The CNIL’s recommendation (in French here) formally brings email tracking pixels under the same legal regime as cookies and similar trackers. In practice, this means that most tracking in emails—particularly for marketing or behavioural analysis—requires prior consent that is separate from consent to receive the communication. The CNIL narrows the scope of exemptions to strictly technical or security-related uses and imposes strong requirements on transparency, consent collection, and proof. It also addresses operational realities, including legacy databases and practical consent mechanisms, signalling a clear expectation that organisations redesign their email practices to ensure genuine user control.
Find here below the full text in English:
- Introduction
The use of invisible tracking pixels (sometimes referred to as “tracking pixels”) inserted into electronic mail (hereinafter “emails”) has experienced significant growth in recent years. These technical tools, widely used in electronic communications, serve various purposes: ensuring the proper receipt of emails (referred to as “deliverability”), measuring audience, personalising communication according to users’ interests, etc.
This practice raises specific issues in the context of email messaging, a personal space intended for consulting private content, accessible after an authentication procedure. The CNIL is receiving an increasing number of reports and complaints, reflecting heightened awareness among individuals regarding these practices.
The European Data Protection Board has published its Guidelines 2/2023 on the technical scope of Article 5(3) of the “Privacy and Electronic Communications” Directive (hereinafter the “ePrivacy Directive”), transposed into Article 82 of the French Act of 6 January 1978 (hereinafter the “Data Protection Act”). These guidelines recall the application of these provisions to pixels inserted into emails.
The principles and obligations set out in Article 82 of the “Data Protection Act” with regard to operations involving the reading or writing of information have been the subject of guidelines and a recommendation. This recommendation therefore clarifies the application of all these texts, taking into account the technological and operational specificities relating to pixels, and proposes concrete recommendations to ensure compliance. Any processing relating to personal data produced or collected via a tracker (hereinafter “subsequent processing”) must comply with the provisions of the General Data Protection Regulation and the relevant provisions of the “Data Protection Act”.
The recommendation applies to operations of reading or writing, without prejudice to compliance with the GDPR for subsequent processing.
The recommendation, and in particular the examples it provides, is neither regulatory nor exhaustive and is intended solely to assist professionals in their compliance efforts. It was developed following consultations with representatives of the relevant professions and civil society. It was also subject to a further public consultation from 12 June to 24 July 2025.
2. Scope of the recommendation
2.1 Technologies and environments concerned
In the context of emails, tracking pixels are images, most often of very small size, which are not directly contained in the email in question but are hosted on remote servers. Their display within an email client (whether in a dedicated software application or within a browser) requires making a network request, using the URL provided in the body of the message.
The URL of the image most often contains individualised parameters relating to the user or to the context in which the image appears. In response to this request, the image in question is downloaded and written into the memory of the user’s terminal, so that the email client can display it.
The display of this image generally has no informative value in itself for the user; however, the process that leads to this display allows the sender of the message or one of its partners to obtain information relating to the consultation of an email by a given user or in a given context.
The inclusion of these tracking pixels in emails therefore constitutes an instruction triggering communication between the user’s terminal and a remote server to send back targeted information (pixel identifier, IP address, etc.) to the actors who deploy them. These pieces of information are communicated through the parameters of the request, and their collection, by the server hosting the image, constitutes a reading operation on the user’s terminal.
Consequently, and in accordance with the position expressed by the European Data Protection Board in its guidelines, Article 82 of the “Data Protection Act” is applicable to the use of tracking pixels in emails.
The recommendation is limited to the use of tracking pixels in emails. While certain closed messaging systems (for example secure messaging services offered by banks) may present formal similarities with emails, they rely on different protocols, which excludes them from the scope of this recommendation.
2.2 Actors concerned and qualifications under the GDPR
The recommendation is addressed to public and private sector organisations involved in operations of reading or writing related to tracking pixels in emails. Each of these actors must determine its role with regard to the processing carried out.
The sender of the email
The term “sender of the email” refers to the actor (company, public body, association, etc.) that has decided to send the email, whether or not it is technically the sender.
It may decide to use solutions that involve the use of tracking pixels and then determines the purposes for which these trackers are used as well as the means. It must therefore be considered a controller, including where it outsources to third parties (for example, an email service provider) the management of the trackers implemented at its request.
In principle, it will also be a joint controller for the operations of reading or writing, which it contractually accepts, carried out by third parties within the emails whose sending it has requested⁴. Indeed, the purposes and means of these operations are then jointly determined⁵, even if the subsequent processing operations may fall under the independent responsibility of one or the other of these parties.
