Email tracking pixels: what marketing teams should fix after the CNIL recommendation
- 24 Aug, 2026
An email tracking pixel often looks harmless. It is tiny, invisible, enabled by default in many email platforms, and it feeds a familiar metric: the open rate.
But that simple metric can hide a compliance decision. A pixel may reveal that a specific address loaded a message, when it happened, and sometimes technical context associated with that request. The event can then feed a CRM profile, a campaign report, a lead score or an automation workflow. This is not always just campaign statistics. In many setups, it is tracking.
In April 2026, the French data protection authority, CNIL, published its final recommendation on tracking pixels in emails. For marketing, CRM, growth and communications teams, the useful question is no longer: “Should we keep open rates?” The useful question is: what purpose does the pixel serve, what data does it collect, for which recipients, and on what basis?
This article gives teams a practical way to review email measurement without abandoning useful reporting altogether.
Why this changed in 2026
CNIL published its final recommendation on tracking pixels in emails on 14 April 2026, after a public consultation. The recommendation applies to private and public organisations using such pixels, and to the technical providers involved in that ecosystem.
It clarifies three areas:
- the role of each actor, especially senders and providers;
- when consent is required;
- when a pixel may be exempt, under strict conditions.
CNIL also introduced a progressive approach for email addresses collected before publication. Senders could continue using certain pixels if recipients received clear information within a period that should not, in principle, exceed three months from 14 April 2026, and if no objection was received after recipients had an easy way to object.
At the time of publication of this article, that period has passed. For teams that have not reviewed their emails, this is no longer a theoretical issue. Tool settings, email templates and real purposes should be checked.
What an email tracking pixel actually measures
A tracking pixel is usually a tiny image loaded from a remote server when an email is opened. The image URL may contain an identifier tied to a recipient, campaign, message or variant.
When the email client loads the image, it sends a request. Depending on the platform configuration, that request may reveal or record:
- that a message was opened or loaded;
- the date or time of the opening;
- a recipient or message identifier;
- the campaign or segment;
- technical data transmitted with the request;
- sometimes approximate location or email-client-related information, depending on the processing performed.
The important point is that the pixel is not automatically an abstract performance metric. In many configurations, it first creates an individual signal, and that signal is later aggregated into a report.
Teams should also be careful with the business interpretation. An “open” does not necessarily mean a person read the message. Images may be blocked, preloaded, proxied or loaded in ways specific to the email client. Open rate can still help with broad trends, but it should not be treated as a reliable measure of individual attention.
The starting point: define the purpose
The risky shortcut is to classify pixels by platform: “our email tool does this, so it must be standard.” CNIL’s framework pushes teams to start with purpose instead.
The same technical mechanism can serve several goals:
- measuring campaign audience;
- personalising future messages;
- scoring a prospect;
- triggering a sales alert;
- cleaning an inactive list;
- improving deliverability;
- authenticating the user for a requested service.
Those goals do not all lead to the same analysis. Article 82 of the French Data Protection Act governs operations that access information stored in terminal equipment or store information there. It is built around consent, with exceptions where the operation exclusively enables or facilitates electronic communication, or where it is strictly necessary to provide an online communication service expressly requested by the user.
In practice, two questions must be separated:
- Does the pixel require consent under tracker rules?
- Does the related personal data processing also comply with the GDPR, including legal basis, information, retention and rights?
Tracker consent and the GDPR legal basis are connected, but they are not the same thing. A sender may be allowed to send a commercial email in certain situations, yet that does not automatically permit the use of a tracking pixel under the rules for trackers.
Uses that usually require consent
Individualised marketing uses are the most sensitive. This is the case when the pixel reveals that a person opened a message and that signal changes the profile, score, segment or next step in the journey.
Typical examples include:
- showing in the CRM that a contact opened an email;
- triggering a follow-up after an open;
- prioritising a lead because they opened several messages;
- personalising a newsletter based on previous opens;
- measuring a recipient’s interest in a category of offers;
- producing contact-level or account-level reporting.
These uses go beyond deliverability. They aim to understand, influence or personalise the relationship with a person. They should be treated as tracking purposes in their own right.
Mixed-purpose pixels deserve particular attention. One pixel can pursue both an exempt purpose and a purpose subject to consent. But the purpose that requires consent can only be activated after valid consent has been collected. It is not healthy to place a pixel “just in case” and decide later how it will be used.
Deliverability may be exempt, but only narrowly
The recommendation recognises a possible exemption for certain individual deliverability measurements. The operational idea is to identify recipients who no longer open emails so the sender can reduce frequency, stop sending or clean the list. This can protect sender reputation and avoid repeatedly contacting people who appear inactive.
