Industry News
Meta Pixel on Your Website: What the German Court Rulings Change for Irish Businesses
The email arrives on a Tuesday morning, polite and precise. The sender opened the shop's website, did not touch the cookie banner, and watched her browser send a request to Facebook before she had clicked anything. She works in compliance. She would like to know why.
The shop in this composite is a bridal boutique in Carlow, stitched together from patterns that turn up constantly when you look under the bonnet of small business websites. It had started running Instagram ads for an autumn sample sale. Meta's ad setup told the owner to install the pixel, so a snippet went into the site header through a plugin, the ads went out, and the bookings came in. A cookie banner had sat at the bottom of the site for years. Everyone assumed the two were talking to each other. They were not.
That email used to be an awkward afternoon. After this year's rulings in Germany, it is the opening line of a claim.
What the German Courts Actually Decided
Strip out the noise and the story is short. Meta sells what it calls Business Tools: the pixel, the Conversions API and related code that businesses install on their own websites so Meta can see what visitors do there. German Facebook users started suing Meta, arguing that data about them was being collected on thousands of third-party sites without valid consent.
They are winning. As heise online reported, the Leipzig Regional Court awarded one user €5,000 in July 2025, describing the tracking as close to complete monitoring of a person's online behaviour. The claimant did not have to prove individual harm; the court assessed damages on the concern of an ordinary, reasonable person.
Then the appeal courts weighed in. On 3 February 2026, according to the Saxony justice ministry's own press release, the Higher Regional Court in Dresden ruled against Meta in four parallel cases, awarding €1,500 to each claimant and ordering Meta to stop processing the data it had collected. The court found the necessary consents simply were not there. It based the damages on loss of control over personal data, the feeling of being comprehensively watched, rather than any proven distress. It refused leave to appeal, so those judgments are final.
| Decision | When | What it established | Who was on the hook |
|---|---|---|---|
| CJEU, Fashion ID | July 2019 | A site embedding a Facebook plugin is a joint controller for collecting and sending the data | The website operator, alongside Facebook |
| Irish Circuit Court, Kaminski | 2023 | Irish courts will award money for non-material GDPR damage | An Irish employer |
| Leipzig Regional Court | July 2025 | €5,000 for Business Tools tracking without consent, no proof of harm required | Meta |
| Higher Regional Court, Dresden | February 2026 | €1,500 per claimant, final, no valid consent found | Meta |
Now the honest caveat, because I have no time for scare stories. Every one of those German awards was made against Meta, not against a café or a boutique. I am not aware of any court, in Germany or here, that has yet ordered a small website owner to pay a visitor over a pixel. So why should the boutique in Carlow care?
Why Your Website Is in the Frame
Because the data does not leave Meta's servers. It leaves hers.
Back in July 2019, the Court of Justice of the EU ruled in the Fashion ID case, involving a German online clothes shop that had embedded a Facebook Like button. The court held that the shop was a joint controller with Facebook for two specific steps: collecting the visitor's data and transmitting it to Facebook. What Facebook did with it afterwards was Facebook's problem. The collection and the handover were shared.
Our own regulator took the same line. The Data Protection Commission's guidance on cookies and tracking technologies names pixel trackers and like buttons explicitly, says they generally require consent before they run, and warns site owners that they may be considered a controller for data they collect and pass to third parties, citing Fashion ID by name.
Then there is Meta's own paperwork. The Business Tools Terms, which you agreed to when you created the pixel, say that where the law requires consent (the EU is named) you must ensure, in a verifiable manner, that the visitor has given it before the tools store or access anything on their device. Meta wrote the obligation down and handed it to you.
Put those three together and the shape of the risk is clear. Under Article 82 of the GDPR, where more than one controller is involved in the same processing, each can be held liable for the whole damage. The German claimants chose to sue Meta because Meta has deep pockets and a single address. Nothing in the law obliges the next claimant to make the same choice.

Could an Irish Visitor Bring the Same Claim?
