Businesses should review their email tracking practices in light of the French data protection authority’s (CNIL) recommendation on tracking pixels in emails, dated 12 March 2026 and published on 14 April 2026.
Who is in scope of the Recommendation?
The CNIL’s recommendation on tracking pixels in emails, dated 12 March 2026 and published on 14 April 2026 (the ‘Recommendation’) applies to all public and private entities involved in the use of tracking pixels in emails.
While several entities can be involved in the use of tracking pixels in emails, their role as data controller or processor and obligations under data protection laws (including with respect to obtaining consent and informing email recipients) vary depending on the capacity in which they act.
Email senders generally qualify as data controllers, emailing service providers typically act as data processors, while mailing list providers and tracking technology providers may act either as processors or joint controllers if they use the data for their own purposes. Mailbox providers are generally not considered controllers or processors in relation to tracking pixel processing as there is no use of the data generated by the pixel.
What is a tracking pixel?
Tracking pixels typically consist of an invisible 1×1 pixel image embedded in an email.
When the image is loaded, it transmits information to the sender, allowing them to determine that the user has opened an email. Tracking pixels in emails have become increasingly common and are primarily used to measure engagement, personalise communications, and monitor email deliverability.
Because they qualify as tracking technologies under the ePrivacy Directive and Article 82 of the French Data Protection Act, such pixels are in principle subject to prior information and valid informed consent, unless they are exempt under French law.
Which tracking pixels need consent?
The CNIL considers that the use of tracking pixels requires the email recipient’s prior consent where such pixels are used to:
- Analyse the email opening rate to measure and optimise the performance of email campaigns, or for deliverability purposes where the email was not requested by the recipient or relates to a service which was not requested by the recipient.
- Create profiles of recipients with regard to their expressed preferences and interests in order to target them in contexts other than email.
- Detect and analyse suspected fraud.
However, the CNIL indicates that, where the email was requested by the recipient or relates to a service requested by the recipient, certain tracking pixel processing activities are exempt from the consent requirement under the French Data Protection Act and the ePrivacy Directive, namely:
- Pixels used for the implementation of security measures involved in user authentication.
- Pixels used for database cleaning, i.e., to individually measure the opening rate of emails for deliverability purposes, including assessing and adapting the communication channel to choose alternative contact methods, and demonstrating compliance with legal obligations regarding the transmission of information to the recipient.
What are the obligations for data controllers using tracking pixels?
For tracking pixels that require email recipients’ consent, the CNIL recommends that recipients be informed of the purposes of those trackers before they opt in, in an intelligible manner and in language that is appropriate and sufficiently clear to enable them to understand precisely the scope of their choice.
In addition, the CNIL recommends that recipients’ opt-ins be obtained when their email address is collected, or where that is not possible, by sending an email which does not contain a tracking device subject to consent.
Although Article 82 of the French Data Protection Act does not require recipients to be informed about the use of pixels that do not require consent, the CNIL still recommends, as good practice, that recipients of exempted pixels be informed of their existence for full transparency.
When does the Recommendation apply?
The Recommendation was adopted on 12 March 2026 and published on 14 April 2026 (the Publication Date).
For email addresses collected before the Publication Date, the CNIL indicated that tracking pixels may still be used, provided that clear and accessible information, including a clear possibility to opt out, is sent to recipients within three months of publication (i.e., by 14 July 2026). Ahead of the deadline, several organisations and email solution providers began adapting their practices and tools in light of the Recommendation. The CNIL also recognised that the three-month deadline may not always be sufficient due to potential technical issues associated with batching mailings. In such cases, the deadline could be extended by a reasonable period, subject to valid justification.
After this deadline, for email addresses collected before the Publication Date, a specific opt-in must be obtained from, and clear information must be provided to, email recipients in accordance with the Recommendation.
Likewise, for email addresses collected after the Publication Date, a valid opt-in mechanism and appropriate information must be provided in accordance with the Recommendation.
What does the Recommendation mean for businesses?
Organisations that use tracking pixels in marketing or customer communications should now verify that their practices comply with the Recommendation, particularly where tracking is used for campaign measurement, recipient profiling, or fraud detection, all of which require valid prior consent.
To comply with the Recommendation, organisations should ensure appropriate information is provided and valid consent mechanisms are in place, failing which they may be subject to enforcement action.
For more detail, read the CNIL’s full recommendation.
Client Alert 2026-155