Back to Blog

Retargeting Pixels and Consent: GDPR & CCPA

A retargeting pixel drops an advertising identifier the moment it fires, which is exactly what privacy law regulates. Here is how to fire pixels the compliant way under GDPR, ePrivacy, and CCPA.

Karan Bhakuni
Karan Bhakuni
Founder, Flyn
SecurityJul 1, 202612 min readUpdated Jul 1, 2026
Retargeting Pixels and Consent: GDPR & CCPA

Why a retargeting pixel is a privacy-law event

The moment a retargeting pixel fires, it drops an advertising cookie or a device identifier and tells an ad network "this exact person was here." That is not a neutral analytics ping. It is the precise activity that GDPR, the ePrivacy Directive, and CCPA were written to govern. If you attach a pixel to a short link and think the redirect somehow sits outside privacy law, you are mistaken: the identifier gets set on the visitor's browser either way, and the law follows the visitor.

What the pixel actually does to the visitor

A pixel is a tiny piece of code that, when loaded, writes an identifier the ad platform can later match to a user profile. That identifier is personal data under GDPR because it can single out an individual across sites. It is a cookie or cookie-equivalent under ePrivacy. And it counts as a "sale" or "share" of personal information under CPRA when you pass it to an ad network for cross-context behavioral advertising. One line of code, three separate legal hooks.

Fires on the redirect, still counts

With Flyn retargeting pixels, the pixel fires on the interstitial served from the flyn.to domain before forwarding to the destination. That is genuinely useful because it lets you retarget on links you do not own. But it does not change your compliance duties. You are still the party choosing to set an advertising identifier on that visitor, so you are still on the hook for a lawful basis and, in the EU and UK, for consent.

Which laws apply, and what each one wants

Three regimes cover most of the traffic you will ever pixel. They overlap but they are not the same, and the biggest split is opt-in versus opt-out. Get that split wrong and you are non-compliant in one whole hemisphere of your audience.

Three columns comparing GDPR for EU and UK opt-in, ePrivacy governing the cookie in EU and UK, and CCPA CPRA for California opt-out with a Do Not Sell or Share link
GDPR governs the data, ePrivacy governs the cookie, CCPA and CPRA govern the sale or share. Different mechanics, same pixel.

GDPR: the data-protection layer

GDPR (EU) and UK GDPR require a lawful basis to process the personal data a pixel generates. For cross-site advertising, that basis is consent in practice, because legitimate interest is very hard to defend for behavioral ad tracking. GDPR also gives people rights of access and erasure, which is why you keep records of who consented and when.

The ePrivacy Directive (the "cookie law") sits on top and governs the act of storing or reading anything on the visitor's device. It requires prior consent for any non-essential cookie or identifier, and a retargeting pixel is the textbook non-essential case. This is the rule that literally forces the pixel to wait for the click.

CCPA and CPRA: the opt-out layer

California flips the model. Under CCPA as amended by CPRA you may fire the pixel by default, but passing identifiers to an ad network counts as a "sale" or "share," so you must give consumers a clear way to opt out. That is the Do Not Sell or Share My Personal Information link, and you must honor the Global Privacy Control signal too.

Side-by-side comparison

DimensionGDPR (EU/UK)ePrivacy (EU/UK)CCPA/CPRA (California)
Default stanceNo processing without lawful basisNo cookie without prior consentAllowed until the user opts out
Consent modelOpt-inOpt-inOpt-out
When the pixel may fireAfter consentAfter consentImmediately, unless opted out
Required user controlWithdraw consent, erase dataRefuse or revoke the cookieDo Not Sell or Share link, honor GPC
Who it protectsPeople in the EU/UKPeople in the EU/UKCalifornia residents

Pixeling on a redirect vs on your own site

People assume that firing a pixel from a short-link redirect is a loophole. It is not. The obligations are identical; only the mechanics of where you place the consent check differ. Understanding that difference keeps you honest.

On your own site: banner sits in front of the page

When the pixel lives on a page you control, your consent manager loads first, holds the pixel, and releases it on accept. This is the standard pattern and the tooling is mature. Your UTM parameters and analytics can coexist with it as long as advertising pixels stay gated.

On a redirect: the interstitial is the moment

With Flyn, the pixel fires on the fast interstitial before forwarding. That is powerful for retargeting affiliate clicks because you never touch the merchant's page. But because you are the one setting the identifier, you still owe EU and UK visitors a consent path. In practice that means directing consented traffic to your pixel-attached short links and keeping a plain, un-pixeled link available where you cannot establish consent.

