Executive Summary
In April 2026, the French data protection authority, the CNIL, published its final recommendation on the use of tracking pixels in emails.
The timing explains why many users suddenly started receiving emails about tracking pixels, consent, preferences, and privacy settings.
These pixels are invisible to the recipient, but they can reveal whether an email was opened, when it was opened, from what type of device, and sometimes an approximate location based on the recipient’s IP address.
The CNIL’s position is not that all email tracking is prohibited.
The point is more subtle: companies must distinguish between limited technical uses and tracking used for marketing, profiling, personalization, or campaign optimization.
In many cases, receiving an email does not mean accepting to be tracked while reading it.
That distinction is now becoming central to email marketing compliance in France.
What Is an Email Tracking Pixel?
An email tracking pixel is a tiny invisible image embedded in an email.
When the recipient opens the message, the image loads from a remote server. That loading event can tell the sender that the email was opened.
Depending on the configuration, the sender may also collect information such as:
- the opening date;
- the time of opening;
- the device used;
- the email client;
- an approximate location inferred from the IP address.
Individually, this may seem harmless.
In practice, it turns a simple email opening into behavioral data.
That is why the CNIL considers email pixels to be a privacy issue, not merely a marketing feature.
Why Did Users Receive So Many Emails About Tracking Pixels?
The CNIL published its recommendation on April 14, 2026.
For email addresses already collected, companies had a limited period to update their practices, inform recipients clearly, and offer a way to refuse certain tracking operations before July 14, 2026.
That explains the sudden wave of emails received by users in France.
Many companies had to review their email tracking practices at the same time.
The objective was not only to update privacy wording.
Companies also had to identify which pixels they used, for what purposes, with which vendors, and under which legal basis.
When Is Consent Required?
The key legal distinction is the purpose of the pixel.
Consent is generally required when tracking pixels are used to measure individual engagement for marketing, personalization, campaign optimization, profiling, or retargeting.
Examples include:
- measuring whether a specific recipient opened an email;
- adapting the frequency of marketing messages;
- personalizing content based on email behavior;
- building a profile of interests;
- targeting the person on other channels.
In these cases, the pixel does more than support the technical delivery of an email.
It observes behavior and turns that behavior into exploitable data.
That is why consent becomes necessary.
When Can Tracking Pixels Be Exempt From Consent?
Some uses may be exempt from consent, but the exemption is narrow.
For example, certain pixels may be used for security, authentication, legal communication, or strictly necessary deliverability purposes.
The CNIL also recognizes a limited exemption for measuring email deliverability when the objective is to stop or reduce messages sent to inactive recipients.
However, this exemption must remain strictly limited.
The data collected must be necessary for that purpose and cannot be reused for marketing, profiling, personalization, or broader analytics.
In practice, companies should not treat the exemption as a general permission to track email behavior.
The Core Rule: Receiving an Email Is Not the Same as Accepting Tracking
This is the most important lesson.
A person may agree to receive a newsletter, a commercial email, or a service-related message.
That does not automatically mean they agree to be tracked when reading it.
The CNIL’s recommendation separates two things that were often treated together:
- consent to receive communications;
- consent to tracking pixels inside those communications.
This distinction matters for legal departments, marketing teams, CRM teams, and data protection officers.
It means that email compliance is no longer only about unsubscribe links.
It is also about tracking choices, consent records, vendor contracts, preference centers, and proof.
What Should Companies Do Now?
Companies using email tracking pixels should take practical steps.
They should first identify all pixels used in their emails.
Then they should classify each pixel by purpose: security, deliverability, analytics, personalization, profiling, or marketing optimization.
Where consent is required, companies should collect it through a clear, specific, and informed mechanism.
They should also allow recipients to refuse tracking without necessarily unsubscribing from the emails themselves.
Finally, companies should document the choices expressed by users and update their privacy notices, cookie policies, email preference centers, and contracts with technical providers.
This is not only a marketing issue.
It is a governance issue.
Why This Matters Beyond Email Marketing
The email tracking pixel debate reflects a broader shift in data protection law.
Privacy compliance is no longer limited to obviously sensitive data.
It also applies to small behavioral signals that, once collected and reused, reveal something about a person’s attention, habits, interests, or engagement.
Opening an email may look insignificant.
But when that opening is recorded, analyzed, connected to a profile, and used to influence future communication, it becomes part of a data strategy.
That is why the CNIL’s recommendation matters.
It reminds companies that transparency must apply even to invisible forms of tracking.
Key Takeaways
Email tracking pixels are invisible but can collect meaningful behavioral data.
The CNIL does not prohibit all tracking pixels, but it requires a clear distinction between technical uses and marketing or profiling uses.
Consent is generally required when pixels are used to measure individual engagement, personalize content, optimize campaigns, or enrich profiles.
Some limited uses may be exempt, especially for security or strictly necessary deliverability purposes.
Receiving an email does not automatically mean accepting to be tracked while reading it.
Companies should update their consent flows, preference centers, privacy notices, vendor contracts, and proof mechanisms.
What is an email tracking pixel?
An email tracking pixel is an invisible image embedded in an email. When the email is opened, the image loads and can inform the sender that the message was read.
Are email tracking pixels illegal in France?
No. Email tracking pixels are not automatically illegal. Their legality depends on the purpose, transparency, legal basis, and whether consent is required.
When is consent required for email tracking pixels?
Consent is generally required when pixels are used for marketing analytics, personalization, campaign optimization, profiling, retargeting, or individual engagement measurement.
Can a company use pixels for email deliverability without consent?
In limited cases, yes. The CNIL allows a narrow exemption for certain deliverability purposes, especially when the goal is to reduce or stop emails to inactive recipients. The use must remain strictly necessary and limited.
Can users refuse tracking without unsubscribing?
Yes. A key practical point is that refusing tracking should not necessarily force the user to unsubscribe from the email communication itself.
What should companies document?
Companies should document the purposes of tracking, consent choices, refusals, withdrawal mechanisms, vendors involved, and the technical functioning of their pixels.