Is Your Website Tracking Legal?

Summary
Website tracking is legal when the tags on your site collect and share data the way the law and your own consent banner say they do. It becomes illegal when a tag fires before a visitor agrees, ignores an opt-out, or sends personal or health data to a third party without a lawful basis.
Most tracking problems are not a decision anyone made. A marketing pixel gets added for a campaign, a tag manager update re-enables something that was blocked, or a script loads before the consent banner has an answer. The tracking looks fine on the surface and breaks the rules underneath. This guide explains which laws apply to analytics and marketing tags, what actually triggers a violation, and how to check your own site.
The page also gives quick answers for specific platforms, and explains whether a consent banner makes your tracking legal. Start with the market you operate in, because the rules differ by region.
What makes website tracking illegal?
A tag is not illegal because it exists. It becomes a legal problem when it does one of a few specific things.

It fires before consent. In the EU, storing or reading information on a visitor’s device needs consent first unless it’s strictly necessary. In California and most US states with privacy laws, advertising use of personal data is opt-out instead, so there the problem is a tag that ignores an opt-out.
It ignores an opt-out. When a visitor declines, or their browser sends an opt-out signal, tags that keep firing turn a consent banner into a display that does nothing.
It shares personal data with a third party. Analytics and advertising tags routinely send data to platforms like Google, Meta, TikTok, and LinkedIn. When that data identifies a person, or reveals something sensitive such as a health condition, sharing it without consent or a contract in place is the basis of many enforcement actions and class actions (see Enforcement Watch).
It captures more than anyone intended. A pixel placed on a checkout, a registration form, or a health intake page can pick up an email address, a diagnosis, or a payment detail from fields it was never meant to read.
PII here means personally identifiable information: names, email addresses, phone numbers, device identifiers, or anything else that can single out a person. PHI is protected health information, the health-specific data that HIPAA covers.
Which laws apply to your tracking tags?
Five laws cover most of what a US marketing or analytics team needs to worry about. Each one is explained in full on its own page. Here is what each one asks of your tags.
California Invasion of Privacy Act (CIPA).
A state wiretapping law from the 1960s that plaintiffs now apply to session replay, chat widgets, and tracking pixels. The theory is that a tracker recording a visitor without consent is an unauthorized interception. CIPA does not require a plaintiff to show financial loss, but the interception must be willful or intentional.
Read the CIPA explainer.Video Privacy Protection Act (VPPA).
A federal law that restricts sharing a person’s video-viewing history tied to their identity. If your site has video and a Meta Pixel or similar tag sends the video watched along with an identifier, VPPA is the exposure.
Read the VPPA explainer.California Consumer Privacy Act and CPRA (CCPA/CPRA).
California’s consumer privacy law treats passing personal data to advertising platforms through tags as a “sale” or “share,” which triggers opt-out rights, a duty to honor the Global Privacy Control signal (since 2023), and, since January 2026, a duty to let visitors confirm their opt-out was processed.
Read the CCPA/CPRA explainer.General Data Protection Regulation (GDPR).
The EU privacy law. It reaches companies outside the EU when they offer goods or services to people in the EU or monitor their behavior there, and tracking people online counts as monitoring. Under GDPR a tag may not process personal data without a lawful basis, and for cookies and similar tracking the EU cookie rule requires consent first.
Read the GDPR-for-tags explainer.HIPAA.
The US health privacy law. It applies when a covered entity or its business associate puts a tracking tag on a patient portal, an appointment scheduler, or any page that reveals a person’s health information, and that tag discloses the data to a third party without the patient’s authorization. Without authorization, that disclosure needs a signed business associate agreement and a permission under the HIPAA Privacy Rule. Outside HIPAA, the FTC’s Health Breach Notification Rule covers health apps and similar services, and Washington’s My Health My Data Act requires authorization before consumer health data is sold. For tracking pixels specifically, see HIPAA and tracking pixels.
Read: is Google Analytics HIPAA compliant?FERPA and COPPA.
The two US laws for student and children’s data. FERPA covers student education records at funded schools, and COPPA covers personal information collected online from children under 13, counting cookies and device identifiers as personal information.
Read the FERPA and COPPA explainer.GLBA.
The US law for financial institutions. It limits how they share a customer’s nonpublic personal information, and pixel lawsuits against financial sites run on wiretap laws like CIPA.
Read the GLBA explainer.Two more signals sit alongside these laws and come up on almost every page. Global Privacy Control (GPC) is a browser setting that broadcasts an opt-out, which 12 US states require businesses to act on: nine directly, including California, Colorado, Connecticut and Oregon, and three, including Texas, through a browser setting that acts as the consumer’s authorized agent. Google Consent Mode is the mechanism Google uses to adjust how its tags behave based on consent. Both have their own explainers. Global Privacy Control · Google Consent Mode v2
Which market are you in?
