ConsentPixel – Privacy · Verified

HomeBlogTracking Pixel EU › TikTok Pixel GDPR
Tracking Pixel · EU

TikTok Pixel GDPR: What EU Websites Must Do After the €530M Fine

In May 2025, Ireland's Data Protection Commission fined TikTok €530 million — and the reason matters for every EU site running the pixel. This wasn't about a cookie banner. It was about where EU data ends up. If you run the TikTok Pixel on a site with European visitors, you're wiring your traffic into the exact data flow regulators just penalised. Here's what that means, and what to do about it.

By The ConsentPixel TeamUpdated July 202614 min readEU & UK focusNot legal advice
€530M
Irish DPC fine against TikTok — €485M for unlawful transfers, €45M for transparency
Two risks
The pixel fails GDPR twice: pre-consent tracking and data transfers to China
On page load
The pixel sets its _ttp cookie and fires before any consent, by default

What the €530M fine was actually about

On 2 May 2025, Ireland's Data Protection Commission (DPC) — TikTok's lead supervisory authority in the EU — issued one of the largest GDPR penalties on record. It's tempting to file it under "big tech gets fined again" and move on. For EU site owners running the TikTok Pixel, that would be a mistake, because the reasoning points straight at your own setup.

The €530 million total broke into two distinct infringements, and the split is the whole story:

  • €485 million under Article 46(1) — for transferring the personal data of European users to China without being able to guarantee it received protection "essentially equivalent" to EU standards. TikTok couldn't demonstrate that its Standard Contractual Clauses and supplementary measures were actually effective against access under Chinese law.
  • €45 million under Article 13(1)(f) — for a transparency failure: its privacy policy did not adequately tell users their data was being transferred to China.

The DPC also ordered TikTok to bring its processing into compliance within six months and to suspend transfers to China if it didn't. Notably, during the inquiry TikTok told the regulator it did not store EEA user data on servers in China — then, in April 2025, disclosed it had in fact done so to a limited extent. This followed an earlier €345 million DPC fine in 2023 over children's data. The pattern is clear: TikTok's data flows are under sustained, aggressive scrutiny in Europe.

Why the fine matters to your website

Here's the connection most coverage skips. The €530M decision was about TikTok moving data to China — but the TikTok Pixel is the mechanism by which your visitors' data enters TikTok's systems in the first place. Every PageView, every event, every identifier the pixel collects on your site is personal data you have chosen to route to ByteDance — whose infrastructure spans the United States, Singapore, and, as the DPC established, has included remote access from China.

That makes you more than a bystander. Under GDPR you are a data controller for the processing you initiate on your own site, and — as we'll see — very likely a joint controller with TikTok for the pixel's data collection. The regulator's finding doesn't stay contained to TikTok — it raises the obvious question for your site: on what basis are you sending EU personal data into a pipeline a supervisory authority has already ruled deficient? For the broader framework these obligations sit within, see our GDPR compliance guide.

The two GDPR risks in one pixel

Most tracking pixels carry a single, well-understood GDPR problem: they fire before consent. The TikTok Pixel carries that one and a second, compounding one that puts it near the top of DPA enforcement priorities. Understanding both is the key to configuring it lawfully — or deciding whether to run it at all.

TWO RISKS, STACKED RISK 1 — CONSENT LAYER (every pixel has this) The pixel fires and sets _ttp on page load, before the visitor consents. Violates ePrivacy Art. 5(3) + GDPR — the same failure as the Meta Pixel. + RISK 2 — TRANSFER LAYER (TikTok-specific) Collected data flows to ByteDance — US, Singapore, and access from China. The exact Article 46 transfer problem behind the €530M fine. 🌏

A generic pixel gives regulators one thing to object to. The TikTok Pixel gives them two — and the second is the one Europe is enforcing most aggressively.

The standard TikTok installation guide tells you to paste the pixel snippet into your page header. Follow it, and the pixel fires the instant the page loads — running a PageView event and writing its cookies before the visitor has clicked anything. That is a textbook violation of EU law.

Article 5(3) of the ePrivacy Directive is unambiguous: storing or accessing information on a user's device requires prior consent, unless it is strictly necessary for a service the user explicitly requested. Conversion tracking for your ad campaigns is not strictly necessary to deliver your website. The GDPR then reinforces this by requiring a valid legal basis for the personal data the pixel processes. The two work together: ePrivacy governs the act of dropping the cookie; GDPR governs what happens to the data after. (For the consent standard itself, see our cookie consent guide.)

