What France's CNIL now requires for email open pixels: which uses need consent, the narrow exemptions, the July 14 transition and what to change.
The CNIL's recommendation on tracking pixels in emails is France's official reading of how consent rules apply to the invisible image that tells a sender you opened a message. An open pixel reads information from the recipient's device, so it needs prior consent unless it fits one of two narrow exemptions. The CNIL adopted it as deliberation no. 2026-042 on March 12, 2026, published it in the Journal Officiel on April 14, 2026, and added a 27-question FAQ on July 22, 2026.
If your ESP pixels every email, as most do, and your signup form never mentions it, every French recipient is a problem, wherever you are based. Recommendation quotes use the CNIL's English courtesy translation of the French original. FAQ and webinar quotes are our translations.
This is not legal advice. The recommendation calls itself "neither regulatory nor exhaustive", so have counsel review your setup.
Article 5(3) of the ePrivacy Directive (consolidated text) allows reading or storing information on a user's device "only" if the user "has given his or her consent", unless access is needed to transmit a communication or is "strictly necessary" for a service the user explicitly requested. France transposed this as Article 82 of the loi Informatique et Libertés, also the basis of the CNIL's cookie cases.
The EDPB's Guidelines 2/2023 (version 2.0, adopted October 7, 2024) already said tracking information in URLs or images "constitutes an instruction to the terminal equipment to send back the targeted information". The GDPR governs what happens next, including proof of consent under Article 7(1).
| Date | What happened |
|---|---|
| June 12 to July 24, 2025 | Public consultation on the draft |
| March 12, 2026 | CNIL adopts deliberation no. 2026-042 |
| April 14, 2026 | Published in the Journal Officiel. Applies at once to new addresses |
| May 28 and June 4, 2026 | Webinars for senders and email providers |
| July 14, 2026 | Notice window for existing contacts ends |
| July 22, 2026 | FAQ published |
The June 2025 draft exempted only a global open rate and recommended identical pixels for every recipient. The final text is softer, exempting individual deliverability measurement under strict conditions.
The recommendation describes a tracking pixel as a remote image whose URL "usually has individualised settings relating to the user or context". Loading it sends the pixel ID, IP address and similar data to whoever placed it. Article 82 regulates that.
Bank-style secure message centres run on other protocols and are excluded.
Section 3.1 lists four:
Item 1 is the big one. Open-based send times, "opened in the last 30 days" segments and open-triggered automation branches all need consent.
Permission to send doesn't settle it. Section 4.2 says pixel consent "may be necessary for emails which do not, in principle, require the consent of the recipients", citing order confirmations, soft opt-in marketing, charity appeals and B2B prospecting.
![]()
What needs consent, by email type and pixel purpose, per the CNIL recommendation and July 2026 FAQ.
A pixel used only to secure an authentication can be exempt, such as checking that a login-code email was opened on the user's known device. FAQ question 13 includes password resets. General fraud prevention, bot detection and ad inventory protection are not covered.
Most senders will lean on this one. All four conditions apply.
A signup newsletter counts as requested, so its deliverability pixel can be exempt. Marketing sent under the soft opt-in exception in article L34-5 of the French postal and electronic communications code (CNIL guide) does not, so its pixel needs consent (FAQ questions 15 and 17). Abandoned cart emails are promotional and need consent too.
FAQ question 18 says collecting only aggregated data does not remove the consent requirement, because Article 82 applies "whether the data are personal or not". Question 6 says lawfully collected data, from an exempt or consented pixel, can be anonymised into a campaign open rate without further consent.
So an exempt pixel still gets you a campaign open rate, not open times, device data or segments. One pixel may serve exempt and consented purposes together (question 10), but not sit idle waiting for consent.
Ask on the address form, with a short purpose label, brief description and link to details. Show which address is affected and that tracking covers every device.
Start from the CNIL's wording. Its sample for campaign measurement (our translation): "[Sender] and [third parties] use trackers (tracking pixels) to know whether you open emails, the time you do so and information about the device you use, in order to personalise message content and adapt sending frequency or the channel used."
Ask per purpose. "Accept all" is fine if a second screen offers each purpose. Closely linked purposes, such as a newsletter sold as personalised, can share one consent.
Ask later only in an email without a consent-requiring pixel, linking to a page that needs a positive action so prefetching mail clients cannot consent. Silence means no, refusing must be as easy as accepting, and waiting 6 months before asking again is, in the CNIL's words, good practice.
Put withdrawal in every footer, as a per-recipient link that needs no typed address. A combined pixel and unsubscribe page is fine if it adds no steps. Afterwards, ignore hits from old pixels and delete data whose only legal basis was consent.
Keep proof per person. Record each consent and how you got it. A contract clause saying a partner collected it is not proof.
Addresses collected since April 14, 2026 get the full rules. Older ones could keep pixels if senders notified recipients and let them object within 3 months, by July 14, 2026. FAQ question 25 allows a "reasonable" extension only for documented high-volume staggering. The slides accept a dedicated email with proof of sending, or a clearly visible notice in a regular email.
The recommendation says the CNIL "receives an increasing number of reports and complaints" about pixels, and it plans to check in future inspections. Pixels are not among its 2026 priority themes, which is weak comfort. Of its several hundred inspections a year, prompted by complaints, reports, earlier corrective measures or the news, only about 20% come from priority themes.
Article 20 of the French law caps fines at €10 million or 2% of worldwide annual turnover, whichever is higher, or €20 million or 4% for certain GDPR breaches. On September 1, 2025 the CNIL fined Google €325 million over ads between Gmail messages and cookie consent at account creation. In November 2025 it fined American Express €1.5 million, partly for "continuing to read previously placed cookies despite the withdrawal of their consent". An old pixel still logging opens after withdrawal is the same breach. Simpler cases go through a simplified procedure capped at €20,000, or €100,000 above €50 million in turnover.
If you mail people in France, we'd go in this order:
Tracked links are "not directly" covered, but FAQ question 1 says they must meet Article 82 too. Clicks are better data anyway, as Apple's Mail Privacy Protection already "prevents senders from seeing if you've opened the email message". The EDPB applies Article 5(3) to tracking links, and the CNIL's slides say consent "depends on the purpose and not on the technology". Our reading, not the CNIL's, is that a per-recipient tracked link used to optimise campaigns is treated like a pixel. Shared UTM tags identify no one, and on-site conversions fall under your website's cookie consent.
Brew measures opens with a 1x1 pixel and clicks with recipient-tagged links (metrics docs).
pixelConsent property at signup and filter audiences on it.Our September State of Email has a shorter summary of the FAQ.
For most marketing uses, yes. Only authentication-security pixels and tightly limited deliverability pixels in requested emails are exempt.
Yes, if you track people in France, whether you are based elsewhere in the EU or outside it. The one-stop-shop does not apply to Article 82 checks.
Only for deliverability, where the pixel keeps just the last open date to stop or slow mail to inactive recipients. Analytics or personalisation needs consent, and adding promotions loses the exemption.
Yes, if the data came from an exempt or consented pixel and you anonymise it effectively. Collecting only aggregates does not remove the consent requirement, since Article 82 covers non-personal data too.
Not directly. The CNIL says tracked links still fall under Article 82 and are judged by purpose. The recommendation treats a unique footer withdrawal link as an exempt security measure.
