TikTok says it found potentially prohibited data in what our health website shares
On this page
TikTok's "potentially prohibited data" notice means its systems detected what may be health, financial or children's information in the data your website or app shares through the TikTok Pixel or Events API, and TikTok wants you to find it and stop sending it. TikTok says "If TikTok detects potentially prohibited data in the data you're sharing, you may receive a notification through email, in Events Manager's Diagnostics tab or in TikTok Ads Manager." It asks you to "immediately take steps to review and update your implementations". On a clinic or telehealth site, the usual sources are the Pixel on booking or intake pages, condition names in URLs and campaign names, and health terms in event, product or audience names. Curve Compliance helps health businesses find that data and stop sending it at the source.
Curve replaces browser ad pixels, including the TikTok Pixel, with one script and sends conversions server-side to TikTok, Meta Conversions API, Google Ads, Microsoft Advertising and LinkedIn. Each platform receives only a fixed list of fields, events can use neutral names, and Curve detects PHI-like patterns, such as condition names, form answers and emails in URLs, before data reaches an ad platform. Event Logs show what Curve sent to TikTok and what TikTok accepted. Curve signs a BAA on every plan, and Curve's team does the setup, with most customers live in about a week. Book a call with Curve.
What the notification means
Section 2.8 of TikTok's Business Products (Data) Terms says: "You will not share with us or enable us to access Business Products Data that you know or ought reasonably to know is from or about Children or that includes health or financial information, or other categories of sensitive information". TikTok's help page puts it plainly: "At TikTok, we don't allow advertisers to share information about children, health or financial information, or other categories of prohibited data."
The notice tells you TikTok's systems saw something that may fall in those categories. TikTok says "Prohibited data includes a person's health-related data such as medical conditions, medications or medical treatments". Its health examples are "Ecommerce urls that contain protected health information" and "Information from apps that may be used to schedule medical appointments". TikTok calls its list incomplete and recommends "working with your legal team to review your data sharing." Talk to your counsel about what your site may share.
TikTok's two help pages on these notices don't name a specific penalty, but one says "Sharing prohibited data is a violation of the TikTok Business Products (Data) Terms section 2.8." Clause 6.1(b) of the Business Products (Data) Terms says TikTok "may modify, suspend or terminate your access to" its business products, including "where we determine that you have breached these TikTok Business Products (Data) Terms." TikTok asks you to fix your integration so "your data sharing complies with TikTok's Data Terms." This notice is about data, not ad content. TikTok reviews health ads under separate policies, covered in TikTok ads for clinics: what health rules allow. Meta sends a similar notice, covered in Meta removed potentially prohibited information.
Where health data leaks into TikTok
TikTok asks you to check "URLs from pages with Pixel or Events API installed, UTM parameters, and the names you have chosen for custom audiences or custom events." On a health site, look here first:
- Pixel pages. TikTok says "Make sure you don't use your TikTok Pixel on web pages where you may share personal health or financial information." Its examples include patient data portals and apps used to schedule medical appointments. Check booking, intake, symptom quiz and portal pages first.
- URLs and UTM parameters. TikTok warns that "UTM parameters in a URL string may contain prohibited data from the landing pages viewed." A path like /weight-loss/semaglutide-consult, or a utm_campaign named after a condition, carries that condition into the events from that page.
- TikTok's own URL macros. If your ad URL uses macros such as __CAMPAIGN_NAME__ or __AID_NAME__, TikTok fills in the campaign or ad group name. A campaign called "anxiety-treatment-women" then appears in your landing page URL.
- Event and product names. TikTok asks you to review "event names, product names, product IDs, custom properties and content names." A custom event called ED_consult_booked, or a content name that is a medication, names the treatment.
- Custom audience names. TikTok says "your custom audience must not reflect or imply any prohibited data about people, including in the name you choose and the criteria you establish."
- Forms and Automatic Advanced Matching. TikTok says this setting "Automatically identifies form fields on pages where the Pixel is installed, and hashes and collects the customer information entered on those pages". Its sources also include "Static text displayed on the page" and "Key website variables (e.g., window.dataLayer, window.utag)".
- Enhanced Data Postback. When it's on, TikTok collects "Descriptive page metadata (e.g., page titles, product information, key parameters such as value and currency)" and "Button click text and elements (e.g, button name, descriptive text, and attributes)." A page titled after a condition, or a button that says "Start my hair loss assessment", becomes data TikTok receives.
Find what TikTok flagged: the Diagnostics tab and Pixel Helper
TikTok says the Diagnostics tab shows "information about the types of data and sources that TikTok identified", and asks you to "determine which parameters, from which pages, were identified." To get there:
- Log in to TikTok Ads Manager. In the Tools tab, click Events to open TikTok Events Manager.
- Click your pixel in the Datasets Overview section, then click the Diagnostics tab. TikTok notes that "A number next to the Diagnostics tab indicates an active issue."
