Email Tracking Pixels: What the CNIL (National Commission for Information Technology and Civil Liberties) Recommendation CNIL (National Commission for Information Technology and Civil Liberties) Changes
Article at a Glance: The CNIL (National Commission for Information Technology and Civil Liberties) its final recommendation on tracking pixels in emails on April 14, 2026. You have until July 14, 2026, to comply. In this article: what a tracking pixel is, what the CNIL (National Commission for Information Technology and Civil Liberties) , the two scenarios for adapting to these changes, and how to choose the one that best suits your organization.
Contents
Tracking pixels are a mechanism widely used in marketing and sales practices. Integrated into most email and lead generation tools, they make it possible—among other things—to track when an email is opened,identify when it is viewed, and determine the type of device used, often without any explicit action on the part of Data recipient.
On April 14, 2026, the CNIL (National Commission for Information Technology and Civil Liberties) up the legal uncertainty surrounding this practice by publishing its final recommendation on tracking pixels in emails. The framework is now clear: without prior consent, marketing pixels are illegal under the GDPR the French Data Protection Act.
This recommendation applies to all organizations that use email marketing tools—including marketing teams, sales teams, and communications departments. It applies to both B2C and B2B contexts.
You have until July 14, 2026, to come into compliance. This guide explains what the CNIL (National Commission for Information Technology and Civil Liberties) specifically CNIL (National Commission for Information Technology and Civil Liberties) and how to choose the approach that best suits your organization.
1. What is a tracking pixel in an email?
1.1. What is a tracking pixel? Definition, purposes, and data collected?
A tracking pixel—also known as a spy pixel—is an alternative tracking method to trackers and cookies, typically implemented as a tiny 1-pixel-by-1-pixel image embedded in the body of an email. You can’t see it. Data recipient .
But as soon as they open your email, their client automatically loads that image from a remote server. This loading process—which is identical to the mechanism used when a user visits awebpage —sends data back to the sender:
The email was opened
The date and time of the opening
The device used (mobile, desktop)
The IP address and, in some cases, the approximate location
Key concept regarding tracking pixels: A tracking pixel is a tracker as defined by GDPR the French Data Protection Act. It collects personal data without any visible action on the part of the Data subject. As such, it is subject to the same rules as cookies.
1.2. Why do marketing and sales teams use these tracking services?
The tracking pixel has become a standard feature in most marketing automation and sales lead generation tools. It is used to:
Measuring the Open Rate of Email Campaigns
Assessing a prospect's engagement: Did they open the email? How many times?
Measuring Deliverability: Are Emails Actually Reaching the Inbox?
Good to know:Email providers such as Gmail and Outlook have developed protective mechanisms that can skew the results of image preload tracking and image proxying. As a result, an email may be counted as “opened” without the Data recipient actually read Data recipient . This is one of the lines of reasoning that has informed the work of the CNIL (National Commission for Information Technology and Civil Liberties) this subject.
It is precisely because this practice is so widespread and rarely disclosed to recipients that the CNIL (National Commission for Information Technology and Civil Liberties) clarify the rules governing the protection of this user data.
2. The decision CNIL (National Commission for Information Technology and Civil Liberties) the CNIL (National Commission for Information Technology and Civil Liberties) on April 14, 2026
2.1. Why CNIL (National Commission for Information Technology and Civil Liberties) the CNIL (National Commission for Information Technology and Civil Liberties) launch a public consultation on tracking pixels in emails?
The CNIL (National Commission for Information Technology and Civil Liberties) cookies and trackers for several years. Tracking pixels in emails are an alternative tracking method to similar types of trackers, but their use in email—a personal and private space—raises specific regulatory issues.
In response to the growth of this practice and the increasing number of complaints received, the CNIL (National Commission for Information Technology and Civil Liberties) a dialogue with the main professional associations involved and then launched a public consultation in June 2025. A separate consultation focusing on economic issues was also conducted in parallel, involving private and public stakeholders, associations, and data protection authorities. This process led to Decision No. 2026-042 of March 12, 2026, and the final recommendation—based on the draft recommendation and enriched by the feedback received—was published on April 14, 2026.