Which privacy rules apply to your tracking depends on where your visitors are, so we keep a compliance hub for each primary market. Each one covers the laws that apply there and links to the enforcement actions regulators and courts have brought.
United States
CIPA, VPPA, CCPA/CPRA, and the state privacy laws.
European Union
GDPR and the ePrivacy cookie rules.
United Kingdom
UK GDPR and PECR.
Canada
Quebec Law 25 and PIPEDA.
Australia
the Privacy Act and the Australian Privacy Principles.
Does a consent banner make my tracking legal?
Not on its own. A consent management platform, or CMP, shows visitors their choices and records what they pick. It does not physically stop a tag from firing. Tags that were hardcoded onto a page, added outside the tag manager, or piggybacked by another script can run regardless of what the banner recorded.
This is a common way a compliant-looking site turns out not to be compliant. The banner displays the right options, the visitor opts out, and a back-end tag keeps sending data anyway. Enforcement actions have repeatedly involved companies that had a banner in place. Enforcement Watch: consent banner enforcement cases.
A banner is a promise. Whether your tags keep it is a separate question, and it is one you have to test.
Is a specific platform compliant? Quick answers
Short answers to the pairings we get asked about most. Each links to a fuller treatment where one exists.
Is Google Analytics HIPAA compliant?
No. Google does not sign a business associate agreement for Google Analytics, so using it on pages that handle protected health information is not compliant.
Full answer.Is Google Analytics GDPR compliant?
It can be, but only with consent collected before the tags fire and the current data-transfer safeguards in place. Several EU regulators have ruled specific Google Analytics setups unlawful over data transfers.
Full answer.Does the Meta Pixel violate CIPA?
Not automatically. The exposure comes when the pixel fires without prior consent and captures data a court could treat as an intercepted communication. Consent before firing and controlling what the pixel reads are what reduce the risk.
Full answer.Does the Meta Pixel violate VPPA?
It can, on a site with video, when the pixel sends the video watched together with a Facebook identifier and the viewer has not agreed.
Full answer.Is the Meta Pixel legal?
Yes, as a tool. Whether your specific deployment is legal depends on consent, what data it collects, and where that data goes.
Full answer.How do you know if your website tracking is legal?
You check what your tags actually do, in each consent state, on the pages that matter. That means confirming three things: that nothing fires before a visitor consents, that tags stop when a visitor opts out or sends a GPC signal, and that no tag is sending personal or health data it should not.
This is what DataTrue is built to verify. We run your site the way a real visitor would, in a real browser, in each consent state, and record exactly what every tag sent and when. A Coverage test crawls the whole site and reports what is tagged on every page, including tags added outside your tag manager. A Simulation test walks a specific journey, a checkout or a registration, step by step, and checks what each tag transmitted at each step. Sensitive Data Detection watches those payloads for personal and health data using fictitious personas, so we can test for a leak without ever putting a real customer’s data at risk. GPC is tested by loading your site with a GPC signal switched on and confirming the tags that should stop actually stop.
The result is a timestamped record of what fired, what it sent, and under which consent state. That is the evidence a privacy or legal team needs to show a regulator, and the earliest warning a marketing team gets when a tag starts doing something it should not.
Questions
Is website tracking illegal?
No. Tracking is legal when your tags collect and share data the way your consent banner and the applicable law require. It becomes a violation when a tag fires before consent, ignores an opt-out, or sends personal or health data to a third party without a lawful basis.
Can I get sued for having a tracking pixel?
The pixel itself is not the problem. Class actions under laws like CIPA and VPPA target pixels that fire without prior consent or that share identifiable data, especially on pages involving health, video, or sensitive actions. Confirming your tags wait for consent is the practical defense.
Does having a cookie consent banner mean I am compliant?
No. A banner records choices but does not enforce them. Tags added outside your tag manager, hardcoded onto a page, or loaded by another script can fire regardless of what a visitor chose. Compliance depends on whether your tags honor the banner, which has to be tested.
Do I have to honor Global Privacy Control?
In a growing number of states, yes. Nine states directly require businesses to honor a browser opt-out signal such as GPC, including California, Colorado, Connecticut, and Oregon. Three more, including Texas, accept it through a browser setting that acts as the consumer’s authorized agent. That makes 12.
How do I check whether my own tracking is legal?
Test what your tags do in each consent state on your key pages. Confirm nothing fires before consent, that tags stop on opt-out and on a GPC signal, and that no tag is transmitting personal or health data it should not. DataTrue automates this and produces a timestamped audit trail of the results. It gives teams tools to help them become and stay compliant, and does not certify compliance.
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
