ConsentPixel – Privacy · Verified

HomeBlogEmail Tracking › Email Tracking Consent
The Complete Guide

Email Tracking Consent: The Complete Guide (2026)

For years, the invisible pixel that tells you whether someone opened your email sat in a regulatory grey zone. In 2026 that zone closed. Email tracking consent is now the same legal question as cookie consent — and two European regulators have set the deadlines to prove it. Here's what changed, who it affects, and what to do.

By The ConsentPixel TeamUpdated July 202615 min readEmail Tracking pillar
Art. 5(3)
The ePrivacy rule behind cookie consent now applies to email pixels too
2 regulators
France's CNIL and Italy's Garante both ruled the same way, weeks apart, in April 2026
1×1 pixel
The invisible tracker in nearly every marketing email — now a consent decision

What email tracking consent means

Email tracking consent is a recipient's permission to be tracked when they open your email — specifically, permission for the invisible 1×1 tracking pixel embedded in the message to report that they opened it, when, and often from what device and location. It's the email counterpart to cookie consent on a website: the same kind of invisible tracker, the same kind of permission question, and — as of 2026 — the same legal rule.

Most senders never think of open tracking as a consent issue. It's on by default in nearly every email platform, and it's been standard practice for two decades. That's exactly what changed in 2026: regulators decided that the mailbox is an extension of a person's private space, and that quietly measuring what happens inside it needs permission — just like a cookie on a website. If you send marketing email to anyone in the EU, email tracking pixel GDPR questions are no longer theoretical.

The one-line version

If a pixel loads when someone opens your email and lets you identify who opened it, regulators now treat that exactly like a cookie — it needs prior consent. Open tracking isn't banned; it's reclassified. You can still track opens for people who said yes; for everyone else, you send a version of the email with no pixel.

What changed in 2026 — and why

In the space of a few weeks in April 2026, two of Europe's most active data protection regulators reached the same conclusion independently: an invisible pixel that reports when you opened an email is not meaningfully different from a cookie, and it needs the same consent.

FR
France — CNIL, Délibération n° 2026-042Adopted 12 March 2026, published 14 April 2026. Required senders to inform existing contacts and give them a chance to object by 14 July 2026; new contacts from 14 April needed compliant consent immediately.
IT
Italy — Garante, Provision No. 284Adopted 17 April 2026, published in the Gazzetta Ufficiale 29 April 2026. Six-month compliance window closing 28 October 2026 for pixels that identify individual recipients.

The critical thing to understand: this is not new law. The requirement to get consent before accessing a user's device has existed under the ePrivacy Directive since long before GDPR. What both regulators did in 2026 was remove the ambiguity — they publicly committed to a position and a date, which means there is no grace period to wait out and no "we didn't know the rules" defense left. The pixel didn't change; the enforcement clarity around it did.

Why this spreads beyond France and Italy

EU data protection authorities operate as a network and routinely cite each other's decisions. The legal principle both regulators applied — that a tracking pixel is "access to terminal equipment" under ePrivacy Article 5(3) — is identical under German, Dutch, Spanish, and every other EU member state's transposition of the same directive. France and Italy moved first; the logic already applies everywhere in the EU. Treat these two decisions as the leading edge, not the whole story.

The whole shift rests on one piece of law. Article 5(3) of the ePrivacy Directive — the same provision behind website cookie consent — requires prior consent before storing information on, or gaining access to information already stored in, a user's "terminal equipment" (their device). For years this was read as being about cookies. But in its Guidelines 2/2023 (finalized 7 October 2024), the European Data Protection Board confirmed the rule is technology-neutral: loading a tracking pixel is a form of "gaining access" to the recipient's device, the same operation the cookie rule governs.

That's the hinge. Once a pixel counts as device access, it falls under the same consent requirement as a cookie. France grounds this in Article 82 of its Data Protection Act; Italy in Article 122 of its Privacy Code — both national transpositions of the same ePrivacy Article 5(3). The technology is different; the legal treatment is now identical. For the deeper mechanics of how ePrivacy and GDPR stack on top of each other here, see our explainer on the ePrivacy two-layer consent problem.

Not sure what your site — or emails — track before consent?

ConsentPixel's free scanner shows exactly which trackers fire before consent on your website in about 10 seconds. The same prevention-first logic now applies to your email pixels.

