TPP Privacy Badges

Meta Pixel (Facebook Pixel)

Badge: ⚠️ Caution

This work is licensed under CC BY-SA 4.0

Meta Pixel (Facebook Pixel)

FeldWert
Gruppe / Parent ServiceMeta Pixel
Badge⚠️ Caution
Service-TypParent service
Sub-service / Relationship NoteParent service
Infrastructure Only?No
Kontakt (DPO / Privacy)privacy@meta.com
Bewertungsdatum06/08/2026
Versionv2 (06/08/2026) | v1: 22/06/2026

Badge & Risikobewertung
  • Badge: ⚠️ Caution
  • Red Flags:
    • RF1 — Own advertising / cross-service profiling
    • RF2 — High-risk third-country exposure without meaningful mitigation
  • Risk Indicators:
    • Own-purpose data use (advertising); intrusive tracking; problematic profiling; high-risk international transfers
Begründung & Quellen

Key Facts: The Meta Pixel transmits detailed user behaviour (pages visited, purchases, button clicks) to Meta US servers for advertising attribution, audience building, and retargeting — all for Meta's own advertising purposes. Austrian DPA (2022) found Meta Pixel use violated GDPR. Swedish IMY issued multiple fines in 2024 (€700K–€1.3M per case) to organisations using the Pixel without lawful consent. Irish DPC fined Meta €1.2 billion (May 2023) for unlawful EU–US data transfers encompassing Pixel data. Healthcare providers have incurred regulatory action for Pixel transmitting patient data.

Framework Note (v2.2): FRAMEWORK NOTE (v2.2): RF2 (high-risk third-country exposure) is recorded here as a significant risk factor and lowers the domain E score. Under the revised framework, RF2 alone does not trigger Caution — the Caution badge for this service is driven by RF1 / RF3 / RF4 (as noted above). The US transfer risk (where applicable) is covered by DPF participation and/or SCCs, which GDPR treats as a compliant transfer mechanism.

Quellen:

  • Meta Pixel Terms of Service (facebook.com/legal/terms/businesstools)
  • Meta Privacy Policy (facebook.com/privacy/policy)
  • Austrian DPA Meta Pixel finding (2022)
  • Swedish IMY fines (2024, imy.se)
  • Irish DPC Meta fine (May 2023, dataprotection.ie).
Verarbeitungszwecke (Consenter)
  • Support marketing analytics
  • Receive personalised marketing offers
  • Customise online ads (non-TCF)
Benachrichtigungs- & Widerspruchsstatus
  • TPP Notified?: Not yet notified
  • Decision Contested?: [nicht dokumentiert]

Prüfbedarf

Kein Prüfbedarf identifiziert.

Shape Consenter Together

Consenter is built on an open and participatory process that grows through community collaboration. Whether you share feedback, improve the documentation, or contribute to the Risk Configuration Guides or Technical Integration Guides, your expertise helps make Consenter more privacy-friendly, interoperable, and useful for everyone—including your own users and services: Get finally your benefits and control the risks when sharing personal data.

Last updated on

On this page