Meta Says Your Pixel Sends Restricted Data? Fix It
Why does Meta say my pixel is sending restricted data?
Meta detected information in your pixel or server events that may break its Business Tools Terms, usually health or financial details in a URL, UTM tag, custom parameter or custom event name, and removed it. Fix the source, then review blocked parameters in Events Manager. Repeat notices can put the pixel into core setup for at least 90 days.
The warning means Meta’s filters caught something in your event data they think you should not be sending, and stripped it out before using the event. The data is usually not where you look first: it sits in a page URL, a query string your site generates, or the name someone gave a custom event years ago. Meta tells you which parameters and pages were affected, not what the data was, so the fix starts with reading your own URLs.
What do Meta’s restricted data warnings mean?
The warnings differ in what Meta did and what you must do. Most appear in Events Manager, and Meta may also send them by email or show them in Ads Manager (Troubleshoot prohibited information notifications).
| Warning or status | Where you see it | What Meta did | What it means for you |
|---|---|---|---|
| Event parameters blocked | Diagnostics tab | Blocked one or more parameters that may contain information against its terms | Review, fix, then unblock or keep blocking each parameter |
| Your data is restricted | Diagnostics tab | Placed the pixel or dataset into core setup after repeated notices | Custom parameters and everything in URLs after the domain stop arriving |
| Custom event blocked | Settings, Data controls, Manage event blocking | Blocked a custom event whose name or data may contain prohibited information | You cannot use the event in campaigns, custom conversions or audiences |
| Data source category restriction | Settings, Manage data source categories | Assigned your site or app to a category such as Health and wellness | Some events, or all of them, may be restricted |
| Blocked domain | Diagnostics tab | Blocked a domain or app that breaks Meta’s terms | Events sent while blocked are never usable, even after unblocking |
Sources for the table: How to troubleshoot Meta Pixel error and warning messages, How to review custom events, Understand data sharing restrictions based on data source categories, About prohibited domains and apps and Troubleshoot blocked website domains.
The first two rows are the subject here: data in your events. The category restriction is a decision about your whole site, not a fault in one parameter, and needs a category review rather than a code fix: see why can’t my health brand optimize for purchases on Meta?
What does Meta count as prohibited information?
Meta’s list covers three groups (About prohibited information). It includes:
- Identifiers and secrets: social security numbers or the local equivalent, passwords, GPS coordinates, access tokens, and public services identifiers such as Medicare or EBT information.
- Financial details: bank account, routing or card numbers, income or tax information, credit scores, loan approvals or amounts, account balances, one-time passwords and debt status.
- Health details: diseases, medical conditions and injuries, sexual and reproductive health, mental health, medical devices and trackers, procedures and testing, prescription medicines and over-the-counter products or supplements for specific medical conditions, and places of treatment.
Meta says the list is not exhaustive. It also says the names and criteria you choose for events, custom conversions and custom audiences “must not reflect, imply, or be based on any prohibited information”, so a custom event called diabetes_quiz_complete is a problem even if it carries no other data.
Where does restricted data hide in pixel events?
Meta names the places to check. Work through them on the pages the diagnostic lists:
- Page URLs and query strings. Meta warns that UTM parameters “may contain prohibited data from the landing pages viewed”, and a URL such as
/quiz/result?condition=eczemasends the condition with every PageView. - Parameter names and values. Product IDs, content names and custom properties sent with events.
- Form fields. Data a page passes into events from a form.
- Custom event names. The name itself is data.
- Logged-in areas. Meta says you shouldn’t send information about people from pages where visitors may log in and give sensitive information, such as patient portals.
You can see a summary of the pages, parameters and URLs your business tool recently sent in Events Manager, which is faster than reading the site page by page.
How do I fix blocked parameters in Events Manager?
Fix the source first, then tell Meta what to do with each blocked parameter. You need full control of the business asset. Meta’s steps (How to review blocked parameters):
- Open Events Manager and click Datasets in the left menu.
- Select the name and ID of your dataset, then click the Diagnostics tab.
- Find the message “Event parameters blocked” and click Review.
