August 4, 2026
Data Protection Law

Summary

  • What are tracking pixels? A tracking pixel is typically a tiny image embedded within an email that communicates between the recipient’s device and the sender’s server when the email is opened. This enables the sender to establish whether the email was opened and may also transmit additional information depending on how they are set up.
  • Are tracking pixels regulated? Yes, the European Data Protection Board confirmed that Article 5(3) of the ePrivacy Directive covers tracking pixels as well as cookies. Article 5(3) provides that storing information or gaining access to information already stored on a user’s device is only permitted where the user has given consent and is aware of the purpose of the processing.
  • Is consent always needed? While both French and Italian regulators have identified exceptions to the requirement to obtain consent, these were narrowly framed and limited to circumstances where tracking is necessary for security, legal compliance, or genuinely anonymised aggregate statistics.
  • What should organisations do? Organisations should approach email tracking pixels with caution and assess how they are currently using them. The decisions of the French and Italian regulators are built on an EU-wide framework, and other Member States are likely to take a similar approach.

Introduction

The use of tracking pixels in emails has long raised questions about the interaction between the ePrivacy rules and the GDPR in the EU. Recent guidance from the French data protection authority (the “CNIL“) and the Italian Data Protection Authority (the “Garante“) has brought greater clarity to this area, confirming that organisations cannot assume email tracking is a routine marketing practice. Instead, the guidance reinforces that, in many cases, tracking recipients through pixels requires prior consent, together with clear information about how the technology operates and the purposes for which it is used. While the GDPR governs the processing of the personal data collected through email tracking, the starting point for determining whether tracking pixels can be deployed at all lies in Article 5(3) of Directive 2002/58/EC (the”ePrivacy Directive“).

Article 5(3) of the ePrivacy Directive: the legal foundation for Consent and Email Tracking Pixels

Article 5(3) of the ePrivacy Directive provides that the storing of information, or gaining access to information already stored, on a user’s terminal equipment is only permitted where the user has given consent after receiving clear and comprehensive information about the purposes of the processing.

The only exceptions are where the storage or access is:

  • solely for carrying out the transmission of a communication over an electronic communications network; or

  • strictly necessary to provide an information society service explicitly requested by the user.

The provision is intended to protect users’ terminal equipment as part of their private sphere.

Why Consent and Email Tracking Pixels are caught by Article 5(3)

The European Data Protection Board’s (“EDPB“) Guidelines 2/2023 on the Technical Scope of Article 5(3) of the ePrivacy Directive (Version 2.0, adopted on 7 October 2024) confirm that Article 5(3) is not limited to cookies but also applies to “similar technologies”, including tracking pixels and tracking links.

A tracking pixel is typically an image embedded within an email that automatically establishes communication between the recipient’s device and the sender’s server when the email is opened. This enables the sender to determine whether the email has been opened and may also transmit additional identifiers or metadata depending on the implementation.

The EDPB explains that:

  • the distribution of a tracking pixel to a recipient’s device constitutes storage, at least through the email client’s caching mechanism, even where that storage is only temporary; and

  • the instructions embedded within the tracking pixel cause the recipient’s terminal equipment to transmit information back to the sender, meaning the subsequent collection of identifiers constitutes “gaining access” to information stored on the terminal equipment.

Accordingly, the use of email tracking pixels falls within the scope of Article 5(3).

Building on the framework established by the ePrivacy Directive and the EDPB, the CNIL’s Recommendation, published in April 2026, identifies a number of purposes for which prior consent is required before tracking pixels may be used.

These include:

  • analysing email opening rates to measure and optimise campaign performance, including tailoring message content or adapting the frequency of communications or communication channel;

  • creating recipient profiles based on observed preferences or interests for targeting individuals outside the email environment;

  • detecting and analysing suspected fraud, such as unusual or large-scale automated email openings; and

  • measuring individual email open rates for deliverability purposes where the processing falls outside the limited exempted circumstances.

