Back to the blog
Guide

How to block the Meta Pixel until visitors consent

Facebook icon next to a shield that blocks its data

The Meta Pixel (still often called the Facebook Pixel) is one of the most common marketing scripts on small business websites, and one of the most common to run before visitors have agreed to anything. Here is what it does, which cookies it sets and how to block it until consent.

What does the Meta Pixel do?

The Pixel is a piece of JavaScript from Meta. Once it is on your website, it does three things:

  • Tracks visitors: which pages they view and what they do there
  • Enables remarketing: lets you show ads on Facebook and Instagram to people who have visited your site
  • Measures conversions: reports purchases and sign-ups back to Meta Ads

All of this relies on cookies and on sending data about your visitors to Meta, which is why it needs consent.

Which cookies does the Pixel set?

CookiePurpose
_fbpA unique identifier for the browser, set on your domain the first time the Pixel runs
_fbcThe click ID from a Meta ad (the fbclid parameter in the link). Meta documents a 90-day expiry

Both belong in the marketing category. A cookie scan of your site shows the exact lifetimes they have there, along with any cookies Meta sets on its own domains.

Why block it?

  1. The law requires it: under Article 5(3) of the ePrivacy Directive, cookies that are not strictly necessary need consent before they are set. The Pixel sets its cookie as soon as it loads, so without blocking it runs before the visitor has had a chance to choose.
  2. Regulators look for it: European data protection authorities have stated that by default, no cookies that require consent can be set without it. A marketing script that loads before the banner is answered is easy to spot with a browser's developer tools.
  3. Data leaves your site: the Pixel sends information about your visitors to Meta, which you have to be able to justify under the GDPR.

How to block the Meta Pixel with Consentaur

With the Consentaur script installed first in your <head> (see the installation guide), it takes one attribute. Find your Pixel code and add data-cookiebar-category="marketing":

Before (runs without consent)

<!-- Meta Pixel: runs straight away, without consent -->
<script>
  !function(f,b,e,v,n,t,s)
  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?
  n.callMethod.apply(n,arguments):n.queue.push(arguments)};
  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';
  n.queue=[];t=b.createElement(e);t.async=!0;
  t.src=v;s=b.getElementsByTagName(e)[0];
  s.parentNode.insertBefore(t,s)}(window, document,'script',
  'https://connect.facebook.net/en_US/fbevents.js');
  fbq('init', 'YOUR_PIXEL_ID');
  fbq('track', 'PageView');
</script>

After (waits for consent)

<!-- Meta Pixel: blocked until marketing consent -->
<script data-cookiebar-category="marketing">
  !function(f,b,e,v,n,t,s)
  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?
  n.callMethod.apply(n,arguments):n.queue.push(arguments)};
  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';
  n.queue=[];t=b.createElement(e);t.async=!0;
  t.src=v;s=b.getElementsByTagName(e)[0];
  s.parentNode.insertBefore(t,s)}(window, document,'script',
  'https://connect.facebook.net/en_US/fbevents.js');
  fbq('init', 'YOUR_PIXEL_ID');
  fbq('track', 'PageView');
</script>

That is all. Consentaur stops the script from running until the visitor accepts marketing cookies, then runs it straight away.

What if the Pixel runs through Google Tag Manager?

You have two options:

  • Tag the whole GTM container: add data-cookiebar-category="marketing" to the GTM script. Simple, but it holds back every tag in the container, not just the Pixel.
  • Use Consent Mode in GTM: Consentaur sends Google Consent Mode signals that GTM can use to decide which tags fire. Set the Pixel tag to require ad_storage to be granted. More precise, but it needs setting up in GTM.

How to check that it works

  1. Open your website in a private or incognito window
  2. Open the developer tools (F12) and go to the Network tab
  3. Filter on "facebook": there should be no requests
  4. Click "Reject all" in the cookie banner: there should still be no requests to Meta
  5. Open a new private window, load the page again and click "Accept all": now you should see requests to connect.facebook.net
  6. Under Application → Cookies, check that _fbp only appears after you accepted

Frequently asked questions

Will I lose data if I block the Meta Pixel?

You lose data from visitors who refuse marketing cookies, which is data you were not allowed to collect in the first place. Visitors who accept are tracked as before.

What about the Meta Conversions API?

The Conversions API sends events from your server instead of the browser. It does not remove the need for consent: it usually relies on the _fbp and _fbc values from the visitor's browser, and sharing visitor data with Meta for advertising still needs a legal basis under the GDPR. Use it for visitors who have consented.

What happens to my Meta ad campaigns?

They keep running: you can still create ads, choose audiences and set budgets. What changes is remarketing and conversion tracking, which depend on Pixel data. Visitors who refuse cookies are not added to your remarketing audiences and their conversions are not tracked.

Can I use Meta's own consent API instead?

Meta lets you call fbq('consent', 'revoke') before initialising the Pixel and fbq('consent', 'grant') once the visitor agrees, which pauses sending Pixel events until then. Blocking the script, as described above, is simpler and means nothing from Meta loads before consent.

Hold the Meta Pixel back automatically

Consentaur blocks marketing scripts until visitors consent. Add one attribute and Consentaur handles the rest.

Start your free trial

14-day free trial. No credit card required.