Enhanced Conversions and Advanced Matching are similar technologies introduced by Google and Facebook. They support the operation of tracking codes by feeding them 1st party data. Naturally, the question arises whether such technologies are lawful under the GDPR.
Witold Wrodarczyk (Adequate) talks with attorney-at-law Agnieszka Grzesiek-Kasperczyk (MyLo law firm).
[WW] When using Enhanced Conversions and Advanced Matching, which send the user’s encrypted personal data to Google/Facebook, is consent to Facebook cookies enough, or are additional consents needed?
[AG-K] Let’s first establish what the data transfer process actually looks like with these technologies.
[WW] Let’s recap how the Facebook pixel works:
- When a link to our site is clicked on Facebook (e.g. in an ad or a post), a click identifier — fbclid — is appended to the URL. This identifier lets Facebook identify the person who clicked, so it constitutes pseudonymized personal data.
- This identifier is then read by our site through the Facebook pixel code it contains. It is thereby assigned to the identifier of a corresponding 1st party cookie (our site’s own cookie, accessible only to our site).
- Then, when the user takes an action on our site (opens a subpage, clicks an element marked as an event), our site — using the pixel code — reads the data from that 1st party cookie and sends Facebook the information that the user associated with that cookie identifier and fbclid performed specific actions (e.g. visited a given URL, bought a product, etc.).
- Facebook compares the received identifier with its own database, and on that basis knows what its users are doing on the web — and counts conversions for Facebook Ads advertisers.
The Facebook pixel transmits information about on-site activity linked to identifiers that constitute pseudonymized personal data, because Facebook can associate them with a specific user.
So every site that has the Facebook pixel implemented and uses Facebook cookies processes identifiers that constitute pseudonymized personal data — even though only Facebook can identify a specific person from those identifiers. Is that GDPR-compliant?
[AG-K] In the process you described, our website is a kind of “gateway” through which personal data flows to Facebook. Admittedly, only Facebook can “read” (decrypt) this data, so it is personal data for the owner of the social network. Nevertheless, according to the CJEU judgment of June 5, 2018, in this situation the website owner is jointly responsible for the process of collecting personal data (since it is their website that serves as the collection tool) and is responsible for the fact that this data is transferred to Facebook.

It can be assumed that consent to marketing cookies, together with appropriate information about them, is a sufficient legal basis for the data processing process described above.
Remember that this must be opt-in consent — meaning the Facebook pixel doesn’t transmit data linked to the user identifier before consent is obtained. The second requirement is describing the whole process sufficiently clearly (in plain language a typical internet user can understand). If we don’t take care of that, the consent won’t be informed.

On the other hand, the user also accepts Facebook’s terms of service, so they should be aware from there that the owner of that platform may collect information about their online activity not only within the social network itself, but also elsewhere on the web. Here too, the condition is informing users clearly and simply.
But Advanced Matching is a somewhat different process, right?
[WW] If we use Advanced Matching, then at the moment a conversion occurs, an additional identifier is sent to Facebook — created from the user’s personal data provided to our site, e.g. the contact details given when placing an order or logging in.
We don’t, however, send Facebook the email address or phone number as such. This data is irreversibly encrypted (through so-called hashing), which makes the identifier anonymous. But if Facebook has that person in its database, it will be able to link it to the user and to all the information it holds about them.
So we’re dealing with the transfer to Facebook of an identifier constituting pseudonymized personal data — which, unlike in the classic operation of the Facebook pixel, comes not from the fbclid identifier or a Facebook cookie, but from data the user provided on the site.
Google’s Enhanced Conversions works analogously:

