Email Tracking Pixels and EU Regulators: The 2026 Rules Explained
France’s transition period for existing subscribers ended on July 14, 2026. Italy’s ends six months after the Garante’s guidelines were published in the Official Gazette on April 29, 2026, which puts it at the end of October 2026 (commentators give October 28 or 29; the Garante’s text states a relative period, not a calendar date). If you send marketing email to people in either country, you are already past one deadline and close to the other.
The two regulators acted within three days of each other in April 2026. The CNIL published its recommendation on April 14, and the Garante adopted its guidelines on April 17. Fines for breaching these rules fall under the GDPR and national ePrivacy enforcement framework, where the GDPR ceiling is €20 million or 4% of global turnover. Neither regulator has announced a pixel-specific fine as of October 5, 2026.
What changed is not the law. The ePrivacy Directive has covered tracking technologies since 2002, and the GDPR has applied to personal data since 2018. What changed is that two of the most active data protection authorities in Europe have now said the quiet part out loud: that invisible pixel in your newsletter footer is no different from a cookie, and your subscribers need to know it is there.
What Actually Changed in April 2026
Two regulators issued formal positions on email tracking pixels within three days. They reached almost the same conclusion through slightly different legal mechanisms.
France: The CNIL Recommendation
On April 14, 2026, the CNIL published its recommendation on tracking pixels in email. The text was adopted on March 12, 2026, after a public consultation the CNIL opened in June 2025. A recommendation is not a law, but it sets out how the CNIL reads Article 82 of the French Data Protection Act (the national implementation of the ePrivacy Directive), and that is the reading it will apply in complaints and controls.
The core position: a tracking pixel inserted in an email reads information on the recipient’s device, so it needs the same prior consent as a tracking cookie, unless an exemption applies. The CNIL’s FAQ says the recommendation applies to all emails regardless of sender type or recipient, and to organisations outside France that target French users.
What the recommendation asks for:
- Consent that is independent of email consent. The CNIL says the consent regime for pixels is separate from the one for sending the email itself. It recommends collecting pixel consent at the moment the email address is collected, with a short description of each purpose and a link to more detail. A single global “accept” is allowed if the recipient can still choose per purpose at a second level.
- Silence is a refusal. Consent must be a positive act, so a recipient who does nothing has not consented.
- Withdrawal from every email. The CNIL recommends a unique link in the footer of each email that lets the recipient withdraw pixel consent without further steps, and withdrawal must be as easy as giving consent. Future emails must stop firing the pixel.
- Recorded choices. Record a recipient’s choice for at least six months to avoid asking again too soon (a recommended minimum in the FAQ).
Two uses can run without consent, according to the recommendation. Pixels used only for authentication security are exempt. So is individual open measurement used for deliverability, but only if you limit it to what is strictly necessary to reduce frequency or stop sending to inactive recipients, and the email was requested by the recipient or relates to a requested service. The CNIL says that in principle you should keep only the date (not the time) of the last known open, overwritten on each new open. Cart-abandonment emails are promotional, so they do not qualify as transactional.
The July 14 transition. For addresses collected before April 14, 2026, senders could keep using pixels if they sent clear, accessible information within three months of publication (in principle) and let recipients object to pixels in future emails. That window closed on July 14, 2026. The FAQ states that a sender who informed late has to obtain consent or stop using pixels that require it. Where you already had to ask for fresh consent to use an address (for example, passing it to a new partner for prospecting), you need valid pixel consent for that address regardless.
After the deadline. The CNIL published its FAQ and a webinar replay for pixel suppliers on July 22, 2026, eight days after the deadline. On the pages reviewed on October 5, 2026, the CNIL has not announced a pixel sanction or a formal notice. Its public page says it will support professionals in the coming months, with verification and corrective measures to follow where needed.
Italy: The Garante Guidelines
The Italian Garante adopted its Guidelines on the use of tracking pixels in email communications on April 17, 2026 (Provvedimento n. 284). They were published in the Official Gazette (Series Generale n. 98) on April 29, 2026, and give organisations six months from that publication to comply. That is the late-October 2026 deadline; this is the one still ahead of you.
