The CNIL Email Tracking Pixel Rule: What Changes on July 14, 2026
France’s data protection authority, the CNIL, has reclassified the humble email tracking pixel. Under a recommendation published on April 14, 2026, an open-tracking pixel is no longer treated as a benign byproduct of sending email. It is treated like a cookie. That places it under the ePrivacy consent regime, and it gives senders a hard deadline: July 14, 2026.
If you send email to recipients in France and you rely on open rates, read-time tracking, or pixel-based engagement data, this changes how you operate. This article explains what the CNIL actually said, what now requires consent, the narrow exemptions, and the practical steps to take before the deadline.
What the CNIL actually said
On April 14, 2026, the CNIL published the final version of its recommendation on tracking pixels in emails, following a public consultation. The recommendation had been adopted on March 12, 2026.
The core reasoning is short and worth understanding, because it drives everything else:
- A tracking pixel is a small image embedded in an email that causes the recipient’s device to make a request back to a server when the message is opened.
- That request reads information from the recipient’s terminal: device, timing, sometimes location or client details.
- Reading information stored in or accessed from a user’s terminal without consent is prohibited under Article 5(3) of the ePrivacy Directive, transposed in France as Article 82 of the Postal and Electronic Communications Code.
- Therefore, the CNIL concludes, placing a tracking pixel requires prior, free, specific, informed, and unambiguous consent, the same standard that applies to non-essential cookies on a website.
This is not a marginal clarification. The CNIL explicitly rejects legitimate interests as a legal basis for pixel tracking, and it applies the rule to the pixel itself rather than to the type of email. A marketing newsletter and a transactional receipt are treated the same way once a tracking pixel is involved.
What now requires consent
The rule covers any pixel whose purpose goes beyond what is strictly necessary to deliver a requested service. In practice, that means consent is required for:
- Open tracking: the classic invisible pixel that records when and whether a message was opened.
- Engagement and read-time tracking: pixels and techniques that measure how long a recipient spent reading, or whether they scrolled.
- Click tracking used for analytics or profiling: redirect links that record clicks in order to score engagement, build interest profiles, or segment audiences.
- Third-party data sharing: any pixel or link that forwards engagement data to an advertising platform, a CDP, or another external service for cross-context use.
The common thread is measurement and profiling. If the data feeds a dashboard that tells you how a campaign performed, or shapes a profile of what a recipient cares about, it needs consent.
The two exemptions
Not every pixel requires consent. The CNIL recognises a narrow set of exemptions, and they are worth reading carefully because the boundary is where most compliance mistakes happen.
Strictly necessary technical purposes. Pixels used to maintain deliverability or manage a database (for example, identifying inactive subscribers so they can be removed, or adjusting sending frequency to protect sender reputation) may be used without consent. Crucially, this exemption applies only to emails requested by the individual: a password reset, an account verification, a confirmation the recipient triggered. Marketing emails do not qualify, no matter how “deliverability-focused” the pixel is.
Security and authentication. A pixel used to verify that a login or account-verification email was opened by the intended recipient (for instance, to detect a hijacked account or an unauthorised password change) falls within the exemption.
The catch is the word only. The data collected under an exemption must be used exclusively for that exempted purpose. If you collect open data on a transactional email “for deliverability” and then fold it into a campaign engagement report or share it with a marketing platform, you have left the exemption and entered territory that requires consent. The CNIL is explicit that repurposing exempted data into analytics or profiling breaks the exemption.
The July 14, 2026 deadline
The recommendation includes a 90-day transitional period running from the publication date of April 14, 2026. That period ends on July 14, 2026, and it governs how you treat existing subscribers: people already on your list before the rule took effect.
During the transitional window, senders may continue using pixels on existing contacts provided they:
- Notify those subscribers about the use of tracking pixels, clearly and accessibly.
- Give them a genuine opportunity to object: not a buried link, not a preticked box, but a real choice that is as easy to exercise as accepting.
If you miss the deadline, you lose the transitional regime entirely. The only path back to tracking those contacts is to re-collect explicit, prior consent from each one, the same standard as for a brand-new signup. For a large existing list, that is operationally painful and likely means losing the measurable portion of that audience.
New subscribers acquired after April 14, 2026 are not covered by the transitional regime. For them, the consent requirement applies from the start.
Practical compliance steps
The steps below are what the rule and the surrounding guidance point toward. Treat them as a checklist for the work between now and July 14.
