The ePrivacy "Two-Layer" Consent Problem, Explained Simply
Why is email tracking consent so confusing? Because two different laws apply to the same pixel at the same time — and they don't work the same way. Understand the ePrivacy directive email tracking two-layer structure and every other rule in this space suddenly makes sense. Here it is, without the legalese.
What this covers
Why two layers exist
Most confusion about email tracking consent comes from treating it as one legal question when it's really two. When your email's tracking pixel loads on a recipient's device, it triggers two separate laws simultaneously: the ePrivacy Directive (which governs accessing the device) and GDPR (which governs handling the personal data that results). They stack. They have different requirements. And crucially, they apply in a specific order. Once you see the two layers, the rules that seem contradictory — "you need consent" but "GDPR has six lawful bases" — stop conflicting, because they're describing different layers.
Two laws, stacked: the pixel's device access (ePrivacy) sits on top of the data processing (GDPR), and is checked first.
Layer 1: ePrivacy Article 5(3) — accessing the device
The first layer governs a narrow but critical act: storing information on, or gaining access to information in, a person's terminal equipment (their device). That's what loading a tracking pixel does. ePrivacy Article 5(3) requires consent for this, with only a narrow "strictly necessary" exemption. There is no legitimate-interest option at this layer. The EDPB confirmed in its Guidelines 2/2023 (finalized 16 October 2024) that pixel loading is exactly this kind of device access. This is the layer that catches email tracking — and it's checked before anything else.
Layer 2: GDPR Article 6 — processing the data
Once a pixel has fired and produced data (this recipient opened at this time on this device), using that personal data is governed by GDPR. GDPR Article 6 offers six lawful bases for processing — consent, contract, legal obligation, vital interests, public task, and legitimate interest. This is the layer where legitimate interest actually lives. So the statement "GDPR lets you use legitimate interest" is true — for this second layer, the data-processing layer. It says nothing about whether you were allowed to fire the pixel in the first place.
Why the order matters
The two layers apply sequentially, and that sequence is the whole game. You must satisfy Layer 1 first: did you have consent (or a strictly-necessary exemption) to access the device? Only if yes do you get to Layer 2: what's your GDPR basis for using the data? If you fail Layer 1, Layer 2 is irrelevant — you never lawfully obtained the data to process. This is why "I have a legitimate interest in measuring engagement" doesn't rescue an unconsented pixel: it's a Layer 2 answer to a Layer 1 problem. We unpack that specific mistake in the legitimate interest myth — this article explains the architecture; that one applies it to the LI confusion specifically.
The same two layers govern your website
Website cookies and pixels sit under the identical ePrivacy-over-GDPR structure. ConsentPixel's free scanner shows what fires before consent in ~10 seconds.
Scan your site free →Lex specialis: why ePrivacy wins where they overlap
A reasonable question: if GDPR allows legitimate interest and ePrivacy demands consent, which governs the pixel? The answer is a legal principle called lex specialis — where a specific law and a general law both apply, the specific one prevails. ePrivacy is the specific law for device access and electronic communications; GDPR is the general data-protection law. So for the act of accessing the device, ePrivacy's consent rule wins over GDPR's more flexible bases. GDPR doesn't disappear — it governs the data once lawfully collected — but it can't override ePrivacy's consent requirement for the access itself. This is the technical reason the two layers don't simply collapse into "just use GDPR."
What happened to the ePrivacy Regulation
You may have heard that an ePrivacy Regulation was coming to replace the aging Directive. For years it was expected to modernize and unify these rules across the EU. That effort was withdrawn in 2025 after failing to reach agreement — which means the 1990s-era ePrivacy Directive remains the governing instrument, implemented through each member state's national law (France's Article 82, Italy's Article 122, the UK's PECR, and so on). This is why the rules feel patchwork: there's no single modern regulation, just a Directive transposed 27 different ways, with national regulators like the CNIL and Garante now applying it to email pixels. For how those national applications play out, see the email tracking consent pillar and our guide to the equivalent device-access logic behind US website tracking law.
Key takeaways
Email tracking triggers two laws at once. ePrivacy (device access) and GDPR (data processing) both apply to the same pixel.
Layer 1 is ePrivacy Article 5(3): consent to access the device, checked first, with no legitimate-interest option.
Layer 2 is GDPR Article 6: the lawful basis to use the data — where legitimate interest lives, but only after Layer 1 is cleared.
Lex specialis means ePrivacy wins for the device access. And the ePrivacy Regulation that would have modernized this was withdrawn in 2025, leaving the Directive in force.
Both layers, handled — web and email
ConsentPixel — Privacy · Verified blocks trackers before consent and logs every decision. Scan your site free, then start a 14-day trial.
Start 14-day free trial → Scan a site freeNo credit card required · from $8.99/domain/mo
We explain the device-access consent architecture behind web and email tracking. This article is educational and is not legal advice; consult a qualified privacy professional about your compliance.
Frequently asked questions
What is the two-layer consent problem in email tracking?
It's the fact that email tracking triggers two separate laws at once. When a tracking pixel loads on a recipient's device, ePrivacy Article 5(3) governs the device access (Layer 1) and GDPR governs the processing of the resulting personal data (Layer 2). The two have different requirements: Layer 1 requires consent with no legitimate-interest option, while Layer 2 offers GDPR's six lawful bases. They apply in order — you must satisfy the ePrivacy consent layer first. Most confusion about email tracking consent comes from treating these two layers as one question.
How do ePrivacy and GDPR relate for email tracking?
They stack, with ePrivacy on top for the device-access act. ePrivacy Article 5(3) governs loading the tracking pixel (accessing terminal equipment) and requires consent. GDPR governs what you do with the data once collected and offers several lawful bases. Where they overlap on the pixel itself, the principle of lex specialis applies — the specific law (ePrivacy) prevails over the general one (GDPR) — so ePrivacy's consent requirement wins for the device access. GDPR still governs the downstream data processing, but it can't override the ePrivacy consent requirement for firing the pixel.
What does "terminal equipment" mean in ePrivacy?
Terminal equipment is simply the user's device — their phone, laptop, tablet, or the email client running on it. ePrivacy Article 5(3) was deliberately written about accessing "terminal equipment" rather than naming specific technologies like cookies, so the rule would stay relevant as technology changed. Loading an email tracking pixel accesses information tied to that terminal equipment, which is why it falls under the same consent rule as cookies. The EDPB's Guidelines 2/2023 confirmed this technology-neutral reading, extending the rule clearly to pixels and similar trackers.
Why does ePrivacy override GDPR's legitimate interest here?
Because of lex specialis — where a specific law and a general law both apply to the same situation, the specific one governs. ePrivacy is the specific law for accessing devices and electronic communications; GDPR is the general data-protection law. For the act of loading a tracking pixel onto a device, ePrivacy's consent requirement is the specific rule and prevails over GDPR's more flexible lawful bases, including legitimate interest. GDPR still applies to how you process the resulting data, but it can't be used to bypass the ePrivacy consent needed to access the device in the first place.
Is the ePrivacy Regulation replacing the Directive?
No — the proposed ePrivacy Regulation was withdrawn in 2025 after years without agreement. It was intended to modernize and unify the rules across the EU, replacing the 1990s-era ePrivacy Directive. With it withdrawn, the Directive remains the governing instrument, implemented through each member state's national law — France's Article 82, Italy's Article 122, the UK's PECR, and so on. This is why email tracking rules feel fragmented: there's no single modern regulation, just one Directive transposed differently across countries, with national regulators applying it to email pixels through decisions like the CNIL's and Garante's in 2026.