All posts

TikTok Pixel and UK GDPR: the risks most businesses don't know about

24 August 20268 min read

If you've installed the TikTok Pixel on your website, you are almost certainly a joint controller of personal data under UK GDPR. Most businesses using the Pixel don't know that. Fewer still have done anything about it.

This post covers what the Pixel actually does, why the joint controller question matters, what the China data transfer problem looks like in practice, and the specific steps you need to take.

---

What the TikTok Pixel actually does

The TikTok Pixel is a snippet of JavaScript you embed in your website. Once installed, it tracks visitor behaviour and fires that data back to TikTok so you can measure ad conversions, build retargeting audiences, and optimise your campaigns.

The data it collects is not trivial. It includes IP addresses, browser and device information, pages visited, events like button clicks, form submissions and purchases, and timestamps of visits. If you have the Advanced Matching feature enabled, it can also transmit hashed versions of email addresses, phone numbers, names and postal codes. That data is hashed client-side before being sent, but it remains personal data under the GDPR.

All of that data goes to servers controlled by ByteDance, TikTok's parent company.

---

Two problems most businesses haven't noticed

1. You may be a joint controller, not just a data controller

Most businesses think of themselves as the data controller and TikTok as their data processor: TikTok processes data on your behalf, following your instructions. That's how most vendor relationships work under UK GDPR.

With TikTok, it's more complicated.

TikTok's own Analytics Joint Controller Addendum states that when you publish content and use TikTok Analytics for your own purposes, you and TikTok jointly determine the means and purposes of processing that engagement data. That makes you joint controllers under UK GDPR Article 26, which says that where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers.

This isn't a technicality. Joint controller status changes your obligations significantly. The arrangement must specify which controller is responsible for which GDPR obligations: breach notification under Article 33, data subject request handling under Articles 15 to 22, maintaining records of processing activities under Article 30, and DPIA obligations under Article 35.

The ICO's own internal DPIA (published under a freedom of information request) acknowledged this directly. The TikTok Analytics Joint Controller Addendum, which must be accepted to create an account, designates the account holder and TikTok as joint controllers for the creation and collection of engagement data and its aggregation into TikTok Analytics. The ICO's DPIA also noted that the ICO would remain responsible for compliance with controller obligations under UK GDPR with TikTok, but would have limited influence over this processing. If that's a problem for the ICO itself, it's a problem for you too.

The practical consequence: if you have no documented Article 26 arrangement in place, or if you've been treating TikTok purely as a processor when the relationship is actually joint controllership, your compliance position has a gap. A significant share of recent enforcement actions have traced back to organisations that were joint controllers with a third party and had no Article 26 arrangement in place.

2. The Pixel fires data to a country with no UK adequacy decision

China does not have a UK adequacy decision. That means the UK government has not determined that China provides an equivalent level of data protection to the UK. Transferring personal data there requires a separate legal mechanism.

TikTok (ByteDance) processes personal data on servers some of which are located outside the EEA. ByteDance is a Chinese company subject to Chinese national security law, which can compel data disclosure to Chinese authorities without judicial review and without the ability to notify the data subject.

TikTok relies on Standard Contractual Clauses (SCCs) as its transfer mechanism. For UK transfers, the relevant instrument is the International Data Transfer Addendum (IDTA) to the EU SCCs, issued by the ICO. TikTok's Developer Data Sharing Agreement confirms that where the UK GDPR applies to a restricted transfer, the UK SCC Addendum (version B.1.0, in force 21 March 2022) issued by the UK Information Commissioner applies.

SCCs are not a blank pass, though. Under UK GDPR Chapter V, transferring personal data to a third country requires either an adequacy decision, Standard Contractual Clauses with a transfer impact assessment, or another approved mechanism. The transfer impact assessment (TIA) is the part most businesses skip entirely. It requires you to assess whether the protections in the SCCs can actually be upheld given the laws of the destination country.

This is not a theoretical concern. In May 2025, Ireland's Data Protection Commission fined TikTok €530 million under EU GDPR specifically for failures in its data transfers to China. TikTok primarily relied on SCCs for transfers to China, but fell short by not adequately assessing the impact of Chinese surveillance and access laws on transferred data, wrongly assuming Chinese laws didn't apply because the data wasn't physically stored in China, and failing to transparently disclose China as a data transfer destination in privacy notices from 2021. The DPC established that organisations transferring data globally must scrutinise every jurisdiction, especially countries like China, where legal protections fall significantly short of GDPR standards.

That was an EU GDPR decision, not a UK one. But there are lessons all UK organisations can take away from this decision in respect of international transfers to any non-adequate country. The ICO has not yet issued a parallel UK enforcement action on TikTok's transfer practices, but the legal framework is the same and the ICO has the same investigative powers.

---

Why this matters for small businesses specifically

Large businesses have compliance teams. Small businesses usually don't. That's exactly why these risks tend to accumulate quietly.

The TikTok Pixel is easy to install. You copy a snippet of code, drop it into your site header or Google Tag Manager, and your ads start working. Nothing in that process prompts you to think about Article 26, transfer impact assessments, or your Records of Processing Activities (ROPA) under Article 30.

But the law applies regardless of your size. UK GDPR applies to any website or business that processes personal data of individuals in the UK, regardless of where the company is based. The ICO can fine organisations up to £17.5 million or 4% of global annual turnover, whichever is higher. When viewed against the maximum fine the ICO can issue, based on TikTok's 2022 revenue that ceiling was around £2.56 billion. For a small business, 4% of turnover is a meaningful number even if the absolute figure is smaller.

