Skip to main content

X (Twitter) Ads GDPR Compliance: A Guide for EU Businesses

How to run X Ads in the EU without GDPR or DSA trouble: consent for the X Pixel and Conversion API, what Restricted Data Use really does, sensitive targeting rules and X's EU cases.

Team Adverizeo11 min read

Illustration: a feed of posts with a promoted post and a warning shield
On this page

X Ads GDPR compliance for EU businesses rests on three things: consent before the X Pixel or Conversion API sends anything about a visitor, targeting that never relies on sensitive data, and a clear view of X's own regulatory position in the EU. X (formerly Twitter) gives advertisers the tools, but its policies put the legal work on you. This guide covers the X Pixel, the Conversion API, custom audiences, Restricted Data Use, and what the Digital Services Act and the open EU proceedings against X mean for your campaigns, as of October 2026.

1. What X itself requires from advertisers

X's Policies for Conversion Tracking and Custom Audiences are short and clear. If you use these products on a website, you must:

  • give visitors legally sufficient notice that you work with third parties to collect data for conversion tracking and interest-based ads, including the storing and accessing of cookies;
  • obtain legally sufficient consent for those activities;
  • tell visitors how to opt out of X's interest-based advertising, including through an opt-out mechanism X specifies.

The same policy bans custom audiences and conversion events built on sensitive information, bans ads that assert or imply knowledge of personal or sensitive information, and bans using these products on any site or app directed to children under 13. A note on names: older guides talk about "Tailored Audiences". X's current policy pages use "Custom Audiences", and the website retargeting lists built from pixel data are called Website Activity Audiences.

X's help centre also says plainly that it cannot give legal guidance and that you should check notice and consent requirements with your own counsel. Use of its conversion tracking tools is subject to X's Conversion Tracking Program terms. In the EU, the X service is provided by X Internet Unlimited Company, an Irish company, which the European Commission lists as the provider of X under the DSA.

The X Pixel replaced the older Universal Website Tag and Single Event Tag. X recommends moving to it, and its Restricted Data Use guide still shows code for the legacy tags. The setup lives in X Ads Manager:

  1. Sign in at ads.x.com, open Tools and choose Events Manager. If you have no pixel yet, choose Add event source.
  2. On the install page, decide on the Allow first-party cookies checkbox, which is ticked by default. When it is ticked, the pixel stores the X click ID (twclid) from your landing page URL in a first-party cookie, so conversions on later pages can be matched. That is storage on the visitor's device, so it belongs behind your consent banner.
  3. Install the base code on every page and event code at key actions such as purchase or sign-up. Configure your consent tool or tag manager so that neither fires until the visitor accepts marketing cookies.
  4. If page URLs can reveal sensitive information (for example a clinic's appointment path), set twq('set', { hide_page_location: true }); before the init or config call. X documents this setting for exactly that purpose.
  5. Test with X's Pixel Helper and your browser's developer tools: refuse cookies, browse, and confirm that no request reaches X.

In the help pages we reviewed, X does not describe a consent-mode signal like Microsoft's ad_storage or Google's Consent Mode. For EU traffic, that leaves blocking as the reliable method: no consent, no pixel. Our cookie consent guide for European SMEs covers banner design, and the consent management implementation guide covers tag blocking.

X's Conversion API sends conversions from your server instead of the browser. It needs at least one identifier: the X click ID (twclid), an email address or phone number hashed with SHA-256 (phones in E.164 format first), or an IP address or a user agent. X does not accept either of these two on its own: each must come with a second identifier, which can be the other one. A conversion_id lets X remove duplicates when the pixel and the API report the same conversion.

Moving tracking to the server does not change the legal analysis much. The click ID still arrives through a tracking link, and the EDPB treats tracking links and pixels as falling under Article 5(3) of the ePrivacy Directive. The hashed email is still personal data, because its purpose is to match a real X user. Send API events only for visitors who consented, and describe the data sharing in your privacy notice. Our article on server-side tracking and GDPR goes into detail.

