Skip to main content Skip to footer

Your emails are being tracked. Europe is taking notice.

That tiny image sitting quietly inside an email could soon become a bigger issue for marketers.

For years, email tracking pixels have been a routine part of digital marketing. Usually, invisible to the recipient, these small pieces of code help brands see whether an email has been opened and understand campaign performance. They can also improve deliverability and, increasingly, help tailor future communications based on individual behaviour.

But regulators across Europe are taking a closer look at what happens behind the scenes when that pixel loads.

In 2026, both France and Italy introduced clearer rules around email tracking pixels, signalling a shift towards treating them more like cookies and other tracking technologies. For marketers, the message is becoming harder to ignore: an email being opened is not necessarily just another campaign metric. It can involve accessing information on a recipient's device and monitoring their behaviour. 

France: Consent takes centre stage

In April 2026, France's data protection authority, the CNIL, published its final recommendation on tracking pixels in emails, following a public consultation. The recommendation, adopted on 12 March, clarifies how Article 82 of the French Data Protection Act applies to this technology. 

The basic principle is straightforward: tracking pixels generally require prior consent unless a specific exemption applies.

This is particularly relevant when pixels are used to measure campaign performance, personalise communications, understand recipient interests or build profiles for marketing purposes.

Importantly, the CNIL makes a distinction between sending an email and tracking what happens after it lands in someone's inbox. In other words, a recipient may have consented to receive an email without having automatically consented to being tracked when they open it.

There are limited exceptions. For example, the CNIL allows certain individual-level deliverability measurements for emails linked to a requested service, such as identifying inactive recipients so they can be removed from mailing lists. However, the data must be limited to what is strictly necessary and used only for that deliverability purpose. Transactional emails such as order confirmations, shipping notifications, password resets and security alerts can also fall within specific exemptions.

The CNIL has also taken a pragmatic approach to existing databases. For email addresses collected before the recommendation was published, organisations have three months to inform recipients clearly about the use of tracking pixels. They must also provide an easy way for recipients to object.

Italy: A similar direction, with a clear deadline

Italy has taken a similarly firm position.

On 17 April 2026, the Italian Garante adopted dedicated guidelines on tracking pixels in email communications, published in the Official Gazette on 29 April. The guidelines explain that tracking pixels can amount to accessing information stored on a user's device, bringing their use within the country's implementation of the ePrivacy rules.

The Garante highlights just how much information a seemingly harmless pixel can reveal. Depending on how it is configured, it can indicate whether a specific recipient has opened an email. It may also provide information such as their IP address, device type, access time and the number of times the message has been opened. 

As a result, prior consent is generally required when pixels are used to measure campaign performance or analyse customer behaviour. The same applies when they are used to personalise communications, support profiling or enable targeted marketing.

Again, exemptions exist for certain strictly necessary activities, including transmitting a communication or providing a service explicitly requested by the user. The Garante also emphasises transparency, user control and privacy by design.

With a six-month compliance period following publication, organisations operating in Italy have until late October 2026 to adapt their practices.

What this means for marketers

The bigger story is not simply that two European regulators have introduced new guidance. For marketers, the traditional assumption that an email open is simply a harmless performance metric is becoming harder to sustain. Open tracking, behavioural segmentation and profiling may all need to be reassessed. The same applies to automated journeys triggered by individual engagement, particularly where they rely on tracking without explicit consent.

This could mean rethinking consent journeys, preference centres and CRM configurations. It may also require changes to marketing automation, reporting dashboards and even the KPIs teams use to measure email performance.

It may also push brands towards a healthier question: how do we create meaningful engagement without needing to observe every interaction?

As privacy expectations continue to evolve, the strongest customer engagement strategies may be the ones that do more than comply. They make tracking transparent, give people genuine control and build value through relevance rather than relying on invisible observation.

For agencies and brands alike, the email pixel may be tiny. The strategic implications are anything but.

Want to explore the bigger picture?

Email tracking is just one example of how privacy, data and technology are reshaping customer engagement. Explore our digital and martech work to see how we help brands navigate these changes and turn emerging challenges into opportunities.

For a deeper dive, read the full article on our Insights page and explore what these developments could mean for your CRM and customer engagement strategy.

Simplify your marketing execution and increase your performance

By

adm Indicia