- Read the acknowledgement that you may only send data that follows the Business Tools Terms, then click I acknowledge.
- Check each parameter in the Action required tab, and change your site, tag manager or server code so it no longer sends prohibited information.
- Select a fixed parameter, click Next, choose Unblock parameter and click Confirm. You may not be able to unblock a parameter Meta blocked itself.
- Choose Keep blocking parameter for anything you cannot fix now or cannot confirm is clean. A blocked parameter cannot be used in custom conversions or custom audiences.
Meta adds one rule that matters more than the clicks: “You must not attempt to send data that has previously been detected and removed” (Troubleshoot prohibited information notifications). Unblocking a parameter without changing what it sends invites the next notice.
What happens if the warnings keep coming?
Meta says that if you receive these notifications multiple times, it may place your business tool into core setup “for at least 90 days” (How to review blocked parameters). Core setup stops custom parameters and everything in a URL after the domain: Meta’s example shortens https://jaspersmarket.com/clothes/summer/dresses?item=10 to https://jaspersmarket.com/ (About core setup).
The knock-on effects for a store:
- Website custom audiences built on URL rules or custom parameters may populate slowly, stop updating or become unavailable, which can shrink the ad sets that use them.
- Automatic advanced matching may stop working; Meta suggests setting up advanced matching manually instead.
- Catalog updates through the pixel may stop; add items another way.
- Custom events must be reviewed and confirmed before you can use them.
- Events Manager stops showing custom parameters and full URLs, including in the Test Events tool.
Standard parameters such as value, currency and content_ids are not custom, so purchase value reporting can continue under core setup.
How do I stop it happening again?
- Remove the pixel from pages where visitors give sensitive information, such as account areas, quizzes about conditions or patient portals.
- Rename custom events, conversions and audiences that describe a person’s health, finances or other sensitive traits: custom events under Settings, Data controls; custom conversions in their Events Manager tab; audiences in Ads Manager.
- Strip sensitive query strings before your tags fire, and keep UTM values to IDs and channel names.
- Consider turning on core setup yourself. Meta lists this as an option to help prevent sharing prohibited information, while warning it is no substitute for your own compliance checks.
- Add a check to your release process. The parameter list in what should I check when setting up Meta Pixel and CAPI? is the natural place for it.
If the pixel has stopped sending events altogether rather than sending restricted ones, that is a different fault: why does my Meta pixel show no recent activity? Customer lists you upload carry their own rules, covered in is uploading a customer list to Meta compliant? The other tracking guides are on the Meta Pixel and CAPI hub.
FAQ
Can I appeal a custom event Meta blocked?
Yes, once. In Events Manager, open your dataset’s Settings tab, go to Data controls, click Review under Manage event blocking, select the event in the Blocked tab, click View details and Request review. If Meta does not approve it, the event stays blocked and you cannot request another review.
Does Meta show me the data it removed?
No. Meta says the Diagnostics tab gives detailed information about what was removed, such as which parameters on which pages, but the actual data that was detected and removed is not displayed. You find it by checking those pages and parameters in your own site and tag setup.
Will core setup stop my purchase tracking?
Not by itself. Core setup restricts custom parameters and URL paths after the domain. Standard parameters, which Meta defines to include value and currency on a purchase event, are not custom parameters. Meta’s list of what may stop working starts with custom audiences that rely on URLs or custom parameters.
Is Meta responsible for filtering this data out?
No. Meta says its systems are designed to filter out prohibited information they detect, but you remain responsible for the data you share, and its systems are not a substitute for your own compliance mechanisms. For a data-sharing compliance plan, Meta points you to your own legal counsel.
Sources
Sources: Meta Business Help Center, About prohibited information, Troubleshoot Meta Business Tools prohibited information notifications, How to review blocked parameters in Meta Events Manager, About core setup, How to troubleshoot Meta Pixel error and warning messages, How to review custom events in Meta Events Manager, Understand data sharing restrictions based on data source categories, About prohibited domains and apps and Troubleshoot blocked website domains (checked 2 Oct 2026).