Good to know: This recommendation applies to all parties that use tracking pixels in their emails (companies, organizations, government agencies), as well as to the technical service providers who implement them. The B2B sector is not exempt.
2.2. What is the deadline for complying with the CNIL (National Commission for Information Technology and Civil Liberties) recommendation CNIL (National Commission for Information Technology and Civil Liberties) email trackers?
You have three monthsfrom April 14, 2026— that is, until July 14, 2026—to choose your plan and implement it.
For contact databases created before that date, the CNIL (National Commission for Information Technology and Civil Liberties) a phased approach: at a minimum, recipients must be clearly informed about the use of tracking pixels and given the option to easily opt out.
3. Without consent, tracking pixels are prohibited
3.1. Which pixels are covered by the CNIL (National Commission for Information Technology and Civil Liberties) recommendation CNIL (National Commission for Information Technology and Civil Liberties) data protection?
The principle established by the CNIL (National Commission for Information Technology and Civil Liberties) clear: any tracking pixel used for marketing purposes constitutes the processing of personal data. Without a valid legal basis—and, in practice, without prior consent—such processing is unlawful under the GDPR Article 82 of the French Data Protection Act.
The objectives of this ban apply to all pixels used to:
Measuring the open rate for marketing analysis
Score or qualify leads based on their behavior
Trigger reminders or automated sequences
Tailor communications based on engagement
3.2. Are there any pixels that are exempt from the consent requirement under data protection laws?
Yes. The CNIL (National Commission for Information Technology and Civil Liberties) an exemption for pixels used solely for deliverability purposes —that is, for measuring individual open rates in order to identify inactive contacts and protect the reputation of email delivery systems.
This exemption applies only to emails related to a service requested by the Data recipient , transactional Data recipient , or emails for which the Data recipient given consent. It is strictly regulated:
The data collected must be limited to what is strictly necessary
They cannot be reused for other purposes (profiling, scoring, follow-up)
Good to know: Transactional emails (order confirmations, account alerts, password resets) are eligible for this exemption. Marketing emails, however, are not.
4. What are the two options for achieving compliance and adopting best practices?
The rules differ depending on whether email addresses were collected before or after April 14, 2026. Email addresses already in your database are subject to a 3-month transition period (from April 14 to July 14, 2026). However, new email addresses collected on or after April 14, 2026, are immediately subject to the new rules.
4.1. For Your Existing Database
If you already have a contact list, you have two options:
Scenario 1: You disable tracking pixels
This is the simplest option in terms of compliance. You don’t have to manage a consent process, send out an information campaign, or keep track of your contacts’ choices.
In practical terms:
Identify the tools that activate tracking pixels in your emails.
Turn off this feature in each of your tools.
Make sure there are no more tracking pixels in your communications.
In practice: If your email marketing, lead generation, or marketing automation tool does not allow you to disable tracking pixels, consider switching providers. As a data controller, you are required to use only processors sufficient safeguards for the protection of personal data (Article 28 of GDPR).
Scenario 2: You keep the marketing pixels
During the transition period (April 14 through July 14, 2026)
If you wish to continue using tracking pixels on your existing database, the CNIL (National Commission for Information Technology and Civil Liberties) is giving CNIL (National Commission for Information Technology and Civil Liberties) three months to bring your practices into compliance.
During this period, you may continue to send emails containing tracking pixels. In return, you must:
notify the individuals concerned about the use of tracking pixels;
clearly explain what they are used for;
allow them to easily opt out of receiving such emails in the future.
In practical terms, how do you do that?
Send an informational email to all affected individuals. This email must clearly explain that your emails contain tracking pixels, specify their Purpose for example, to track opens or clicks), and include a link or mechanism allowing recipients to opt out of their use.
Also, be sure to keep a record of this email (date sent, email content, list of recipients, etc.). In the event of an audit by the CNIL (National Commission for Information Technology and Civil Liberties), you must be able to demonstrate that this information was indeed transmitted during the transition period in order to benefit from the provisions set forth in the recommendation.
Effective July 14, 2026
Effective July 14, 2026, you will no longer be able to send emails containing tracking pixels to your database without first obtaining the free, specific, informed, and explicit consent of each Data recipient.
What does that mean?
