Meta put my dataset in core setup: what still works?
On this page
Most of your campaigns still work. Meta says that under core setup "most campaigns should continue to run as expected". Standard events and standard parameters, such as value and currency on a purchase, keep flowing unless a separate standard-event restriction also applies. What stops is every custom parameter and every part of a URL after the domain. That breaks custom audiences built on URL or parameter rules, can switch off automatic advanced matching, and blocks custom events until you review and confirm them.
Curve Compliance helps you get what your site sends to Meta right. Curve's team reviews it with you and shows which URLs and parameters are likely triggering the flag, then rebuilds your conversion tracking so it is HIPAA-compliant and keeps your campaigns optimizing. PHI-like patterns are detected before data reaches Meta, and a BAA is signed on every plan. Book a call with Curve.
What core setup removes
Meta's definition is short: "Core setup restricts the transmission of custom parameters and anything in a URL following the domain."
Custom parameters are anything not on Meta's list of standard parameters. Value, currency and content_id are standard. A field your developer added, such as a service line, a quiz answer or an intake step, is custom.
URLs are cut back to the domain. In Meta's own example, https://jaspersmarket.com/clothes/summer/dresses?item=10 "would be shortened to" https://jaspersmarket.com/. On a clinic site, a page path that names a treatment, and a query string carrying UTM values, both arrive as the bare domain.
What changes, and what to do about each
- Custom audiences. Audiences that "rely on custom parameters or URLs in their rules can't be prefilled and may take longer to populate or not be available". Audiences that combine device rules or aggregation values with custom parameters or URLs "can't be created and won't update". Rebuild them on standard events. The custom audiences checklist covers what those audiences may contain.
- Ad sets that use those audiences. They may shrink or stop updating. Meta's advice is to update the custom audience or create a new one for the ad set.
- Automatic advanced matching. Meta says it "may be unavailable" and that "you can set up advanced matching manually instead". Treat that as a compliance decision for your team, not a performance fix, and follow Meta's hashing rules if you use it.
- Events Manager views. Custom parameters and URL paths disappear from Sampled activities and the test events tool. That is expected and does not mean the pixel is broken.
- Catalog updates. Adding items to a catalog through the pixel may stop working. Meta says you can add them manually.
- Custom events. Meta says they "need to be reviewed". Confirm only the ones whose names and parameters carry no prohibited information. See why Meta blocked your custom events.
Why your dataset is in core setup
Meta lists four reasons, and the next step depends on which one applies:
- Meta placed the data source in a category that requires core setup, such as Health and wellness. If the category is wrong, see how to request a category review. If it is right, core setup is the tier you plan around. What Meta restricts for health and wellness data sources explains the other tiers.
- Someone on your account assigned the dataset to a restricted category. Meta says self-assigned categories may be updated in Events Manager without a review. Change it only if it is genuinely wrong.
- You "received multiple notifications that data you're sharing potentially goes against the Meta Business Tools Terms". This is the one you cause and can fix. For blocked parameters, Meta says repeat notices can put you in core setup "for at least 90 days".
- You turned core setup on yourself in Events Manager. Meta offers it as a safeguard against sending prohibited information.
What to fix first
Do not put the same information back into a standard parameter or a new event name. Meta says prohibited information "should not be shared in Meta Business Tools data such as URL parameters, custom audiences, custom conversions, custom event names, and custom data."
- In Events Manager, open the dataset's Settings and check Manage data source categories to see whether a category is involved.
- Open the Diagnostics tab and read every prohibited information message and every "Event parameters blocked" message.
- Fix the source. Take condition and treatment names out of URL paths, query strings and UTM values, and out of parameter names and values. See what to do when Meta removes potentially prohibited information.
- Review custom events. Confirm the clean ones and block the rest.
- Rebuild custom audiences that depended on URL or custom-parameter rules, using standard events.
- Keep measuring bookings and purchases in your own reporting, so you can see whether performance really moved.
Talk to Curve
Core setup is a signal to look closely at what your site sends before the next notice arrives. Curve's team will show you which URLs and parameters are likely triggering the flag and set up HIPAA-compliant conversion tracking that keeps your campaigns optimizing, with a BAA signed on every plan. To see exactly what your site is sending, book a call with Curve.
How Curve helps
- Curve's team reviews what your website sends to Meta, Google and TikTok with you, and shows what is likely triggering the flag.
- Curve rebuilds your conversion tracking so it is HIPAA-compliant and keeps your campaigns optimizing, sending conversions server-side to Meta Conversions API, Google Ads, TikTok, Microsoft and LinkedIn.
- Curve detects PHI-like patterns before data reaches an ad platform.
- Curve signs a BAA on every plan, and Curve's team does the setup for you, typically live in about a week (it varies case by case).
Frequently asked questions
Is core setup permanent?
Meta doesn't give one end date. When it follows repeated blocked-parameter notifications, Meta says it can last "for at least 90 days". When it comes from a data source category, it is tied to that category.
Do my standard events still count under core setup?
Yes. Core setup restricts custom parameters and URL paths, not standard events. If Purchase or Schedule are also restricted, that is Meta's separate standard-event restriction.
Why can't I see full URLs in Events Manager anymore?
Core setup cuts URLs back to the domain, so Sampled activities and the test events tool show only the domain. It is expected behavior, not a broken pixel.
Does core setup affect Google or TikTok?
No. Core setup is a restriction on Meta Business Tools. Google, TikTok and other platforms apply their own health rules, so check each one separately.
How can Curve help with core setup?
Curve's team reviews what your website sends to Meta with you and shows which URLs and parameters are likely triggering the flag. Curve then rebuilds your conversion tracking so it is HIPAA-compliant and detects PHI-like patterns before data reaches Meta, which helps prevent the repeat notices that are one route into core setup. Book a call with Curve.
Sources
- Meta Business Help Center: About core setup
- Meta Business Help Center: How to review blocked parameters in Meta Events Manager
- Meta Business Help Center: Understand data sharing restrictions based on data source categories
- Meta Business Help Center: How to manage data source categories in Meta Events Manager
- Meta Business Help Center: About prohibited information
Last verified
Related pages
- Meta Restricted Purchase Events for Health and WellnessWhy Meta restricts Purchase and other lower-funnel events for health and wellness sites, what still works in each tier, and the compliant way back.
- Meta Removed Potentially Prohibited Information: Next StepsWhat Meta's prohibited information notice means for a health business, where to find what was removed, how to fix it, and why you must never re-send it.
- Meta Blocked My Custom Events Until I Review ThemWhy Meta blocks every custom event once a dataset has data restrictions, which events to confirm, which to keep blocked, and why renaming is not a fix.
- How to Request a Meta Data Source Category ReviewCan you get Meta's Health and wellness category removed? Who can request a review, the exact Events Manager path, and when a review won't help.
- Meta Conversions Stopped: Restriction or Broken Tracking?Meta conversions dropped. How to tell a data restriction from broken tracking or a page change, event by event, and which layer to fix first.
Talk to Curve about the data side of your restriction
Book a call and Curve's team will look at what your site sends to Meta, Google and TikTok, and show you the compliant setup that keeps your campaigns optimizing.
Book a call