TikTok Pixel and GDPR: Consent Rules

The TikTok Pixel is how small brands measure what their TikTok ads actually sell, and how they retarget the people who watched. If you advertise on TikTok, you probably have it on your site, often installed in one click by a Shopify or WordPress integration. That one click is where the GDPR problem usually starts: the pixel goes live for every visitor, before anyone has been asked.

What the TikTok Pixel stores

TikTok’s help article on using cookies with the TikTok Pixel lists the cookies:

CookieSet onPartyCategory
_ttpYour website’s domainFirst-partyAdvertising
_ttp.tiktok.comThird-partyAdvertising
ttcsid_ and ttcsid_<pixel code>Your website’s domainFirst-partyAdvertising
ttclidYour website’s domainFirst-partyAdvertising
_pangleanalytics.pangle-ads.comThird-partyAdvertising

TikTok states that they expire 13 months after being set on a browser or last used. You can switch first-party cookies off in TikTok’s settings, but TikTok also says existing ones keep working until they expire, and the third-party ones are untouched by that switch.

Every cookie in that table is an advertising cookie, and that settles it. Article 5(3) of the ePrivacy Directive lets a site store or read information on a visitor’s device only once the visitor has consented, apart from what is strictly necessary for the service they asked for. Measuring your ad campaigns is not that, so the pixel must stay off until the visitor accepts.

  1. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing.

— ePrivacy Directive, Article 5(3)

Switching off first-party cookies does not change this. The pixel still runs on the visitor’s device and sends events to TikTok, and the EDPB’s Guidelines 2/2023 on the technical scope of Article 5(3) apply the rule to tracking pixels and URL tracking, not only to cookies. TikTok’s own help page points the same way: it suggests a consent management platform so that the pixel is used in compliance with user consent.

The transfer question

There is a second layer for TikTok specifically. In May 2025, Ireland’s Data Protection Commission fined TikTok €530 million, finding that it had not shown that the data of European users accessed remotely from China enjoyed protection essentially equivalent to EU law, and that it had not been transparent about those transfers. TikTok announced an appeal. The decision concerned the data of TikTok’s own users rather than pixel events, but it shows where the regulator’s attention lies, and there is no adequacy framework for China comparable to the EU-U.S. Data Privacy Framework.

For you, the practical consequence is simple: your privacy policy must say that pixel data goes to TikTok and may be processed outside the EU, and consent must come before any of it.

Our free cookie consent banner (CCB) has the TikTok Pixel in its catalogue, in the marketing category. Its signature is:

[./]analytics([.-][a-z0-9]{1,10})?\.tiktok\.com(?![\w-])

In plain words: requests to analytics.tiktok.com, where the pixel’s library lives, and to regional variants of that host, but not to other parts of tiktok.com. The pattern is anchored on purpose: an earlier, looser rule in our catalogue could match an unrelated page that merely contained “tiktok.com” followed later by “analytics”, so we tightened it.

On a real page:

  1. Before consent, the inline part of TikTok’s snippet runs, which only sets up the ttq queue, but the request for the pixel library is held. No _ttp, nothing sent to TikTok, and the library that would go on to contact other TikTok advertising hosts never runs.
  2. On acceptance of marketing, the banner releases the script and the pixel works normally.
  3. On refusal or withdrawal, the banner deletes the _ttp cookie from your domain.

Two installation rules make this work. The banner must be the first script in your <head>, without defer or async, and never loaded through a tag manager. And if a platform integration writes the pixel directly into your HTML, the browser may fetch it before any script runs: the banner page shows how to neutralise such tags with type="text/plain" and data-wl-src.

What no client-side banner can block: TikTok’s Events API, which sends events from your server. If you use it, send events only for visitors whose consent cookie says yes.

Check it on your site

Open your site in a fresh browser profile with DevTools open and do nothing. In Network, filter on tiktok: there should be no request. In Application > Cookies, there should be no _ttp and no ttclid. Accept, and they should appear. Our free GDPR compliance checker runs this test for you and lists every tracker firing before consent.

Put it in your policies

The TikTok Pixel belongs in your cookie policy (purpose, provider, the cookies above, 13-month lifetime) and in your privacy policy (recipient, possible processing outside the EU). Every WebLegal pack includes both documents, starting with the Essential pack at €19.90.

If you also run Meta ads, read Meta Pixel cookie consent; if TikTok is fired through a tag container, see does Google Tag Manager need cookie consent? For every other service your banner should hold back, see the 37 trackers your cookie banner must block.