When the TikTok Pixel loads, it sets two cookies that matter here:

CookieType & lifespanPurpose
_ttpFirst-party, ~13 monthsIdentifies the visitor for TikTok targeting and conversion measurement — links every event on your site into a single profile
_tt_enable_cookieSessionSignals that TikTok tracking is active on the page

Both are marketing cookies feeding TikTok's advertising algorithms. Crucially, the _ttp cookie alone is enough to constitute a tracking cookie under EU ePrivacy guidance — so even a stripped-down pixel with advanced matching disabled still requires consent before it loads. Dropping it silently, with no visible UI, is one of the most common failures DPAs flag in cookie audits precisely because site owners assume "no visible tracker" means "no problem."

🚫

The banner is irrelevant if the pixel already fired

A consent banner that appears while the TikTok Pixel is loading in the background does nothing for compliance — the cookie is already set and the PageView already sent. Under EU law the tracking must be technically blocked until the visitor actively accepts, not merely accompanied by a notice. This is the single most consequential detail on the page, and the one most "compliant" setups get wrong.

Risk 2: the data goes to China

This is the layer that makes the TikTok Pixel different from a Meta or Google pixel, and it's the layer the €530M fine was about. The data your pixel collects doesn't stay in Europe. It flows to TikTok's parent, ByteDance, across infrastructure in the United States and Singapore — and, as the DPC established, has been remotely accessible from China.

Transferring EU personal data outside the EEA is only lawful under Chapter V of the GDPR if you have a valid transfer mechanism — typically Standard Contractual Clauses (SCCs) — and can demonstrate the destination actually protects the data to an essentially equivalent standard. The DPC found this bar was not met for China: ByteDance is subject to national security laws that can compel data disclosure, and SCCs on paper don't neutralise that. This is why a Transfer Impact Assessment (TIA) and a Data Protection Impact Assessment (DPIA) are strongly recommended before deploying the pixel at all — the ByteDance ownership structure creates a documented, foreseeable government-access risk you're expected to have assessed.

The practical consequence: even if you fix the consent problem perfectly, you still have to confront the transfer question every time a consenting EU visitor's data leaves for ByteDance infrastructure. Consent makes the collection lawful; it does not by itself make the international transfer lawful.

See whether the TikTok Pixel fires before consent on your site

Most "compliant" TikTok setups still drop _ttp on page load. See which trackers fire before consent on your site, in about 10 seconds — no signup, no install.

Scan your site free →

The joint-controller trap most site owners miss

When you embed the TikTok Pixel, you and TikTok jointly determine why and how your visitors' data is collected — you place the pixel to measure conversions and build audiences; TikTok uses the same data for its own ad products. Under GDPR Article 26, that shared determination generally makes you joint controllers, not a controller and a mere processor.

That distinction carries real obligations: you must inform visitors that data is shared with TikTok, specify the purposes, provide a way to withdraw consent as easily as it was given, and reflect all of this in your privacy policy. Many EU site owners run the pixel believing TikTok "handles the compliance side." It doesn't work that way — the controller who placed the pixel is on the hook for the collection that happens on their own domain.

A common temptation is to claim legitimate interest (GDPR Article 6(1)(f)) as the legal basis, avoiding a consent banner altogether. For an advertising pixel, this is a bet most privacy professionals would refuse to make, for two reasons.

First, ePrivacy Article 5(3) requires consent to set the cookie in the first place — legitimate interest is a GDPR lawful basis and cannot override the ePrivacy consent requirement for device storage. Second, even on the GDPR side, retargeting and cross-site profiling are intrusive by nature, involve tracking people across the web, and are difficult to justify against a visitor's reasonable expectations. European guidance and enforcement have landed consistently on consent — an opt-in, not opt-out — as the appropriate basis for advertising cookies and pixels. In practice, consent under Article 6(1)(a) is the only defensible route for the TikTok Pixel — which brings us back to blocking it until that consent exists.

What a compliant TikTok Pixel setup looks like

Compliance here is binary in its first requirement — the pixel is blocked before consent, or it isn't — and layered after that. Here's the contrast that matters.

✕ Non-compliant (the default install)

  • Pixel pasted in the header, fires on page load
  • _ttp cookie set before any consent click
  • Banner appears while tracking already runs in the background
  • "Legitimate interest" claimed for advertising tracking
  • Privacy policy silent on the transfer to ByteDance / China
  • No TIA or DPIA documenting the transfer risk
  • No record of who consented, or when

✓ Compliant

  • Pixel technically blocked until the visitor actively accepts
  • Granular opt-in for marketing cookies, reject as easy as accept
  • Nothing fires — no cookie, no PageView — before consent
  • Consent (Art. 6(1)(a)) used as the legal basis, not legitimate interest
  • Privacy policy names TikTok, the purposes, and the third-country transfer
  • TIA + DPIA completed and on file for the ByteDance transfer
  • Every consent decision logged with a timestamp
🔧

What about TikTok's Limited Data Mode?

