# CNIL email tracking pixel rules: what needs consent

Canonical: https://brew.new/blog/cnil-tracking-pixel-rules-email
Author: Philip Sørensen
Published: 2026-10-06
Updated: 2026-10-06

The CNIL's recommendation on tracking pixels in emails is France's official reading of how consent rules apply to the invisible image that tells a sender you opened a message. An open pixel reads information from the recipient's device, so it needs prior consent unless it fits one of two narrow exemptions. The CNIL adopted it as deliberation no. 2026-042 on March 12, 2026, published it in the Journal Officiel on April 14, 2026, and added a 27-question FAQ on July 22, 2026.

If your ESP pixels every email, as most do, and your signup form never mentions it, every French recipient is a problem, wherever you are based. Recommendation quotes use the CNIL's [English courtesy translation](https://www.cnil.fr/sites/default/files/2026-05/recommandation_tracking_pixels_emails.pdf) of the [French original](https://www.cnil.fr/sites/default/files/2026-04/recommandation-pixels_de_suivi.pdf). FAQ and webinar quotes are our translations.

This is not legal advice. The recommendation calls itself "neither regulatory nor exhaustive", so have counsel review your setup.

## Key takeaways

- Opens used to optimise campaigns, build profiles or detect fraud need prior consent.
- Two uses are exempt: authentication security, and deliverability pixels in requested emails that keep only the last open date to slow or stop mail to inactive recipients. Soft opt-in and abandoned cart emails don't qualify.
- Contacts collected before April 14, 2026 needed notice and a chance to object by July 14. Without it, they now need consent.
- Ask for pixel consent as its own choice on the address form, and put a withdrawal link in every footer.
- Tracked links face the same Article 82 test, judged by purpose.

## Where the rule comes from

Article 5(3) of the ePrivacy Directive ([consolidated text](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02002L0058-20091219)) allows reading or storing information on a user's device "only" if the user "has given his or her consent", unless access is needed to transmit a communication or is "strictly necessary" for a service the user explicitly requested. France transposed this as [Article 82 of the loi Informatique et Libertés](https://www.cnil.fr/fr/le-cadre-national/la-loi-informatique-et-libertes#article82), also the basis of the CNIL's cookie cases.

The EDPB's [Guidelines 2/2023](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en) (version 2.0, adopted October 7, 2024) already said tracking information in URLs or images "constitutes an instruction to the terminal equipment to send back the targeted information". The GDPR governs what happens next, including proof of consent under Article 7(1).

| Date | What happened |
|---|---|
| June 12 to July 24, 2025 | [Public consultation](https://www.cnil.fr/fr/consultation-publique-projet-recommandation-pixels-de-suivi) on the draft |
| March 12, 2026 | CNIL adopts deliberation no. 2026-042 |
| April 14, 2026 | [Published](https://www.cnil.fr/fr/recommandation-pixel-suivi-courriels) in the Journal Officiel. Applies at once to new addresses |
| May 28 and June 4, 2026 | Webinars for senders and email providers |
| July 14, 2026 | Notice window for existing contacts ends |
| July 22, 2026 | [FAQ published](https://www.cnil.fr/fr/faq-recommandation-pixels-courriers-electroniques) |

The [June 2025 draft](https://www.cnil.fr/sites/default/files/2025-06/projet_de_recommandation_pixels_de_suivi.pdf) exempted only a global open rate and recommended identical pixels for every recipient. The final text is softer, exempting individual deliverability measurement under strict conditions.

## What is in scope

The recommendation describes a tracking pixel as a remote image whose URL "usually has individualised settings relating to the user or context". Loading it sends the pixel ID, IP address and similar data to whoever placed it. Article 82 regulates that.

- **Every email**, including to customers, prospects and your own staff on work addresses (FAQ question 3).
- **Every sender** whose pixels track people in France, EU or not (FAQ question 2). The one-stop-shop does not apply to Article 82 checks.
- **Every party.** The sender is the controller. The ESP is normally a processor, or a joint controller if it uses pixel data for its own ends and the contract says so.

Bank-style secure message centres run on other protocols and are excluded.

## Which pixel uses need consent

Section 3.1 lists four:

1. "Analysis of the email opening rate to measure and optimise the performance of campaigns by customising the content of messages or by adapting the frequency of sending or the communication channel." This includes filtering ad fraud from the measurement.
2. "The creation of profiles of recipients" to target them on websites, apps or other channels.
3. "Detection and analysis of suspected fraud, such as the identification of unusual or massive openings of emails."
4. Individual open measurement for deliverability outside the section 3.2 exemption.

