Skip to main content
Ad Account Rescue

Meta says "potentially prohibited information was removed from the data you're sharing"

The notice
potentially prohibited information was removed from the data you're sharing
On this page

Meta's filters detected something in your event data that may be prohibited information, a category that includes health information, and removed it. The rest of your events still arrive. Treat the notice as a request to fix the source now: Meta lists receiving "multiple notifications that data you're sharing potentially goes against the Meta Business Tools Terms" as one reason a dataset is placed into core setup, and it says "You must not attempt to send data that has previously been detected and removed."

Curve Compliance makes this notice less likely to come back, though no setup can promise it never will. Only the fields you explicitly map leave your site, Curve detects PHI-like patterns in the data, and conversions go server-side under a BAA signed on every plan. Curve does not clear notices in Events Manager, lift restrictions, restore restricted events, fix creative or file appeals.

Where the notice shows up and what it tells you

Meta says the notice can arrive "through email, in the diagnostic tab in Meta Events Manager, or in Meta Ads Manager". The removed data itself is not shown: Meta notes that "actual data that has been detected and removed is not displayed". What the Diagnostics tab does show is "which parameters, from which pages, had information removed". That is your starting point.

For a health business, Meta's examples of prohibited information include "Diseases, medical conditions and injuries", "Medical procedures, treatments and testing", prescription medications, and "Physical locations that identify a health condition, or places of treatment and counseling".

Where to look on a clinic or telehealth site

Meta tells you to check "URL strings from pages on which you use a Meta Business Tool, parameter names and values you are sharing, and the names you have chosen for custom events." In practice, that means:

  • Page paths and query strings that name a condition or treatment, on any page where the pixel runs.
  • UTM values. Meta warns that "UTM parameters in a URL string may contain prohibited data from the landing pages viewed." A campaign named after a condition ends up in utm_campaign.
  • Parameter values such as content names, content categories, product IDs and custom properties.
  • Custom event names.
  • Form fields. Meta asks you to analyze "data fields, such as forms, on your webpages".
  • Logged-in pages. Meta says "You shouldn't send information about people from web pages where visitors may log in and provide potentially sensitive information, such as patient portals."

How to fix it

Meta also suggests you "may want to turn on core setup" to help prevent further prohibited information being shared. Read what core setup still allows before you decide.

  1. In Events Manager, open the dataset's Diagnostics tab and note every parameter and page Meta lists.
  2. Compare that list with the summary of pages, parameters and URLs your Business Tools recently sent, which Meta also shows in Events Manager.
  3. Trace each item to where it starts: a page template, a tag manager variable, a booking or intake tool, or your campaign naming.
  4. Change the integration so the information is no longer sent. Remove the pixel from pages that shouldn't have it, stop sending the field, and take conditions out of URLs and campaign names.
  5. If Meta blocked custom events and you think that was an error, Meta says you may be able to request a review from Events Manager or Ads Manager.
  6. If a developer or agency maintains the site, bring them in. The fix lives in their code.

What not to do

If your events were also restricted because of your data source category, that is a separate issue. See what Meta restricts for health and wellness data sources.

  • Don't re-send the removed information by another route, such as a renamed parameter, a different event name or a server-side call. Meta says "You must not attempt to send data that has previously been detected and removed."
  • Don't encode or hash a condition to get it past the filter. Hashing is the format Meta's API requires for some customer information parameters. It does not change what the data is or make it allowed.
  • Don't ignore repeat notices. For blocked parameters, Meta says repeats can put a dataset into core setup "for at least 90 days".
  • Don't rely on Meta's filter as your safeguard. Meta says "Meta's systems are not a substitute for your own compliance mechanisms."

Talk to Curve

If you want to see exactly which fields your site sends to Meta and why, book a call with Curve. We will go through it with you and your developer.

Where Curve Compliance fits

What Curve does

  • Sends only the fields you explicitly map, so URLs, parameters and form fields aren't sent unless they are mapped.
  • Detects PHI-like patterns in the data it handles.
  • Sends conversions server-side.
  • Signs a BAA on every plan.

What Curve doesn't do

  • Does not clear or dismiss Meta's notices.
  • Does not lift restrictions or restore restricted events.
  • Does not fix ad creative.
  • Does not file appeals or review requests with Meta.
  • Does not control what Meta's filters decide to flag.

Frequently asked questions

Will my ads stop because of this notice?

The notice itself means data was removed, not that ads stopped. Repeated notices can lead to data restrictions such as core setup, which is why the fix can't wait.

Can I see exactly what Meta removed?

No. Meta says the actual removed data is not displayed. The Diagnostics tab shows which parameters and pages were affected.

How is this different from "Event parameters blocked"?

"Event parameters blocked" means specific parameters are being blocked, while this notice tells you data was removed. Both point to the same fix, and both can lead to core setup if they repeat.

Can Curve make sure this never happens again?

No. Curve limits what leaves your site to explicitly mapped fields and detects PHI-like patterns, which makes the notice less likely, but Meta's filters make their own decisions.

Sources

Last verified

Talk to Curve about the data side of your restriction

Curve Compliance fixes the data layer: conversions go server-side and only explicitly mapped fields leave. It does not lift a restriction or restore restricted events.

Book a call