The email sending service provider (or “emailing” provider)
This refers to the company that provides the technical solution for sending emails. It is most often the one that offers the integration of tracking functionalities via pixel technology. This provider generally acts on behalf of the sender and in accordance with its instructions. In this context, it will act as a processor.
The provider of mailing list rental and email sending services
This refers to a company that provides its clients with a “turnkey” solution to send communications to mailing lists made available for rental. In this case, a case-by-case analysis is necessary.
Where the provider integrates tracking tools using pixel technology in order to provide information on behalf of its client, acting as controller, it acts, in principle, as a processor.
The provider may also use these pixels for its own purposes, which are generally not linked to a specific client (for example, improving the relevance of its mailing lists or the deliverability of emails with messaging service providers). In such situations, where a client contractually accepts the implementation of such operations, joint controllership may be established for these operations. In accordance with Article 26 of the General Data Protection Regulation, this relationship requires a clear and transparent allocation of respective obligations, in particular with regard to informing data subjects and ensuring their rights are respected.
The provider of tracking technology
Pixels integrated into emails may be provided by a specialised third-party actor, distinct from the email sending provider. The qualification of this actor depends on the purposes it pursues on the basis of the data resulting from tracking.
If the operations of reading or writing are carried out exclusively on behalf of the sender, the technology provider will be a processor.
However, if the data collected via the pixels are also used for its own purposes (for example, to improve the solution provided), where a client contractually accepts the implementation of such operations, the technology provider and the sender may be considered joint controllers for the reading or writing operations.
The email client/service provider (mailbox provider)
The mailbox provider ensures the reception and display of emails addressed to its users. Although it is a technical actor essential to the functioning of email, it does not directly intervene in the processing linked to the use of pixels.
This provider may, however, technically influence the ability of the pixel to trigger a reading operation on the terminal, for example by blocking the automatic loading of images. Nevertheless, insofar as it does not use the data generated by the pixel, it is neither a processor nor a controller.
3. Objectives pursued by the processing (purposes)
Tracking pixels in emails may be used for several purposes. In accordance with the provisions of Article 82 of the “Data Protection Act”, the insertion of tracking pixels in emails requires the prior collection of the recipient’s free, specific, informed and unambiguous consent, unless these operations: have the exclusive purpose of enabling or facilitating communication by electronic means or; are strictly necessary for the provision of an online communication service at the explicit request of the user.
3.1 Purposes requiring the recipient’s consent
In light of these legislative provisions, the CNIL considers that the use of pixels for the following purposes requires obtaining the recipient’s consent:
The analysis of email open rates in order to measure and optimise campaign performance by personalising message content or adapting the sending frequency or the communication channel (email, SMS, push notification, etc.). This purpose includes mechanisms aimed at ensuring the reliability of this measurement (for example, combating advertising fraud).
The creation of profiles of recipients based on the preferences and interests expressed, in order to target them in contexts other than email (on websites, mobile applications or via other communication channels).
The detection and analysis of suspected fraud, such as the identification of unusual or mass opening of emails, likely to indicate automated behaviour (for example, mass registrations for a competition, attempts to exfiltrate information, etc.).
The individual measurement of email open rates for deliverability purposes when it is carried out outside the cases referred to in section 3.2 of this recommendation.
3.2 Purposes exempt from the requirement to obtain consent
In light of the same provisions of Article 82 of the Act, and based on the practices brought to its attention, the CNIL considers that pixels used exclusively for the following purposes may be exempt from consent:
The implementation of security measures contributing to user authentication. In this context, the use of a tracking pixel pursues the sole purpose of contributing to the security of an authentication process (for example, by ensuring that the email containing a code used in the authentication process is indeed opened on a device known to belong to the intended user).
The individual measurement of email open rates for deliverability purposes. The management of a mailing list almost systematically requires the use of email open statistics in order to identify potential deliverability issues. For pixels to be exempt on this basis, the controller must demonstrate that the operations carried out are intended to be limited to what is strictly necessary to adapt the frequency or to stop sending emails to so-called “inactive” recipients (database cleaning).
Subject to this condition, pixels may also be used for the following objectives:
– to assess and adapt the communication channel in order, where appropriate, to choose alternative means of contact;
– to contribute to demonstrating compliance with a legal obligation relating to the transmission of information to the recipient: retaining a record of the opening of the email may help demonstrate compliance with a legal obligation in the context of certain emails (for example, providing information required by legal and regulatory provisions before, during or after contractualisation, etc.).