Scan your site free →

Who this affects (almost every sender)

If you send marketing or promotional email to recipients in the EU — and your platform tracks opens — this affects you, regardless of where your business is based. The rules reach any sender whose recipients are in France or Italy, wherever the sender itself sits. That sweeps in a very wide group: eCommerce brands running newsletters, B2B companies sending campaigns, agencies managing client sends, nonprofits, and SMBs running a basic Mailchimp list. If open tracking is on — and it's on by default nearly everywhere — you're in scope.

A common and costly misconception is that B2B or cold outreach is exempt. It isn't — commercial prospecting emails to business contacts still involve personal data and device access. We cover that trap in detail in B2B & cold outreach email tracking consent.

Email tracking consent requirements for 2026

The email tracking consent requirements mirror what you already know from cookie consent. Valid consent for an email tracking pixel must be:

PriorObtained before the tracked email is sent — not inferred after the fact.
Specific & informedThe recipient knows their opens will be tracked and why — not buried in a privacy policy.
Freely givenThey can decline tracking and still receive the email. No forcing.
WithdrawableAs easy to withdraw as to give — Italy specifically requires granular withdrawal (opt out of tracking, keep the newsletter).
ProvableYou keep a record of who consented, when, and to what — the controller bears the burden of proof.

There's one notable difference in approach between the two regulators. Italy takes a more pragmatic line: tracking consent may be bundled with newsletter/marketing consent, provided the recipient is properly informed — but withdrawal must be granular, so someone can opt out of tracking while keeping the newsletter. France is stricter on the consent moment. When you serve both markets, design to the stricter standard.

What's exempt — and what isn't

Not every pixel needs consent. The line both regulators draw is about identification: a pixel that ties an open back to an individual recipient needs consent; genuinely anonymous, aggregate measurement is treated more leniently. The exemptions are narrow and specific:

Anonymised, aggregate open statistics (no individual identification)
Generally permitted — the Garante explicitly allows this
Strictly necessary to deliver the service the recipient requested
Exempt — narrow, e.g. confirming a transactional message displayed
Open tracking to measure campaign performance per person
Needs consent — this is the common marketing use
Building a profile of a recipient's interests / behaviour
Needs consent — profiling is squarely in scope

The transactional-vs-marketing distinction is where many senders get it wrong — an order confirmation is treated differently from a promotional newsletter, but the line is narrower than people assume. We unpack it in transactional vs marketing email tracking. And the "we'll just rely on legitimate interest" argument that many senders reach for does not work here — we explain why in the legitimate interest myth.

How to comply, practically

You don't need to panic, and you don't need to stop emailing. The practical path is straightforward once you know the shape of it:

Audit what you send

Find out whether open tracking is on (it usually is), which platform sets the pixel, and whether click tracking is also in play. You can't fix what you haven't inventoried.

Add a tracking consent moment

At signup, add a clear, specific opt-in for open tracking — separate and informed. For existing contacts, run a re-permission campaign before you rely on tracking them.

Send pixel-free to non-consenters

For recipients who haven't consented, send the same email with no tracking pixel. Most major platforms now support per-contact or per-send tracking toggles.

Log consent & honor withdrawal

Keep a record of who consented and when, and make withdrawal granular — opt out of tracking without losing the newsletter. Proof is your defense.

If you'd rather not manage pixel-level tracking consent at all, the cleanest option is often to switch off individual open tracking and rely on aggregate or click-based signals — the "pixel-off-first" approach several advisors recommend as minimum viable compliance. For the platform-by-platform how-to, see how to disable email open tracking.

The bigger picture: email is catching up to the web

Here's why this matters beyond two deadlines. The exact legal logic that created the website consent industry — ePrivacy Article 5(3), device access, prior consent — has now been pointed at email. A tracking pixel in an inbox and a cookie on a website are, in the eyes of the regulators, the same kind of thing: invisible technology accessing a person's device to watch what they do. The web had its consent reckoning years ago. Email is having its now.

For anyone who already manages website tracking consent, this is familiar territory arriving on a new surface — and the same prevention-first principle applies: don't fire the tracker until you have permission. See exactly how the two connect in tracking pixel vs cookie, and how this all traces back to the same wiretap-and-device-access logic behind CIPA and website tracking.