One underreported consequence of the TikTok ruling is that it signals data protection authorities are increasingly willing to look upstream from platforms to the brands using them. Regulators are not only going after TikTok. They are establishing the legal principles that apply to every business that embeds its tools.

---

What the common failure looks like

Here's a realistic scenario. A small e-commerce business installs the TikTok Pixel via Google Tag Manager to track purchases and run retargeting ads. They have a cookie banner on their site. They believe that's enough.

In practice, several things may be wrong:

The Pixel fires before consent. In its standard configuration, the TikTok Pixel loads on page load and sets cookies before any user interaction with a consent banner. That is a direct violation of the ePrivacy Directive and UK GDPR. The cookie banner is only compliant if the Pixel is technically blocked until consent is granted. Having a banner that doesn't actually stop the Pixel from firing is not compliance.

There is no documented legal basis for the transfer to TikTok. The TikTok Pixel is a non-essential advertising technology and requires explicit opt-in consent from UK visitors under UK GDPR and the ePrivacy Directive. Consent needs to be granular, specific, and freely given. Pre-ticked boxes or bundled consent don't meet the standard.

The privacy policy doesn't mention TikTok or China. Your privacy policy must name TikTok as a data recipient and disclose that data may be transferred internationally. The TikTok Pixel mirrors visitor behaviour on your own site, meaning your privacy policy needs to cover both first-party and TikTok data sharing. If it doesn't, you have a transparency failure under UK GDPR Article 13.

There is no transfer impact assessment. Most small businesses have never heard of one. But if you're relying on SCCs to legitimise a transfer to a country without an adequacy decision, you are required to assess whether those SCCs can be enforced in practice. Organisations must ensure that no foreign laws undermine SCC protections, especially in terms of government surveillance, access to data, and judicial oversight.

The ROPA doesn't include TikTok Pixel processing. The processing of data through the TikTok Pixel must be documented in the records of processing activities in accordance with Article 30 GDPR. If the ICO asked to see your ROPA today, TikTok Pixel would need to be in it, with the legal basis, data categories, retention periods, and transfer details recorded.

---

What to do about it

None of this requires you to stop using TikTok ads. It requires you to use them with the right documentation and technical controls in place.

Step 1: Check whether your Pixel fires before consent. Use your browser's developer tools or a tool like a tag auditor to verify that the Pixel does not load until a user has actively accepted marketing cookies. If you deploy the TikTok Pixel via Google Tag Manager, configure the tag with a conditional trigger based on the marketing consent signal from your CMP. The tag should only fire when the marketing consent variable is granted. Note: TikTok does not have a native equivalent to Google's Consent Mode v2, so you need to manage this blocking yourself.

Step 2: Review TikTok's terms and accept the relevant addenda. TikTok's Analytics Joint Controller Addendum is incorporated into TikTok's Terms of Service when you create an account. Read it. Understand what it says your responsibilities are. Under the addendum, you are responsible for disclosing any information required by Articles 12, 13 and 14 GDPR to your users. That responsibility sits with you, not TikTok.

Step 3: Update your privacy policy. Name TikTok as a data recipient. State the categories of data collected via the Pixel. Identify the legal basis (consent). Disclose that data may be transferred to countries outside the UK, name those countries, and state the transfer mechanism (the UK IDTA). Your privacy policy needs to cover both first-party and TikTok data sharing.

Step 4: Complete a transfer impact assessment. This doesn't have to be a lengthy document, but it does have to exist. Record what data is transferred, where it goes, what mechanism you're relying on (the UK IDTA), and your assessment of whether Chinese law undermines the protections in those clauses. Be honest in that assessment. The €530 million EU fine against TikTok turned partly on the fact that TikTok wrongly assumed Chinese laws didn't apply because the data wasn't physically stored in China. Don't make the same assumption.

Step 5: Add TikTok Pixel processing to your ROPA. Your Article 30 records need an entry for TikTok Pixel that covers: the purpose of processing (advertising, conversion tracking), the legal basis (consent), the categories of personal data, the recipient (TikTok Technology Limited), the transfer destination and mechanism, and your retention period. TikTok's `_ttp` cookie has a documented retention period of 13 months. Use that as a starting point.

Step 6: Consider whether you need a DPIA. If you use Advanced Matching, which involves transmitting hashed personal identifiers, or if you run large-scale profiling through TikTok's audience tools, you may be required to complete a Data Protection Impact Assessment under UK GDPR Article 35 before that processing continues.

---

The ICO's track record on TikTok

The ICO has already demonstrated it will act. On 4 April 2023, the ICO issued a £12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc for breaches of data protection law, including failing to use children's personal data lawfully. The original notice of intent proposed a fine of £27 million. The fine was confirmed after a First-tier Tribunal ruled in October 2025 that the ICO did have the power to issue the monetary penalty notice.

The ICO has also announced investigations into how TikTok uses 13 to 17-year-olds' personal information to make recommendations to them, signalling continued regulatory attention on the platform.

The enforcement to date has focused on TikTok's own conduct. But data protection authorities are increasingly willing to look upstream from platforms to the brands using them. The principles established in these cases apply to your use of the Pixel too.

---

If you're not sure whether your business is covered, Rowpa generates your full ROPA in 15 minutes. Start free at rowpa.app.

---

Sources

---

This post is for information only and does not constitute legal advice.