In principle, in compliance with the principle of data minimisation (Article 5(1)(b) of the General Data Protection Regulation), only the date (at day level, without recording the time) of the last known opening of emails, updated with each new opening and replacing the previous one, should be retained.
Insofar as Article 82 of the Act refers to an “explicit request” from the user, these exemptions can only concern emails requested by the recipient or which are linked to a service requested by the latter.
These include, for example, so-called “transactional” emails (see box) or emails for which recipients have given their consent.
What is a so-called “transactional” email?
For the purposes of this recommendation, a transactional email may be understood as a message triggered by a specific action or event on the part of a user. These emails are generally sent to provide users with important information relating to a requested service, their account, or their transaction.
They are not promotional messages, but rather informational or functional messages, necessary for the contractual relationship or for the requested service.
These include, for example, welcome emails, account alerts, notifications related to events such as the shipment of a parcel, order confirmations and purchase invoices, password reset reminders, responses to requests sent to customer service, appointment or booking reminders, payment notifications, as well as breach notification emails related to the requested service.
Pixels inserted in emails sent by public authorities, where these are addressed in the context of an activity directly linked to a public service mission, in particular those sent as part of proactive measures benefiting the user (information about the possibility of benefiting from a right), also fall within the scope of these exemptions.
The reuse of data that has been effectively anonymised is presumed not to create any additional interference with privacy in light of the protection provided by Article 82 of the “Data Protection Act”. It follows that where personal data is collected for an initial purpose—whether subject to the consent of the data subjects or exempt—its reuse does not require consent provided that it has been effectively anonymised beforehand. The General Data Protection Regulation remains applicable to the anonymisation process itself.
4. Information and consent
Consent must be obtained under the conditions recalled in Article 2 of the guidelines⁶ and Article 2 of the recommendation⁷ on “cookies and other trackers”, subject to the specific recommendations set out below which take into account the technological and operational specificities related to the pixel environment.
4.1 Information on the purposes of trackers
In addition to the other information necessary for obtaining informed consent (identity of the controllers, categories of data, etc.), it follows from the applicable texts, as interpreted by case law, that the purposes of the trackers must be presented to recipients before offering them the possibility to consent or refuse: they must be formulated in an intelligible manner, using appropriate language that is sufficiently clear to enable data subjects to understand precisely the scope of their choice.
The CNIL recommends that each purpose be highlighted with a short heading and that this be accompanied by a brief description. Examples enabling compliance with the applicable rules are set out below:
Analysis of email open rates for deliverability purposes:
– [Name of the email sender] and [third-party companies] use trackers (tracking pixels) to determine whether you open emails and the date on which you do so, in order to establish distribution statistics and undertake the actions (adjusting frequency or stopping sends) necessary for managing mailing lists.
Analysis of email open rates to measure and optimise campaign performance:
– [Name of the email sender] and [third-party companies] use trackers (tracking pixels) to determine whether you open emails, the time at which you do so, as well as information about the device you use, in order to personalise message content, adjust sending frequency or the communication channel used.
Creation of recipient profiles based on expressed preferences and interests in order to target you in contexts other than emails:
– [Name of the email sender] and [third-party companies] use your preferences (for example, the emails you have opened or the topics that interest you) to offer you content or advertisements tailored to you on other websites, applications or communication channels.
– These trackers allow us to determine whether you open emails, the time at which you do so, and to obtain information about the device you use.
Detection and analysis of suspected fraud:
– [Name of the email sender] and [third-party companies] use trackers (tracking pixels) in order to detect and analyse suspected fraud. These trackers allow us to determine whether you open emails, the time at which you do so, and to obtain information about the device you use.
The CNIL further recommends that a detailed description of these purposes be made easily accessible from the consent collection interface. This information may, for example, be displayed under a drop-down button that the user can activate directly at the first level of information. It may also be made available by clicking on a hyperlink present at the first level of information.
Finally, although Article 82 of the “Data Protection Act” does not require informing individuals about the use of pixels that do not require their consent, the CNIL recommends, as a matter of good practice, that they be informed of their existence in order to ensure full transparency regarding these operations. This information may be provided within the privacy policy.
4.2 Practical modalities for obtaining consent
Information on the scope of consent
It follows from the applicable texts, as clarified by case law, that the recipient must be aware of the scope of the consent they intend to give. Consequently, the CNIL considers that the information provided must, in particular, enable the recipient to identify the email address that will be concerned by the use of tracking pixels.
Similarly, this information must also enable them to understand that trackers will be placed on all the devices on which they are likely to access their emails.
