Does the Meta Pixel Violate the VPPA?

Summary
VerdictIt depends.
It can, on a site with video. The Meta Pixel creates Video Privacy Protection Act (VPPA) exposure when a video page’s pixel sends what the visitor watched together with a Facebook identifier, without consent. The pixel is not a violation by itself. Whether a given claim succeeds is currently unsettled in the courts.
The VPPA is a 1988 federal law that restricts sharing a person’s video-viewing history tied to their identity. A pixel on a video page can transmit exactly that: the video’s title or URL and the Facebook ID that identifies the viewer.
The sections below explain how the exposure works and why the answer is currently unsettled. They finish with how to check your video pages and how to reduce the exposure.
How the exposure works
The Meta Pixel is a snippet that reports activity from your site back to Meta for advertising. On a page with video, it can include the page or video URL and, from a cookie, the visitor’s Facebook ID. Sent together, those two pieces can reveal that an identifiable person watched a specific video. That is the disclosure the VPPA restricts, and it is the theory behind the wave of pixel VPPA class actions.

Three conditions have to line up: the page has video, the pixel captures what was watched, and an identifier goes with it. Remove any one and the VPPA pattern is not present.
Why the answer is currently unsettled
Courts disagree, so the honest answer is that it depends on where a case is filed and how the facts fall. The Second Circuit held in 2025 (Solomon v. Flipps Media) that video URLs and a Facebook ID sent in code were not personally identifiable information, because an ordinary person could not use them to identify what someone watched. The First Circuit applies a broader test. The Supreme Court agreed in January 2026, in Salazar v. Paramount Global, to decide part of the dispute: who counts as a “consumer” under the law. It hears argument on October 14, 2026, and a decision is expected by mid-2027. Until then, identical pixel behavior can be treated differently in different places.
The practical takeaway does not wait on the Court. The exposure is a payload you can see and control, so the sensible move is to know whether your video pages are sending it.
For specific Meta Pixel VPPA lawsuits and settlements, see our Enforcement Watch tracker.
How to check your video pages
The question that matters for your site is concrete: on pages that play video, is a pixel sending what was watched together with an identifier, and does it fire before consent?
DataTrue answers it by loading your video pages in a real browser and recording what each tag transmits. You can see whether the Meta Pixel is sending a video title or URL alongside a Facebook identifier, and whether it fires before the visitor agrees. Sensitive Data Detection inspects the payloads with fictitious personas, so the check never uses a real visitor. The output is a list of which video pages carry the VPPA pattern.
How to reduce the exposure
Get consent before the pixel fires on video pages. Consent is the VPPA’s clearest exception, and it has to be informed, written consent in a separate form, which a general cookie banner click has not been shown to meet. And limit what the pixel collects on those pages, so it is not sending the video watched. Confirm both with testing rather than assuming, because the exposure lives in the actual payload.
Questions
Does the Meta Pixel violate the VPPA?
It can, on a site with video, when it sends what a visitor watched together with a Facebook identifier and the visitor has not consented. The pixel is not a violation on its own. The exposure is that specific pairing sent from a video page without agreement, and whether a claim succeeds is currently unsettled in the courts.
What data does the pixel send that triggers VPPA claims?
The theory is that the pixel sends the video’s title or URL along with the visitor’s Facebook ID from a cookie. Together those can identify a person as having watched specific video, which is what the VPPA restricts.
Does this apply if my site is not a streaming service?
Potentially yes. Any site that shows video and sends viewing data with an identifier could face the same theory, including sites with embedded clips or demo libraries.
How do I stop the Meta Pixel from creating VPPA exposure?
Get informed, written consent in a separate form before it fires on video pages, limit what it collects there so it is not sending the video watched, and verify with testing that neither the video title nor an identifier is leaving before consent.
Related guides
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