[AG-K] If I understand correctly, through Advanced Matching Facebook collects the same kind of information (that a given user of theirs performed some action on some website) — it’s just that the order of the user’s actions is different?
With fbclid: the user is first on Facebook, clicks a link there (receiving the identifier at that moment), lands on our website, and then Facebook receives information about that user’s actions on our site.
With Advanced Matching: the user has a Facebook account, but may not have visited the platform for a long time, or may never have had any contact with our brand there. The user visits our website (so far with no connection to Facebook at all) and provides an email address that happens to be the address assigned to their Facebook account. At that moment, Facebook learns about that user’s actions on our website.
Is that right?
[WW] Yes. There are even more similarities, because matching the fbclid with the identifier of the “classic” Facebook cookie can also happen when the user first visits our site directly, and then visits again by clicking through from Facebook — at which point Facebook learns it wasn’t their first visit.
Moreover, the Facebook pixel also creates a 3rd party cookie. Unless our browser blocks it, that cookie simply allows our earlier visit to the site to be associated with a later Facebook login, with no need to pass the fbclid identifier at all.
With Advanced Matching, the encrypted personal data is sent to Facebook regardless of whether the person has a Facebook account. Our site, after all, doesn’t know whether we use Facebook. However, since the encryption is irreversible, Facebook won’t be able to read this data unless it already holds it. Furthermore, to process this data, Facebook is obliged to hold the appropriate consents, which we grant by accepting Facebook’s terms.
Only Facebook — provided it has that person in its database — will be able to link them to the user and to all the information it holds about them.
Advanced Matching is in a sense independent of cookies; in particular, it makes it possible to attribute the conversions of a user browsing in incognito mode — provided they log in to Facebook with the same email address they gave on the website.
Still, the nature of both processes is similar — it consists in sending Facebook a unique identifier that Facebook can link to our data, provided we use Facebook ourselves.
[AG-K] So it can be said that Advanced Matching and Enhanced Conversions perform a function very similar to classic Facebook tracking. Through an identifier constituting pseudonymized personal data, activity from our website gets attributed to a specific Facebook user.
As I said earlier, processing such data requires the user’s active consent. The user should also be able to read about how their data is processed before consenting. In my opinion, we can achieve this using the same consent window we use to obtain consent for Facebook cookies.
[WW] Except Advanced Matching as such doesn’t use cookies…
[AG-K] That doesn’t matter here. User consents cover the use of cookies or “other similarly operating technologies”. Telecommunications law says consent is needed for “storing information on the user’s device” or “gaining access to information” on the user’s device. So it doesn’t matter how the technology works — what matters is that information is obtained. Collecting opt-in consents isn’t about cookies as such, but about acquiring information, and, along the way, about processing personal data by these means.
The nature of Advanced Matching and Facebook cookie tracking is similar — it consists in sending Facebook a unique identifier that Facebook can link to our data, provided we use Facebook ourselves. Consent for this can be collected using the same consent window we use to obtain consent for Facebook cookies.
I’ll add that even if we weren’t collecting personal data via cookies (or other technologies), we would still need consent. That follows from telecommunications law. The consent requirement only exempts so-called necessary cookies (or other technologies) — necessary for the site to work, for security, for providing the service, for carrying out the data transfer itself, and so on.
[WW] So should we collect consent for cookies, or for the processing of personal data?
[AG-K] For Advanced Matching? I’d venture to say: neither. We don’t collect cookie consent, because — as you said — this technology doesn’t use them. We could use the words “consent to the processing of personal data” — but that won’t be sufficient.
The user must give informed consent, meaning they must know exactly what they’re agreeing to. So it all comes down to properly informing them about how this data is processed. I recommend using simple, even non-legal language — free of marketing and technology jargon too. We should explain to the user as to a layperson: what information about them we want to obtain, and what we intend to do with it.
For example, for Advanced Matching I might propose wording like this:
On our website you may sometimes provide personal data (e.g. an email address or phone number), for instance when making a purchase in our store. We may transform this data into an irreversibly encrypted identifier, which we may send to Meta Platforms (Facebook). If you are a user of that platform, Facebook will attribute your activity on our website to you. This data may then be used, in accordance with Facebook’s terms, for statistical and marketing purposes.
The site must also ensure that for people who don’t consent, the Advanced Matching and Enhanced Conversions functions are not activated. I assume this is technically possible?
[WW] Yes — the simplest way is to just block the Facebook pixel and Google codes from sending data when there’s no consent. In other words, the consent management system must block the tracking scripts from running, not merely the cookies themselves. That’s exactly how well-configured consent management systems work.
[AG-K] To sum up: Enhanced Conversions and Facebook’s Advanced Matching are GDPR-compliant, provided the system of consents for cookies and other similar technologies is implemented correctly. Correctness is required both on the formal side — fulfilling the information obligation and obtaining informed consent — and, of course, on the technical side of the consent management implementation. Whoever implements the consent management platform must make sure the system genuinely respects the user’s preferences.
Enhanced Conversions and Facebook’s Advanced Matching are GDPR-compliant, provided a consent management system is implemented correctly both formally and technically.
[WW] Thank you — I think this will clear up many doubts about using these important technologies.