The substance is close to the French position. Pixels count as access to the recipient’s terminal equipment, so consent must be given before the pixel fires. Withdrawal must be granular: a recipient can stop pixel tracking while continuing to get the emails, or stop both. The Garante suggests a standardised icon or a footer link for this.
One real difference from France: the Garante says consent to tracking can, in principle, be part of the broader consent to receive promotional emails, as long as the request is worded neutrally. France recommends collecting pixel consent as its own choice. If you send to both countries, the separate-choice design satisfies both.
The Garante names three situations where consent is not required:
- Anonymised statistical measurement. Statistical counting that uses anonymised data is exempt. If you can show that the data is not tied to individual recipients, you do not need consent.
- Security and authentication. Pixels used in authentication processes, such as account activation or password changes, are exempt.
- Mandatory institutional communications. Legally required notifications are exempt.
The Garante also recommends privacy by design: use non-sequential, unintelligible identifiers linked internally to email addresses, and keep the email address itself out of the tracking requests.
The Poste Italiane fine is a different case. On April 20, 2026, the Garante announced fines on Poste Italiane and Postepay. That decision (n. 237 of April 17, 2026) concerned the BancoPosta and Postepay mobile apps, which required users to allow monitoring of data on their devices, including installed and running apps. It was not a tracking pixel case. Poste Italiane announced it would appeal. On July 17, 2026, the Court of Rome issued a precautionary order suspending the decision’s enforceability, and the Garante has temporarily removed the decision from its website while the opposition proceedings are pending. So Italy has issued guidelines on pixels but, as far as the Garante’s published pages show, has no pixel-specific fine yet.
How Tracking Pixels Actually Work
A tracking pixel is a 1×1 transparent image embedded in an email. The image URL is unique to each recipient, so when the email client loads it, the sender’s server records who opened the message, when, from which IP address, and on what device. Most major platforms also use the same trick on click links: every URL is rewritten through a redirect that logs the click before sending the user to the destination.
This is how every commercial email tool calculates open rates, drives “did open” or “did not open” automation triggers, populates re-engagement segments, and feeds engagement scores to deliverability heuristics. It is the load-bearing measurement layer underneath most modern email marketing.
It is also why the CNIL and Garante moved. None of this happens transparently to the recipient. There is no visible cookie banner before a marketing email loads, and most people have no idea their inbox is reporting back to a sender every time they open a message.
What You Actually Need to Do
If you send marketing email to French or Italian recipients, the work breaks into four steps. For France, the transition window has closed, so if you skipped it, steps 2 to 4 are overdue. For Italy, you have until the end of October 2026.
1. Audit Your Tracking
Open your email platform and list the tracking it does by default. Per-recipient open tracking is on by default in almost every tool. Click tracking is also on by default. Some platforms additionally track device, OS, and geographic location.
Decide what you actually use. If you only ever report aggregate open rates to a marketing director and do not run open-based automations, you can probably disable per-recipient tracking and rely on aggregate measurement. If you run re-engagement campaigns triggered by inactivity, you depend on per-recipient open data and you need to collect consent properly.
2. Update Your Signup Forms
The CNIL recommends collecting pixel consent when you collect the address. A practical layout is two separate choices:
- Box 1: “I agree to receive marketing emails from [Company].” (required to subscribe)
- Box 2: “I agree that you may use tracking pixels to measure my email engagement.” (optional)
Box 2 should be unticked by default, and a person must be able to subscribe without ticking it. The CNIL treats inaction as refusal. Your email tool must then leave pixels out of emails to that contact, which many platforms cannot do per contact, so check this before you rely on it. For Italy, a single neutrally worded consent can cover both under the Garante’s text, but the separate box satisfies both regulators.
3. Add a Tracking Withdrawal Link
The CNIL recommends a unique link in the footer of every email that lets the recipient withdraw pixel consent without entering their address again. Clicking it should flip a flag on the contact so your sending system omits the pixel from later campaigns. The Garante suggests a footer link or a standardised icon for the same purpose.
Some platforms handle this through a preference centre. Others need a custom solution. Confirm what your tool supports.
