Email Tracking Pixels and EU Regulators: The 2026 Rules Explained
If you send marketing email to anyone in France, you have until July 14, 2026 to disclose your tracking pixels and give people a real way to turn them off. If you send to Italy, you have until October 28, 2026 to do the same. Miss either deadline and you are exposed to fines of up to €20 million or 4% of global turnover under the GDPR enforcement framework — the Italian Garante just used that power on April 20, 2026 to hit Poste Italiane with a combined €12.5 million penalty for unlawful tracking. The two regulators acted within three days of each other in April, and the rest of the EU is watching closely.
What changed is not the law. The ePrivacy Directive has covered tracking technologies since 2002, and the GDPR has applied to personal data since 2018. What changed is that two of the most active data protection authorities in Europe have now said the quiet part out loud: that invisible pixel in your newsletter footer is no different from a cookie, and your subscribers need to know it is there.
What Actually Changed in April 2026
Two regulators issued formal positions on email tracking pixels within three days. They reached almost the same conclusion through slightly different legal mechanisms.
France: The CNIL Recommendation
On April 14, 2026, the CNIL published a formal recommendation on tracking pixels in email. It was adopted internally on March 12, 2026 and released after a public consultation that ran through 2025. The recommendation is not technically binding in the way a regulation is, but it sets the standard the CNIL will use when it investigates complaints — which makes it effectively binding for any sender that wants to avoid enforcement action.
The core position: a tracking pixel placed in an email accesses information stored on the recipient’s device, which puts it inside the scope of Article 82 of the French Data Protection Act (the national implementation of the ePrivacy Directive). That means it requires the same kind of consent a tracking cookie would, with some narrow exceptions.
Three operational requirements stand out:
- Separate consent at signup. Consent to receive emails is not the same as consent to be tracked inside those emails. The two questions must be asked separately when an email address is first collected.
- Tracking-only opt-out in every email. Each marketing email must contain a link that lets the recipient stop tracking while continuing to receive emails. This is in addition to the unsubscribe link, not a replacement for it.
- Privacy policy disclosure. Your privacy policy must name the categories of data collected by pixels (open events, IP address, device type, timestamps) and the purposes for which it is processed.
The CNIL gave a grace period for existing subscribers. Anyone whose address was collected before April 14, 2026 can keep receiving tracked emails as long as they are notified about pixel use and given an opportunity to object by July 14, 2026. Addresses collected on or after April 14 must be covered by a compliant consent flow from the first email.
Italy: The Garante Guidelines
The Italian Garante moved three days later, on April 17, 2026, with Provision No. 284. The Italian text is binding rather than advisory — once published in the Official Gazette on April 29, 2026, it became enforceable law subject only to a six-month transition period that ends October 28, 2026.
The substance is very close to the French position. Pixels are treated as a form of access to terminal equipment. Consent must be prior, specific, freely given, and informed. Withdrawal must be granular — a recipient can choose to stop pixel tracking while continuing to receive emails, or stop both at once.
What is interesting about the Italian text is the list of carve-outs. The Garante named three situations where consent is not required:
- Anonymised aggregate counting. A single shared pixel used to count overall opens, with no per-recipient data retained, falls outside the rule. If you only care about the total open rate for a campaign and you can prove the pixel does not tie events to individuals, you do not need consent.
- Security and authentication. Pixels in account activation messages, password resets, and similar security flows are exempt.
- Mandatory institutional communications. Legally required notifications — for example, regulated banking communications or public health notices — are exempt.
How Tracking Pixels Actually Work
A tracking pixel is a 1×1 transparent image embedded in an email. The image URL is unique to each recipient, so when the email client loads it, the sender’s server records who opened the message, when, from which IP address, and on what device. Most major platforms also use the same trick on click links — every URL is rewritten through a redirect that logs the click before sending the user to the destination.
This is how every commercial email tool calculates open rates, drives “did open” or “did not open” automation triggers, populates re-engagement segments, and feeds engagement scores to deliverability heuristics. It is the load-bearing measurement layer underneath most modern email marketing.
It is also why the CNIL and Garante moved. None of this happens transparently to the recipient. There is no visible cookie banner before a marketing email loads, and most people have no idea their inbox is reporting back to a sender every time they open a message.
What You Actually Need to Do
If you send marketing email to French or Italian recipients, the work breaks into four discrete steps. Do them in order — the deadlines are real.
1. Audit Your Tracking
Open your email platform and list the tracking it does by default. Per-recipient open tracking is on by default in almost every tool. Click tracking is also on by default. Some platforms additionally track device, OS, and geographic location.
