What tracking pixels are running on your site? You already promised someone an answer.

Your browser will show you most of the pixels on your site. The harder part is that UAE law says you owe visitors that list before you process anything.

By Bracketworks
· 9 min read

Ninety seconds, and that is not the hard part

Open your homepage, press F12 (Cmd+Option+I on a Mac) and click Network. Right-click the column headers to add Domain, then reload and sort by it. Everything that is not your own domain is a third party you are handing your visitors to. Most people open that panel expecting a short list and close it having stopped counting.

Two kinds of tag slip past that first pass. Server-side tagging can be served from your own domain, on a subdomain or on a path of the main site, and Google calls the path its best practice. Those requests pass the domain test while the server behind them routes the data on to a vendor, so question any first-party request you cannot account for. And tags waiting on a consent banner only appear once a visitor accepts it, so accept the banner and reload again.

That is the whole detection method, and it costs less time than reading this paragraph. Which is awkward, because nearly every article written on this subject treats finding the pixels as the interesting part: scanner tools, browser extensions, comparison tables of scanner tools, all of it solving a problem you did not have.

Here is the problem you do have. Somewhere on your site is a privacy notice that names the third parties you share data with. Somebody wrote that list, and it was probably accurate on the day it was written. Under UAE law it is closer to a filing than a formality. The list in that notice and the list in your Network tab have almost certainly drifted apart, and nobody on your team currently knows by how much.

One thing to set aside first. The usual argument for cleaning this up is page speed, and it is the argument that loses. Tell a marketing director that removing a retargeting pixel saves 300 milliseconds and they will pay the 300 milliseconds without blinking, correctly, because the audience is worth more than the fraction of a second. Treat speed as a side effect here. The reason to do the work sits somewhere else entirely.

What you will actually find

Nobody sits down and chooses a set of pixels. They arrive in layers, one era at a time, which is why the Network tab reads less like a configuration and more like a core sample.

The oldest layer is whoever built the site: a tag manager container, a hard-coded gtag that predates it and still fires alongside it, a Meta Pixel installed during the build because it was on the checklist. Above that sits the campaign layer, a LinkedIn Insight Tag from a lead-gen push or a TikTok Pixel from the quarter somebody wanted to try TikTok. Then the experiment layer, the most personal of the four, because every item in it is somebody’s good idea that stopped being anybody’s job. Hotjar. Clarity. A chat widget from a vendor trial. And underneath all of it the platform layer, which nobody chose at all: analytics that shipped with the theme, an app that brought its own tracking, a payment provider’s fraud script.

The scale is not exotic. In the HTTP Archive’s 2025 Web Almanac, around 90% of pages load third-party resources, and the median page makes 79 third-party requests on mobile. Requests run higher than vendors, and the median site is somebody else’s site. But if your instinct is that a tidy marketing site carries three or four third parties, that instinct is calibrated to a web that no longer exists.

The mechanism that keeps the pile growing is the handover. Access to the CMS transfers when a site changes hands. Access to the ad accounts transfers, sometimes. The list of what fires on page load transfers approximately never, because it was never written down in the first place, and the incoming team inherits a page they cannot describe.

Three questions that decide whether a pixel stays

The obvious question is whether a pixel is firing correctly. Ask that one second. A pixel firing perfectly into an account nobody has opened since 2023 is still a leak, and a well-maintained one.

Start instead with the question that has no technical answer. Who reads this data, by name? Not which department. A person. If the answer takes more than ten seconds you have found something, and skipping this question is how a site ends up with four analytics tools and one analyst.

The second is cheaper to ask and easier to get wrong. What breaks if it is gone? Sometimes the honest answer is a retargeting audience that takes ninety days to rebuild, which is a real cost and a good reason to keep it. Sometimes the answer is nothing at all, and it takes asking to find out.

The third is the one that matters legally, and no scanner will answer it for you. What is it sending?

Existence is not behaviour

A scanner tells you the Meta Pixel is present. It does not tell you whether advanced matching is on, and those are different facts about your site.

With advanced matching enabled, the pixel reads customer information from your page, hashes it with SHA-256, and sends it alongside the event so Meta can match the visitor to an account. Meta’s developer documentation lists what that covers: email, first and last name, phone number, gender, birthdate, city, state, zip, country and your own customer ID. The hashing is real protection, and it leaves the substance intact. A tool your team files under conversion counting is a customer-data pipe, and the difference is a toggle in Events Manager whose state nobody is ever prompted to record. Meta documents the mechanism and the toggle but publishes no default, so do not assume yours. Go and look.