Favour collecting consent at the time the relevant email address is collected
The CNIL recommends that consent for the use of tracking pixels in emails be obtained at the time the relevant email address is collected. Indeed, by informing the user when they provide their email address, the controller may, on that occasion, clearly specify that trackers may be inserted in the emails that will be sent to the address provided, in particular those that require valid consent.
The direct link between the email address collected and the subsequent use of trackers is thus made explicit and strengthens the user’s understanding of the scope of their consent.
In practice, the CNIL therefore recommends integrating, at the level of the email collection form, the information necessary to obtain informed consent, including a concise description of the purposes of the trackers (see section 4.1), together with a link to more detailed information (for example, the “cookies and other trackers” policy).
Subsequent collection of consent via a link included in an email without tracking pixels
Where consent cannot be obtained at the same time as the collection of the relevant email address, the controller may request the consent of the person concerned by sending an email message that must not contain any tracking mechanism subject to consent.
This method of obtaining consent is appropriate in the following situations:
– in order to use pixels subject to consent in emails sent to an email address, where such consent was not obtained at the time the address was collected;
– where the email address is collected by a third party without the transmission of proof of consent for tracking pixels;
– where the email address is collected under conditions that make it difficult to obtain valid consent for tracking pixels (for example, where the address is collected orally).
In practice, the email may include a link to collect the choices of the data subject, but care should be taken to avoid consent being collected inadvertently through automatic pre-loading of the link by certain email clients.
For this purpose, the CNIL recommends, for example, that the link redirects to a page on which the individual must perform a positive action (clicking on a button, etc.) to confirm their consent, in a manner similar to mechanisms used for unsubscribe links.
The CNIL recommends the use of a tracking link in order to ensure that only the holder of the email address can express their consent.
Tracking links used to contribute to user security may be exempt from consent within the meaning of Article 82 of the “Data Protection Act”.
As recalled in Guidelines 2/2023 of the European Data Protection Board, the use of tracking links is subject to Article 5(3) of the “ePrivacy Directive”, transposed into national law in Article 82 of the “Data Protection Act”.
However, the use of a unique link per recipient limits the use of a functionality (in this case, the expression of choices) to the intended user alone and prevents unauthorised access to this functionality.
Consequently, insofar as these tracking links contribute to protecting the recipient against unauthenticated access to functionalities reserved for them, such use constitutes a security measure related to user authentication and is exempt from consent, the trackers being strictly necessary for the service requested by the user.
Where consent to the use of tracking pixels is requested through the sending of an email containing a link to an interface for collecting choices, this request must not be designed in such a way as to exert disproportionate pressure on individuals in order to encourage them to consent, in particular by preventing or hindering the reading of emails.
Since consent must result from a positive act, the inactivity of the recipient must be interpreted as a refusal to consent to the use of tracking pixels.
The CNIL recommends that the recipient be offered the possibility to explicitly refuse tracking pixels, in a manner that is as simple as their acceptance, and that the recipient’s choices be recorded so that they are no longer solicited in subsequent emails for a certain period of time. The absence of solicitation for a period of 6 months constitutes good practice on the part of publishers.
Expression of freely given consent
Consent can only be valid if recipients are able to exercise their choice freely.
Collecting a single consent simultaneously for several processing operations serving distinct purposes (bundling of purposes), without the possibility of accepting or refusing each purpose individually, may, in certain cases, affect the freedom of choice and therefore the validity of consent (Recital 43 of the General Data Protection Regulation).
Consequently, in order to ensure that consent is freely given, the CNIL recommends requesting recipients’ consent independently and specifically for each distinct purpose. However, where the consent collection mechanism provides for two levels of information, it is possible to obtain overall consent at the first level only if the user is able, at the second level, to give consent per purpose, or per group of purposes where these are related.
It is possible to obtain a single consent—therefore without offering the recipient the possibility to make a granular choice at the second level of information—for direct electronic marketing (in accordance with Article 34-5 of the Postal and Electronic Communications Code) and for the use of tracking pixels in marketing emails for related purposes.
By way of example:
Where marketing is expressly presented as personalised, consent to such marketing and the use of tracking pixels directly contributing to this personalisation (for example, for content personalisation or adapting the frequency of sending) may be covered by a single consent.
A single consent may be given for direct electronic marketing and the use of tracking pixels to combat fraudulent registrations for a competition by email, in order to ensure equal conditions for participants by excluding those who use automated solutions to register multiple times.