X's Restricted Data Use (RDU) parameter lets you ask X to limit how it uses an individual conversion event to certain business purposes on your behalf, such as measurement. On the pixel you set restricted_data_use: 'restrict_optimization' (the default is 'off'), either on the base code or on single events. On the Conversion API you add restricted_data_use to each conversion object.

X leaves it to advertisers to decide when to use RDU, for example per user after an opt-out signal, or by region where certain laws apply, and it warns that RDU can hurt reach and performance. For EU visitors, RDU does not replace consent: the pixel still runs and still reads or stores data on the device. Treat it as an extra limit, for example when a visitor accepts measurement but later objects to personalised advertising, and document the logic you choose.

5. Settings table for EU campaigns

Tool or settingWhereGDPR and DSA action
X Pixel base codeTools > Events ManagerFire only after marketing consent. Migrate any legacy UWT or Single Event Tags.
Allow first-party cookiesPixel install pageStores the click ID on the device. Keep it behind consent.
hide_page_locationPixel codeSet to true if URLs can reveal health, finance or similar details.
Restricted Data UsePixel or Conversion API parameterOptional extra limit. Not a substitute for consent.
Conversion APIX Ads APISend events only for consenting visitors. Hash email and phone with SHA-256.
Custom audiences (lists)Audience ManagerConfirm your legal basis and notice before uploading. No lists built on sensitive data.
Website Activity AudiencesAudience ManagerOnly populated from consented pixel data. Exclude sensitive pages.
Keyword and interest targetingCampaign targetingNo keywords or exclusions that stand in for sensitive categories.

6. Targeting: sensitive categories, minors and your own liability

X's Targeting of Sensitive Categories policy forbids targeting on: alleged or actual commission of a crime, health, negative financial status, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, gender identities other than cisgender, political affiliation or beliefs, trade union membership, and genetic or biometric data. It explicitly includes keyword targeting, and it bans reaching an audience under 13. The EU adds two rules on top. DSA Article 26(3) bars online platforms from showing ads based on profiling that uses special categories of personal data. DSA Article 28(2) bars profiling-based ads to users the platform knows with reasonable certainty are minors.

The risk for advertisers is that a policy existing on paper does not make your targeting lawful. Three cases show how it plays out:

  • In December 2023, noyb filed a GDPR complaint with the Dutch data protection authority. It alleged that X let an EU Commission campaign include or exclude users by keywords linked to political views and religious beliefs.
  • On 13 December 2024, the European Data Protection Supervisor reprimanded the Commission for that campaign. noyb reports that the EDPS held the Commission, as the advertiser and controller, fully liable for the unlawful targeting.
  • On 14 July 2025, nine civil society groups filed a joint DSA complaint with the Digital Services Coordinators of France, Germany and the Netherlands. They cited ads from large brands and a media company that used targeting and exclusions linked to politics, sexual orientation, religion and health.

Two practical lessons follow. First, exclusions count: the Commission campaign the EDPS reprimanded worked largely by excluding users interested in keywords such as "Brexit" or the names of party leaders, and it was still treated as unlawful use of data about political views and religious beliefs. Second, X must keep a public ad repository under DSA Article 39, and that repository must show whether an ad was targeted and the main parameters used, including exclusions. The 2025 complaint was built on research into that repository. Assume your keyword lists will be read by outsiders. Our GDPR retargeting guide covers lawful audience building in more depth.

