HomeKnowledge HubWeekly Guidance Watch › Garante Linee Guida — Tracking Pixels in Email

Regulator guidelines · surfaced resource

Garante Linee Guida — Tracking Pixels in Email

Garante per la protezione dei dati personali (Italy)Guidelines — Provvedimento n. 284, 17 April 2026Italian onlyCompliance deadline: 29 October 2026

Three days after the CNIL published its recommendation on email tracking pixels, the Italian supervisory authority adopted its own guidelines on the same technology — and built its flagship consent exemption on the opposite premise. The linee guida carry a compliance clock that is still running: six months from publication in the Gazzetta Ufficiale, which runs out on 29 October 2026 — where the CNIL’s three-month transition closed in July. Italian only; we summarise the load-bearing points in English below.

Published by
Garante per la protezione dei dati personali — the Italian supervisory authority. We have no relationship with the Garante and this is not an endorsement in either direction.
Type
Guidelines (linee guida) — Provvedimento of 17 April 2026, Registro dei provvedimenti n. 284, doc. web n. 10241943, adopted under Art. 154-bis(1)(a) of the Codice privacy. Press release of 21 April 2026 (doc. web n. 10241977). Published in Gazzetta Ufficiale, Serie Generale, n. 98 of 29 April 2026 (ELI 26A02030), with six months from that publication to comply — 29 October 2026, exactly.
Versions and language
Italian only. We could not locate an English edition on garanteprivacy.it as at 17 August 2026.
Jurisdiction
Italy — Art. 122 of the Codice privacy, the Italian transposition of ePrivacy Directive Art. 5(3). Not binding in the UK. All three national instruments in this area run off the same European provision through different doors — Art. 122 (IT), Art. 82 of the loi n° 78-17 (FR), PECR regulation 6 (UK) — which is why they read so similarly and diverge where they do.
Primary audience
The Garante’s own addressee list names information society service providers, providers of publicly accessible online services, email providers and operators of mass email-sending platforms, as well as anyone using tracking pixels — naming the infrastructure layer expressly, where the CNIL holds the mailbox provider to be neither controller nor processor.
Topic tags
tracking pixels · email marketing · ePrivacy · consent · privacy by design · Codice Art. 122 · open rates
Availability
Free, garanteprivacy.it; the provvedimento is also in the Gazzetta Ufficiale.

Why it matters

The position: tracking pixels fall within Art. 122 of the Codice, and in the ordinary case (“nei casi ordinari”) their use requires prior, free, specific and informed consent. Exemptions remain — security, strictly necessary technical requirements, institutional and service communications — subject to proportionality and minimisation, with clear, layered information and withdrawal that must be simple and available selectively. The guidelines put marked emphasis on privacy by design and by default, and at §6 make a concrete technical recommendation: the sender should generate an unintelligible, non-sequential identifier and hold the mapping to the recipient’s email address in a separate internal layer of the platform.

What the document does not share with the CNIL’s recommendation is the part worth reading closely. The Garante’s principal consent exemption is aggregate statistical measurement of open rates — a pixel identical for every recipient of the campaign, with the technical data anonymised, following WP29 Opinion 05/2014. The CNIL’s principal exemption is individual open-rate measurement for deliverability, minimised to a single overwritten date. Two supervisory authorities, the same technology, within days of each other — and exemptions built on opposite premises. The consent architecture differs the same way: the Garante expressly permits a single combined consent covering the promotional send and the pixel, provided withdrawal is granular; the CNIL’s model is purpose-by-purpose. For any group running email marketing across both countries, the operational consequence is that one consent-and-measurement design will not satisfy both texts without deliberate choices.

The clock matters too. Publication in the Gazzetta Ufficiale on 29 April 2026 started a six-month compliance window, so senders into Italy have until 29 October 2026. That is a live deadline, and open-tracking defaults in sending platforms are the estate it bites first.

The value, as with the French text, runs in both directions: a design that measures campaigns in aggregate keeps the signal marketing actually reports on, drops the per-recipient observation most recipients never knew about, and is the version of the practice a regulator has now written down as acceptable without consent. For a UK reader nothing here is binding — PECR reg. 6 and the ICO’s storage and access technologies guidance govern — but where a UK programme also sends into the EU, this pair of documents is where the operational detail on the question currently sits.

Read alongside the CNIL recommendation it diverges from, the EDPB Guidelines 2/2023 that explain why a pixel engages Art. 5(3) at all, and the EDPS and EDPB audit tools for establishing what your own estate does.

A Weekly Guidance Watch resource entry, curated by VulaPri. We summarise and link to the original; we do not reproduce or host it. Suggest a correction.