4. Update Your Privacy Policy
The CNIL says you are not required to describe exempt pixels, but recommends doing so for transparency. For pixels that need consent, the information you give at the point of consent has to cover each purpose in plain language. Your privacy policy should also cover:
- The technical mechanism (1x1 pixel embedded in HTML emails)
- The data collected (open events, timestamps, IP address, device type, email client)
- The purposes (measuring engagement, triggering automations, deliverability)
- The retention period for tracking data
- The legal basis (consent under Article 82 of the French Data Protection Act, or the corresponding Italian provisions)
- How to withdraw consent
Tools That Make This Easier
A handful of email platforms are better positioned for the new rules than others: either because they are EU-based and already build consent flows into their forms, or because they make per-recipient tracking optional rather than mandatory.
Brevo
Brevo is a French company, so it sits directly inside the CNIL’s jurisdiction. It has published a help-centre article on the CNIL pixel recommendation (we could not load it past Brevo’s bot protection on October 5, 2026, so check what it says about per-contact tracking controls before you rely on them). Ask Brevo specifically whether you can suppress the pixel for contacts who did not consent, and whether you can add a withdrawal link to every template.
Pricing starts around $9/month for the Starter plan, which removes Brevo’s free-tier daily send cap. Check Brevo’s pricing page for current figures, as plan names have shifted recently. The weakness: Brevo’s automation builder is less expressive than ActiveCampaign’s, and its template library is smaller than Mailchimp’s. If you want sophisticated multi-branch journeys, it is not the strongest pick.
Brevo (Sendinblue)
The most approachable CRM suite
Brevo (formerly Sendinblue) stands out with its unique pricing model based on email volume rather than subscriber count. This makes it particularly attractive for businesses with...
MailerLite
MailerLite is headquartered in Lithuania, so it is an EU provider. We have not verified how its forms and unsubscribe pages handle a separate pixel-consent choice or a tracking-only withdrawal link, so test those two features before you commit.
Paid plans start at $12/month (Comfort, monthly billing). See MailerLite’s pricing page for current figures by list size. The free plan covers up to 250 subscribers with 2,500 monthly emails. The weakness: MailerLite’s CRM functionality is thin, and customer support response times have drawn complaints in busier periods. It is not the right tool for a sales-led organisation that wants tight CRM integration.
MailerLite
Email marketing tools for growing businesses
MailerLite is known for its simplicity, affordability, and clean design. It's one of the best options for small businesses and beginners who want professional email marketing...
Postmark
Postmark works differently: open tracking is off unless you turn it on, either per email (the TrackOpens property) or for a whole server in its settings. Many transactional and notification senders never needed pixels in the first place. If you only send password resets and order confirmations, you can simply leave open tracking off and have nothing to consent to.
Pricing starts at $15/month for 10,000 emails. The weakness: Postmark is built for transactional and lifecycle email, not marketing campaigns. Its template library is minimal, there is no drag-and-drop builder for marketing newsletters, and segmentation features are basic. Pair it with a separate marketing tool if you do both kinds of sending.
Postmark
Transactional email with exceptional deliverability, now by ActiveCampaign
Postmark, originally built by Wildbit and acquired by ActiveCampaign in 2022, is a transactional email service laser-focused on deliverability and speed. It consistently achieves...
| Feature | Brevo (Sendinblue) | MailerLite |
|---|---|---|
| Rating | 4.5/5 | 4.6/5 |
| Starting Price | $9/mo | $12/mo |
| Free Plan | Up to 100,000 contacts, 300 emails/day | 250 subscribers, 2,500 emails/month |
| Founded | 2012 | 2010 |
| Email Templates | 60 | 90 |
| Integrations | 60 | 140 |
| Deliverability Rate | 96.5% | 97% |
| Marketing Automation | Yes | Yes |
| A/B Testing | Yes | Yes |
| Landing Pages | Yes | Yes |
| Segmentation | Yes | Yes |
| Drag & Drop Editor | Yes | Yes |
| SMS Marketing | Yes | No |
| Ecommerce Features | Yes | Yes |
| API Access | Yes | Yes |
| Multi-Language | Yes | No |
| Web Push Notifications | Yes | No |
| Live Chat | Yes | Yes |
| Advanced Analytics | Yes | Yes |
Common Mistakes to Avoid
Three patterns will get you in trouble even if you ship the cosmetic changes on time.