Decide what you actually use. If you only ever report aggregate open rates to a marketing director and do not run open-based automations, you can probably disable per-recipient tracking and rely on aggregate measurement. If you run re-engagement campaigns triggered by inactivity, you depend on per-recipient open data and you need to collect consent properly.
2. Update Your Signup Forms
Add a second, separate checkbox to every form that collects an email address:
- Box 1: “I agree to receive marketing emails from [Company].” (required, drives email consent)
- Box 2: “I agree that you may use tracking pixels to measure my email engagement.” (optional, drives pixel consent)
Box 2 must be unticked by default. The user must be able to subscribe without consenting to tracking. Your email tool must respect this and refrain from inserting pixels for those contacts.
3. Add a Tracking-Only Opt-Out Link
Every marketing email needs a footer link that disables tracking for the recipient without unsubscribing them. The wording the CNIL suggests is along the lines of “stop tracking my opens in future emails.” When clicked, this should flip a flag on the contact’s record that tells your sending system to omit the pixel from subsequent campaigns.
Some platforms handle this through a “preference centre” link. Others require a custom solution. Confirm what your tool supports before the July 14 deadline.
4. Update Your Privacy Policy
The policy must list:
- The technical mechanism (1×1 pixel embedded in HTML emails)
- The data collected (open events, timestamps, IP address, device type, email client)
- The purpose of processing (measuring engagement, triggering automations, list hygiene)
- The retention period for tracking data
- The legal basis (consent under Article 82 of the French DPA / corresponding Italian provisions)
- How to withdraw consent (the tracking-only opt-out link)
Tools That Make This Easier
A handful of email platforms are better positioned for the new rules than others — either because they are EU-based and already build consent flows into their forms, or because they make per-recipient tracking optional rather than mandatory.
Brevo
Brevo is a French company with EU data residency by default. Because its head office sits inside the CNIL’s direct jurisdiction, it has incentive to ship product changes that match the recommendation rather than ignore it. Brevo’s signup forms already support multiple consent checkboxes with separate purposes, and its preference centre lets recipients toggle tracking settings. It offers a signed DPA, double opt-in, and detailed consent record export.
Pricing starts around $9/month for the Starter plan, which removes Brevo’s free-tier daily send cap — check Brevo’s pricing page for current figures, as plan names have shifted recently. The weakness: Brevo’s automation builder is less expressive than ActiveCampaign’s, and its template library is smaller than Mailchimp’s. If you want sophisticated multi-branch journeys, it is not the strongest pick.
Brevo (Sendinblue)
The most approachable CRM suite
Brevo (formerly Sendinblue) stands out with its unique pricing model based on email volume rather than subscriber count. This makes it particularly attractive for businesses with...
MailerLite
MailerLite is headquartered in Lithuania, with data storage in the EU and ISO 27001 certification. Its signup forms support multiple consent purposes, and its unsubscribe page builder can be repurposed to host a tracking preference toggle. It is GDPR-ready out of the box, and the support team has historically been quick to ship features when EU regulation shifts.
Pricing starts at $12/month for the Comfort plan at 500 subscribers — verify on MailerLite’s pricing page, as figures vary by list size and billing frequency. The free plan covers up to 250 subscribers with 2,500 monthly emails. The weakness: MailerLite’s CRM functionality is thin, and customer support response times have drawn complaints in busier periods. It is not the right tool for a sales-led organisation that wants tight CRM integration.
MailerLite
Email marketing tools for growing businesses
MailerLite is known for its simplicity, affordability, and clean design. It's one of the best options for small businesses and beginners who want professional email marketing...
Postmark
Postmark is worth mentioning for a different reason: it lets you disable tracking entirely without breaking your sending. Many transactional and notification senders never needed pixels in the first place, and Postmark’s settings make it trivial to turn open and click tracking off at the account level. If you fall under the Italian “security and authentication” exemption — for example, you only send password resets and order confirmations — Postmark is the cleanest setup.
Pricing starts at $15/month for 10,000 emails. The weakness: Postmark is built for transactional and lifecycle email, not marketing campaigns. Its template library is minimal, there is no drag-and-drop builder for marketing newsletters, and segmentation features are basic. Pair it with a separate marketing tool if you do both kinds of sending.
