Skip to main content

Is the Meta pixel legal on my website?

Last reviewed
2026-09-16

Installing a pixel is not unlawful in itself. The exposure comes from what it collects, whether you disclosed it, whether it loads before consent where consent is required, and what kind of page it sits on. Pixels on health, financial or video pages have attracted particular attention.

The longer version

An advertising pixel sends data about a visit to a third party, which under US state privacy laws can count as sharing personal information for cross-context behavioral advertising. That triggers disclosure duties and an opt-out right, and it can bring a business over a CCPA threshold it thought it was under.

In the EU and UK a pixel is non-essential storage and tracking, so it must not load before consent. A pixel that fires on page load behind a consent banner is the single most common finding in a privacy review.

Context raises the stakes sharply. Pixels on pages relating to health services have been the subject of federal guidance to covered entities, and pixels on video pages have attracted claims under video privacy law. Sensitive context is where a routine marketing decision becomes a legal one.

What to do

  1. Establish exactly which pages the pixel loads on and what it sends.
  2. Make sure it does not fire before consent in regions where prior consent is required.
  3. Disclose it accurately in your privacy notice and cookie table, by name.
  4. Remove it from any page dealing with health, finances or video content until somebody has assessed that specifically.

The obligation behind this

Sources

  1. California Consumer Privacy Act (CCPA)California Office of the Attorney General

WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business.