Glossary
Meta Pixel
The Meta Pixel is a snippet of Facebook/Instagram advertising code installed on websites to measure ad performance and build retargeting audiences. It transmits visitor events (page views, button clicks, purchases) to Meta along with identifiers, and with 'advanced matching' enabled it can send hashed emails and phone numbers from forms. Because those payloads can describe what an identifiable person viewed or did, the Pixel sits at the center of VPPA, consumer-health-data, and state-privacy litigation.
What it actually transmits
Out of the box the Pixel sends the page URL and standard events with a browser identifier (and the user's Meta cookie when present). Configuration widens the stream: custom events can carry product, video, or appointment details; advanced matching scrapes form fields for hashed contact info; and the Conversions API moves the same data server-side where page-level scanners can't see it. None of this is hidden (it's documented ad infrastructure), but on the wrong page, the payload becomes legally significant.
The settlement pattern
The fact pattern recurs across statutes. On video pages, the URL-plus-identifier payload is what the VPPA calls disclosing viewing information ($2,500 per person): Markels v. AARP settled for $12.5M over exactly this; Tubi paid $19.99M. On health-adjacent pages, the same mechanics produced the Henry Ford ($12.28M) and Advocate Aurora ($12.25M) settlements and the FTC's GoodRx and BetterHelp actions. Under CCPA-style laws, Pixel data flowing pre-consent or past an ignored Global Privacy Control signal is the Sephora pattern ($1.2M). The common thread: the Pixel did what it was configured to do, on pages where that data shouldn't have left.
How Complidar checks this
Complidar captures every request the Pixel makes during a scan: which pages it fires on, whether it fires before consent, whether the payload carries page/video identifiers, and whether GPC changes its behavior. It then tags the findings with the comparable settlements above.
Related questions
Is using the Meta Pixel illegal?
No. It's standard ad infrastructure on millions of sites. The legal exposure comes from placement and configuration: firing on video, health, or intake pages; firing before consent; ignoring opt-out signals. The settlements punished configurations, not the existence of the tool.
Does removing the Pixel from sensitive pages fix the problem?
Scoping it off video/health/intake pages (or stripping identifying parameters) removes the ongoing fact pattern; the Conversions API needs the same review server-side. Past transmissions are a counsel question. A scan shows where the Pixel fires today, which is the map you remediate from.
What's 'advanced matching' and why does it matter legally?
Advanced matching has the Pixel hash and send contact info (email, phone) it finds in your forms, improving ad attribution, and turning 'a browser viewed this page' into 'this identifiable person viewed this page.' That identification step is what privacy and VPPA theories need; enabling it site-wide without consent review is the configuration mistake.
22 checks · up to 120 pages · no card
Last updated 2026-06-11 · Informational, not legal advice