Postmark
Transactional email with exceptional deliverability, now by ActiveCampaign
Postmark, originally built by Wildbit and acquired by ActiveCampaign in 2022, is a transactional email service laser-focused on deliverability and speed. It consistently achieves...
| Feature | Brevo (Sendinblue) | MailerLite |
|---|---|---|
| Rating | 4.5/5 | 4.6/5 |
| Starting Price | $9/mo | $12/mo |
| Free Plan | Up to 100,000 contacts, 300 emails/day | 250 subscribers, 2,500 emails/month |
| Founded | 2012 | 2010 |
| Email Templates | 60 | 90 |
| Integrations | 60 | 140 |
| Deliverability Rate | 96.5% | 97% |
| Marketing Automation | ✓ | ✓ |
| A/B Testing | ✓ | ✓ |
| Landing Pages | ✓ | ✓ |
| Segmentation | ✓ | ✓ |
| Drag & Drop Editor | ✓ | ✓ |
| SMS Marketing | ✓ | ✕ |
| Ecommerce Features | ✓ | ✓ |
| API Access | ✓ | ✓ |
| Multi-Language | ✓ | ✕ |
| Web Push Notifications | ✓ | ✕ |
| Live Chat | ✓ | ✓ |
| Advanced Analytics | ✓ | ✓ |
Common Mistakes to Avoid
Three patterns will get you in trouble even if you ship the cosmetic changes on time.
Treating tracking consent as bundled with email consent. A single checkbox that says “I agree to receive emails and analytics tracking” is not valid under either the CNIL recommendation or the Garante guidelines. The CNIL explicitly called this out. Each purpose needs its own affirmative action.
Hiding the tracking opt-out inside the unsubscribe page. The opt-out for tracking must be reachable from the email itself, not only after the user has clicked “unsubscribe.” If a recipient must initiate an unsubscribe to find the tracking toggle, the design fails the “easily withdrawn” standard both regulators set.
Assuming aggregate reporting equals anonymised tracking. The Italian exemption requires that data not be tied to individuals at the point of collection. A pixel that records a per-recipient open event into a database, even if the dashboard you look at only shows the total, is per-recipient tracking. The exemption applies to genuinely shared pixels with no individual linkage. If your tool’s audit log shows “user X opened campaign Y at 10:14 UTC,” you are not exempt.
How This Connects to Wider Compliance
The April rulings are part of a larger compliance posture that EU regulators have been building since GDPR took effect. Tracking pixels are now the most visible front, but the underlying expectations — explicit consent, granular withdrawal, transparent disclosure — are the same ones the GDPR has required for years. If you have a thin or vague privacy policy, the pixel issue is a signal to fix the wider document at the same time.
The deliverability angle matters too. The same authentication and list-hygiene work that keeps your emails out of the spam folder also demonstrates good faith to regulators reviewing a complaint. See our deliverability guide for the SPF, DKIM, and DMARC fundamentals — these are not strictly part of the pixel rules but they signal a properly run programme.
Senders that operate primarily transactional flows have an easier path. If your sending falls under the security and authentication carve-out, you can switch off tracking entirely with no business cost. Marketing senders need to do the harder work: redesign signup flows, add tracking-only opt-outs, refresh privacy policies, and re-permission the existing list before July 14.
For senders weighing whether to switch platforms in light of these rules, the relevant question is not “which tool is most GDPR-compliant” — most major platforms have adequate baseline compliance. The relevant question is “which tool gives me granular control over per-recipient tracking and supports multi-purpose consent at signup.” That narrows the field, and an EU-based provider with native consent tooling is the most pragmatic answer for most senders. See our best email marketing tools for small business roundup for the broader picture, and our Brevo vs MailerLite comparison if you are choosing between the two EU options above.
Brevo (Sendinblue)
The most approachable CRM suite
Free plan · from $9/mo
Sources
- CNIL — Pixels de suivi dans les courriers électroniques (Recommendation) — accessed 2026-07-23
- Garante Privacy — Provvedimento n. 284/2026 (Tracking Pixel Guidelines) — accessed 2026-07-23
- Brevo — Pricing — accessed 2026-07-23
- MailerLite — Pricing — accessed 2026-07-23
- Postmark — Pricing — accessed 2026-07-23
Related Articles
Email Marketing and GDPR: What You Need to Know
GDPR compliance for email marketing explained: consent rules, tracking pixels, lawful basis, and what changed after the ePrivacy Regulation was withdrawn.
How-ToDMARC's New Rulebook: What RFC 9989 Changes for Senders
The IETF replaced RFC 7489 with RFC 9989, 9990 and 9991 in May 2026. Here is what actually changed in DMARC, what didn't, and the records you should fix.
How-ToSPF, DKIM, and DMARC: The 2026 Email Authentication Setup Guide
Set up SPF, DKIM, and DMARC the right way for the 2026 bulk sender rules from Gmail, Yahoo, and Microsoft. A step-by-step guide with the exact DNS records.