworks, which are outside the scope of this entry.
Why it matters
The TC String sits at the technical heart of how consent choices are communicated across the online advertising ecosystem in the EU/EEA. Because it encodes what a user was told and how they responded regarding the processing of their personal data by advertising vendors, it functions as the machine-readable record on which downstream vendors rely to determine whether they may process data. If the disclosures behind the string are inadequate, or the consent it records does not meet the GDPR standard of being freely given, specific, informed, and unambiguous, then the string may propagate a defective legal basis throughout the supply chain.
A significant reason the TC String matters is that the Court of Justice of the European Union has held that a TC String constitutes personal data within the meaning of Article 4(1) of the GDPR. This means the generation, storage, and transmission of the string are themselves subject to GDPR obligations, independent of the underlying consent the string records. Organisations relying on the IAB Europe Transparency and Consent Framework (TCF) therefore cannot treat the string as a neutral technical artifact; the string carries its own data protection implications.
It is important to note that the TCF is presented by IAB Europe as an accountability tool that relies on standardisation to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR. It does not by itself guarantee compliance, and the framework has been the subject of regulatory and judicial scrutiny. The treatment described here reflects the EU/EEA context; the position under the UK regime, US state privacy laws, and other frameworks may differ and is outside the scope of this entry.
Who it's relevant to
Inside TC String
Common questions
Answers to the questions practitioners most commonly ask about TC String.

