Meta says "Data sharing restrictions applied" on our dataset
Data sharing restrictions applied. One or more of your data sources are in categories with restrictions. For details on these restrictions and an option to request a review if you think the categories are not appropriate, select Manage categories.
On this page
It means Meta has placed your website or app in a data source category that limits what your dataset can share, and for a clinic, telehealth service or pharmacy that category is almost always Health and wellness. It is a restriction on the data your site sends, not on your ad account, so your ads can keep running. What changes depends on which of Meta's three restrictions the category carries: core setup, a restriction on certain standard events, or full restrictions. Meta says it will tell you "via email and notifications in Meta Events Manager", so the banner and the email usually describe the same change. Open Manage categories, note the restriction on each data source, confirm the custom events you want to keep, and move campaigns to events Meta still accepts. Request a review only if the category is wrong.
Curve Compliance sets up the conversion tracking a health business needs once a notice like this arrives. Curve's team replaces browser pixels with HIPAA-compliant, server-side conversion tracking to Meta Conversions API, Google Ads and TikTok, sends events under neutral event names, and detects PHI-like patterns before data reaches Meta. Identifiers are SHA-256 hashed to each platform's requirements, setup is typically live in about a week, and a BAA is signed on every plan. Book a call with Curve.
What the banner and the email mean
Meta says data sources "may be assigned to a data source category based on the topics related to the data source and the products and/or services provided." Its Health and wellness category covers a data source that "Is associated with medical conditions or specific health statuses, provider/patient relationships, services for accessing personal health information, or health-related products and services", and its examples include "a patient portal, wellness tracker, telemedicine platform, pharmacy, health insurance marketplace, or condition-specific support group".
"When a data source is assigned to a category with additional data sharing restrictions, we may limit or fully restrict the ability to share event data with us via the Meta Business Tools." The restrictions "can be specific to certain countries or regions, or they could be applied globally." The High priority banner in Events Manager and the email about a category with restrictions are two ways Meta announces this, and both point to the same place: Manage categories on your dataset.
Which restriction you have, and what it changes
A category can carry one or more of three restrictions. The Manage categories screen shows which applies to each data source, and the next steps are different for each.
- Core setup: "Restricts the sharing of custom parameters and parts of URLs following the domain." Meta says most campaigns "should continue to run as expected", but custom audiences built on URL or parameter rules can stop updating. See what still works under core setup.
- Restriction on certain standard events: "Restricts the sharing of specific mid and lower funnel events." Meta suggests you "explore alternative events that can help you meet your business objectives". See which events you can still optimize for.
- Full restrictions: "Fully restrict the sharing of all events in specific regions or all regions. In these circumstances, Meta Business Tools cannot be used for ads purposes where restrictions are in place." Meta points to objectives such as Awareness, Engagements and Traffic, which don't rely on your website data.
- Every level: "If your Meta Business Tool has data restrictions, custom events are automatically blocked until you review and confirm them". See why Meta blocked your custom events.
What to do first
- Screenshot the banner or keep the email, and note the date.
- In Meta Events Manager, click Datasets, select your dataset, open the Settings tab and click Manage in the Manage data source categories section.
- For each data source, note its category, its status and the restriction it carries. Meta says you may not see data sources there "if they are not in any of the categories with data sharing restrictions."
- Still in Settings, go to Data controls and click Review in Manage event blocking. Confirm only the custom events whose names and data carry no health information, and block the rest.
- In Ads Manager, find campaigns that optimize for a restricted event and move them to an event or objective that is still available.
- Keep counting bookings and purchases in your own reporting, so you can see the real effect on patients, not only what Meta reports.
Should you request a review?
Only if the category is wrong. "If you think a category assigned by Meta is not appropriate, you can ask us to review it again." Select View details, then Request review, and Meta will email its decision. You can edit a category you chose yourself, but "you will not be able to modify a Meta-assigned categorization for your data source."
If you run a clinic, a telehealth service or a pharmacy, Meta's own definition probably describes you, and a review looks at the same site. Your time is usually better spent adjusting campaigns inside the category. How to request a category review, and when not to covers the rest.
