Meta Restricted Categories: Ad Policy vs Data Source Restrictions

Summary / TL;DR
Meta maintains three separate policy layers that can restrict a health, pharmaceutical, or regulated-goods advertiser: Community Standards (platform-wide content rules), Advertising Standards (paid ad eligibility and creative rules), and data-source classification in Events Manager (restrictions on what event data your website can share). Each layer evaluates a different object, uses a different category list, and produces a different consequence.
An ad can pass review and continue to deliver clicks while Meta simultaneously classifies the destination domain and suppresses conversion events from that domain. These are two independent automated systems. Fixing ad creative does not restore suppressed events. Restoring events does not get a rejected ad approved.
Start with the interface that shows the problem. If an ad is rejected, the issue is in Ads Manager, and the fix is an ad-level correction. If conversion events are missing or suppressed, the issue is in Events Manager, and the fix is in your data architecture and event payloads.
What Are Meta Restricted Categories?
"Meta restricted categories" is a search term, not the name of one controlling policy list. Meta documents platform content rules, advertising rules, and data-source categories on different pages and inside different products.
Meta uses the word "category" across several of these systems. The repeated label causes advertisers to conflate ad eligibility, product rules, audience restrictions, and event-data controls into a single problem. Each system evaluates a different object and produces a different consequence.
An ad can pass review while Meta limits information sent from the destination website. A pharmaceutical advertiser can satisfy a creative rule while still needing product-specific authorization. A dental clinic may run a compliant lead ad while its dataset carries a Health & Wellness Provider category in Events Manager.
Meta applies three layers of policy to health, pharmaceutical, and regulated-goods advertisers. Each layer has its own category list, its own evaluation criteria, and its own enforcement mechanism.
Layer 1: Community Standards: The Platform-Wide Baseline
Community Standards govern content and behaviour across Meta technologies. Ads must comply with these standards before the advertising-specific rules are considered. The Restricted Goods and Services standard covers regulated and high-risk goods such as drugs, cannabis-derived products, prescription medicines and other controlled products.
Product eligibility under Community Standards is evaluated before the wording of a particular ad is reviewed. If the underlying good or service cannot be promoted under the applicable standard, compliant grammar and neutral creative cannot make the offer eligible.
THC, CBD, prescription medicines, over-the-counter medicines and general health information each have their own eligibility test. Whether a product can be promoted depends on jurisdiction, the product's legal status, age-gating requirements, certification and authorization requirements, and the advertiser's role (manufacturer, retailer, telehealth provider, educational publisher). A single business can have one product eligible and another prohibited.
Layer 2: Advertising Standards: The Rules for Paid Ads
Advertising Standards apply to paid placements. Meta reviews the ad's copy, image or video, promoted offer, landing page, and targeting configuration against these standards.
A product can be eligible under the Community Standards while a specific ad for that product violates an Advertising Standard. This happens regularly in health and pharmaceutical advertising for three reasons.
The personal attributes rule. Meta's ad policy prohibits copy that implies knowledge of a viewer's personal condition, disability, financial status, weight or other protected attribute. "Book an online consultation" describes a service. "Are you suffering from anxiety?" assigns a health condition to the viewer. The distinction is whether the copy describes what the business offers or implies something about the person seeing the ad.
If you are seeing ad rejections related to personal attributes, the issue is in your ad copy. The fix is rewriting the ad to describe the service without asserting that the viewer has a condition. For a guide on how to write compliant health and wellness ad copy, read: Why Meta Blocks Your Health and Wellness Ads
Weight-management and appearance advertising rules. Meta's health and wellness advertising guidance addresses negative self-perception, sensational outcomes, before-and-after imagery, and selected weight-related products. A compliant product still requires compliant creative execution. For the full guide to before-and-after image rules, read:
Pharmaceutical-specific authorization. Meta's Drugs and Pharmaceuticals Advertising Standard distinguishes prescription medicines, over-the-counter medicines, unsafe substances, and cannabis-derived products. Eligible online pharmacies and telehealth providers promoting prescription medicines need active LegitScript certification and Meta authorization. Pharmaceutical manufacturers may use the certification route or Meta's internal review process. Prescription-drug ads also carry country-level and adult-targeting requirements.
These requirements govern whether and how an ad can run. They are evaluated in Ads Manager. If an ad is rejected, the rejection message names which Advertising Standard was triggered.
Ad-policy evaluation is separate from data-source evaluation. The Advertising Standards do not evaluate what data a website sends to Meta through the Pixel or Conversions API. That is Layer 3.
Layer 3: Data Source Classification: The Restriction on Event Data
In Events Manager, Meta organizes data from websites, apps, and offline sources into datasets. Meta's automated system can classify a domain based on the topics, products, and services it finds on the website. When a classification is applied, Meta restricts what event data that domain can share through the Meta Pixel and Conversions API (CAPI, Meta's server-side event delivery system).