Hiding the tracking purposes inside email consent. A single checkbox that says “I agree to receive emails and analytics tracking” does not meet the CNIL’s expectation that the purposes of the pixels are described to the recipient before they choose, and the CNIL says the pixel consent regime is independent of the email one. The Garante is more permissive and allows pixel consent to sit inside promotional consent if the wording is neutral. Design for the stricter French rule if you send to both countries.
Hiding the tracking opt-out inside the unsubscribe page. The CNIL recommends withdrawal through a link in the footer of each email, on a page that needs no extra steps. If a recipient must start an unsubscribe to find the tracking toggle, the design fails the “as easy to withdraw as to give” standard.
Assuming aggregate reporting equals anonymised tracking. A pixel that records a per-recipient open event, even if the dashboard you look at only shows the total, is per-recipient tracking. The CNIL’s FAQ says that collecting user-agent or IP data removes the exemption even if you anonymise it right afterwards. If your tool’s log shows “user X opened campaign Y at 10:14 UTC,” the Italian anonymised-statistics exemption does not cover you.
How This Connects to Wider Compliance
The April texts apply to pixels the same expectations (explicit consent, granular withdrawal, transparent disclosure) that the GDPR has required for years. If you have a thin or vague privacy policy, the pixel issue is a signal to fix the wider document at the same time.
The deliverability angle matters too. The same authentication and list-hygiene work that keeps your emails out of the spam folder also demonstrates good faith to regulators reviewing a complaint. See our deliverability guide for the SPF, DKIM, and DMARC fundamentals. These are not strictly part of the pixel rules but they signal a properly run programme.
Senders that operate primarily transactional flows have an easier path. If your sending falls under the security and authentication carve-out, you can switch off tracking entirely with no business cost. Marketing senders need to do the harder work: redesign signup flows, add a tracking withdrawal link, refresh privacy policies, and collect consent from existing Italian subscribers, or inform them and let them object, before the end of October (France’s window has closed).
For senders weighing whether to switch platforms in light of these rules, “which tool is most GDPR-compliant” is the wrong question, since most major platforms have adequate baseline compliance. The better question is “which tool gives me granular control over per-recipient tracking and supports multi-purpose consent at signup.” That narrows the field. Ask each vendor those two questions directly. See our best email marketing tools for small business roundup for the broader picture, and our Brevo vs MailerLite comparison if you are choosing between the two EU options above.
Brevo (Sendinblue)
The most approachable CRM suite
Free plan · from $9/mo
Sources
- CNIL — Pixels de suivi dans les courriers électroniques (public page, April 14, 2026) — accessed 2026-10-05
- CNIL — Recommandation relative aux pixels de suivi dans les courriers électroniques (adopted March 12, 2026) — accessed 2026-10-05
- CNIL — Questions-réponses sur la recommandation pixels (July 22, 2026) — accessed 2026-10-05
- Garante Privacy — Provvedimento del 17 aprile 2026, Linee guida sui tracking pixel (n. 284) — accessed 2026-10-05
- Garante Privacy — Provvedimento n. 237 del 17 aprile 2026 (Poste Italiane / Postepay), suspended by Court of Rome order of July 17, 2026 — accessed 2026-10-05
- Brevo — Pricing — accessed 2026-07-23
- MailerLite — Pricing — accessed 2026-10-05
- Postmark — Pricing — accessed 2026-10-05
- Postmark — How do I enable open tracking? — accessed 2026-10-05
Related Articles
Email Marketing and GDPR: What You Need to Know
GDPR compliance for email marketing explained: consent rules, tracking pixels, lawful basis, and what changed after the ePrivacy Regulation was withdrawn.
How-ToEmail Marketing and CAN-SPAM: What US Senders Need to Know
The US CAN-SPAM Act lets you email without opt-in, but penalties reach $53,088 per violation. Learn the required elements, the opt-out rules, and who's liable.
How-ToGmail Deleted Your Reputation Score: A Postmaster Tools v2 Playbook
Gmail removed Domain and IP Reputation from Postmaster Tools in 2026. Here is how to diagnose deliverability problems using Compliance Status and your own data.