The Meta Pixel (still widely called the Facebook Pixel) is the reason many small businesses can advertise on Facebook and Instagram at all: it measures which ads lead to a sale and builds the audiences that make retargeting work. Switching it off is rarely an option. Installing it without consent, on the other hand, is one of the most common violations a European site can make.
Here is what the pixel stores, what Meta itself asks of you, and how to keep it quiet until the visitor says yes.
The Facebook Pixel cookies list
On your domain, Meta’s developer documentation on the fbp and fbc parameters describes two first-party cookies:
| Cookie | What it holds | When it appears |
|---|---|---|
_fbp | A browser identifier (version, subdomain index, creation time, random number) | Set automatically by the pixel when first-party cookies are enabled and none exists yet |
_fbc | The fbclid click identifier from a Meta ad | Set when a visitor arrives through a link carrying fbclid; Meta recommends a 90-day expiry when you set it server-side |
Meta also uses cookies on its own domains, described in its cookie policy. Those are set by Meta when the pixel’s library talks to Meta’s servers, and no script on your site can read or delete them. Which is the whole argument for blocking the pixel before it loads, rather than cleaning up afterwards.
Why the pixel needs prior consent
Article 5(3) of the ePrivacy Directive allows storing or reading information on a visitor’s device only after consent, except where it is strictly necessary for the service the visitor requested. Conversion tracking and retargeting serve the advertiser, so there is no exemption to argue about: the pixel must not load before the visitor accepts.
- Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing.
— ePrivacy Directive, Article 5(3)
Three other facts make this more than theory:
- Meta’s own terms put it on you. In section 3 of the Meta Business Tools Terms, the advertiser warrants that it gives users prominent notice and, in jurisdictions that require informed consent for storing and accessing cookies (the EU is named), that end users give that consent in a verifiable way. Meta’s developer guide on GDPR adds that “each company is responsible for ensuring their own compliance with the GDPR”.
- You share responsibility with Meta. In Fashion ID (C-40/17, 29 July 2019), the EU Court of Justice held that a site embedding a Facebook plugin can be a joint controller with Facebook for the collection and transmission of its visitors’ data, limited to the stage the site actually influences. The pixel works the same way: you decide to send the data.
- Data goes to the United States. Meta’s privacy center states that Meta Platforms, Inc. participates in the EU-U.S. Data Privacy Framework, whose adequacy decision the EU General Court upheld in September 2025 (an appeal is pending before the Court of Justice). That answers the transfer question, not the consent one.
How the WebLegal cookie banner handles the Meta Pixel
Our free cookie consent banner (CCB) has the Meta Pixel in its catalogue, in the marketing category. Three signatures from our catalogue cover the ways the pixel reaches Meta:
[./]connect\.facebook\.net(?![\w-]): the host that serves the pixel library;[/]fbevents\.js(?![\w-]): the library file itself, even if it is served from another host;[./]facebook\.com/tr(?![\w-]): the tracking endpoint the pixel sends events to.
What happens on a real page:
- Before consent, the standard pixel snippet still runs its inline part, which only sets up the
fbqqueue, but the request forfbevents.jsis held. No_fbp, nothing sent to Meta. - On acceptance of marketing, the banner releases the script and the pixel starts normally.
- On refusal or withdrawal, the banner deletes
_fbpand_fbcfrom your domain, so a visitor who changes their mind does not keep a Meta identifier for months.
Because the library never loads before consent, you do not need Meta’s fbq('consent', 'revoke') call for blocking. You can still use it if your developer prefers an explicit signal.
Three gaps no banner closes for you
Be clear about what a client-side banner cannot see:
- The
<noscript>image. Meta’s snippet includes a fallback<img src="https://www.facebook.com/tr?...">for browsers without JavaScript. Without JavaScript, no banner can collect consent, so that image fires unconditionally. Remove it. - The Conversions API. Events sent from your server to Meta never pass through the visitor’s browser, so no banner can block them. Send them only for visitors whose consent cookie says yes.
- Script order. The banner must be the first script in your
<head>, withoutdeferorasync, and never loaded through a tag manager. A pixel tag written directly in your HTML can also be fetched by the browser before any script runs; the banner page shows how to neutralise it withtype="text/plain"anddata-wl-src.
Check it on your site
Open your site in a fresh browser profile with DevTools open and do nothing yet. In Network, filter on facebook: there should be no request. In Application > Cookies, there should be no _fbp. Then accept and watch both appear. Or use our free GDPR compliance checker, which loads your page as a first-time visitor and lists everything that fires before consent.
Put it in writing
The pixel must appear in your cookie policy (purpose, provider Meta Platforms, cookies, retention) and in your privacy policy (joint responsibility with Meta, transfer to the United States). Every WebLegal pack includes both, starting with the Essential pack at €19.90.
The Meta Pixel is one of 37 services our banner knows. Its closest cousin is covered in TikTok Pixel and GDPR, and the full list is in the 37 trackers your cookie banner must block.