@aral To clarify (after giving the ruling a quick read): it's specifically the IAB's mechanism of a 'consent string' that's ruled illegal, because it itself is identifiable/fingerprintable, rather than the consent popups themselves being ruled illegal.
At least that's how I understand the ruling, as a native Dutch speaker.