Tracking pixels in email: consent, GDPR and analytics without open rate
A tracking pixel in an email is an invisible image that is loaded when an email is opened and conveys technical data to the sender. With its help, the mailing service can determine the fact and time of loading, device type and approximate IP location.
In 2026, the French regulator CNIL issued final recommendations on such pixels, and then a separate FAQ for businesses. The main takeaway is that hidden tracking should not be considered a harmless feature of an email platform. Depending on the purpose of the pixel, prior consent, the ability to opt-out, and proof of the chosen legal scenario may be required.
The material is useful for companies that work with clients in France or build European email marketing. This is not individual legal advice: the applicability of GDPR, ePrivacy and national regulations should be checked for specific countries, roles and types of mailings.
What exactly does CNIL regulate?
On April 14, 2026, CNIL published final recommendation. The document addresses pixels in emails and explains:
- when the sender and the platform provider are considered parties to the processing;
- what purposes require consent;
- what limited scripts might receive an exception;
- how to inform the recipient;
- how to ensure withdrawal of consent or objection;
- how to store evidence of the chosen basis.
The recommendation does not turn any technical pixel into a violation. It requires first defining a goal. Pixels for personal profiling, discovery response and advertising segmentation are evaluated differently than a strictly limited technical delivery test.
When consent is particularly likely to be necessary
A company should assume an increased risk if the pixel is used for:
- personal determination of whether a specific person has opened a letter;
- building a profile of interests;
- automatic launch of the next marketing chain;
- lead scoring based on opening;
- combining opens with behavior on a site or application;
- transferring data to multiple advertising and analytics providers;
- determination of device, time and approximate geography for personalization.
A general privacy policy line is not enough if the scenario requires consent. The user must understand the purpose and have real choice before tracking begins.
What exceptions does the regulator describe?
The CNIL allows for limited scenarios in which consent may not be required, but the conditions are narrow. For example, this could involve technically assessing deliverability and identifying inactive addresses to protect sender reputation.
This exception cannot be automatically transferred to marketing analytics. Data should be kept to a minimum and used only for the stated technical purpose. If the same signal then ends up in an advertising profile, segmentation or personal lead scoring, the original logic no longer works.
Transactional writing also does not provide universal relief. It is necessary to separately evaluate why there is a pixel in the order confirmation, invoice or security notice and whether it is really necessary to provide the requested service.
What has changed after July 14, 2026
B FAQ July 22, 2026 The CNIL has clarified the transition period for addresses collected before the publication of the recommendations.
For the old base, the company had to clearly communicate the use of pixels within three months after April 14 and provide an opportunity to object. Base period end date - July 14, 2026.
If the information was not sent on time and there is no documented basis for a reasonable extension, the sender must:
- stop using pixels in scenarios where consent is required;
- collect correct consent before renewal;
- document exceptions and limitations to purposes;
- check if the platform continues to download the pixel automatically.
User silence is not a permanent permission. If partners, processing purposes or sending conditions change and new consent for sending is required, consent to tracking pixels must also be re-evaluated.
Tracking links and pixels are not the same thing
Links with a unique identifier allow you to associate a click with a specific recipient. The CNIL FAQ says that such links are not directly subject to the pixel recommendation, but they still need to be assessed against general data protection and tracking rules.
Therefore, disabling the 1x1 image but maintaining hidden identification in each link is not a complete compliance strategy. You need a map of all signals:
| Signal | What does it record? | Main question |
|---|---|---|
| Tracking pixel | Uploading an image | Is there a consensus or a narrow exception? |
| Unique link | Click on a specific recipient | Is identification required and how is it described? |
| UTM tags | Source and campaign | Does it contain personal data? |
| Event on the site | Action after transition | Is there consent to web analytics and advertising? |
| CRM status | Deal stage | Is it legal to combine it with email signals? |
Why open rate can no longer be considered the main KPI
Even without legal restrictions, open rate remains a noisy metric. It is affected by image preloading, email client privacy protection, image blocking, and automatic security checks.
Opening does not prove that the person read the letter or showed interest. In B2B, it is especially dangerous to turn open into a signal for a manager to call: technical loading can make a cold contact seem warm.
The working measurement model is built around validated actions:
- delivered letters and refusals;
- clicks on semantic links;
- transitions to landing pages;
- registration, application or order;
- qualified lead;
- campaign revenue and retention;
- unsubscribes, complaints and negative signals.
Open rate can be left as a diagnostic indicator where its collection is acceptable, but not used alone for personal decisions.
Email tracking audit plan
Step 1. Find all pixels
Check not only the email template, but also the functionality of ESP, CRM, CDP, automation and external widgets. Some platforms enable tracking automatically.
Step 2: Describe the purpose of each signal
Formulation для аналитики too wide. Separate deliverability, aggregated statistics, personal scoring, automated chains and advertising profiling.
Step 3. Record supplier roles
Determine who makes decisions about the purposes and means of processing, who acts as the processor, where the data is stored, and what subprocessors are connected.
Step 4. Check consent and refusal
The user must be able to understand the choice and change it. Failure should not require a support email or searching for a hidden setting.
Step 5. Limit data and storage period
Don’t store personal opens indefinitely just because the platform knows how to do it. The deadline must follow from the purpose and internal policy.
Step 6: Rebuild reports
Make clicks, conversions and business results the core of your dashboard. Otherwise, the team will continue to optimize for the metric that the compliance model itself is trying to limit.
Common mistakes
- Assume that the GDPR does not apply because the letter is sent by an American service.
- Hide tracking pixels inside the general newsletter consent.
- Use a technical exception for advertising segmentation.
- Ignore old automatic chains.
- Pass email, IP or ID via analytics URL.
- Do not synchronize the withdrawal of consent between the CRM and the mailing platform.
- Continue to evaluate managers based on open rate.
FAQ
Does tracking pixel always require consent?
No, but exceptions depend on strictly limited purpose and conditions. Personalized marketing analytics, profiling, and discovery-based automation typically require a stronger foundation and transparent choices.
Can I use a pixel in a transactional email?
The type of letter itself does not solve the issue. You need to prove the need for a specific goal. Advertising profiling does not become technically necessary just because a pixel is embedded in the order confirmation.
What if the base was not notified by July 14, 2026?
Terminate scenarios that require consent, evaluate possible documented exceptions, and collect correct consent before re-enabling tracking.
Can I leave UTM tags?
Yes, as long as they describe the campaign and do not contain personal information. Unique recipient identifiers require separate evaluation.
How to replace open rate?
Clicks, post-click events, qualified leads, sales, retention, unsubscribes and complaints. These indicators are closer to the real result.
Useful on the topic
- Digital compliance for the website
- GDPR compliance
- Email and SMS marketing
- Web analytics and end-to-end measurement
