Meta says "potentially prohibited information was removed from the data you're sharing"
potentially prohibited information was removed from the data you're sharing
On this page
Meta's filters detected something in your event data that may be prohibited information, a category that includes health information, and removed it. The rest of your events still arrive. Treat the notice as a request to fix the source now: Meta lists receiving "multiple notifications that data you're sharing potentially goes against the Meta Business Tools Terms" as one reason a dataset is placed into core setup, and it says "You must not attempt to send data that has previously been detected and removed."
Curve Compliance makes this notice less likely to come back, though no setup can promise it never will. Only the fields you explicitly map leave your site, Curve detects PHI-like patterns in the data, and conversions go server-side under a BAA signed on every plan. Curve does not clear notices in Events Manager, lift restrictions, restore restricted events, fix creative or file appeals.
Where the notice shows up and what it tells you
Meta says the notice can arrive "through email, in the diagnostic tab in Meta Events Manager, or in Meta Ads Manager". The removed data itself is not shown: Meta notes that "actual data that has been detected and removed is not displayed". What the Diagnostics tab does show is "which parameters, from which pages, had information removed". That is your starting point.
For a health business, Meta's examples of prohibited information include "Diseases, medical conditions and injuries", "Medical procedures, treatments and testing", prescription medications, and "Physical locations that identify a health condition, or places of treatment and counseling".
Where to look on a clinic or telehealth site
Meta tells you to check "URL strings from pages on which you use a Meta Business Tool, parameter names and values you are sharing, and the names you have chosen for custom events." In practice, that means:
- Page paths and query strings that name a condition or treatment, on any page where the pixel runs.
- UTM values. Meta warns that "UTM parameters in a URL string may contain prohibited data from the landing pages viewed." A campaign named after a condition ends up in utm_campaign.
- Parameter values such as content names, content categories, product IDs and custom properties.
- Custom event names.
- Form fields. Meta asks you to analyze "data fields, such as forms, on your webpages".
- Logged-in pages. Meta says "You shouldn't send information about people from web pages where visitors may log in and provide potentially sensitive information, such as patient portals."
How to fix it
Meta also suggests you "may want to turn on core setup" to help prevent further prohibited information being shared. Read what core setup still allows before you decide.
- In Events Manager, open the dataset's Diagnostics tab and note every parameter and page Meta lists.
- Compare that list with the summary of pages, parameters and URLs your Business Tools recently sent, which Meta also shows in Events Manager.
- Trace each item to where it starts: a page template, a tag manager variable, a booking or intake tool, or your campaign naming.
- Change the integration so the information is no longer sent. Remove the pixel from pages that shouldn't have it, stop sending the field, and take conditions out of URLs and campaign names.
- If Meta blocked custom events and you think that was an error, Meta says you may be able to request a review from Events Manager or Ads Manager.
- If a developer or agency maintains the site, bring them in. The fix lives in their code.
What not to do
If your events were also restricted because of your data source category, that is a separate issue. See what Meta restricts for health and wellness data sources.
- Don't re-send the removed information by another route, such as a renamed parameter, a different event name or a server-side call. Meta says "You must not attempt to send data that has previously been detected and removed."
- Don't encode or hash a condition to get it past the filter. Hashing is the format Meta's API requires for some customer information parameters. It does not change what the data is or make it allowed.
- Don't ignore repeat notices. For blocked parameters, Meta says repeats can put a dataset into core setup "for at least 90 days".
- Don't rely on Meta's filter as your safeguard. Meta says "Meta's systems are not a substitute for your own compliance mechanisms."
Talk to Curve
If you want to see exactly which fields your site sends to Meta and why, book a call with Curve. We will go through it with you and your developer.
Where Curve Compliance fits
What Curve does
- Sends only the fields you explicitly map, so URLs, parameters and form fields aren't sent unless they are mapped.
- Detects PHI-like patterns in the data it handles.
- Sends conversions server-side.
- Signs a BAA on every plan.
What Curve doesn't do
- Does not clear or dismiss Meta's notices.
- Does not lift restrictions or restore restricted events.
- Does not fix ad creative.
- Does not file appeals or review requests with Meta.
- Does not control what Meta's filters decide to flag.
Frequently asked questions
Will my ads stop because of this notice?
The notice itself means data was removed, not that ads stopped. Repeated notices can lead to data restrictions such as core setup, which is why the fix can't wait.
Can I see exactly what Meta removed?
No. Meta says the actual removed data is not displayed. The Diagnostics tab shows which parameters and pages were affected.
How is this different from "Event parameters blocked"?
"Event parameters blocked" means specific parameters are being blocked, while this notice tells you data was removed. Both point to the same fix, and both can lead to core setup if they repeat.
Can Curve make sure this never happens again?
No. Curve limits what leaves your site to explicitly mapped fields and detects PHI-like patterns, which makes the notice less likely, but Meta's filters make their own decisions.
Sources
- Meta Business Help Center: Troubleshoot Meta Business Tools prohibited information notifications
- Meta Business Help Center: About prohibited information
- Meta Business Help Center: About core setup
- Meta Business Help Center: How to review blocked parameters in Meta Events Manager
Last verified
Related pages
- Meta Core Setup for Health Businesses: What Still WorksMeta core setup strips custom parameters and everything after the domain. What still works for a health business, why it happened, and what to fix first.
- Meta Blocked My Custom Events Until I Review ThemWhy Meta blocks every custom event once a dataset has data restrictions, which events to confirm, which to keep blocked, and why renaming is not a fix.
- Meta Restricted Purchase Events for Health and WellnessWhy Meta restricts Purchase and other lower-funnel events for health and wellness sites, what still works in each tier, and the compliant way back.
- Does Server-Side Tracking Get Around Health Restrictions?No. Meta restricts health data by data source, not by route, and forbids re-sending removed data. Here is what server-side tracking is really for.
- Meta Conversions Stopped: Restriction or Broken Tracking?Meta conversions dropped. How to tell a data restriction from broken tracking or a page change, event by event, and which layer to fix first.
Talk to Curve about the data side of your restriction
Curve Compliance fixes the data layer: conversions go server-side and only explicitly mapped fields leave. It does not lift a restriction or restore restricted events.
Book a call