CNIL Recommendation — Tracking Pixels in Emails
A tracking pixel in an email is an embedded resource whose job is to tell the sender the message was opened — when, and on what. The CNIL’s recommendation is the most granular regulator treatment of that single technology we have found: which purposes need consent, which are exempt, and precisely how little data the exempt path is allowed to carry. It is framed expressly on the EDPB’s Guidelines 2/2023, and it arrives with a 27-question FAQ and a recorded webinar.
- Published by
- Commission nationale de l’informatique et des libertés (CNIL) — the French supervisory authority. We have no relationship with the CNIL and this is not an endorsement in either direction.
- Type
- Recommendation — Délibération n° 2026-042 of 12 March 2026, published 14 April 2026 (Légifrance JORFTEXT000053876850), following a public consultation run 12 June – 24 July 2025. Accompanied by a 27-question FAQ published 22 July 2026 and a recorded webinar.
- Versions and language
- French is authoritative; the CNIL publishes an English courtesy translation carrying the notice that the French text prevails. One translation caution: the English text cites “Article 5.1.b)” GDPR for minimisation — minimisation is Art. 5(1)(c), so cite the principle rather than the sub-paragraph.
- Jurisdiction
- France — Article 82 of the loi n° 78-17 of 6 January 1978, the French transposition of ePrivacy Directive Art. 5(3), applied through the frame of EDPB Guidelines 2/2023. Not binding in the UK. The UK analysis runs through PECR regulation 6 and the ICO’s storage and access technologies guidance (final 29 April 2026), which covers pixels expressly.
- Primary audience
- Email-marketing owners, martech and CRM teams, DPOs and counsel reviewing campaign tooling — and anyone whose sending platform switched open-tracking on by default.
- Topic tags
- tracking pixels · email marketing · ePrivacy · consent · minimisation · open rates · ePD Art. 5(3)
- Availability
- Free, no registration, cnil.fr — recommendation, FAQ and webinar together.
Why it matters
The recommendation’s structure is the useful part. It names four purposes for which a pixel requires prior consent, and two that are exempt: authentication security, and individual open-rate measurement for deliverability — and the deliverability exemption is conditional on being limited to what is strictly necessary to adjust sending frequency or stop sending to inactive recipients. The minimisation limit on that exempt path is unusually specific: in principle only the date — the day, without the time — of the last known opening, overwritten at each new opening with the previous entry deleted. The FAQ closes the anonymise-it-afterwards workaround (Q7), while preserving a documented-necessity carve-out. Whatever jurisdiction you sit in, that is a regulator answering the question measurement vendors usually answer for you.
The line most likely to be missed sits in an attention box at §4.2, and is worth quoting in full: “The consent regime for tracking pixels is independent of that applicable to the sending of the email in question: thus consent for tracking pixels may be necessary for emails that do not, in principle, require the consent of the recipients (confirmation of an order, marketing for similar products or services provided by the same company to its customers, charity marketing, prospecting for professionals related to the profession of the person being marketed, etc.).” The soft-opt-in email and the order confirmation are exactly the sends where open-tracking tends to run unexamined.
Two practical notes. The transition period was three months from publication for addresses already held, so it closed around 14 July 2026 — in France this is current expectation in application, not a future state. And the recommendation should be read against its Italian counterpart: the Garante adopted its own linee guida on email tracking pixels three days after the CNIL published, and the two build their flagship exemptions on opposite premises — the CNIL exempts individual open-rate measurement for deliverability; the Garante’s principal exemption is aggregate statistical measurement using a pixel identical for every recipient. Same technology, same European provision, two national doors — Art. 82 (FR) and Art. 122 of the Codice (IT), with PECR reg. 6 as the UK’s — and the divergence is the clearest illustration we have seen that the exemptions are where the national positions actually differ.
The value runs both ways. Knowing which measurement purposes are exempt, and on what conditions, lets you keep the deliverability signal your sending genuinely needs and switch off the rest deliberately — rather than putting every campaign behind a consent you may not need or running tracking nobody decided on. And the person receiving the email gets observation that was chosen and minimised, not defaulted. For a UK reader the binding analysis is PECR reg. 6 and the ICO’s guidance; read this for the level of operational detail — purpose by purpose, field by field — that generalist guidance deliberately leaves open.
Read alongside the EDPB Guidelines 2/2023, which establish why a pixel engages the storage-and-access rule at all, and the two regulator-built audit tools — the EDPS Website Evidence Collector and the EDPB Website Auditing Tool — for establishing what your own estate actually does.