Watch out

A short-link redirect does not anonymize anything or move the liability to the destination. If you attach a Meta or TikTok pixel to a link and blast it at EU users with no consent mechanism anywhere in the funnel, you are the controller who set the cookie, and you carry the ePrivacy and GDPR exposure. The redirect changes the plumbing, not the law.

The affiliate and sponsor case

Retargeting a merchant or sponsor link is the most common redirect use case, and it is also where people get sloppy about consent because "it is not my site." Read retargeting links you do not own and the affiliate link tracking guide together: the tracking is yours, so the consent duty is yours.

The five-point compliance checklist

You do not need a law degree to get the basics right. You need a short, honest checklist that you actually run before a campaign goes live. Here is the one we use as a starting point.

Five-point compliance checklist: consent banner before pixels, opt-out honored, privacy policy lists ad cookies, only pixel lawful traffic, keep consent records
Five checks that cover the vast majority of retargeting-pixel compliance work.

The five checks

  1. Consent banner loads before any pixel for EU and UK visitors, and holds the pixel until they accept.
  2. Opt-out is honored for California, with a visible Do Not Sell or Share link and Global Privacy Control support.
  3. Your privacy policy names the ad cookies and platforms you use, so disclosure is specific, not generic.
  4. You only pixel lawful, consented traffic, and keep a clean un-pixeled path for everyone else.
  5. You keep consent records (who, when, what they agreed to) so you can prove it if asked.

Where the platforms fit

All thirteen supported platforms follow the same checklist. Whether you are running TikTok, Pinterest, Reddit, or Facebook campaigns, the pixel is the same kind of advertising identifier and the same five checks apply. The platform-specific setup lives in the Meta guide and the TikTok guide.

Enforcement reality: what actually happens

It is easy to treat privacy law as theoretical until a fine lands. The enforcement picture is uneven but real, and the trend is toward more scrutiny of ad tracking specifically, not less. Here is the measured version.

The EU has teeth

GDPR fines can reach the higher of 20 million euros or 4 percent of global annual turnover. In practice, most retargeting-related penalties are far smaller, but data protection authorities have repeatedly gone after cookie banners that fire trackers before consent or make rejection harder than acceptance. The pattern of enforcement targets exactly the shortcuts this guide tells you to avoid.

California enforces through opt-out failures

CCPA and CPRA enforcement has centered on businesses that ignored opt-out requests or failed to honor the Global Privacy Control signal. Statutory penalties run per violation, and "per violation" can multiply fast across an audience. The California Privacy Protection Agency has signaled that ad-tech sharing is a priority.

The realistic risk for a small operator

If you are a solo marketer or small team, your practical risk is less a headline fine and more a platform problem: ad networks can suspend accounts for compliance issues, and a complaint can trigger a review you do not want. Getting the consent gate right also keeps your pixel data clean, which is the point of building an audience with rotated or QR-driven campaigns in the first place. Compliance and data quality pull in the same direction.

