The tracking pixel just became a consent problem in the EU, and France's deadline already passed
France's CNIL and Italy's Garante now require consent for email tracking pixels, with the first deadline already passed. The carve-outs most senders miss, why it's a clarification not a new law, and why Dubai teams emailing EU buyers are on the hook.
The open rate is the most trusted number in email marketing. In France and Italy, it's now the one most likely to get you fined.
The mechanism producing that number is a tracking pixel: a transparent one-by-one image that loads when the email is opened and reports back the when, the where, and the device. It feeds open rates, lead scoring, send-time optimisation, the whole analytics layer. Two European regulators have now ruled that loading it without consent was never legal, and they've attached dates to that position.
Key facts: France's CNIL published its recommendation on 14 April 2026 (adopted 12 March). Italy's Garante adopted Provision No. 284 on 17 April, published in the Gazzetta Ufficiale on 29 April. Both rest on rules that already existed under the ePrivacy Directive and GDPR. Neither is a new law.
That last point gets misread constantly, so it's worth slowing down on.
The regulators didn't write a new rule, they enforced an old one
Calling this "new legislation" is the comfortable reading, because new laws come with grace periods and phase-ins. This isn't that. The CNIL and the Garante are saying the consent obligation was already in force under existing EU law, and that the market had simply been ignoring it for tracking pixels the way it ignored cookie consent a decade ago.
Which changes your posture. You can't wait out a transition on a rule the regulator considers already binding. What's actually new is enforcement clarity, and a clock.
France's clock already ran out for existing lists
Under Article 82 of the French Data Protection Act, a tracking pixel is lawful only with the recipient's prior consent, unless it's strictly necessary to deliver what the user asked for.
There's a carve-out worth knowing, because it's narrower than it sounds. The CNIL does exempt open-tracking used purely for deliverability: adjusting send frequency, or culling recipients who never open so you stop mailing dead addresses. That's list hygiene, and it can run without consent. The moment the same pixel feeds behavioural analytics, lead scoring, or automation triggers, you are back inside the consent requirement. Most marketing stacks are firmly on the wrong side of that line.
Two dates define the exposure:
- Existing contacts had until 14 July 2026 to be brought into compliance.
- Contacts collected from 14 April 2026 onward got no transitional period at all. Consent is required from the first send.
Read those together and the position is uncomfortable. Any French investor list built this spring, with behavioural open-tracking left on by default, has been non-compliant since the addresses were collected. The deadline for the older contacts is not approaching. It's behind you.
Italy gives you until October, and it drew the line at withdrawal
The Garante's Provision No. 284 grants a six-month window. Compliance is required by 28 October 2026.
Here is where the two regulators diverge, and it matters for how you build. The Garante is actually more permissive on collection: it lets you fold tracking consent into the general "receive our emails" consent, as long as the request is neutral and non-coercive, and it exempts fully anonymised global open-counts (standardised pixels, no per-user identification, anonymised IP). What it does not bend on is withdrawal. A recipient must be able to switch off pixel tracking while continuing to receive your emails. One combined "unsubscribe from everything" control fails that test.
So the Italian requirement is not "ask twice." It's "let them stop the tracking without losing the emails."
Sending an email and tracking it are two different permissions
Strip away the country-specific detail and the shared principle is this: consent to receive a marketing email and consent to be measured inside it are not automatically the same permission.
Sending can stand on its own legal basis. Legitimate interest or an existing-customer relationship may cover the send. The behavioural pixel needs its own footing on top of that, whether that's a separate opt-in (France's cleaner path) or a bundled-but-separately-revocable consent (Italy's). And this holds in B2B, where senders routinely assume the rules loosen. For the tracking pixel specifically, they don't.
The practical translation is blunt. You can keep emailing a qualified prospect. You cannot silently log when they opened it, unless the tracking has a lawful basis of its own.
If you want the machinery-level version of why this matters beyond compliance, the same fragility already shows up in ad tracking: half your Meta conversions were probably already going uncounted before any regulator got involved. Consent gaps and measurement gaps are the same problem wearing different clothes.
This reaches Dubai, not just Paris and Milan
EU data protection attaches to the person, not the sender's postcode. A brokerage operating from Dubai that emails a buyer resident in Paris inherits that buyer's protections, in full. A UAE trade licence is not a carve-out from the CNIL when the list includes French residents, and international property lists routinely do.
So the senders most exposed here aren't European. They're the ones running European campaigns out of markets that assumed distance was a defence.
It's probably switched on right now, and no one chose it
Reported figures put a tracking pixel in roughly 68% of all email. That number is not the product of deliberate decisions. It's the product of defaults: Mailchimp, Klaviyo, and HubSpot all ship open-tracking enabled, and most operators have never opened the setting to look.
The remediation, then, usually isn't a policy document. It's a toggle in the sending platform that has been quietly collecting data with no lawful basis, generating the open rate you've been reporting to clients as if it were clean. If you want to see how deep the "clean number that isn't" problem runs across the whole tracking stack, it's worth auditing your Meta pixel and CAPI setup and reading the server-side versus native tracking comparison before you rebuild anything.
How to turn off open tracking in the platforms that default it on
Because the pixel is a default rather than a decision, the fix is usually a setting, not a project. Here is where each of the big three keeps the switch.
Mailchimp. Open tracking is on for every campaign except plain-text sends. In the email builder, open the Settings & Tracking section, click Edit, and uncheck Track opens. It's per-campaign, so unless you bake it into a template, it has to be unchecked on each send.
Klaviyo. The invisible open pixel is on by default. You can disable open and click tracking per message and per campaign inside the campaign's settings. There's no single global kill switch, so the audit has to cover your active flows, not just one-off sends.
HubSpot. Per email, the control lives under Tracking — Track opens and clicks for this email. Two catches: it only appears when your global tracking is enabled (Settings → Marketing → Email → Tracking), and a super admin has to grant the Override Marketing Email Tracking Settings permission before the toggle shows up for a user at all.
Turning the pixel off doesn't touch your ability to send. It removes the measurement, not the message, which is exactly the line the regulators drew.
Email tracking consent: the questions senders keep asking
Is email open tracking legal?
Sending the email is. Tracking the open without a lawful basis is where it breaks. In France and Italy that basis now has to be consent for anything beyond narrow deliverability use. Outside the EU, it turns on your list: if it includes EU residents, their protections travel with them regardless of where you send from.
Does GDPR require consent for tracking pixels?
GDPR and the ePrivacy Directive together do, for any pixel that identifies a recipient and feeds marketing analytics. The exceptions the regulators carved out are narrow: security and authentication, legally required service messages, and purely anonymised or deliverability-only open counts. Behavioural tracking that scores or segments a named recipient is not exempt.
France and Italy moved first. The ePrivacy and GDPR principles they are citing sit in the same statute books in every other member state, and the other data-protection authorities have the identical text in front of them. Treating this as a two-country problem is how the third and fourth rulings catch you flat.
---
Sources
- CNIL, Recommandation relative aux « pixels » dans les courriels (adopted 12 March 2026, published 14 April 2026): cnil.fr
- Garante per la protezione dei dati personali, Provvedimento del 17 aprile 2026 (Provision No. 284, Gazzetta Ufficiale n. 98, 29 April 2026): garanteprivacy.it
- Platform settings: Mailchimp — Use Open Tracking in Emails; HubSpot — Manage marketing email open and click tracking
This article is general information, not legal advice. For obligations specific to your lists and jurisdictions, consult a qualified data-protection professional.
Written by Foreground Digital. Start a project →