ConsentPixel – Privacy · Verified

HomeBlogEmail Tracking › Is Email Open Tracking Legal?
Foundation · Legal Status

Is Email Open Tracking Legal? What the Law Actually Says in 2026

The short answer: email open tracking is legal — but in the EU it now generally requires the recipient's prior consent, and tracking without it is where the legal problem begins. Here's the full answer, jurisdiction by jurisdiction, and where enforcement actually stands in 2026.

By The ConsentPixel TeamUpdated July 202610 min read
Legal, but…
Open tracking isn't banned — tracking without consent is the violation
EU: consent
ePrivacy Art. 5(3) requires prior consent when a pixel identifies you
US: laxer
No direct US equivalent yet — but state privacy law is tightening

The short answer

Is email open tracking legal? Yes — the technology itself is legal everywhere. But whether a specific use is lawful depends on jurisdiction and, increasingly, on consent. In the EU as of 2026, tracking that identifies an individual recipient generally requires their prior consent; doing it without consent is what crosses the line. In the US, there's no direct federal equivalent yet, though state privacy laws are moving in the same direction. So the honest answer isn't "yes" or "no" — it's "legal if you have consent where consent is required."

The distinction that matters

"Is email tracking legal?" and "is tracking email opens illegal?" are the same question from opposite ends, and both have the same answer: the pixel is legal; tracking a named person without the consent their jurisdiction requires is not. The question is never really about the technology — it's about permission.

Is email open tracking legal in the EU?

In the EU, open tracking is lawful only with a valid legal basis — and in 2026 regulators clarified that the basis must be consent. The reason is ePrivacy Article 5(3), the same rule behind cookie consent: it requires prior consent before accessing information on a person's device. The European Data Protection Board confirmed in its Guidelines 2/2023 that loading a tracking pixel counts as that kind of device access. So an open-tracking pixel that identifies a recipient sits under the same consent requirement as a cookie.

Many senders assume they can rely on "legitimate interest" instead of consent. Under the ePrivacy layer, they generally can't — consent is the required basis for device access, and legitimate interest doesn't substitute for it. That misunderstanding is common enough that we dedicated a whole piece to it: the legitimate interest myth.

France and Italy: the 2026 rulings that set the standard

Two regulators turned the general EU principle into concrete, dated requirements in 2026:

FR
France — CNILDélibération n° 2026-042, published 14 April 2026. Prior consent required as the general rule; existing contacts had to be informed and given a chance to object by 14 July 2026.
IT
Italy — GaranteProvision No. 284, published 29 April 2026. Prior consent for pixels identifying individuals; six-month compliance window closing 28 October 2026.

These are the clearest statements of the law's direction, and because EU authorities cite one another, they signal where the rest of the bloc is heading. For the country-specific detail, see our guides to CNIL's rules and the Garante's rules.

See what tracks before consent — on your site

The same device-access logic behind email pixels drives website tracking law. ConsentPixel's free scanner shows what fires before consent on your site in ~10 seconds.

Scan your site free →

The UK position

The UK mirrors the EU approach through UK GDPR and PECR (the Privacy and Electronic Communications Regulations), which implement the same ePrivacy Article 5(3) device-access rule. The ICO's guidance treats tracking technologies that access a user's device as requiring consent on the same basis. So the UK answer tracks the EU answer closely: open tracking that identifies a recipient generally needs consent.

The US position

The US is more permissive — for now. There's no federal law that directly requires consent for email open tracking the way ePrivacy does in the EU. CAN-SPAM governs commercial email but focuses on deception, sender identification, and unsubscribe mechanics, not tracking pixels. However, the direction of travel is unmistakable: state comprehensive privacy laws are expanding, and the same "tracking without consent" theories driving website litigation (including California's wiretapping-based CIPA claims) show how quickly a permissive gap can close. US senders emailing EU recipients are, of course, bound by the EU rules for those recipients.

So when is tracking email opens illegal?

Pulling it together — tracking email opens becomes unlawful when:

You track an identifiable EU recipient's opens without their prior consent
Unlawful under ePrivacy Art. 5(3) as applied in 2026
You rely on "legitimate interest" for the pixel instead of consent (EU)
Not a valid basis for device access
You make withdrawal impossible or bundle it so opting out loses the newsletter
Fails the withdrawable-consent requirement
You track opens only for recipients who consented, and send pixel-free to others
Lawful
You measure only anonymised, aggregate opens (no individual identification)
Treated more leniently

For the practical "what do I actually do" version of this — the yes/no/it-depends decision path — see our companion piece, do you need consent to track email opens?. This article covers what the law says; that one covers what to do about it.

