FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. TikTok Pixel
T

TikTok Pixel

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does TikTok Pixel do?

The TikTok Pixel is an advertising measurement and audience building tool from TikTok (ByteDance) that tracks website conversions and enables retargeting audiences for TikTok ads. It faces heightened GDPR scrutiny due to ByteDance's Chinese ownership and concerns about potential data access under Chinese national security laws. Multiple EU member state authorities have investigated or restricted TikTok's data practices. Consent is required before the pixel loads, SCCs are required for US/Singapore transfers, and a DPIA is strongly recommended.

What is the TikTok Pixel?

The TikTok Pixel is a JavaScript snippet installed on websites to measure conversions from TikTok advertising, build custom audiences for retargeting, and optimise ad delivery algorithms. It tracks page views, add-to-cart events, purchases, lead form submissions, and other custom events. The TikTok Events API provides a server-side alternative sending conversion data directly from the server to TikTok without browser cookies.

The ByteDance risk factor

TikTok is owned by ByteDance, a Chinese company. Chinese national security laws (National Intelligence Law 2017, Data Security Law 2021, Personal Information Protection Law 2021) may require ByteDance to provide data to Chinese government authorities on request. This creates a transfer risk beyond standard SCCs — even with SCCs, data may be subject to Chinese government access without GDPR-compliant safeguards. Multiple EU regulators have investigated TikTok''s data practices and several EU institutions have banned TikTok from employee devices.

EU regulatory actions against TikTok

TikTok has faced significant EU regulatory action: a 345 million EUR fine from the Irish DPC (September 2023) for mishandling children''s data, investigations by multiple DPAs into data transfers to China, and device bans by the European Commission, European Parliament, and several member state governments. These actions create heightened GDPR risk for organisations deploying TikTok advertising tools.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Practical compliance steps

Conduct a DPIA before deploying the TikTok Pixel on EU-facing websites. Block the Pixel via CMP until advertising consent. Accept TikTok''s Data Processing Agreement. Sign SCCs. Disclose the US/Singapore transfer and ByteDance ownership in your privacy policy. Consider using TikTok Events API (server-side) instead of the browser Pixel to reduce cookie-based tracking. Assess whether the ByteDance risk warrants a Transfer Impact Assessment.

GDPR consent category

Marketing

Websites using TikTok Pixel must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) required for TikTok Pixel cookies and cross-site tracking. The pixel must not fire until advertising consent is obtained. The ByteDance ownership raises additional transfer concerns beyond standard SCCs due to Chinese national security legislation.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, SCCs required. TikTok has received regulatory bans and fines in multiple EU member states. DPIA strongly recommended.

DPIA considerations

A DPIA is strongly recommended for TikTok Pixel deployments due to: cross-site advertising tracking, US and Singapore data transfers, ByteDance ownership creating potential Chinese government access risk, and TikTok's history of EU regulatory action.

Sample consent text

We use the TikTok Pixel to measure the effectiveness of our TikTok advertising campaigns. This involves cookies and transfer of data to TikTok (ByteDance) in the US and Singapore. You can decline advertising cookies below.

Technical details

Tracking methodJavaScript pixel, first-party cookies, cross-site conversion tracking, TikTok Events API (server-side), audience building, advanced matching
Server locationUnited States and Singapore (TikTok/ByteDance infrastructure)
Data transferred outside the EUTikTok Pixel is operated by TikTok (ByteDance). Data is processed on infrastructure in the US and Singapore. EU personal data transfers require Standard Contractual Clauses. TikTok has faced significant regulatory scrutiny in Europe regarding its data practices and potential Chinese government access under national security laws.

Third-party domains contacted

analytics.tiktok.combusiness.tiktok.comads.tiktok.com

Cookies placed

NameTypeDurationPurpose
_ttppersistent13 monthsTikTok cross-site tracking identifier for conversion measurement and audience building
_tt_enable_cookiepersistent13 monthsTikTok consent flag cookie recording whether visitor has accepted TikTok advertising tracking

TikTok Pixel places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Does the TikTok Pixel require GDPR consent?

Yes. The TikTok Pixel sets advertising cookies requiring consent under the ePrivacy Directive. It must not load until advertising consent is obtained. Block via CMP.

What is the ByteDance risk for GDPR?

ByteDance is a Chinese company subject to Chinese national security laws that may require data disclosure to Chinese authorities. SCCs alone may not adequately protect EU data from such access. Conduct a Transfer Impact Assessment to document the risk and any supplementary measures.

What EU regulatory actions have targeted TikTok?

TikTok received a 345 million EUR GDPR fine from the Irish DPC in September 2023 for mishandling children's data. Multiple EU institutions including the European Commission and Parliament banned TikTok from employee devices. Dutch, French, and other national DPAs have investigated TikTok's data transfers to China.

What cookies does the TikTok Pixel set?

TikTok Pixel sets _ttp (tracking and conversion, 13 months) and _tt_enable_cookie (consent flag). These require advertising consent. The pixel also uses Advanced Matching to hash personal data for better attribution.

Is the TikTok Events API a GDPR-compliant alternative?

The Events API is server-side and avoids browser cookies. This bypasses the ePrivacy cookie consent requirement. However, it still transfers personal data (hashed email, IP, browser data) to TikTok in the US and Singapore. GDPR disclosure, SCCs, and a DPA are still required.

Do I need a DPIA for the TikTok Pixel?

Yes, strongly recommended. The combination of advertising tracking, ByteDance ownership, US/Singapore transfers, and potential Chinese government access constitutes high-risk processing requiring a DPIA under GDPR Article 35.

How do I sign a DPA with TikTok for advertising?

Accept TikTok's Data Processing Agreement in TikTok Ads Manager (Account Settings, Data Processing Agreement). This covers the Pixel data and Events API. Sign SCCs separately if required by your legal team.

Should I use TikTok advertising on EU-facing websites?

TikTok advertising is legally permissible with consent, a signed DPA, and SCCs. However, the ByteDance risk factor means some organisations — particularly in regulated sectors or those processing sensitive data — may choose to avoid TikTok advertising for EU audiences pending further regulatory clarity.