You must send an email without tracking pixels to all affected individuals to request their consent. This email must clearly explain what tracking pixels are, what they are used for (for example, to measure opens or clicks), and request explicit consent.
Only those who have given their consent will then be able to receive emails containing tracking pixels. Others will continue to receive emails without tracking pixels or will no longer be tracked.
4.2. For new addresses collected on or after April 14, 2026
The transition period does not apply to new addresses collected on or after April 14, 2026. You have two options:
Scenario 1: You don't use marketing pixels
You choose not to track page views or interactions using tracking pixels. In that case, no consent process is required.
Please note: As mentioned earlier, this scenario is only possible if your tool allows you to disable tracking pixels. Otherwise, you will need to either obtain explicit consent from your contacts (Scenario 2) or switch providers.
Scenario 2: You use marketing pixels
If you wish to use tracking pixels in emails sent to new contacts, you must obtain their consent before using them.
This consent must be freely given, specific, informed, and explicit.
In practical terms, how can this be implemented?
If you collect contact information through a form
Add a separate checkbox for agreeing to the Terms and Conditions.
The CNIL (National Commission for Information Technology and Civil Liberties) a single consent for commercial marketing and the use of tracking pixels when such pixels serve a Purpose related to marketing (measuring open rates, personalizing content, adjusting the frequency of mailings, etc.).
Example:
☐ I agree to receive offers, news, and personalized content from S’investir / S’investir Conseil via email, as well as the use of tracking pixels to measure the opening of these emails in order to personalize their content and adjust their frequency.
However, separate purposes (such as sharing data with partners or targeted advertising in other contexts) require specific consent.
If you're doing B2B lead generation (data scraping, data enrichment, or purchasing databases)
Before sending an email containing a tracking pixel, you must first send an email without a tracking pixel to explain your approach and obtain the Data subject explicit consent.
Only those who have given their consent will then be able to receive emails containing tracking pixels.
In both cases, you will also need to:
keep proof of consent (date, form or email, version of the accepted text, etc.);
update your privacy policy to explain the use of tracking pixels;
document this processing in your processing log, citing consent as the legal basis;
to allow people to withdraw their consent just as easily as they gave it.
⚠️ Warning: Obtaining consent is only the first step. You’ll then need to be able to manage it over time. Be sure to create dedicated fields or tags in your CRM or email marketing tool to identify people who have given, denied, or withdrawn their consent. Without this organization, you risk sending emails containing tracking pixels to people who have never authorized them.
In summary:
Phase
What You Need to Do
Before July 14, 2026 (addresses collected before April 14, 2026)
✓ Clearly inform users about the use of tracking pixels, their purposes, and the data collected.
✓ Provide a simple, accessible, and immediately effective opt-out mechanism.
✓ Keep a record of this information campaign (date sent, content, recipients involved).
✓ Verify that your email marketing tool is capable of automatically processing opt-outs.
Effective July 14, 2026
✓ Disable tracking pixels for anyone who has not given their explicit consent.
✓ Continue sending emails if you wish, but without tracking pixels for those who have not consented.
✓ Obtain free, specific, informed, and explicit consent to continue using tracking pixels.
New addresses collected starting April 14, 2026
✓ Obtain opt-in consent before using any tracking pixels.
✓ Use a dedicated, unchecked checkbox (or send a preliminary email without a tracking pixel for B2B lead generation).
✓ Keep a record of consent and allow users to withdraw it at any time.
5. How This Will Affect Your Marketing and Sales Teams
5.1. What is the practical impact on your daily work?
For marketing teams, the open rate was a key performance metric. For sales teams, an email being opened was often the trigger for a follow-up. These practices aren’t disappearing—they’re evolving.
What's actually changing:
Open rates can no longer be measured without prior consent
Tools that trigger pixels by default must be reconfigured or replaced
The KPIs for your email campaigns are changing: click-through rates, direct responses, and conversions are becoming the best benchmarks.
5.2. Does the GDPR recommendation GDPR tracking pixels affect B2B lead generation?
Yes. The CNIL (National Commission for Information Technology and Civil Liberties) recommendationdoes not distinguish between B2C and B2B emails. As long as you contact individuals—including professionals—at their personal email addresses, the rules apply.