Meta does not send a notification through Ads Manager when a data-source classification is applied. The classification appears in Events Manager under Settings → Manage Data Source Categories. Ads can be approved and deliver clicks while the domain is classified and events are suppressed.
Why Meta classifies domains and restricts event data. When someone buys a product from a website, the pixel sends a purchase event to Meta. That event contains data: the product name, the URL, the content category, and custom parameters. If that product is called "Blood Sugar Support Formula" and the URL reads /products/blood-sugar-support-formula?category=diabetes-supplements, Meta can infer that this specific person, identified by email, phone number, or IP address through advanced matching, likely has a blood sugar condition. Under privacy regulations, that inference can constitute Protected Health Information that Meta is not permitted to receive.
Meta classifies domains and restricts event data to reduce its exposure to receiving information it cannot legally hold. The same logic applies across all data-source categories: financial service data implies someone's financial situation, political organization data implies political affiliation, trade union event data reveals union membership.
The data-source categories are a different list from the ad-policy categories
The Advertising Standards use categories like "Drugs and Pharmaceuticals," "Weapons," "Alcohol" and "Tobacco." The Events Manager data-source classification uses a different list.
As per Meta, the data-source categories are:
Economic vulnerability: associated with individuals experiencing personal economic hardship that impacts housing, food security or freedom
Financial service: provides financial tools, consultation, services or consumer credit reports
Health & wellness - other: associated with general health and wellness topics (pharmacy services, optician services, health insurance, weight management, GLP-1 supplements, meal replacement, weight-loss coaching)
Health & wellness condition: associated with one or more medical conditions or health statuses (cancer, anxiety, arthritis, addiction, substance-use disorders, suicide, self-injury)
Health & wellness provider: provides or facilitates access to healthcare providers, products or services (hospitals, clinics, urgent care, physicians, specialists, therapists, telemedicine, medications, testing, treatments, devices)
Nationality: associated with individuals of a specific citizenship status, immigration status or refugee status
Personal hardship: associated with individuals likely facing personal hardship
Politics: associated with a specific political party, political position or political issues
Race: associated with individuals of a specific race or ethnicity
Religion: associated with individuals with specific religious or spiritual beliefs and practices
Sexuality or gender identity: contains topics related to sexuality or sexual orientation, or caters to individuals of a specific gender identity
Trade union: associated with members of a trade union
Meta describes its published help-centre list as non-exhaustive. The live Events Manager interface remains the operational reference.
Categories that appear in the ad policy but not in the data-source list: Drugs and Pharmaceuticals, Weapons, Alcohol, Tobacco, Online Gambling, Endangered Species. A THC gummies business is restricted under "Drugs and Pharmaceuticals" in the ad policy, but in Events Manager, Meta classifies the domain or website selling THC under "Health & wellness", because the data-source system evaluates the health-related information the events carry, not the regulatory status of the product.
Categories that appear in the data-source list but not in the ad policy: Economic Vulnerability, Nationality, Personal Hardship, Politics, Race, Religion, Sexuality or Gender Identity, Trade Union. A political campaign or a trade union can have approved ads while their event data is restricted.
The two category lists exist because the two systems solve different problems. The ad policy controls what can be promoted. The data-source classification controls what personal information Meta receives through its tracking tools.
How the Three Health & Wellness Sub-Categories Differ
The Health & Wellness parent category splits into three sub-categories in Events Manager. Each one catches different businesses based on different signals.
Health & wellness - other covers general health and wellness topics without a condition-specific or provider-specific focus. Supplement brands, vitamin companies, weight management products, meal replacement sellers, pharmacy services, optician services, and health insurance providers typically receive this classification. A product named "Collagen Peptides" or "Daily Multivitamin" with a URL path like /products/collagen-peptides-30-day-supply signals health-adjacent content without implying a specific medical condition.
Health & wellness condition covers domains associated with one or more specific medical conditions or health statuses. Cancer support organizations, mental health services, diabetes management products, addiction recovery programs and arthritis supplement brands receive this classification. The distinction from "other" is that the event data can reveal which specific condition a person may have. A supplement brand can land in this sub-category if its product names or URL paths reference specific conditions: /products/blood-sugar-support-formula implies a condition in a way that /products/daily-multivitamin does not.
Health & wellness provider covers domains that provide or facilitate access to healthcare providers, services, or products. Medical practices, hospitals, dental clinics, urgent care centres, telemedicine platforms, therapist directories and medical device companies receive this classification. A dental clinic's booking page at /book-appointment?service=root-canal, a telemedicine platform showing /providers/psychiatrist/dr-smith or a hospital with /departments/oncology trigger this classification.