- Audit where pixels fire. Map every email your platform sends (marketing, automated, transactional) and confirm which carry pixels and what each pixel’s data feeds. You cannot comply with what you have not inventoried.
- Separate tracking consent from marketing consent. Consent to receive marketing email and consent to be tracked are two different things. Present them as separate choices at signup. You may bundle the marketing-consent choices together, but tracking consent must stand on its own.
- Make refusal as easy as acceptance. The CNIL is explicit that objecting to tracking must not be harder than agreeing. Add a clear, always-available “revoke tracking consent” link (typically in the email footer) and make it work for the specific email address, not just a generic preference page.
- Notify your existing base before July 14. Send a clear, standalone notification to contacts acquired before April 14 explaining that you use tracking pixels, what they collect, and how to object. A single, honest message before the deadline preserves the transitional regime.
- Restrict transactional-email pixels. If you place pixels on transactional messages, limit them to strictly necessary technical or security purposes, and do not route that data into marketing analytics. If you want it for analytics, get consent or remove the pixel.
- Turn off third-party data sharing. Stop feeding engagement data to advertising networks, CDPs, or other external platforms unless the recipient has consented to that specific sharing. This is the area where the CNIL is least forgiving.
- Document consent records. For each email address you track, record what was consented to, when, and how. If the CNIL asks, the burden is on you to demonstrate that valid consent exists.
What about click tracking?
Click tracking sits in a greyer zone than open pixels, but the CNIL’s logic leads to the same destination. A tracked redirect link reads information from the terminal when clicked, so it falls under the same ePrivacy framing.
The deciding question is purpose. Clicks that are strictly necessary to deliver a service the recipient requested (a confirmation link that completes a signup, a “download your invoice” link) can qualify for the exemption. Clicks measured to gauge campaign performance, build an interest profile, or feed a third-party platform require consent.
A growing number of tools implement an intercepted-consent pattern: when a recipient clicks a link, a short interstitial asks whether they accept tracking before forwarding them to the destination. It is a workable middle ground for senders who want to preserve click analytics without blanket tracking, though it adds friction to the click itself.
If you send across borders, note that Italy’s Garante has issued parallel guidance with broadly similar conclusions but slightly broader exemptions: it tolerates anonymised aggregate statistics using a non-individualised pixel. For senders operating across the EU, the safe approach is to meet the stricter CNIL standard across the board rather than maintain two tracking configurations.
What changes for deliverability metrics
There is an honest reality underneath all of this: open rates were already broken. Apple’s Mail Privacy Protection loads pixels by default for Apple Mail users, and many webmail and corporate clients proxy or block images. The “open rate” in most dashboards has been a noisy, inflated approximation for years.
The CNIL rule accelerates a shift that was already underway. As consent becomes the gate for pixel tracking, the measurable audience shrinks further, and the opens you do see are drawn from a self-selecting, non-representative subset of your list.
The healthier direction is to stop leaning on open rate as a primary signal and weight your measurement toward signals that survive the consent model:
- Click-through rate on links, where the click itself can carry the consent decision.
- Replies and conversations, which are unambiguous evidence of engagement.
- Domain and IP reputation, monitored through postmaster data and deliverability tools. If you want a starting point, run your domain through the free email health check; it reads the signals that do not depend on opens.
- Inbox placement testing, which tells you whether your mail lands in the inbox regardless of whether anyone opens it.
Open rate is not going to zero overnight, and it still has diagnostic value at the margin. But it is no longer a metric you can build a deliverability programme on, and the CNIL rule is one more reason to plan around its absence.
Quick checklist for July 14, 2026
The compliance steps above are also available as a printable checklist you can keep on hand and work through offline. You’ll find it just below this article: enter your email and the PDF arrives in your inbox.
The bottom line
The CNIL did not ban email tracking. It brought it under the same consent regime that already governs cookies on the web, and it gave senders 90 days to bring existing lists into line. The senders who come out of this cleanly are the ones who treat tracking as a deliberate, disclosed, revocable choice rather than a default, and who stop pretending the open rate was ever telling them the whole truth.
For the authoritative text, read the CNIL’s recommendation on tracking pixels in emails directly. This article is an explainer, not legal advice; for a specific send configuration, confirm against the official source and, where the stakes warrant, with counsel.
Get the printable CNIL compliance checklist
Quer uma cópia para guardar? Informe seu e-mail e enviaremos uma versão em PDF imprimível deste checklist para você concluir offline.