To learn more about the rules governing B2B sales prospecting in compliance with GDPR, see our guide to B2B prospecting
Download our guide to B2B lead generation
This guide provides practical advice on how to excel at B2B lead generation while complying with GDPR
How can Dipeeo help you identify best practices for data protection?
Choosing between the two scenarios proposed by the CNIL (National Commission for Information Technology and Civil Liberties) a detailed analysis of your situation. This is not a one-size-fits-all decision; it depends on the tools you use, how your contact lists were compiled, and your marketing and sales objectives.
At Dipeeo, you’ll have a dedicated legal advisor who analyzes your risks, helps you choose between the two scenarios recommended by the CNIL (National Commission for Information Technology and Civil Liberties) on your specific situation, monitors regulatory changes, and supports you throughout the process until you achieve GDPR compliance.
Dipeeo becomes your external DPO registered with the CNIL (National Commission for Information Technology and Civil Liberties) handles your compliance from start to finish:
A dedicated legal advisor with unlimited consultations.
All your legal documents drafted and updated.
A collaborative platform to easily manage your compliance.
A Trust Center to demonstrate your compliance with a single click.
A GDPR certification to highlight your commitment to your clients partners.
To make compliance your best business ally.
Contact us to set up an initial consultation → Dipeeo, an external DPO registered with the CNIL (National Commission for Information Technology and Civil Liberties)
7. Frequently Asked Questions About Tracking Pixels and the CNIL (National Commission for Information Technology and Civil Liberties) Recommendation
Are tracking pixels completely banned by the CNIL (National Commission for Information Technology and Civil Liberties)
No. The CNIL (National Commission for Information Technology and Civil Liberties) tracking pixels. It regulates their use in accordance with data protection principles. Marketing pixels require the prior consent of Data recipient. Pixels used solely for deliverability purposes are exempt, subject to strict conditions.
CNIL (National Commission for Information Technology and Civil Liberties) the CNIL (National Commission for Information Technology and Civil Liberties) recommendation also CNIL (National Commission for Information Technology and Civil Liberties) to B2B?
Yes. The regulations do not distinguish between B2C and B2B emails. As long as you send emails to individuals—including professionals—at their personal email addresses, the rules apply in full. Any company that uses email marketing tools is subject to these rules.
What should I do if my tool activates the pixels by default?
You must either disable this feature in the tool’s settings or implement a consent mechanism that complies with GDPR best practices. If the tool does not allow for either option, the CNIL (National Commission for Information Technology and Civil Liberties) explicitly CNIL (National Commission for Information Technology and Civil Liberties) considering a change in service provider.
Does a deliverability pixel require consent?
No, under certain conditions. The CNIL (National Commission for Information Technology and Civil Liberties) an exemption for pixels used for deliverability purposes in emails associated with a service requested by the Data recipient. The data collected must be limited to what is strictly necessary and may not be reused for other purposes.
How can one establish proof of valid consent?
Proof of consent requires that, for each contact, you keep a record of the date, the channel, and the exact wording through which consent was given. Simply sending an email without a way to track it is not enough. Your contact management tool must allow you to document and export this information at any time.
What is the penalty for noncompliance?
The CNIL (National Commission for Information Technology and Civil Liberties) the authority to impose fines of up to 4% of global revenue or 20 million euros. In addition to financial penalties, a public warning can damage your company’s reputation among your clients partners. The CNIL (National Commission for Information Technology and Civil Liberties) also announced upcoming inspections in this area as part of its regular oversight activities.
Conclusion
The CNIL (National Commission for Information Technology and Civil Liberties) recommendation CNIL (National Commission for Information Technology and Civil Liberties) clear: without prior consent, marketing tracking pixels are illegal under the GDPR. Your organization has two options before July 14, 2026: disable them or obtain consent. The right choice depends on your tools, your practices, and your objectives.
Beyond the deadline, pixel management is part of a GDPR compliance strategy: data processing records, privacy policy, proof of consent, and data security. These best practices also help build trust with your prospects and clients.
At Dipeeo, we help GDPR ensure GDPR compliance and turn these requirements into a real business advantage.