Where enforcement actually stands

Enforcement is early but real. France's CNIL committed to checking compliance once its 14 July 2026 transition period ended, and the Garante's window runs to 28 October 2026. Neither regulator invented new law — they clarified existing rules and set dates, which removes the "we didn't know" defense going forward. Both authorities have strong track records on cookie enforcement (the CNIL has issued nine-figure cookie fines), and the same machinery applies here. The realistic read for 2026: the risk is no longer hypothetical, but the immediate priority is getting compliant, not bracing for an overnight wave of fines.

Key takeaways

Email open tracking is legal — tracking without required consent isn't. The technology is fine; the permission is the issue.

In the EU/UK, identifying pixels need prior consent. ePrivacy Article 5(3), confirmed by EDPB Guidelines 2/2023 and applied by France and Italy in 2026.

The US is more permissive, but tightening. No direct federal equivalent yet; state law and tracking-litigation theories are closing the gap.

Legitimate interest doesn't rescue you in the EU. Consent is the required basis for device access — LI doesn't substitute.

Know exactly what you track — before regulators do

ConsentPixel — Privacy · Verified blocks trackers before consent and logs every decision. Scan your site free to see what fires before consent, then start a 14-day trial.

Start 14-day free trial → Scan a site free

No credit card required · from $8.99/domain/mo

CP
The ConsentPixel Team

We track the device-access rules behind website and email tracking consent. This article is educational and is not legal advice; the law here is developing and fact-specific — consult a qualified privacy professional about your situation.

Frequently asked questions

Is email open tracking legal?

The technology is legal everywhere, but lawful use depends on jurisdiction and consent. In the EU and UK as of 2026, open tracking that identifies an individual recipient generally requires that person's prior consent under ePrivacy Article 5(3) — the same rule as cookie consent. Tracking without the required consent is what's unlawful, not the pixel itself. In the US there's no direct federal equivalent yet, though state privacy law is tightening. The safe summary: legal if you have consent where consent is required, and if you send a pixel-free version to everyone else.

Is tracking email opens illegal under GDPR?

It's not illegal to track opens under GDPR — it's illegal to do so without a valid legal basis, which in the EU means prior consent for a pixel that identifies the recipient. The requirement actually comes from the ePrivacy Directive (Article 5(3)) rather than GDPR itself, but GDPR's consent standard and penalties apply on top. France's CNIL and Italy's Garante both confirmed this in 2026. Anonymous, aggregate open measurement that doesn't identify individuals is treated more leniently, so the illegality turns on identification plus absence of consent.

Can I rely on legitimate interest instead of consent for open tracking?

Generally no, in the EU. Because an email tracking pixel accesses the recipient's device, it falls under ePrivacy Article 5(3), which requires consent — and legitimate interest under GDPR Article 6 does not substitute for that ePrivacy consent requirement. This is one of the most common misconceptions among senders. You can't skip consent by declaring a legitimate interest in measuring engagement; the device-access layer needs consent regardless of your GDPR basis for the underlying data.

Is email open tracking legal in the United States?

There's currently no US federal law that directly requires consent for email open tracking the way EU ePrivacy rules do. CAN-SPAM regulates commercial email but focuses on honesty, sender identification, and unsubscribe handling rather than tracking pixels. That said, US state privacy laws are expanding and the same "tracking without consent" theories behind website litigation are advancing, so the permissive gap is narrowing. And any US sender emailing recipients in the EU or UK is bound by those recipients' rules, which do require consent.

What happens if I keep tracking without consent?

In the EU, you're exposed to enforcement under the ePrivacy and GDPR framework — the regulators that set the 2026 rules (France's CNIL, Italy's Garante) have strong cookie-enforcement track records and have removed the "we didn't know" defense by publishing clear guidance and deadlines. Practically, the immediate risk is a complaint or regulatory inquiry rather than an instant fine, but continuing to track identifiable recipients without consent after the deadlines is a documented, on-notice violation. The low-risk path is to track only consenting recipients and send pixel-free emails to everyone else.

Scroll to Top