TikTok offers "Limited Data Mode" (LDM) — a flag you pass with pixel events to reduce the data processed when a user hasn't consented. It's useful as a signal-passing layer once you have a CMP wired up: when consent is absent, your CMP sets the LDM flag; when consent exists, you omit it and enable full processing. But LDM is not a substitute for blocking. It changes what TikTok does with data after it arrives; it does not stop the cookie being set on your visitor's device in the first place. You still need the pixel blocked until consent — LDM sits on top of that, not instead of it.

The agency exposure — priced in or not?

If you're an agency running TikTok campaigns on client sites, this is exposure you may not have on the books. Installing the pixel without addressing both risks means you've built the on-ramp — the consent violation fires on the client's domain and the transfer question attaches to their data, but you configured it. When a DPA or a client audit surfaces the problem, "the agency set it up" is not a comfortable place to be.

There's a better framing than risk, though. Handling this properly is a service you can sell. "We deploy your TikTok Pixel so it blocks before consent, passes Limited Data Mode signals correctly, and comes with the transfer documentation your DPO expects" is a concrete, defensible deliverable — and it differentiates you from every agency that just pastes the snippet in the header. Getting the consent layer right across a whole client portfolio, from one dashboard, turns a latent liability into a retainer line. Our agency plans are built for exactly that multi-site shape.

How to make the TikTok Pixel GDPR compliant

Six steps, in order of impact. The first is non-negotiable; the rest make the setup defensible and complete.

01

Block the pixel until consent — technically, not visually

Install a consent platform that prevents the TikTok Pixel from loading until the visitor actively accepts marketing cookies. Not a banner that appears alongside the pixel — a mechanism that stops the script executing and the _ttp cookie being set until consent exists. This is the one step that fixes the ePrivacy violation, and it's what ConsentPixel — Privacy · Verified does by default.

02

Use a compliant banner — reject as easy as accept

Present granular opt-in for marketing cookies with a reject-all path that is one click and visually equal to accept-all. No pre-ticked boxes, no cookie walls, no emphasised-accept/hidden-reject dark patterns — the EDPB and national DPAs have called all of these out repeatedly, and they will not survive review.

03

Wire up Limited Data Mode as a signal layer

Configure your CMP to pass TikTok's Limited Data Mode flag when consent is absent and to enable full processing when it's present. This aligns with TikTok's own consent-signalling expectations — but it sits on top of blocking, never in place of it.

04

Update your privacy policy for the transfer

Name TikTok explicitly, state the purposes, and disclose that data is transferred to ByteDance outside the EEA — including the third countries involved. The €45M slice of the fine was a transparency failure of exactly this kind. ConsentPixel's privacy policy generator can build this disclosure from your actual configuration.

05

Complete a DPIA and Transfer Impact Assessment

Because of the cross-border transfer and the documented government-access risk tied to ByteDance ownership, both a DPIA and a TIA are strongly advised. They document that you assessed the risk and identified any supplementary measures — the accountability record a regulator expects to see if they ask.

06

Log every consent decision

Keep a timestamped record of who consented, to what, and when — the evidence that demonstrates compliance under GDPR's accountability principle. If a DPA inquires, a clean consent log is the difference between showing compliance and asserting it.

Key takeaways

The €530M fine was a transfer case, not a cookie case. €485M was for unlawful data transfers to China under Article 46(1), €45M for a transparency failure under Article 13(1)(f). It tells you which data flow Europe considers unlawful.

The TikTok Pixel carries two GDPR risks at once. It fires before consent like any pixel (ePrivacy Art. 5(3)), and it feeds EU data into the ByteDance transfer pipeline the DPC penalised — a compounding exposure most pixels don't have.

The banner is not the control — blocking is. The _ttp cookie must be technically prevented from loading until the visitor consents. A notice that appears while the pixel already ran fixes nothing.

Legitimate interest is not a viable basis, and you are very likely a joint controller with TikTok under Article 26 — so the compliance obligation sits with you, not just the platform.

Consent makes collection lawful; it doesn't make the transfer lawful. A DPIA and Transfer Impact Assessment, plus a transfer disclosure in your privacy policy, are the pieces that address Risk 2.