The CNIL also emphasises that organisations must provide recipients with clear information about the purposes of the tracking, such as whether it is used for deliverability analysis, campaign optimisation, profiling or fraud detection. In addition, controllers must be able to demonstrate that valid consent has been obtained, in accordance with Article 7(1) GDPR.

The Garante’s position: transparency is fundamental

The Garante has adopted a similarly robust approach to the use of email tracking pixels. The Garante states that the use of tracking pixels is lawful only where recipients are informed in advance, regardless of the purpose of the communication or the type of sender. According to the authority, failing to provide this information constitutes a breach of the GDPR’s principle of fairness under Article 5(1)(a).

The Garante also provides practical guidance on how this information may be communicated. Privacy information may be delivered through different channels, including pop-up notices, chatbots or virtual assistants. Where tracking is already taking place, the controller should provide the missing information at the first available opportunity in its relationship with the data subject.

Like the CNIL, the Garante recognises that consent is not required in a limited number of circumstances. These include:

  • anonymised statistical measurement of overall email opening rates, provided that standardised (rather than user-specific) tracking pixels are used and related technical information, such as IP addresses and client information, is anonymised;

  • security measures connected with user authentication, including account activation confirmations and password change management; and

  • institutional or legally required service communications, such as mandatory banking communications, security incident notifications and institutional information campaigns that the controller is legally obliged to send.

The Garante’s guidance therefore reinforces the distinction between tracking that is necessary for security or legal compliance and tracking that is designed to monitor identifiable user behaviour for analytics or marketing purposes.

The CNIL identifies only limited situations in which consent is not required, namely:

  • purely checking whether an email has been successfully delivered; and

  • tracking carried out for security purposes.

The Italian Garante similarly recognises a small number of exceptions, including:

  • anonymised statistical measurement of overall email opening rates, provided that standardised rather than user-specific tracking pixels are used and related technical information, such as IP addresses and client information, is anonymised;

  • security measures connected with user authentication, including account activation confirmations and password change management; and

  • institutional or legally required service communications, such as mandatory banking communications, security incident notifications and legally required institutional information campaigns.

These exceptions are narrowly framed and are limited to circumstances where tracking is necessary for security, legal compliance or genuinely anonymised aggregate statistics.

A developing regulatory landscape

Although the most detailed guidance has recently come from the CNIL and the Garante, organisations should not assume that these developments will remain isolated to France and Italy. Both authorities have built their positions upon Article 5(3) of the ePrivacy Directive and the EDPB’s Guidelines, which are intended to promote a consistent interpretation of the ePrivacy rules across the European Union.

It is therefore reasonable to expect that other supervisory authorities in the EU will issue similar guidance or update their own national regulatory frameworks to reflect these developments. Organisations operating across multiple Member States should therefore view the recent guidance not as country-specific anomalies, but as a strong indication of the direction of travel for the regulation of email tracking technologies throughout the EU. Businesses that proactively review their use of tracking pixels, consent mechanisms and transparency notices will be better placed to meet evolving regulatory expectations as additional national guidance emerges.

The combined effect of Article 5(3) of the ePrivacy Directive, the EDPB’s technical guidance, and the recent positions adopted by the CNIL and the Garante is that organisations should approach email tracking pixels with caution.

Where tracking pixels are used to monitor individual engagement, optimise marketing campaigns, create recipient profiles or undertake similar analytics, prior consent will generally be required before the technology is deployed. Organisations must also ensure that recipients are clearly informed about the purposes of the tracking and that they can demonstrate valid consent where required.

Only a narrow range of activities—principally those relating to transmission, security, legal obligations or genuinely anonymised aggregate statistics—fall outside the consent requirement. The recent guidance provides organisations with a much clearer framework for assessing the lawful use of email tracking pixels and reinforces the importance of building transparency and consent into email marketing practices from the outset.

EM Law are experts in data protection. If you need help navigating AI or data protection, please contact us here or visit our Data Protection Lawyers page for more information. 

 Further Reading