Email best practices

Tracking pixel in the EU: what you need to know and to do

France and Italy have published new recommendations regarding the way emails sent from and to people living in these countries can be tracked.
Image for Tracking pixel in the EU: what you need to know and to do

If you’re sending emails in the European Union and/or to European based contacts, you might have read that the regulation regarding the tracking of email open rates is evolving in some countries, notably Italy and France. Here’s all you need to know and to do to stay compliant, and avoid costly fines.

What are the European recommendations on email tracking pixels?

Following public consultations, France’s data protection authority, CNIL, and its Italian counterpart, Garante per la protezione dei dati personali (shortened to Garante) have published its final recommendation on tracking pixels in emails in April 2026. Both these independent agencies have regulatory powers to protect the data privacy of the individuals and companies in their respective countries. They are, for example, the enforcers of the GDPR, and have the power to issue fines if the regulations they overview are not respected. They can also produce recommendations on regulations, depending how the European laws are evolving. That’s the case here, with this new recommendation regarding tracking pixels in emailing.

What are tracking pixels?

Tracking pixels are tiny (1×1) invisible images embedded in emails that reveal when a message has been opened, via a unique identifier in the image filename. Use of tracking pixels in emails has grown steadily, driven by uses like personalizing communications, measuring audience engagement, and checking deliverability. They are the key to measure email open rates.

But because email is a private, personal space, CNIL says this raises distinct privacy concerns. This assumption has been reinforced by a rising number of complaints the authority has received on the topic. This is also an extension of the guidelines 2/2023 of the European Data Protection Board (EDPB), notably regarding cookies and trackers acceptance by users.

What does the new recommendation say?

This new recommendation doesn’t create any new law, but precise existing regulation, and falls within rules derived from the ePrivacy Directive, in addition to any GDPR requirements applicable to the subsequent processing of personal data. You now need to get prior approval from your recipients to be able to track when they open your emails. So in addition to the opt-in checkbox your recipients have to check to consent to receive your emails, an additional opt-in checkbox for them to consent to their email behavior to be tracked is now needed. Here are the general rules to stay compliant:

  • Prior consent is required unless a specific exemption applies (see below).
  • Recipients must be clearly informed that tracking pixels are being used.
  • The purpose of the tracking must be clearly defined and explained.
  • Only information necessary for the stated purpose should be collected.
  • Consent must be free, specific, informed, unambiguous, and demonstrable.
  • Recipients must be able to withdraw consent easily.
  • The requirements applicable to the tracking pixel are separate from those applicable to sending the email.

In the end, these are the GDPR regulations, extended to your ability to track the email activity of your recipients. That’s why these recommendations apply to any organization, public or private, that uses tracking pixels in emails, plus the technical service providers they rely on.

Still, there are a few exemptions. You don’t necessarily need consent to tracking individual email activity if:

  • You want to identify inactive recipients.
  • You want to adjust sending frequency.
  • You stop sending to inactive recipients.
  • You are cleaning or maintaining the contact database.

Though, note that you will need to demonstrate that the information is strictly limited to these activities.

What about transactional emails?

Most of the recommendation impacts marketing emails. That doesn’t mean transactional emails are not impacted. Even if consent to receive transactional emails is implied because they are triggered after a specific action from the recipient, the consent for these emails to be tracked is not. So you might need additional tracking consent here too.

What are the risks of not being compliant?

The recommendations are still fresh, so no fine has been applied yet for not following the rules. Though, since it is an extension of the GDPR, the same regulations can be applied. That means, depending of the gravity of the infraction:

  • An up to €10 million fine, or 2% of the firm’s worldwide annual revenue from the preceding financial year, for the less severe infrigements.
  • An up to €20 million fine, or 4% of the firm’s worldwide annual revenue from the preceding financial year, if the infrigement is more serious.

How does Sinch Mailjet help you to stay compliant

Sinch Mailjet has always been a spearhead in the emailing industry when it comes to compliancy, data privacy and data protection. This is why our teams are working hard to deliver the tools that will allow you to easily add the needed opt-in checkboxes to your forms, guaranteeing that the subscribers consent to their individual email behavior to be tracked. Furthermore, the ability to anonymize individual data will soon appear on your dashboard. That means you’ll still be able to track the global performance (open rates, click rates…) of your campaigns, but won’t be able to know which specific recipient opened.

Go beyond the open rate

One last thing. We know that the open rate has been the gold standard to measure the performances of your email campaigns, from the very beginning of email marketing. Though, in the last decade, the proliferation of open bots initiated by Apple when the company decided to preemptively automatically open all the emails received in an Apple Mail inbox, to guarantee better security for their users, made the open rate less and less reliable.

So far, the new CNIL recommendations only impact open rates. That’s why we recommend to shift your focus to click and engagement rates, which are, in the end, way more important to your activity. Because, even when emailing was less constrained by regulation, if everybody opened your email but nobody clicked on your CTAs, the campaign was somehow a failure. What is (and has always been) important when it comes to emailing, is the how these messages you are sending convert into revenues.