Block the TikTok Pixel before it fires — verifiably

ConsentPixel — Privacy · Verified blocks the TikTok Pixel and every other tracker before consent is granted, passes Limited Data Mode signals, generates the transfer disclosure for your privacy policy, and logs every consent decision as timestamped proof. See what fires on your site first, then start a 14-day trial.

No credit card required · from $8.99/domain/mo · cancel any time
CP
The ConsentPixel Team

We build ConsentPixel — Privacy · Verified, a prevention-first consent pixel that blocks trackers before consent under GDPR, ePrivacy, and US privacy law. This article is educational and is not legal advice; GDPR obligations are fact-specific and international-transfer rules evolve — consult a qualified privacy professional or your DPO about your specific TikTok Pixel deployment.

TikTok Pixel GDPR — frequently asked questions

Is the TikTok Pixel GDPR compliant by default?

No. Installed the standard way — pasted into the page header — the TikTok Pixel fires on page load and sets its _ttp cookie before the visitor has consented to anything. That violates Article 5(3) of the ePrivacy Directive, which requires prior consent to store or access information on a user's device, and the GDPR's requirement for a valid legal basis. To be compliant, the pixel must be technically blocked until the visitor actively accepts marketing cookies. It is not compliant out of the box, and no configuration inside TikTok's own dashboard changes that — the blocking has to happen on your site, before the pixel loads.

Do I need consent to use the TikTok Pixel in the EU?

Yes. For any website with EEA or UK visitors, the TikTok Pixel requires prior, freely given, specific, informed, and unambiguous consent before it loads. The pixel sets advertising cookies and processes identifiers, IP addresses, and browsing behaviour, which brings it squarely under the ePrivacy Directive's prior-consent requirement and the GDPR's legal-basis requirement. Legitimate interest is not a viable basis for advertising pixels, so consent under Article 6(1)(a) is the defensible route. The only exception is a site with genuinely no EEA or UK visitors that is not otherwise subject to these laws — which, for most businesses, is not a realistic position.

What was the €530 million TikTok fine actually for?

On 2 May 2025, Ireland's Data Protection Commission fined TikTok €530 million in two parts: €485 million under GDPR Article 46(1) for transferring European users' personal data to China without guaranteeing it received protection essentially equivalent to EU standards, and €45 million under Article 13(1)(f) for failing to adequately disclose those transfers in its privacy policy. The DPC also ordered TikTok to bring its processing into compliance within six months and to suspend transfers to China otherwise. The fine was against TikTok itself, but it signals which data flow European regulators consider unlawful — the same flow your site feeds into when you run the pixel.

What are the _ttp and _tt_enable_cookie cookies?

These are the two main cookies the TikTok Pixel sets when it loads. The _ttp cookie is a first-party cookie with a lifespan of around 13 months; it identifies the visitor for TikTok's targeting and conversion measurement and links the events on your site into a single visitor profile. The _tt_enable_cookie is a session cookie indicating that TikTok tracking is active. Both are marketing cookies that feed TikTok's advertising algorithms, so both require prior consent under EU law. Importantly, the _ttp cookie alone is enough to count as a tracking cookie under ePrivacy guidance, so even a minimal pixel deployment needs consent before it fires.

Can I rely on legitimate interest instead of consent for the TikTok Pixel?

In practice, no. Two obstacles stand in the way. First, ePrivacy Article 5(3) requires consent specifically to store or access cookies on a device — and legitimate interest, which is a GDPR lawful basis, cannot override that separate ePrivacy consent requirement. Second, even under the GDPR, advertising retargeting and cross-site profiling are intrusive and hard to justify against a visitor's reasonable expectations, so European guidance and enforcement consistently point to consent as the correct basis for advertising pixels. Relying on legitimate interest for a TikTok or Meta pixel is a bet most privacy professionals would not take. Consent under Article 6(1)(a), with the pixel blocked until it's given, is the defensible approach.

Is TikTok's Limited Data Mode enough for GDPR compliance?

No — Limited Data Mode is useful, but it is not a substitute for blocking the pixel before consent. LDM is a flag you pass with pixel events that reduces the data TikTok processes when a user hasn't consented; the correct pattern is to set the LDM flag when consent is absent and omit it when consent exists. But LDM changes what TikTok does with data after it has been collected — it does not stop the pixel loading or the _ttp cookie being set on the visitor's device in the first place, which is the actual ePrivacy violation. You need the pixel technically blocked until consent, with LDM configured as an additional signalling layer on top of that, not in place of it.

Scroll to Top