Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Meta Pay lets visitors pay using payment details stored in their Meta account. Transaction and device data are sent to Meta in the United States, Meta cookies are set, and both GDPR and PSD2 compliance are required.
Meta Pay (formerly Facebook Pay) is Meta's payment method that lets people pay using payment details already stored in their Facebook or Instagram account. On partner sites the checkout integration loads from Meta domains, verifies the user's identity against their Meta account and processes the payment. Transaction details and device data are shared with Meta, which uses this information for fraud prevention and, depending on settings, for advertising.
Meta Pay sets a range of Meta cookies. The datr cookie (two years) identifies the browser for security purposes. The sb cookie (two years) also supports security functions. The fr cookie (ninety days) is used for advertising. When the user is logged in to their Meta account, the c_user and xs cookies identify the account and session. The wd cookie (session) records the browser window dimensions. Beyond cookies, transaction amount, item details and device fingerprint data are transmitted to Meta.
Meta Pay involves two distinct legal bases under GDPR. Processing the payment itself relies on Article 6(1)(b) as it is necessary to fulfil the contract with the user. However the non essential Meta cookies (especially fr for advertising) and any tracking or profiling beyond the payment require separate consent under Article 6(1)(a). PSD2 adds payment security obligations that overlap with GDPR data minimisation requirements. The high risk rating reflects the combination of financial data, advertising profiling and extensive US transfers.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The payment processing itself does not require consent, but you must inform users clearly about data sharing with Meta before they choose to pay with Meta Pay. Non essential Meta cookies must be blocked until the user gives opt in consent via your cookie consent mechanism. If Meta uses transaction data for advertising profiling, that processing requires separate consent from the user in their Meta account settings, which is outside your direct control but must be disclosed in your privacy policy.
All payment, transaction and device data are processed by Meta Platforms in the United States. The transfer is covered by the EU US Data Privacy Framework and standard contractual clauses. You must disclose this transfer in your privacy policy and make it visible to users at the point they choose the Meta Pay option at checkout.
Complete a DPIA before activating Meta Pay. Block non essential Meta cookies until advertising consent is given. Add a clear disclosure near the Meta Pay button explaining data sharing with Meta in the US. Update your privacy policy to address both Article 6(1)(b) for the payment and Article 6(1)(a) for Meta advertising cookies. Ensure your PSD2 strong customer authentication flow is compatible with the GDPR data minimisation principle. Review Meta's data use policies regularly as they affect your own compliance position.
Websites using Meta Pay must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is required for Meta Pay given the high risk rating, the combination of financial data, device fingerprinting, Meta advertising cookies and US data transfers. Assess the necessity of each data element shared with Meta beyond the payment itself. Evaluate whether Meta uses transaction data for advertising profiling and document your conclusions. The PSD2 dimension adds regulatory complexity that must be addressed alongside GDPR in the DPIA. Complete the DPIA before activating Meta Pay.
Sample consent text
I consent to Meta Pay processing my payment details and device information for the purpose of completing my purchase. I understand that transaction data will be sent to Meta Platforms in the United States under standard contractual clauses. I separately consent to Meta cookies being placed on my device for security and advertising purposes and can withdraw this consent at any time.
Third-party domains contacted
facebook.comwww.facebook.comconnect.facebook.netsecure.facebook.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| datr | Functional | 2 years | Meta browser identifier used for security, fraud prevention and ensuring the integrity of the Meta Pay session |
| fr | Marketing | 90 days | Meta primary advertising cookie used for ad targeting, measurement and frequency capping across Meta products |
| sb | Functional | 2 years | Meta browser security cookie used alongside datr to protect against cross site request forgery and account hijacking |
| c_user | Functional | Session | Identifies the logged in Meta account when the user authenticates via Meta Pay |
| wd | Functional | Session | Records the browser window dimensions used by Meta for rendering and product optimisation |
Meta Pay uses cookies for user preferences — inform visitors with a consent banner.
Meta Pay sets several cookies. datr (two years) identifies the browser for Meta security purposes and fraud prevention. sb (two years) also supports security functions. fr (ninety days) is Meta's primary advertising cookie used for ad targeting and measurement. When a user is logged in to their Meta account, the c_user and xs cookies (session) identify the account and session. wd (session) records the browser window dimensions. The fr cookie is non essential advertising in nature and requires prior consent. datr and sb may be argued as security functional but should be disclosed.
Partially. The payment transaction itself is processed under Article 6(1)(b) GDPR (contract) and does not require consent, but the user must be clearly informed about data sharing with Meta before choosing Meta Pay at checkout. The non essential Meta cookies (particularly fr for advertising) require prior opt in consent under the ePrivacy Directive. You must not place advertising Meta cookies until cookie consent is given, even if the user is actively completing a payment.
Two legal bases apply. The payment processing and transaction data rely on Article 6(1)(b) GDPR as processing necessary to perform the contract (the purchase) that the user initiates. The Meta advertising cookies (fr) and any profiling or targeting beyond the payment rely on Article 6(1)(a) GDPR consent. PSD2 adds payment security requirements that must be met alongside GDPR data minimisation. Both bases must be documented and disclosed in your privacy policy.
Yes. All payment, transaction and device data are processed by Meta Platforms Inc. in the United States. The transfer is covered by the EU US Data Privacy Framework and standard contractual clauses. You must disclose this transfer in your privacy policy, ideally in a specific section about Meta Pay, and make it visible to users at checkout before they select Meta Pay as their payment method.
Yes, a DPIA is required for Meta Pay given the high risk rating. The combination of payment and financial data, device fingerprinting, Meta advertising cookies and US transfers creates significant privacy risks. The DPIA must assess what data Meta receives beyond the payment itself, whether Meta uses transaction data for advertising profiling, how PSD2 strong authentication interacts with GDPR data minimisation, and what rights users have over their data at Meta. Complete the DPIA and obtain legal sign off before going live.
Complete a DPIA before activating Meta Pay. Block non essential Meta cookies (especially fr) until advertising consent is given via your consent management platform. Add a clear disclosure near the Meta Pay button at checkout informing users that payment and device data are shared with Meta Platforms in the US. Update your privacy policy to address Article 6(1)(b) for payment and Article 6(1)(a) for Meta advertising cookies, and describe US transfers under the EU US Data Privacy Framework. Ensure your PSD2 strong authentication flow collects only data strictly necessary for security.
Yes. Payment methods that do not involve sharing transaction data with an advertising network include Stripe (US based but focused on payment only with no advertising use of transaction data), PayPal (US based, similar transfer issue but no advertising profiling of transaction data by default) and EU based options like Klarna or Adyen. If avoiding US transfers is paramount, look for EU regulated payment processors. None of these alternatives combine payment with the social login and advertising profiling that Meta Pay introduces.
Add a Meta Pay section to your cookie policy. List the main cookies: datr (security, two years, Meta), sb (security, two years, Meta), fr (advertising, ninety days, Meta), c_user and xs (account identification, session, Meta when logged in) and wd (functional, session, Meta). Categorise fr as an advertising cookie requiring consent. Categorise datr and sb as security functional. Link each to your consent categories in your consent management platform. Explain that some Meta cookies are only set when the user is logged into their Meta account.