- Click Active issues. Each card shows the issue, severity, affected dataset and impacted ads. Click Learn more for "impact details, issue details, specific instructions on how to fix the issue, and sample data of recent events affected by the issue."
- On the Overview tab, check each event's Connection Method. TikTok shows whether an event is shared via "browser only", "server only", or "server & browser" connection. That tells you whether to fix the page, the server integration or both.
- Open a flagged page in Chrome with TikTok Pixel Helper, a Chrome extension. TikTok suggests it to "view the data being sent to TikTok and ensure it aligns with data sharing policies and does not include data that may be deemed sensitive."
- For events sent through the Events API, review the integration itself. TikTok asks you to "Review your Pixel or Event API integration to make sure you aren't sharing prohibited data from anywhere on your website or app."
Stop sending it at the source
TikTok's instruction is short: "Update your integration to stop sharing any prohibited data with TikTok." Bring in your developer or agency, because the fix lives in their code and campaign setup:
- List every page that carries the Pixel. Curve Compliance's free website scan lists the pixels and trackers on a page.
- Take the Pixel off pages where visitors give health details, such as portals, intake forms, booking flows and condition quizzes. TikTok says you can use it on pages "relevant to your advertising and remove it from the specific pages where you don't want to continue using the pixel."
- Rename anything that names a condition, medication or treatment: campaigns, ad groups, UTM values, custom events, products, content names and custom audiences.
- Switch to Manual Advanced Matching. TikTok says "If you operate within a more regulated or sensitive industry such as financial services or healthcare, consider using Manual Advanced Matching instead of Auto Advanced Matching." The Automatic Advanced Matching button is on your pixel's Settings page in Events Manager. For Manual Advanced Matching, TikTok says "you'll use code for each event you want to track on your website."
- Review Enhanced Data Postback. TikTok says you can opt out "by toggling Enhanced Data Postback off in your Events Manager settings."
- Trim what your server sends. TikTok says that with the Events API, "you only have to share the data required to meet your marketing objectives." Send the fields your campaigns need and nothing from page content or form answers.
- Check again with Pixel Helper and the Diagnostics tab after each change.
How Curve Compliance sends TikTok conversions
With Curve, TikTok conversions leave from Curve's servers, not the browser, and TikTok receives only a fixed list of fields. Contact identifiers are off by default and SHA-256 hashed when turned on. Curve flags PHI-like patterns so they can be stopped at the source, and Event Logs show what Curve sent to TikTok and what TikTok accepted, so you can confirm what changed.
When patients leave to book in tools such as IntakeQ, Calendly or Jane App, Curve keeps the ad attribution, and bookings made days later still match. Curve Forms gives you HIPAA-hosted intake and lead forms with ad attribution attached.
What not to do
- Don't move the same data to the Events API. TikTok's rule covers both routes: "If you measure events on your website or app with tools like Events API or TikTok Pixel, it's your responsibility to review the information you share". Server-side changes the route, not what the data says. See why server-side tracking doesn't lift a restriction.
- Don't count on TikTok's filter. TikTok says "While TikTok's systems are designed to filter out prohibited data they're able to detect, you are ultimately responsible for the data you share with TikTok."
- Don't hash or encode a condition to get it through. Hashing is a format for match keys such as email and phone. Section 2.8 of TikTok's Business Products (Data) Terms makes no exception for health information that has been hashed or encoded.
- Don't just dismiss the card. TikTok lets you click Dismiss "to remove the issue from the dashboard", but that doesn't change what your site sends.
- Don't start over with a new pixel or ad account. A new pixel on the same pages sends the same data. See whether to open a new ad account after a restriction.
- Don't wait. TikTok says to "immediately take steps to review and update your implementations".
Talk to Curve
TikTok decides what it flags. What your site sends is up to you. Curve's team reviews what your website sends to Meta, Google and TikTok with you and shows what's likely triggering the flag. Curve then sends TikTok conversions server-side with a fixed list of fields, detects PHI-like patterns before data reaches an ad platform, and shows what was sent and accepted in Event Logs. TikTok does not sign a BAA for its ad tools (TikTok in the BAA Directory), so nothing sent to TikTok should carry health information. Curve Compliance is SOC 2 Type II, includes consent management and signs a BAA on every plan. To go through your TikTok setup with your developer, book a call with Curve.
How Curve helps
- Curve's team reviews what your website sends to Meta, Google and TikTok with you and shows what's likely triggering the flag.
- Curve replaces browser ad pixels with one script and sends conversions server-side to TikTok, Meta Conversions API, Google Ads, Microsoft Advertising and LinkedIn.
- Each platform receives only a fixed list of fields, and events can use neutral names.
- Curve detects PHI-like patterns, such as condition names, form answers and emails in URLs, before data reaches an ad platform.