7. X's regulatory situation in the EU, as of October 2026

X has been designated a very large online platform since 25 April 2023, which brings the strictest DSA duties. The main matters that affect advertisers:

DateAuthorityMatterStatus
5 Dec 2025European CommissionFirst DSA non-compliance decision: EUR 120 million fine for the deceptive blue checkmark, an ad repository lacking transparency and access, and failing to give researchers access to public data.Decided
16 Jul 2026European CommissionX's action plan on the ad repository and researcher access accepted, with six months to implement and a later audit. The European Board for Digital Services found the audit measures, and so the plan overall, insufficient, and the Commission says it will monitor progress closely.Implementation running
26 Jan 2026European CommissionNew investigation into the Grok features on X, and extension of the December 2023 investigation into recommender systems.Investigation opened
11 Apr 2025Irish Data Protection CommissionGDPR inquiry into the use of EU users' public posts to train Grok models.Inquiry opened
17 Feb 2026Irish Data Protection CommissionGDPR inquiry into non-consensual intimate or sexualised images of real people, including children, created with Grok and published on X.Inquiry opened

None of these decisions stops a business from advertising on X. They concern X's own duties. For you they mean two things: expect the ad repository to become more detailed and easier to search as X implements its action plan, and make brand-safety decisions with these open investigations in mind.

Common mistakes

  • Loading the X Pixel on page load for everyone and relying on the privacy policy alone.
  • Treating Restricted Data Use as a way to track EU visitors without consent.
  • Sending Conversion API events for visitors who refused cookies, on the theory that server-side data is different.
  • Using exclusion keywords linked to parties, religions or health topics "just to reduce wasted spend".
  • Uploading a customer list without checking legal basis and marketing objections.
  • Leaving sensitive details in URLs that the pixel reads.
  • Copying old guidance about "Tailored Audiences" without checking X's current policy pages.

Checklist: what to do this week

  1. Refuse cookies in a clean browser, browse your site, and confirm no request goes to X.
  2. Replace any legacy Universal Website Tag or Single Event Tag with the X Pixel.
  3. Decide on the Allow first-party cookies setting and keep it behind consent.
  4. Add hide_page_location where URLs can reveal sensitive data.
  5. Gate Conversion API events on the stored consent state.
  6. Review every keyword, interest and exclusion list against X's sensitive categories and DSA Article 26(3).
  7. Make sure no campaign uses profiling to reach under-18s.
  8. Add X, the opt-out instructions and the purposes to your privacy and cookie notices.
  9. Write down your RDU rules, if you use RDU at all.

For the rules that apply across all platforms, read the complete guide to GDPR-compliant marketing for European SMEs, and compare this list with our LinkedIn Ads GDPR guide if you run both.

Where Adverizeo fits

Pixel consent and audience settings live in your website and in X Ads Manager, so Adverizeo does not touch them. Adverizeo writes ad copy for X and 23 other channels within each channel's limits and gives every text ad a compliance score from 0 to 100 with suggestions. The score is a risk check, not a legal guarantee, so X's rule against ads that imply knowledge of a reader's health, finances or beliefs still calls for a human read of every line. See how it works on our GDPR page, try the free GDPR ad checker, or create a free account.

This article is general information, not legal advice.

Frequently asked questions

Is it still legal for EU businesses to advertise on X?

Yes. The European Commission's DSA decision and the open investigations concern X's own obligations as a very large online platform. They do not ban advertising on X. Your duties stay the same: consent for tracking, a legal basis for any customer data you upload, and no targeting based on sensitive data or aimed at minors through profiling.

Does Restricted Data Use make the X Pixel GDPR-compliant?

No. Restricted Data Use limits how X may use a conversion event, but the pixel still runs in the visitor's browser and reads or stores data there. Under the ePrivacy rules that needs consent first. Use RDU, if at all, as an extra restriction on top of consent.

Can I upload my customer email list to X as a custom audience?

Only if you have a lawful basis for that use, your privacy notice tells customers their data may be used for advertising on X, and you have removed people who objected to direct marketing. X's policy also forbids custom audiences built on sensitive information, so a list such as the patients of a clinic is off limits.

Who is responsible for X in the EU?

X Internet Unlimited Company, based in Ireland, provides the X service in the EU and is the company the European Commission lists for DSA purposes. The Irish Data Protection Commission has opened GDPR inquiries into it in April 2025 and February 2026.

Comments

Log in to join the discussion.

Loading comments...

Related articles

Check your next ad before it goes live.

Paste an ad into the free GDPR ad checker for a compliance score and flagged issues. No account needed.