Italy's Garante Pixel Rules: The 28 October 2026 Deadline Explained
The Garante tracking pixel email rules landed in April 2026: Italy's data protection authority made the pixel that tracks email opens a consent question with Provision No. 284 — and set a hard deadline of 28 October 2026. Here's what the rule requires, how it differs from France's, and what senders to Italian recipients must do before the window closes.
What this covers
What the Garante decided
On 17 April 2026, Italy's data protection authority — the Garante per la Protezione dei Dati Personali — adopted Provision No. 284, its first dedicated guidelines on the use of tracking pixels in email. Published in the Gazzetta Ufficiale (Official Gazette) No. 98 on 29 April 2026, it triggered a six-month compliance window closing 28 October 2026. The core rule: any tracking pixel that fires when a recipient opens a message and lets the sender identify that recipient now needs prior opt-in consent — the same legal standard already applied to cookies.
If a pixel can be tied back to an individual recipient, the Garante treats it like a cookie: same opt-in rule, same proof-of-consent requirement, same six-month transition. Open tracking isn't outlawed — it's reclassified as terminal-device access that needs consent when it identifies someone.
The legal basis: Article 122 of the Italian Privacy Code
The Garante grounds the rule in Article 122 of the Italian Privacy Code (Codice Privacy), which transposes ePrivacy Article 5(3) — the same device-access provision behind cookie consent. Loading a pixel to identify a recipient is "gaining access" to information on their terminal equipment, so it falls under the consent requirement. The Garante aligned its reading with the EDPB's Guidelines 2/2023, the same European interpretation France's CNIL relied on. Different country, different article number, identical underlying logic — which we lay out in full in the email tracking consent pillar.
The 28 October 2026 deadline
Publication in the Gazzetta Ufficiale on 29 April 2026 started the six-month clock, which expires 28 October 2026. By that date, organizations sending tracked email to recipients in Italy should have updated their consent flows, sign-up forms, privacy notices, and email templates — or disabled pixel tracking. As in France, the transition window primarily covers addresses collected before publication; new collection should be handled compliantly from the start.
Advisors have coalesced on a "pixel-off-first" rule for senders who can't complete a full programme in time: disable all tracking pixels in marketing emails by 28 October 2026 and re-enable them only after compliant consent is collected. This eliminates the highest-risk exposure while you finish the rest of the work — a clean, defensible fallback.
The same logic governs your website trackers
ConsentPixel's free scanner shows which trackers fire before consent on your site in about 10 seconds — the web version of the exact rule the Garante applied to email.
Scan your site free →What's distinctive about Italy's approach
The Garante takes a more pragmatic line than France on how consent is gathered, but a demanding one on how it's withdrawn:
This bundling-allowed-but-granular-withdrawal design is the main practical difference from France's stricter consent-moment stance. If you send to both countries, design to satisfy both: informed consent that's also separable on withdrawal.
What's exempt: anonymised aggregate statistics
The line the Garante draws is identification. A pixel that identifies an individual recipient needs consent; measurement that produces only anonymised, aggregate statistics — total opens across a campaign, with no tie back to a named person — is treated more leniently and generally permitted. This is the escape hatch for senders who want campaign-level insight without managing per-recipient consent: measure in aggregate, or rely on click-based signals, and you sidestep the identifying-pixel problem.
What senders must do before 28 October 2026
Map Italian recipients & pixels
Identify which contacts are in Italy and whether your sends carry identifying open-tracking pixels.
Add informed consent
Update sign-up forms and notices so recipients are clearly informed about tracking — bundling with newsletter consent is acceptable if transparent.
Enable granular withdrawal
Make sure recipients can opt out of tracking while keeping the newsletter — this is a hard Garante requirement.
Pixel-off for the rest
For non-consenting recipients, disable the pixel or rely on aggregate/anonymised measurement. Log consent and secure the data.
France set a parallel rule with an earlier (14 July 2026) deadline and a stricter consent moment — if you also send to French recipients, read our CNIL pixel rules guide. For the plain-language decision path, see do you need consent to track email opens?
Key takeaways
Garante Provision No. 284 makes identifying email pixels a consent question. Prior opt-in required, same standard as cookies, grounded in Article 122 of the Italian Privacy Code.
The deadline is 28 October 2026 — six months from publication in the Gazzetta Ufficiale on 29 April 2026.
Italy allows bundling but demands granular withdrawal. Consent can be combined with newsletter opt-in if informed; recipients must be able to drop tracking without losing the newsletter.
Anonymised aggregate statistics are the escape hatch. Measure opens in aggregate with no individual identification and you sidestep the consent requirement.
Prevention-first consent — website and email
ConsentPixel — Privacy · Verified blocks trackers before consent and logs every decision. Scan your site free, then start a 14-day trial.
Start 14-day free trial → Scan a site freeNo credit card required · from $8.99/domain/mo
We track the device-access consent rules behind website and email tracking. This article is educational and is not legal advice; for Italian compliance specifics, consult a qualified privacy professional or Italian counsel.
Frequently asked questions
What is Garante Provision No. 284?
Provision No. 284 is the Italian Garante's first dedicated set of guidelines on email tracking pixels, adopted 17 April 2026 and published in the Gazzetta Ufficiale on 29 April 2026. It rules that a tracking pixel identifying an individual recipient is access to that person's terminal device under Article 122 of the Italian Privacy Code — the same category as a cookie — and therefore needs prior opt-in consent. It's a binding measure carrying consent, transparency, and data-security obligations, with a six-month compliance window closing 28 October 2026.
What is the Garante's email pixel deadline?
28 October 2026. Publication in the Gazzetta Ufficiale on 29 April 2026 started a six-month compliance window that closes on that date. By then, organizations sending tracked email to recipients in Italy should have updated their consent flows, sign-up forms, privacy notices, and templates — or disabled identifying pixel tracking. Senders who can't complete a full programme in time are advised to disable all marketing-email pixels by the deadline and re-enable only once compliant consent is collected.
How is Italy's rule different from France's CNIL rule?
The underlying logic is identical — both treat an identifying email pixel as device access needing consent under ePrivacy Article 5(3). The differences are practical. Italy is more pragmatic on the consent moment: tracking consent may be bundled with newsletter or marketing consent if the recipient is properly informed. But Italy is demanding on withdrawal — it must be granular, so a recipient can opt out of tracking while keeping the newsletter. France's CNIL takes a stricter line on how consent is obtained. Italy's deadline (28 October 2026) is also later than France's (14 July 2026).
Does the Garante rule apply to companies outside Italy?
Yes. It reaches any sender whose recipients are in Italy, regardless of where the sender is based — a multinational retailer, a B2B supplier, an ESP, or an SME running a Mailchimp newsletter. And because the rule rests on Article 122 of the Italian Privacy Code transposing ePrivacy Article 5(3), the same principle applies EU-wide; Italy and France simply published explicit guidance and deadlines first. If you email anyone in Italy and your platform tracks opens, treat this as applying to you.
Can I still measure open rates under the Garante rules?
Yes, in two ways. You can track opens for recipients who have given consent (which Italy lets you bundle with newsletter consent if you inform them), and you can measure opens in anonymised, aggregate form that doesn't identify individuals — the Garante treats aggregate statistics more leniently. What needs consent is the identifying pixel that ties an open back to a specific person. Many senders rely on aggregate measurement or click-based engagement signals to sidestep per-recipient consent management entirely.