But the exemption is narrow. It does not make open rate a freely available metric. To stay within this framework, the pixel must be limited to the deliverability purpose and linked to a service requested by the recipient.
CNIL also stresses data minimisation. In principle, the central data point for that goal is the date of the last opening. Collecting IP address, user-agent or other additional data, then deleting or anonymising it quickly, does not bring the use into the exemption if that data was not necessary from the start.
For marketing teams, the lesson is simple: excessive data does not become necessary because it is deleted quickly.
Not all newsletters are the same
The word “newsletter” covers very different situations.
A newsletter expressly requested by the user may, in some cases, be linked to a service requested by that user. A pixel used only for deliverability may then benefit from the exemption, if all other conditions are met.
By contrast, a communication sent under the exception for similar products or services does not automatically become a service requested by the user. In that situation, a deliverability pixel should not be treated as automatically exempt.
Teams should examine the source of the list, the subscription method, the promise made at sign-up, and the actual purposes of the pixel.
A personalised newsletter raises another issue. If the pixel directly contributes to personalising content or frequency, consent may be linked to the subscription when the information is clear and the purposes are sufficiently connected. This should not become a vague formula such as “we improve your experience.” The recipient must understand what they accept.
Transactional emails, cart reminders and regulatory messages
Transactional emails often have a more favourable analysis, but not without limits.
An order confirmation, subscription confirmation, invoice, password reset or legal notice may be linked to a service requested by the user. A pixel limited to a compatible purpose, such as deliverability or user authentication, can therefore be analysed within the exemption framework.
But the message content matters. If an email presents itself as transactional while including a strong promotional element, the analysis changes. CNIL gives cart reminders as an example: their purpose is essentially promotional, since they encourage the recipient to complete a purchase, so they cannot benefit from the transactional-email exemption.
The right approach is to classify templates one by one: confirmation, invoice, onboarding, newsletter, prospecting, reminder, support, security, product notification. A single global rule for “all emails” will almost always be too rough.
Tracking links should not be ignored
The recommendation directly addresses pixels in emails. Tracking links are not directly covered by that specific recommendation, but CNIL notes that similar principles should be considered.
A tracking link may contain a recipient, campaign or segment identifier. When clicked, it can associate an action with a person. Depending on the technique, it may also involve operations covered by Article 82.
For acquisition teams, the practical distinction is useful:
- UTM parameters describe a campaign or channel;
- person-level identifiers in links track a recipient.
Pomelo’s guide to UTM tags, referrers and direct traffic explains how to tag campaigns without confusing attribution with individual tracking. The guide to privacy-first URL parameter filtering completes the picture: an email address, customer ID or token should not flow through URLs measured by web analytics.
How to audit your email platform
The audit should start with real emails, not only global platform settings.
List your message categories: newsletter, nurturing, prospecting, transactional, support, security, product, events. For each category, record whether open tracking is enabled, whether clicks are tracked, whether data syncs to the CRM, and whether automations use those signals.
Then ask five questions.
1. What purpose is being pursued?
Write one understandable sentence: “reduce sending frequency for inactive recipients,” “measure overall newsletter performance,” “trigger a sales follow-up,” or “personalise content.” If the purpose is vague, the configuration is probably vague too.
2. What data is collected?
Do not stop at “opened or not opened.” Check identifiers, timestamps, IP address, user-agent, campaign data, CRM tags, exports and provider logs.
3. Is the data necessary?
For deliverability, CNIL indicates that the date of the last opening is, in principle, the central data point. If the tool collects more, the sender should justify that need or disable excessive collection.
4. Is the choice understandable and easy to withdraw?
When consent is required, the recipient must understand the scope of their choice. They must also be able to withdraw consent as easily as they gave it. A preference centre may group several choices, but it must not make rights harder to exercise.
5. What happens after withdrawal?
Because an email already sent cannot be removed from the recipient’s inbox, the sender must have a mechanism to ignore pixel requests associated with withdrawn consent. Previously collected data should also be deleted if no other legal basis justifies keeping it.
A simple decision matrix
| Use case | Conservative reading | Recommended action |
|---|---|---|
| Global open rate for a newsletter | Possible only if the initial collection is lawful and the data is effectively anonymised or aggregated | Check the source collection, then report only aggregated metrics |
| Inactive-list cleaning for an expressly requested newsletter | Deliverability exemption may be possible | Limit data, document the purpose, provide information and objection mechanisms |
| CRM scoring based on opens | Individual tracking | Collect valid consent and document the processing |
| Sales alert after an open | Sensitive individual tracking | Avoid by default or collect explicit and clear consent |
| Order confirmation with no promotion | Requested service | Assess a deliverability or user-authentication exemption, without marketing reuse |
| Cart reminder | Promotional communication | Do not treat as an exempt transactional email |
| Secure unsubscribe link | May be strictly necessary | Keep the link limited to that purpose |
This matrix is not legal advice, but it helps teams remove the most common grey areas.