The mechanism exists. Section 117 of the Data Protection Act 2018 lets a person sue in the Irish courts for breach of their data protection rights, including for non-material damage. In Kaminski v Ballymaguire Foods, the Circuit Court awarded €2,000 to an employee whose CCTV footage was shown to colleagues, as Matheson's summary of the judgment sets out. Different facts entirely. But the principle that an Irish court will put a number on the upset caused by misused personal data is established.
I want to be measured here, because overstated legal warnings do their own damage. Awards in Ireland have so far been modest and fact-specific, and nobody can tell you what an Irish judge would make of a pixel claim against a small shop. That is a question for your solicitor. What I can tell you is what the claim would hinge on, and it is not complicated.
Did your site send the visitor's data to Meta before they agreed to it?
Separately from any damages claim, the same question matters to the DPC. The cookie rules under S.I. 336 of 2011 require consent for non-essential trackers regardless of whether anyone sues, and the regulator's guidance is blunt about banners that nudge people towards Accept or pre-tick the boxes.
The Failure Is Almost Always the Order of Operations
Go back to the boutique. The owner did not ignore the law. She had a banner. The failure was mechanical, and it is the most common one on small WordPress sites: the banner and the pixel were installed separately, by different plugins, at different times, and nothing connected them.
A banner that only displays a message is decoration. For the pixel to be lawful, the banner has to actually hold the pixel back until the visitor clicks Accept, and keep holding it back if they click Reject. Many banner plugins can do this. Most need to be told which scripts to block, and a snippet pasted into a header box three years after the banner went in was never on that list.
So the site looks compliant. The banner appears on schedule. And every visitor who lands from those sample sale ads has already been reported to Meta before they have read a word.
There is a second, quieter version of the same failure. Somebody rejects cookies, the banner disappears, and the pixel fires anyway because the Reject button only closes the box. From the outside the two situations look identical. Only a test tells you which one you have.
How to Verify Your Pixel Waits for Consent
This takes about ten minutes, needs no technical background, and should be repeated after any change to your plugins or theme.
- Open a clean session. Use a private or incognito browser window, so no earlier consent choice is remembered.
- Install the inspector. Meta publishes a free browser extension, the Meta Pixel Helper, which shows whether a pixel has fired on the page you are viewing.
- Verify the default state. Load your homepage and do not touch the banner. If the extension reports a pixel firing at this point, your production site is collecting data before consent.
- Verify the Reject path. Close the window, open a fresh private one, click Reject, then browse two or three pages. The pixel should stay silent throughout.
- Fix, then re-verify. If either check fails, configure your banner plugin to block the pixel script until consent, or remove the pixel, and run steps 1 to 4 again before you relaunch any ad campaign.
If step 3 fails, treat it as a production conflict, not a to-do item. Every hour it stays that way is another batch of visitors whose data left your site without permission.
Moving It Server-Side Does Not Make the Question Go Away
Somebody will tell you the answer is Meta's Conversions API, which sends events from your server rather than from the visitor's browser. It has genuine advantages, mostly around ad blockers and data quality. It does not change whether the visitor agreed to their data going to Meta.
The Dresden cases were about Meta's Business Tools as a family, not only the browser pixel, and German lawyers advising website operators are already pointing out that server-side setups sit squarely in the same frame. Moving the handover from the browser to the server moves where it happens. It does not make it consensual.
One genuine limitation worth knowing before you fix anything. Done properly, consent-gated tracking means your ad reports will show fewer conversions than before, because the visitors who click Reject are no longer counted. Your ads have not suddenly got worse. You are just no longer measuring people who said no. Expect the dip, and do not let anyone talk you into undoing the fix to make the numbers look healthier.

Do You Actually Need the Pixel?
This is the question I would ask the boutique owner first. Plenty of small sites carry a pixel because an ad tutorial said to install it in 2019, and nobody has looked at a retargeting audience since.
A fair concession here. If your business lives on paid social, spending real money on Meta ads every month and relying on the algorithm to find buyers, then a properly configured pixel behind a proper consent management platform, tuned by a specialist who does this all day, genuinely earns its keep. No built-in analytics tool will feed Meta's optimisation, and I would not pretend otherwise.