Frequently Asked Questions

Do retargeting pixels really fall under GDPR?
Yes. A retargeting pixel sets an advertising cookie or device identifier that can single out an individual across sites, which makes it personal data under GDPR. The pixel also stores something on the visitor's device, triggering the ePrivacy Directive. Together they require a lawful basis and, for behavioral advertising, prior opt-in consent from EU and UK visitors. This is true whether you hard-code the pixel on your own page or attach it to a short link that fires on the redirect. The identifier lands on the browser either way, so the obligation is the same.
When exactly is a retargeting pixel allowed to fire under EU law?
Only after the visitor gives valid opt-in consent. Under the ePrivacy Directive, a non-essential cookie or identifier cannot be set until the user actively agrees, and a retargeting pixel is a textbook non-essential tracker. So the correct order is: show the consent banner, wait for a genuine "Accept," then load the pixel. If your pixel is already in the page and the banner merely hides on click, the cookie was set before consent and you have breached the rule. A compliant consent manager holds the pixel until acceptance and re-checks on every visit.
How is CCPA different from GDPR for retargeting?
The core difference is opt-in versus opt-out. GDPR and ePrivacy require you to get consent before firing the pixel for EU and UK visitors. CCPA and CPRA in California let you fire the pixel by default, but because passing identifiers to an ad network counts as a "sale" or "share," you must offer a clear Do Not Sell or Share My Personal Information link and honor it, along with the Global Privacy Control browser signal. So EU visitors get a gate before tracking, while California residents get tracking by default plus an easy way to switch it off.
Does firing a pixel on a redirect avoid consent requirements?
No. Firing on a short-link redirect is a genuine capability that lets you retarget links you do not own, but it does not move the legal liability. You are the party choosing to set an advertising identifier on the visitor, so you are the controller under GDPR and the one responsible under ePrivacy. The redirect changes where the pixel fires, not who is accountable. You still need a consent path for EU and UK visitors and an opt-out for California, exactly as you would if the pixel sat on your own page.
What makes a consent banner actually compliant?
Three things. First, it must block every non-essential pixel from loading until the visitor accepts, not just hide itself on click. Second, "Reject all" must be as easy and prominent as "Accept all" on the first layer, since regulators have fined sites for making refusal harder. Third, consent must be granular and revocable, so people can accept some categories and reject others and change their mind later. When someone withdraws, your tool must stop the pixel on the next request. A banner that fails any of these is decoration sitting on top of tracking that already happened.
Can I use legitimate interest instead of consent for retargeting?
In practice, no, not for cross-site behavioral advertising. GDPR does allow legitimate interest as a lawful basis for some processing, but retargeting is intrusive, involves profiling, and is difficult to justify against a visitor's reasonable expectations. European guidance and enforcement have consistently pointed to consent as the appropriate basis for advertising cookies and pixels. Combine that with the ePrivacy requirement for prior consent to set the cookie at all, and consent becomes the practical route. Relying on legitimate interest for a Meta or TikTok pixel is a bet most privacy professionals would not take.
What is the Do Not Sell or Share link and do I need one?
It is a clearly labeled link, usually in your footer, that lets California residents opt out of having their personal information sold or shared for cross-context behavioral advertising. Under CPRA, sending pixel identifiers to an ad network counts as a share, so if you retarget California traffic you need this link and you must honor the request. You also need to respect the Global Privacy Control signal, which browsers and extensions send automatically. The link should work without forcing the user to create an account or jump through hoops, and the opt-out should take effect promptly.
Do I have to name the ad platforms in my privacy policy?
Yes, specificity matters. Both GDPR and CCPA expect disclosure that is concrete, not a vague "we may use cookies" line. Your privacy policy should name the advertising platforms whose pixels you fire, for example Meta, Google Ads, TikTok, LinkedIn, or Pinterest, describe what data they collect, and explain the purpose (retargeting and measurement). It should also tell people how to withdraw consent or opt out. Naming the platforms lets visitors make an informed choice, which is a core requirement of valid consent, and it makes your disclosures far easier to defend if questioned.
How long should I keep consent records?
Keep them for as long as you rely on that consent, plus a reasonable buffer to demonstrate compliance if a regulator or user asks. GDPR requires you to be able to prove that a person consented, so store who consented, when, what they were shown, and what they agreed to. Most consent management platforms log this automatically. There is no single mandated retention period, but deleting records the moment consent is given defeats the purpose. A common approach is to retain the consent log for the life of the relationship and for a period afterward consistent with your broader data-retention policy.
Are the penalties for getting this wrong actually enforced?
Yes, though unevenly. GDPR fines can reach 20 million euros or 4 percent of global turnover, and EU authorities have repeatedly penalized cookie banners that fire trackers before consent or bury the reject option. In California, enforcement has focused on businesses that ignored opt-out requests or failed to honor the Global Privacy Control. For a small operator the more immediate risk is often an ad platform suspending your account over a compliance complaint. Either way, the shortcuts that draw enforcement are exactly the ones a proper consent gate prevents, so getting it right is cheap insurance.
Does this apply if I only retarget affiliate or sponsor links?
Yes. Retargeting a merchant or sponsor link through a redirect is one of the most common uses, and it is where people wrongly assume the rules do not apply because "it is not my site." The tracking is yours: you chose to attach the pixel and set the identifier, so the consent duty is yours. Read retargeting affiliate link clicks alongside your compliance setup. You still owe EU and UK visitors a consent path and California residents an opt-out, regardless of who owns the destination page the visitor eventually lands on.
Is this article legal advice I can rely on?
No. This is general information to help you understand how retargeting pixels and consent intersect with GDPR, ePrivacy, and CCPA. It is not legal advice, and it cannot account for your specific jurisdiction, audience, data flows, or the way these laws keep evolving. Use the compliance checklist and the pixel documentation as a starting point, review your own obligations under GDPR and applicable US law, and consult a qualified privacy professional or lawyer before you rely on any particular setup for a real campaign at scale.

Ready to try Flyn?

Free plan includes 25 links/month, full analytics, and access to all 30+ free tools above. No credit card required.

Already a member? Log in

Karan Bhakuni
Karan Bhakuni· Founder, Flyn

Karan Bhakuni is the founder of Flyn. He writes about branded links, click analytics, and the link-management tooling growth teams and creators actually need, drawn from building Flyn and reading a lot of user feedback.