- Curve's Event Logs show what was sent to each platform and what it accepted.
- Curve Compliance is SOC 2 Type II and signs a BAA on every plan. Curve's team does the setup, and most customers are live in about a week.
Frequently asked questions
What does "potentially prohibited data" mean on TikTok?
TikTok's systems detected something in your Pixel or Events API data that may be information TikTok doesn't allow advertisers to share. TikTok says "Prohibited data includes a person's health-related data such as medical conditions, medications or medical treatments", along with financial data and data about children.
Where do I see which pages or parameters TikTok flagged?
In TikTok Events Manager, click your pixel, open the Diagnostics tab and click Active issues. Learn more on each card shows issue details and sample data of recent events affected. TikTok asks you to "determine which parameters, from which pages, were identified."
Can our booking or scheduling pages carry the TikTok Pixel?
TikTok lists "Information from apps that may be used to schedule medical appointments" as an example of prohibited health data, and says "Make sure you don't use your TikTok Pixel on web pages where you may share personal health or financial information." Curve keeps ad attribution when visitors leave to book in tools such as IntakeQ, Calendly or Jane App, so you can see which ads drive bookings without the TikTok Pixel on those pages.
Does switching to the Events API make the notification go away?
Not by itself. TikTok asks you to "Review your Pixel or Event API integration to make sure you aren't sharing prohibited data", so its rules apply to both. The Events API helps when you use its control: TikTok says "you only have to share the data required to meet your marketing objectives."
Doesn't TikTok filter this data for us?
TikTok says "While TikTok's systems are designed to filter out prohibited data they're able to detect, you are ultimately responsible for the data you share with TikTok." Treat the filter as a backstop, not the fix.
Should a health website turn off Automatic Advanced Matching on TikTok?
TikTok says "If you operate within a more regulated or sensitive industry such as financial services or healthcare, consider using Manual Advanced Matching instead of Auto Advanced Matching." Automatic Advanced Matching draws on form fields, static text on the page and website variables such as window.dataLayer.
Does TikTok sign a BAA for the Pixel or Events API?
No. TikTok does not sign a BAA for its ad tools, and its terms bar health information (TikTok in the BAA Directory). Curve Compliance signs a BAA on every plan, which covers Curve, not TikTok, so nothing sent to TikTok should carry health information.
How does Curve help with TikTok on a health site?
Curve sends TikTok conversions server-side with a fixed list of fields and neutral event names, detects PHI-like patterns before data reaches an ad platform, and shows what was sent and accepted in Event Logs. Curve's team does the setup and signs a BAA on every plan. Book a call with Curve.
Sources
- TikTok Business Help Center: About notifications of potentially prohibited data sharing on TikTok
- TikTok Business Help Center: How to resolve notifications of potentially prohibited data sharing on TikTok
- TikTok Business Products (Data) Terms
- TikTok Business Help Center: How to manage Web Diagnostics in TikTok Events Manager
- TikTok Business Help Center: About diagnostic and monitoring tools in TikTok Events Manager
- TikTok Business Help Center: Troubleshoot with Pixel Helper
- TikTok Business Help Center: About Advanced Matching for Web
- TikTok Business Help Center: How to set up Automatic Advanced Matching
- TikTok Business Help Center: Enhanced Data Postback with the TikTok Pixel
- TikTok Business Help Center: About UTM parameters
- TikTok Business Help Center: About Events API
Last verified
Related pages
- TikTok Lead Ad Rejected for Health Questions? What to FixTikTok rejected your lead ad for requesting sensitive information? See which health questions instant forms can't ask and how to rebuild the form.
- TikTok Account Suspension Warning: What Clinics Should DoGot a TikTok account suspension warning, or Account Health says Restricted? What it means for a clinic, what to fix first, and how to keep the account.
- TikTok Ad Account Suspended? What Clinics Should DoTikTok suspended your clinic's ad account? Why it happens, the 30-day window, how to appeal by ticket, and why to avoid opening a new ad account.
- Meta Removed Potentially Prohibited Information: Next StepsWhat Meta's prohibited information notice means for a health business, where to find what was removed, how to fix it, and why you must never re-send it.
- Event Parameters Blocked in Meta: Unblock or Keep Blocking?What Meta's "Event parameters blocked" diagnostic means, how to review it, when to unblock or keep blocking, and why repeats lead to core setup.
- Does Server-Side Tracking Get Around Health Restrictions?No. Meta restricts health data by data source, not by route, and forbids re-sending removed data. Here is what server-side tracking is really for.
- Should We Open a New Ad Account After a Restriction?Opening a new ad account, Page or Business Manager to get past a restriction breaks Meta's and Google's rules. Here is the legitimate path instead.
Talk to Curve about the data side of your restriction
Book a call and Curve's team will look at what your site sends to Meta, Google and TikTok, and show you the compliant setup that keeps your campaigns optimizing.
Book a call