Most local businesses are not in that position. What they want to know is simpler: how many people visited, where they came from, which pages they read and whether the sample sale campaign sent anyone. That is measurement, not tracking, and it does not need to hand anybody's data to a third party at all. Campaign-tagged links from your ads, read by a privacy-respecting analytics tool, answer most of it. We covered the approach in detail in our guide to cookie-free website analytics for Irish businesses.
That is the logic behind how we built Web60. Privacy-first analytics is included in Web60's €60 a year, with no cookie consent required for the analytics itself, and the data sits on Irish infrastructure. If you do keep a pixel for ads, you still need the consent setup described above, because no hosting platform can make a third-party tracker lawful on your behalf. But a lot of owners, once they see the traffic numbers without the pixel, realise they were keeping it for a campaign they stopped running long ago.
It is part of a wider habit worth building. The same discipline that keeps your backups and plugins in order, which our WordPress security and backup guide walks through, applies to the scripts on your pages: know what is installed, know why, and remove what no longer earns its place.
The Upshot
The German cases did not create a new law. They showed what the existing one costs when a court takes it seriously: four figures per person, no proof of distress needed, final on appeal. Meta has been the defendant so far. The legal groundwork for pointing at the website owner has been sitting there since 2019, and Meta's own terms already put the consent duty on your side of the table.
The fix is not expensive and it is not technical. Verify that your pixel waits for a yes. Verify that No actually means no. And if the pixel is only there out of habit, take it off and measure your site in a way that does not need anyone's permission. Ten minutes in a private browser window will tell you which of those conversations you need to have.
Frequently Asked Questions
Is the Meta Pixel illegal in Ireland?
No. The pixel itself is lawful when visitors give valid consent before it runs. The Data Protection Commission's guidance says pixel trackers generally require consent, and the problems in the German cases came from data being collected without it. A pixel that fires only after a clear Accept, and never after Reject, is the setup the rules expect.
Can a visitor sue my business over a Facebook pixel?
The route exists. Under the CJEU's Fashion ID ruling, a website that embeds Meta's tools can be a joint controller for collecting and sending the data, and section 117 of the Data Protection Act 2018 allows claims in the Irish courts, including for non-material damage. The German awards so far have been against Meta, and outcomes depend heavily on the facts, so take legal advice if you receive a complaint.
Does a cookie banner make my pixel compliant?
Only if the banner actually blocks the pixel until the visitor accepts. Many sites show a banner while the pixel loads anyway because the two were installed separately. Test it in a private browser window with Meta's free Pixel Helper extension before assuming you are covered.
Is the Conversions API safer than the pixel under GDPR?
It sends data from your server instead of the visitor's browser, which helps with ad blockers and data quality. It does not remove the need for a lawful basis to share that visitor's data with Meta, and the German rulings concerned Meta's Business Tools generally, not only the browser pixel.
How can I measure my Facebook ads without a pixel?
Add campaign tags to the links in your ads and read the results in a privacy-first analytics tool. You will see visits, sources and the pages people viewed without any cookie consent needed for the analytics itself. You lose Meta's automated optimisation, which matters mainly for businesses spending heavily on paid social.
Sources
- Saxony Ministry of Justice press release: Higher Regional Court Dresden rules against Meta over Business Tools, February 2026 (German)
- heise online: Wave of lawsuits foreseeable, €5,000 in damages due to Meta Business Tools
- Data Protection Commission: Guidance note on cookies and other tracking technologies
- IAB Europe: Case C-40/17 Fashion ID summary
- Matheson: Irish court awards €2,000 for non-material loss under the GDPR
Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.
More by Graeme Conkie →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
Google Lens Search: What the New Multimodal Filter Means for Your Business Website
Google Lens now handles billions of camera searches and Search Console tracks them. How to make your business website photos the match Google finds.
Google Business Profile Changes: Your Phone Number Is Not Only Yours to Control
Google Business Profile changes in September 2026 let strangers alter your listing and lean on your website as proof. What Irish owners should verify this week.