What not to do
Meta is clear that its filters are a backstop, not your compliance program: its systems "are not a substitute for your own compliance mechanisms."
- Don't create a new dataset, pixel or domain for the same business to leave the category behind. A new data source for the same business still describes the same business, and Meta can assign the same category to it.
- Don't rename events so they look less like healthcare. Confirm or block what you send honestly.
- Don't expect server-side sending to change the category on its own. Events sent through the Conversions API land in the same dataset. See whether server-side tracking gets around a restriction.
Talk to Curve
A data sharing restriction is a good moment to rebuild the tracking behind your Meta campaigns properly. Curve's team sets up HIPAA-compliant, server-side conversion tracking in place of browser pixels, uses neutral event names, detects PHI-like patterns before data reaches Meta, hashes identifiers with SHA-256 to each platform's requirements, and keeps attribution through booking tools such as IntakeQ, Calendly and Jane. It is typically live in about a week, with a BAA signed on every plan, so book a call with Curve.
How Curve helps
- Replaces browser pixels with HIPAA-compliant, server-side conversion tracking to Meta Conversions API, Google Ads and TikTok.
- Sends events under neutral event names and detects PHI-like patterns before data reaches Meta.
- Hashes identifiers with SHA-256 to each platform's requirements, and includes consent management.
- Keeps attribution through booking tools such as IntakeQ, Calendly and Jane, so you can see which campaigns book patients.
- Signs a BAA on every plan, with setup done for you by Curve's team, typically live in about a week.
Frequently asked questions
Does "Data sharing restrictions applied" mean our ad account is restricted?
No. It is a restriction on the data your website or app shares through Meta's business tools. Account restrictions show in Business Support Home under Account status overview. Check there separately if ads have stopped delivering.
Why did Meta put our website in a category with restrictions?
Meta assigns categories based on the topics of the data source and the products or services it offers. Its Health and wellness category covers provider/patient relationships and health-related products and services, including telemedicine platforms and pharmacies.
Will our campaigns stop delivering?
Usually not. Under core setup Meta says most campaigns should continue to run as expected. Campaigns that optimize for a restricted standard event lose that signal and need a different event, and under full restrictions Meta Business Tools can't be used for ads where the restriction applies.
Can we remove the category ourselves?
Only if you assigned it. You can't modify a Meta-assigned category, but you can request a review from Manage data source categories if you believe it is not appropriate.
How does Curve help after this notice?
Curve's team sets up HIPAA-compliant, server-side conversion tracking with neutral event names and PHI-like pattern detection, keeps attribution through your booking tool, and signs a BAA on every plan. Book a call with Curve.
Sources
- Meta Business Help Center: Understand data sharing restrictions based on data source categories
- Meta Business Help Center: About data source categories in Meta Events Manager
- Meta Business Help Center: How to manage data source categories in Meta Events Manager
- Meta Business Help Center: About core setup
- Meta Business Help Center: How to review custom events in Meta Events Manager
Last verified
Related pages
- How to Request a Meta Data Source Category ReviewCan you get Meta's Health and wellness category removed? Who can request a review, the exact Events Manager path, and when a review won't help.
- Meta Core Setup for Health Businesses: What Still WorksMeta core setup strips custom parameters and everything after the domain. What still works for a health business, why it happened, and what to fix first.
- Meta Restricted Standard Events: What You Can Still UseWhat Meta's standard-event and full restrictions stop, which events and objectives still work, and how to pick a new optimization event for a clinic.
- Meta Blocked My Custom Events Until I Review ThemWhy Meta blocks every custom event once a dataset has data restrictions, which events to confirm, which to keep blocked, and why renaming is not a fix.
- Meta Restricted Purchase Events for Health and WellnessWhy Meta restricts Purchase and other lower-funnel events for health and wellness sites, what still works in each tier, and the compliant way back.
Talk to Curve about the data side of your restriction
Book a call and Curve's team will look at what your site sends to Meta, Google and TikTok, and show you the compliant setup that keeps your campaigns optimizing.
Book a call