Item 1 is the big one. Open-based send times, "opened in the last 30 days" segments and open-triggered automation branches all need consent.

Permission to send doesn't settle it. Section 4.2 says pixel consent "may be necessary for emails which do not, in principle, require the consent of the recipients", citing order confirmations, soft opt-in marketing, charity appeals and B2B prospecting.

## The two exemptions

![A decision table showing which email tracking pixel uses need consent under the CNIL recommendation, by email type and purpose.](/images/blog/cnil-tracking-pixel-rules-email-decision-table.png)

*What needs consent, by email type and pixel purpose, per the CNIL recommendation and July 2026 FAQ.*

### Authentication security

A pixel used only to secure an authentication can be exempt, such as checking that a login-code email was opened on the user's known device. FAQ question 13 includes password resets. General fraud prevention, bot detection and ad inventory protection are not covered.

### Deliverability

Most senders will lean on this one. All four conditions apply.

1. **The person asked for the email or the underlying service.** The recommendation lists welcome emails, account alerts, shipping notifications, order confirmations, invoices, password resets, support replies, appointment reminders, payment notifications and breach notices. An order confirmation with promotions stops counting (FAQ question 16).
2. **The data only cleans the list,** limited to what is needed "to adjust the frequency or stop the sending of emails to so-called 'inactive' recipients". Switching channel and proving delivery of a legally required notice are also allowed.
3. **You keep only the last open date.** In principle, "only the date (at the day and without recording the time) of the last known opening", overwritten at each open. FAQ question 7 says collecting IP address or user agent, even if anonymised soon after, breaks the exemption.
4. **You act on it.** FAQ question 8 expects senders to stop, slow or switch channel for non-openers and document it, for example the share of contacts removed for inactivity.

A signup newsletter counts as requested, so its deliverability pixel can be exempt. Marketing sent under the soft opt-in exception in article L34-5 of the French postal and electronic communications code ([CNIL guide](https://www.cnil.fr/fr/la-prospection-commerciale-par-courrier-electronique)) does not, so its pixel needs consent (FAQ questions 15 and 17). Abandoned cart emails are promotional and need consent too.

### Aggregate open rates

FAQ question 18 says collecting only aggregated data does not remove the consent requirement, because Article 82 applies "whether the data are personal or not". Question 6 says lawfully collected data, from an exempt or consented pixel, can be anonymised into a campaign open rate without further consent.

So an exempt pixel still gets you a campaign open rate, not open times, device data or segments. One pixel may serve exempt and consented purposes together (question 10), but not sit idle waiting for consent.

## How consent has to be collected

**Ask on the address form,** with a short purpose label, brief description and link to details. Show which address is affected and that tracking covers every device.

**Start from the CNIL's wording.** Its sample for campaign measurement (our translation): "[Sender] and [third parties] use trackers (tracking pixels) to know whether you open emails, the time you do so and information about the device you use, in order to personalise message content and adapt sending frequency or the channel used."

**Ask per purpose.** "Accept all" is fine if a second screen offers each purpose. Closely linked purposes, such as a newsletter sold as personalised, can share one consent.

**Ask later only in an email without a consent-requiring pixel,** linking to a page that needs a positive action so prefetching mail clients cannot consent. Silence means no, refusing must be as easy as accepting, and waiting 6 months before asking again is, in the CNIL's words, good practice.

**Put withdrawal in every footer,** as a per-recipient link that needs no typed address. A combined pixel and unsubscribe page is fine if it adds no steps. Afterwards, ignore hits from old pixels and delete data whose only legal basis was consent.

**Keep proof per person.** Record each consent and how you got it. A contract clause saying a partner collected it is not proof.

## The July 14 transition

Addresses collected since April 14, 2026 get the full rules. Older ones could keep pixels if senders notified recipients and let them object within 3 months, by July 14, 2026. FAQ question 25 allows a "reasonable" extension only for documented high-volume staggering. The slides accept a dedicated email with proof of sending, or a clearly visible notice in a regular email.

- **Notice sent, no objection.** Rely on it until conditions change. If you need fresh consent anyway, say for new partners, collect pixel consent then too (FAQ question 27).
- **Notice sent, person objected.** Stop adding pixels to their email. Per the slides, data collected before publication can stay.
- **No notice sent.** FAQ question 26 says consent is now required. Without it, stop using those pixels.

## Enforcement risk

The recommendation says the CNIL "receives an increasing number of reports and complaints" about pixels, and it plans to check in future inspections. Pixels are not among its [2026 priority themes](https://www.cnil.fr/fr/controles-prioritaires-2026), which is weak comfort. Of its several hundred inspections a year, prompted by complaints, reports, earlier corrective measures or the news, only about 20% come from priority themes.