Session recorders sit in the same category with a different edge. The major ones suppress form input by default, which is the right default and the reason this gets less scrutiny than it deserves. The exposure is in the exceptions. Where a tool lets you unmask a field, one can get unmasked to debug a checkout, and the exemption stays in place until somebody removes it. Masking aimed at input fields also leaves the text your page renders outside them. Microsoft Clarity ships in Balanced mode, which masks numbers and email addresses in that text and still leaves a customer’s name and most of their address readable on an order confirmation or account page.

Then the placement question, duller and more damaging. Tags loaded through your tag manager respond to consent only if they are configured to. Google’s own tags have consent checks built in, but a non-Google tag whose consent setting was never touched runs none of its own. Tags hard-coded into the template fire on page load, before the banner renders, regardless of what the visitor is about to click, unless something higher in the template intervenes. That can be a consent platform that blocks scripts automatically or, for Google’s own tags, a consent-mode default. Neither arrives on its own, so check that your template has one. Hard-coded tags are also invisible to anyone auditing the container rather than the page. If you want the layer below this, the container itself is where that audit lives.

You have already published the list

The UAE’s Federal Decree-Law No. 45 of 2021 gives a data subject the right to obtain, among other things, “targeted sectors or establishments with which his/her Personal Data is to be shared, whether inside or outside the State.” That is Article 13(1)(d), and on its own it would be a response obligation, something you handle when asked.

Article 13(2) is the one that changes the work. In all cases, it says, the controller shall, before starting the processing, provide the data subject with the information in paragraphs (b), (d) and (g). Paragraph (d) is the list of entities you share data with. Before starting the processing. Not on request.

So the deadline on that list has already passed. It was owed to the visitor before the first pixel fired. And if your privacy notice names five vendors while your Network tab shows twenty-seven, that gap is not untidiness. It is a disclosure that does not match the processing.

Article 7(4) sits beside it, requiring the controller to keep a record of the categories of personal data held, who may access it, the purposes of processing, and the cross-border movement of that data, produced to the Data Office on request. That record is not constructible from a site whose tag inventory nobody has run. You cannot describe where data goes if you cannot say what is sending it.

The Gulf does not answer this with one voice, and the difference matters more than the similarity. Saudi Arabia’s PDPL and its Implementing Regulations came into force in September 2023, the one-year transition period ended in September 2024, and SDAIA has been enforcing since. If you take Saudi traffic, this is live today.

The UAE decree-law came into force on 2 January 2022. Article 28 gave the Cabinet six months to issue the executive regulations, and Article 29 then gives controllers six months from that issuance to regularise their status. Those regulations are years overdue and still unpublished, which supports a comfortable reading that the clock has not started. Read Article 13(2) again, though. The duty to tell people who receives their data sits in the decree-law itself, in force for four years, rather than in the regulations that explain how to comply with it.

Notice what this does to the shape of the job. Elsewhere a pixel inventory is maintenance, the kind of task that loses to everything else on the list. Here it is a document you already owe and cannot currently produce. That is a different priority.

What to remove this week, and where to stop

Take the list from your Network tab and cut three categories without much ceremony. Start with anything that failed the named-owner question. Then the tags pointing at platform accounts nobody can log into, which surface the moment you ask who reads them. Last, the duplicates: two copies of the same measurement double-count conversions that a paid team is about to optimise against, and the second copy earns nothing.

Then stop, because the failure on the other side is real and gets discussed far less. Do not remove a tag somebody reconciles against until you have spoken to them. Ripping out the script finance uses to tie web orders back to the ledger is a worse outcome than three dormant pixels, and it is the kind of mistake that ends pixel-cleanup projects permanently. Slow is fine here. The pixels have been there for years and they will survive a week of asking.

For everything that stays, write down who owns it and what it is for. Then adopt one rule going forward: anything you add gets a deprecation date at the moment you add it. A pixel with a review date is a decision. A pixel without one is sediment.

Cutting the pile is a longer job than counting it, and the full reduction workflow covers what each category of third party costs you and when replacing pixels with server-side measurement earns its keep. If the numbers coming out the far end are what brought you here, the property configuration matters as much as what fires into it, and GA4 ships with defaults aimed at somebody else’s business. The seven systems behind your reporting run wider than either.

Our free Site Audit checks whether your tracking is present and sane. It will not hand you a vendor-by-vendor inventory. That part is the Network tab, ninety seconds, and a list of names you either can or cannot produce.

Standing offer

The hard part is deciding what to do first

Bring us a URL, an audit report, or a proposal you're not sure about. We'll tell you which problems deserve budget this quarter, and you'll leave with an order of operations you can hand to whoever does the work, whether that's us or not.

Book twenty minutes