A single business can overlap multiple sub-categories. A telehealth company connects patients with providers (Provider), discusses specific diagnoses on landing pages (Condition), and may sell supplements through its shop (Other). The account's live Events Manager messages show which classification has been applied.
For a full breakdown of what each restriction level blocks and how data-sharing restrictions work, read:
The Side-by-Side Comparison
How to Determine Which System Is Causing Your Problem
How to check your data-source classification
Go to Meta Events Manager. Select the dataset or Pixel connected to your website. Open Settings. Scroll to Manage Data Source Categories.
If Meta has classified your domain, the assigned category, connected source, and restriction status are displayed here. Record the exact category name, the date, and take a screenshot.
Check the Diagnostics tab for "Event parameters blocked" (Meta has flagged specific parameters in your events) and "Your data is restricted" (Meta has placed your data source into Core Setup, which strips custom parameters and truncates URLs).
Run Test Events. Complete a controlled page view, lead or purchase on your website. Compare what your browser or server sends with what Events Manager displays. If events are missing or arriving without parameters, the data-source classification is actively restricting your event flow.
What Does Not Fix a Data-Source Restriction
Rewriting an approved ad. Ad edits affect the advertising review layer. They do not change an Events Manager classification or the event payloads a website sends to Meta. If ads are already approved and events are suppressed, the ad creative is in a different system from the problem.
Installing the Conversions API without reviewing the payload. The Conversions API changes the transport path from browser to server. Meta's data-sharing restrictions apply to the information received, regardless of delivery method. A server event containing content_name: "Testosterone Booster 90 Caps" and a URL path of /products/testosterone-booster?category=mens-health carries the same health-adjacent context as a browser pixel event. CAPI is the correct delivery infrastructure for the structural fix described below, but CAPI alone, without changing what the payload contains, sends the same restricted data through a different pipe.
Renaming the event while keeping descriptive parameters. Meta evaluates the full payload: URLs, content names, item categories, custom fields, and other values that can reveal a condition, service, or regulated product. An event called "conv_a" carrying a product name that implies a health condition is suppressed the same way a Purchase event would be. The event name is the least important variable in the payload.
Appealing an inaccurate classification. Meta provides a review route in Events Manager for categories that appear inaccurate. If the business genuinely sells health products, provides healthcare services, or operates in a regulated vertical, the classification reflects what is on the domain. Across the 75+ Meta ad accounts we reviewed, we found no documented case of a genuine health brand successfully reversing an accurate classification through Meta's built-in review.
Using a historical category list as a reference. Meta states that its published list is non-exhaustive. Interfaces and enforcement can change. Record the category options, restriction message, and date shown in the live account before making a production decision.
What Fixes Each Type of Restriction
Advertising-policy problems require an advertising-policy correction. Rewrite personal-attribute language. Remove prohibited creative. Correct the destination. Apply the required age or country targeting controls. Complete the applicable product authorization or certification. These changes are made in Ads Manager and affect the advertising review layer.
Data-source problems require a change in what information reaches Meta. The data-source classification reflects what Meta's automated system found on the domain. The restriction controls what event data Meta will accept from that domain. The fix is changing what event payloads contain so that Meta receives the conversion data it needs for optimization: that a real user converted, at a specific time, with a specific value, without the health-adjacent, condition-specific, or regulated context that triggered the classification.
For domains classified at Level 1 (Core Setup) and most Level 2 restrictions: Server-side payload cleansing on the existing domain. A server sits between the website and Meta. Every event passes through it before reaching Meta. The server strips the signals that triggered the restriction: product names that imply a health condition, URL paths containing restricted terms, content categories with condition-adjacent language, and non-standard custom parameters. Meta receives a clean, compliant payload. The conversion event goes through.
For domains classified at Level 3 (full domain restriction): A clean intermediary domain is required in addition to payload cleansing. This is a separate root domain with no restriction history and no restricted content. Ads point to this domain. The server captures session data on the clean domain, passes the user to the actual website, stitches the session across both domains using persistent identifiers (_fbp, _fbc, UTMs, click IDs), and sends a cleansed event to Meta from the unrestricted domain.
For domains where the domain name itself contains restricted terms (getslim.com, glp1clinic.com, semaglutidedirect.com): An intermediary domain is required regardless of restriction level. The restricted signal is in the domain string itself, which appears in every event URL.
For a full walkthrough of how this architecture works, including payload transformation examples, read: Purchase Events Blocked on Meta? Here's How to Fix It
Unrestrict by Zappush helps brands in Health & Wellness, Supplements, CBD & Hemp, THC & Cannabis, GLP-1, Med Spa, Telehealth, Sexual Wellness, and other restricted categories restore their conversion events on Meta. We review the complete signal path: the domain Meta evaluates, browser events, server events, URLs, parameters, identity fields, and the events that remain available for optimization.

