- Does the TikTok Pixel require consent in the EU?
- Yes. The TikTok Pixel is a non-essential advertising technology and requires explicit opt-in consent from EU and UK visitors under the GDPR and ePrivacy Directive. Technical validation is required: the Pixel must not fire before consent is granted and must be completely blocked, not just send denied signals, in the reject state.
- What is TikTok advanced matching and how does it affect my policy?
- Advanced matching allows you to pass hashed personal identifiers (email address, phone number, name) alongside Pixel events to improve conversion attribution. When enabled, this transmits personal data in hashed form to TikTok, which changes the nature of the processing from pseudonymous event data to a more direct personal data transfer. Your policy must describe this processing activity separately from standard Pixel event tracking.
- What regulatory risks are associated with the TikTok Pixel?
- The TikTok Pixel carries elevated regulatory attention because of ongoing scrutiny of TikTok's data transfers between the United States and China, the platform's processing of minors' data, and enforcement activity by EU supervisory authorities and US state regulators. In addition to the standard GDPR and CCPA obligations that apply to any advertising pixel, organizations should assess the cross-border transfer risk specific to TikTok and ensure their DPA and Standard Contractual Clauses are current.