Where operations of reading or writing pursue distinct and unrelated purposes (see section 4.1), consent must be obtained independently and specifically for each of them. The CNIL recalls that advertising—whether personalised or contextual—displayed within online advertising banners (also referred to as display advertising) and direct marketing are two distinct purposes. Users must therefore be able to consent independently and specifically to these two purposes.
Point of attention
The consent regime for tracking pixels is independent from that applicable to the sending of the email itself: thus, consent for tracking pixels may be required for emails that do not, in principle, require the consent of recipients (order confirmations, marketing of similar products or services provided by the same company to its customers, charitable marketing, marketing to professionals in connection with the profession of the person targeted, etc.).
Collection of consent for pixels via a consent management platform (CMP)
Today, CMPs are generally perceived by users as tools designed to collect choices relating to trackers placed on websites or within mobile applications. Moreover, in certain cases, consent for pixels may be collected separately from the collection of the email address.
The use of a CMP to collect consent for the insertion of pixels in emails therefore requires particular attention. The requirement for “informed” consent implies, in particular, that individuals can easily understand the scope of their consent—specifically, that their choice also covers operations carried out in connection with an environment (email) that is distinct from the one in which they express their consent (web or mobile application), as well as the email address that will ultimately be affected by those choices.
5. Withdrawal and management of consent
It follows from the applicable texts, as clarified by case law, that individuals who have given their consent to the use of trackers must be able to withdraw it at any time. Moreover, it must be as easy to withdraw consent as it is to give it.
In the context of the use of tracking pixels in emails, the CNIL recommends that the possibility to withdraw consent be offered through a tracking link in the footer of each email.
The controller must implement appropriate technical measures to enable easy withdrawal of consent. Where the link directs the user to a web page, this page should allow the withdrawal of the consent(s) given without any additional action (in particular without having to enter the relevant email address in a form).
The use of a unique link per recipient makes it possible to limit the use of this functionality to the intended recipient of the withdrawal tool and thus avoid unauthorised access to this functionality, while respecting the requirement that withdrawal of consent be easy.
Consequently, as recalled in the box above (“Tracking links used to contribute to user security may be exempt from consent within the meaning of Article 82 of the ‘Data Protection Act’”), such use constitutes a security measure for the benefit of the user and is exempt from consent since the trackers are then strictly necessary for the service requested by the user, in accordance with Article 82 of the “Data Protection Act”.
The controller must ensure the effectiveness of the withdrawal of consent: the reading or writing operations concerned by this withdrawal must no longer take place when sending future emails.
With regard to emails already sent, given the specific technical context, it may be necessary to implement solutions to ensure that previously used trackers are no longer exploited (in particular where the recipient reopens the email), so that the withdrawal of consent is effective.
6. Proof of consent
The controller must be able to demonstrate, at any time, that users have given their consent (Article 7(1) of the General Data Protection Regulation).
In principle, the mechanisms implemented by organisations must make it possible to retain proof of consent on an individual basis, that is to say, a record of each person’s consent, as well as the conditions under which that consent was obtained.
In certain situations, the controller does not itself collect the consent of the data subjects. This is the case, in particular, where the data is transmitted by a third party who is also responsible for collecting consent in its name and on its behalf.
The obligation to demonstrate proof of consent cannot be fulfilled solely by the presence of a contractual clause whereby one of the parties undertakes to collect valid consent on behalf of the other party. Indeed, such a clause does not enable the organisation to guarantee, in all circumstances, the existence of valid consent.
The contract may, however, be used to govern:
– the mechanisms implemented to demonstrate the collection of valid consent;
– the provision of evidence to the organisation that seeks to rely on the consent;
– where applicable, the conditions under which such evidence must be retained, in particular in order to preserve its probative value;
– the arrangements for regular auditing of consent collection mechanisms.
These contractual commitments do not release the controller from its responsibility if it is unable to provide proof of consent due to the failure of the third party.
7. Modalities for applying the CNIL recommendation
The recommendation clarifies the scope of the provisions applicable to this type of reading or writing operations.
Under these conditions, with regard to email addresses already collected, reading or writing operations may continue to be implemented, subject to the sending of clear and accessible information to recipients within a period which should not, in principle, exceed three months from the publication of the recommendation.
This information must enable such recipients, where their consent has not been obtained in accordance with the modalities set out in this recommendation, to be put in a position to object to such operations for future emails.
However, where the controller is required to obtain new consent for the use of the email address (for example, for the transmission of data to new controllers for the purpose of electronic marketing), it must obtain valid consent for the implementation of reading or writing operations that are not exempt.
0 Comments