IAB Europe – Fine (Belgium, 2022)

Fine
Autorité de Protection des Données2 February 2022Belgium
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

IAB Europe faced complaints for misleading cookie consent practices and not providing clear information about third-party cookies. The Belgian authority found that the company did not meet GDPR requirements for cookie consent. This case highlights the importance of clear communication and consent in digital advertising.

What happened

IAB Europe was found to have misleading cookie banners and did not obtain proper consent for third-party cookies.

Who was affected

Users who interacted with websites using IAB Europe's advertising services without proper cookie consent.

What the authority found

The Belgian authority ruled that IAB Europe violated GDPR principles related to transparency and consent for cookies.

Why this matters

This decision underscores the need for companies to provide clear and honest cookie information. Website operators should review their cookie consent practices to ensure compliance with GDPR.

GDPR Articles Cited

AI-verified

Art. 13(GDPR)
Art. 14(GDPR)
Art. 30(GDPR)
Art. 31(GDPR)
Art. 37(GDPR)
Art. 5(1)(a) GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 9(1) GDPR
Art. 12(1) GDPR
Art. 24(1) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1) a) GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 9(1) GDPR
(2) GDPR
Art. 12(1) GDPR
Art. 13(GDPR)
Art. 14(GDPR)
Art. 24(1) GDPR
Art. 30(GDPR)
Art. 31(GDPR)
Art. 32(1) GDPR
Art. 37(GDPR)

Original data from scraper before AI verification against source document.

Source verified 20 March 2026
amount discrepancy
scope corrected
corrected bucket
Full Legal Summary
Detailed

The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the compliance of the 'Transparency & Consent Framework (TCF)' with the GDPR was mainly questioned. The TCF was developed by IAB to promote compliance with the GDPR by organizations using the OpenRTB protocol. The OpenRTB protocol is a protocol for 'real-time bidding,' which is the automated online auction of user profiles for the sale and purchase of advertising space on the Internet. When users visit a website that contains an ad space, technology companies, through an automated auction system, can bid in real time for that ad space to display personalized advertising. When users visit a website for the first time, an interface appears through which they can consent to the collection and sharing of their personal information or object to various types of processing. As part of the TCF, a consent management tool appears during this process. The tool allows the user to object to certain types of data processing. The TCF registers the user's preferences through the tool by generating a TC string and sends it to all partners participating in the OpenRTB system. Based on this TC string, user profiles are compiled, which are then passed on to advertisers. This makes it visible to them what kind of data processing the users have agreed to. Within the scope of its investigation against IAB, the DPA identified a number of violations of the GDPR. It found that the TC strings already constituted personal data and therefore IAB was required to have a legal basis for processing these data. However, IAB was unable to demonstrate any such legal basis. In addition, IAB did not properly inform users about the functioning of the TCF. For example, the information provided to users was too generic and vague to understand the scope of the data processing. Furthermore, IAB had not maintained a register of its processin

Violations (4)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Misleading Banner Messaging
critical

The cookie banner uses misleading language to trick or pressure users into accepting cookies (dark patterns).

Art. 7 GDPR

No Granular Cookie Choice
high

Users cannot select or deselect individual cookie categories; consent is presented as all-or-nothing.

Art. 4(11) GDPR

Details

Fine Date

2 February 2022

Authority

Autorité de Protection des Données

Enforcement Tracker ID

ETid-1051

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. IAB Europe - Belgium (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: