Facebook Ads and the GDPR: What Companies Really Need to Watch in 2025

What must companies do in 2025 to run Facebook ads in a GDPR-compliant way? This guide covers US data transfers, why the Meta Pixel requires active opt-in, CMP requirements, and what to watch for with Custom Audiences, Conversion API, privacy policies and DPAs—plus a practical compliance checklist.

Content

The core issue: data transfers to the USMeta Pixel: Only with valid consentConsent Management Platform (CMP): Not optional, but mandatoryCustom Audiences: The legal basisConversion API (CAPI): More privacy-friendly than the Pixel?iOS 14 and the loss of trackingPrivacy policy and Meta usagePractical checklist: GDPR-compliant Facebook marketingConclusion