Article 20 of the French law caps fines at €10 million or 2% of worldwide annual turnover, whichever is higher, or €20 million or 4% for certain GDPR breaches. On September 1, 2025 the CNIL [fined Google €325 million](https://www.cnil.fr/fr/publicites-inserees-entre-les-courriels-et-cookies-la-cnil-sanctionne-google-dune-amende-de-325) over ads between Gmail messages and cookie consent at account creation. In November 2025 it [fined American Express €1.5 million](https://www.cnil.fr/en/cookies-american-express-fined-eu15-million-cnil), partly for "continuing to read previously placed cookies despite the withdrawal of their consent". An old pixel still logging opens after withdrawal is the same breach. Simpler cases go through a [simplified procedure](https://www.cnil.fr/fr/la-procedure-de-sanction-simplifiee) capped at €20,000, or €100,000 above €50 million in turnover.

## What to change

If you mail people in France, we'd go in this order:

1. **List pixels by stream** (transactional, signup newsletter, soft opt-in, B2B prospecting, cart recovery, win-back), including ad, survey and analytics pixels.
2. **Place each use in the decision table.** Opens feeding segments, send-time models or reports need consent.
3. **Add an unticked pixel consent box to every address form,** storing the answer, timestamp, form version and exact wording.
4. **Store pixel consent as its own contact field,** separate from subscription status.
5. **Drop the pixel for contacts without consent.** If you can't, use exemption-compliant deliverability tracking or switch off open tracking for that audience.
6. **Measure with data you may use.** Exempt last-open dates can drive sunset rules. Judge performance on conversions, revenue, replies and unsubscribes ([metrics that hold up](/blog/email-metrics-that-matter)).
7. **Add the footer withdrawal link,** and make sure old pixels stop recording after withdrawal.

### Clicks

Tracked links are "not directly" covered, but FAQ question 1 says they must meet Article 82 too. Clicks are better data anyway, as Apple's [Mail Privacy Protection](https://support.apple.com/guide/iphone/use-mail-privacy-protection-iphf084865c7/ios) already "prevents senders from seeing if you've opened the email message". The EDPB applies Article 5(3) to tracking links, and the CNIL's slides say consent "depends on the purpose and not on the technology". Our reading, not the CNIL's, is that a per-recipient tracked link used to optimise campaigns is treated like a pixel. Shared UTM tags identify no one, and on-site conversions fall under your website's cookie consent.

## How this works in Brew today

Brew measures opens with a 1x1 pixel and clicks with recipient-tagged links ([metrics docs](https://docs.brew.new/analytics/key-metrics-and-terms)).

- **Consent lives on the contact.** Each contact can carry a marketing consent record with source, capture time, policy version and evidence. Add a `pixelConsent` property at signup and [filter audiences on it](https://docs.brew.new/audience/create-audiences).
- **Old pixels are removed on import.** Brew neutralises the previous platform's open pixels in imported HTML.
- **Withdrawal is one click.** Every marketing email carries a signed unsubscribe link unique to each recipient.
- **Intelligent Send picks each person's send hour** from recent opens and clicks ([how it works](https://docs.brew.new/create-emails/send-options#intelligent-send)). That is section 3.1 optimisation, so reserve it for consented contacts.
- **Tracking is on for every send.** There is no per-send, per-contact or per-domain pixel switch yet, so filter French residents without pixel consent out of those sends for now, and tell us if you need the switch.

Our [September State of Email](/blog/state-of-email-september-2026) has a shorter summary of the FAQ.

## Frequently asked questions

### Do I need consent for email open tracking in France?

For most marketing uses, yes. Only authentication-security pixels and tightly limited deliverability pixels in requested emails are exempt.

### Does the CNIL pixel rule apply to companies outside France?

Yes, if you track people in France, whether you are based elsewhere in the EU or outside it. The one-stop-shop does not apply to Article 82 checks.

### Are transactional emails exempt from pixel consent?

Only for deliverability, where the pixel keeps just the last open date to stop or slow mail to inactive recipients. Analytics or personalisation needs consent, and adding promotions loses the exemption.

### Can I report an aggregate open rate without consent?

Yes, if the data came from an exempt or consented pixel and you anonymise it effectively. Collecting only aggregates does not remove the consent requirement, since Article 82 covers non-personal data too.

### Is click tracking covered by the CNIL recommendation?

Not directly. The CNIL says tracked links still fall under Article 82 and are judged by purpose. The recommendation treats a unique footer withdrawal link as an exempt security measure.