What if you did not inform existing lists before 14 July 2026?
For addresses collected before 14 April 2026, CNIL provided a transition period. In principle, clear information enabling objection had to be sent within three months, meaning before 14 July 2026. CNIL’s FAQ notes that a longer period may be justified in certain situations, such as database size or deliverability issues, but those difficulties must be objectively documented.
If no information was sent and there is no strong documented justification, the sender should apply the recommendation. That means collecting consent where the pixel requires it, or stopping the use of pixels that require consent.
The safest operational response is often progressive: disable unnecessary pixels, keep only strictly justified measurements, and rebuild preferences cleanly at the next collection or subscription point.
Keep useful reporting without tracking every open
Reducing pixels does not mean giving up email marketing measurement.
Post-click measurement is often more useful than open tracking. A click to an acquisition page, a qualified visit, a demo request, a registration or a download usually says more about intent than an image load.
To do this well, tag links with non-identifying campaign parameters and read results in web analytics. UTM values should describe the campaign, channel and possibly variant, not the person. A URL such as utm_source=newsletter&utm_medium=email&utm_campaign=product_update is useful. A URL containing an email address or customer ID creates privacy debt.
This is also where a clean separation between tools helps. The email platform manages sending, preferences and channel-specific obligations. Web analytics measures what happens after the click with limited and documented collection. Pomelo’s data collection summary can help explain what the analytics tool receives and what it does not receive.
Pomelo follows that logic: measure useful web signals without turning every marketing interaction into person-level tracking. But no analytics tool can, by itself, make an email platform configuration compliant. The two scopes should be audited separately.
Correction checklist for marketing teams
Before the next campaign, review these points:
- identify all email templates containing a pixel;
- separate opens, clicks, personalisation, scoring, deliverability and security;
- disable pixels with no clear purpose;
- check whether the emails were actually requested by the recipient;
- limit data collected for deliverability;
- avoid IP address, user-agent and other additional data when unnecessary;
- separate aggregate statistics from individual signals;
- provide a simple withdrawal or objection mechanism;
- ensure pixels already sent are no longer exploited after withdrawal;
- update the privacy notice and, where needed, the preference centre;
- document platform settings and retained choices;
- check contracts and roles with providers.
The analytics privacy notice offers a useful method for avoiding overly broad wording. The same principle applies here: do not promise “anonymous” or “purely statistical” measurement if the tool first processes signals tied to a person.
Conclusion
CNIL’s recommendation does not say that all email measurement is forbidden. It imposes clearer discipline: name the purposes, limit the data, separate deliverability from individualised marketing, and give people real control where consent is required.
Open rate can still exist in some reports. But it should be placed where it belongs: a fragile metric, sometimes useful in aggregate, rarely sufficient to steer a campaign alone, and legally sensitive when it relies on individual tracking.
For marketing teams, the fix is not only to change one checkbox in Mailchimp, Brevo, HubSpot or another platform. It is to rebuild email measurement so it is more limited, more explicit and more coherent with the rest of the analytics stack.
FAQ
Are email tracking pixels always subject to consent?
No. Some pixels may be exempt, especially for tightly defined deliverability or user-authentication purposes. But individualised marketing, scoring, personalisation and sales alerts usually require a consent analysis.
Can a global open rate be calculated from aggregated data?
It can be calculated from lawfully collected data that is then effectively anonymised or aggregated. This does not remove the need to analyse the initial pixel collection. Downstream aggregation does not fix excessive or unauthorised collection.
Can an expressly requested newsletter use a deliverability pixel?
Yes, it may be possible if the newsletter is a service requested by the user and the pixel is limited to deliverability. The sender should limit the data and avoid reusing that signal for scoring or uncovered personalisation.
Are tracking links covered?
The recommendation directly covers pixels in emails. Tracking links are not directly covered by that text, but they should be analysed using the same principles: purpose, transparency, possible consent and minimisation.
What should we do first if pixels are enabled everywhere?
Start by disabling uses with no clear purpose, then separate deliverability, aggregate measurement and individual tracking. After that, update information, preferences, consent evidence and tool settings.
Sources
- CNIL, Tracking pixels in emails: CNIL publishes recommendations to better protect privacy, 14 April 2026
- CNIL, Q&A - recommendation on tracking pixels in emails, 22 July 2026
- Légifrance, Article 82 of the French Data Protection Act
- EDPB, Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, final version, 16 October 2024
- CNIL, Cookies and other trackers topic page