Deep dives: the full cluster

This guide is the hub. Each question below has its own detailed article:

Is email open tracking legal?

What the law actually says in 2026, jurisdiction by jurisdiction.

Read →

CNIL's pixel rules (France)

What senders had to do by 14 July 2026 — and what happens now it's passed.

Read →

Garante's pixel rules (Italy)

The 28 October 2026 deadline explained.

Read →

Tracking pixel vs cookie

Why email is catching up to the web — the bridge piece.

Read →

Key takeaways

Email tracking consent is now the same question as cookie consent. A pixel that identifies who opened your email is device access under ePrivacy Article 5(3), confirmed by EDPB Guidelines 2/2023 — it needs prior consent.

Two 2026 deadlines made it real. France's CNIL (14 July 2026) and Italy's Garante (28 October 2026) — but the underlying rule applies EU-wide, not just in those two countries.

It's not new law and there's no grace period to wait out. The consent requirement always existed; 2026 removed the ambiguity and the "we didn't know" defense.

You can still track — just get consent, or go pixel-free. Track opens for those who said yes; send a pixel-free version to everyone else. Aggregate, anonymised stats are treated more leniently.

Website consent, handled — email is next

ConsentPixel — Privacy · Verified blocks trackers before consent, honors opt-outs in real time, and logs every decision. See what fires before consent on your site free, then start a 14-day trial.

Start 14-day free trial → Scan a site free

No credit card required · from $8.99/domain/mo

CP
The ConsentPixel Team

We built our name on website tracking consent — CIPA, cookies, and the device-access rules behind them. The 2026 CNIL and Garante decisions extend that same logic to email, which is squarely our territory. This article is educational and is not legal advice; consult a qualified privacy professional for your specific situation.

Frequently asked questions

What is email tracking consent?

Email tracking consent is a recipient's permission to be tracked when they open your email — specifically, permission for the invisible tracking pixel in the message to report that they opened it, when, and often from what device. As of 2026, EU regulators treat this pixel like a cookie: it accesses the recipient's device, so under ePrivacy Article 5(3) it generally requires prior consent when it identifies an individual. Open tracking isn't banned, but tracking a named recipient's opens now needs their opt-in.

Do email tracking pixels really need consent under GDPR now?

Yes, in the EU, when the pixel identifies an individual recipient. The legal basis is ePrivacy Article 5(3), which requires consent before accessing a user's device — and the European Data Protection Board confirmed in its Guidelines 2/2023 that loading a tracking pixel counts as such access. France's CNIL (Délibération 2026-042) and Italy's Garante (Provision No. 284) both applied this in 2026. It's technically an ePrivacy requirement rather than GDPR itself, but GDPR's definition of valid consent and its penalties apply on top. Genuinely anonymous, aggregate open statistics are treated more leniently.

What are the 2026 email tracking deadlines?

Two so far. France's CNIL set 14 July 2026 as the date by which senders had to inform existing contacts and give them a chance to object to pixel tracking; contacts collected from 14 April 2026 onward needed compliant consent immediately, with no grace period. Italy's Garante set a six-month window closing 28 October 2026 for pixels that identify individual recipients. Both dates flow from the same ePrivacy logic, and because EU authorities cite each other, other member states are expected to follow — so these are leading indicators, not isolated national rules.

Does this apply to my business if I'm not in France or Italy?

If you send tracked email to recipients in France or Italy, yes — the rules apply based on where the recipient is, not where the sender is based. And because both decisions rest on ePrivacy Article 5(3), which every EU country has transposed, the same legal principle already applies across the EU; France and Italy simply moved first with explicit guidance and deadlines. If you email anyone in the EU and your platform tracks opens, treat this as applying to you and design to the strictest standard.

Can I still track email opens at all?

Yes. Open tracking is reclassified, not banned. You can track opens for recipients who have given consent; for those who haven't, you send the same email with no tracking pixel. Genuinely anonymised, aggregate statistics that don't identify individuals are treated more leniently by the regulators. Many senders adopt a "pixel-off-first" approach — disabling individual open tracking and relying on aggregate or click-based signals — as the simplest way to reduce exposure while they build compliant consent flows.

Scroll to Top