This is not legal advice
This orients you to a fast-moving area; it is not legal advice. These rulings are recent and obligations turn on where your recipients are. Take qualified advice for your specific situation.
See legislation and compliance for the sending-consent regimes this sits alongside.
Two different consents: to send and to track
Most compliance discussion is about the right to send: may you put a marketing message in this person’s inbox. That is governed by PECR, the GDPR, CAN-SPAM and the rest. There is a second, separate question that owned-channel programmes routinely overlook: may you track what the recipient does with the message, the open pixel that fires when images load and the redirect that records a click.
In the EU these are not the same permission. Nor does a single tracking regime replace the one behind sending. The GDPR governs both. Sending a marketing message and measuring what the recipient does with it are each processing of personal data, each needing its own lawful basis and each bound by the GDPR’s principles and rights. What sets tracking apart is a further requirement that applies only when the measurement touches the device. Because an open pixel reads from and writes to the recipient’s device exactly as a cookie does, it also falls under Article 5(3) of the ePrivacy Directive, the provision behind the cookie banner, which requires prior consent for the access in its own right. Tracking that reaches the device therefore needs both Article 5(3) consent and a GDPR basis; tracking that never touches the device, such as a server-side click redirect, needs only the GDPR basis.
The right to send is not the right to track
You can have a clean, fully consented right to email someone and still have no lawful basis to measure their opens.
The Article 5(3) baseline
Article 5(3) of the ePrivacy Directive requires consent before information is stored on a user’s terminal equipment or information already stored there is accessed, unless it is strictly necessary to provide a service the user requested. The European Data Protection Board’s Guidelines 2/2023 on the technical scope of Article 5(3) confirmed that the provision is technology-neutral and reaches email tracking pixels, not only browser cookies. Because every EU and EEA member state transposes the same directive, this baseline applies across the bloc, with national authorities citing each other’s reasoning when they apply it.
So an open pixel in the EU is presumptively a consent activity under Article 5(3), with a narrow strictly-necessary exemption, regardless of how solid your sending consent is.
Article 5(3) applying does not remove the GDPR; both govern the same measurement. Recording who opened or clicked is processing of personal data, which always needs a lawful basis under Article 6 and must meet the GDPR’s transparency, purpose-limitation and data-subject-rights obligations. Where Article 5(3) requires consent for the access to the device, that consent is also the operative GDPR basis for the collection: the EDPB’s Opinion 5/2019 on the interplay between the two instruments treats Article 5(3) as the more specific rule, which rules out placing the pixel on consent and then reclassifying the same collection as legitimate interest to avoid the consent requirement. Click tracking runs the other way. It usually works by rewriting the link through a redirect that logs the click on the server before forwarding. That stores and reads nothing on the recipient’s device, leaving Article 5(3) not necessarily engaged. The GDPR still is, because the click tied to a person is personal data. Every open and click therefore raises a GDPR question; the open pixel raises an ePrivacy one as well.
France: the CNIL recommendation
In April 2026 the CNIL adopted a recommendation on tracking pixels in email (Decision No. 2026-042), applying Article 82 of the French Data Protection Act, France’s transposition of Article 5(3). Its core positions:
- Two independent consents. One to receive marketing email and a separate consent for the deployment of the tracking pixel. One does not imply the other; bundling them is not valid.
- Consent is the default for analytics uses. Prior, specific consent is required wherever pixels are used for campaign performance analysis (measuring open rates to tune frequency, content or channel); recipient profiling; fraud or bot detection; individual-level open tracking beyond what deliverability strictly needs.
- A narrow exemption. Limited security purposes and basic list hygiene can fall outside the consent requirement, but most marketing and analytics uses do not.
The CNIL stressed it was clarifying rules in force since the GDPR applied in 2018, not creating new ones.
Italy: the Garante guidelines
Days later, in April 2026, the Italian Garante adopted guidelines on tracking pixels in email under the ePrivacy Directive, the Italian Data Protection Code and the GDPR. Its positions track the CNIL’s with one notable difference on aggregate measurement:
- Consent at collection, no bundling. Pixels are prohibited unless prior consent is obtained or an exemption applies. Consent should be taken when the email address is collected, after clear information about the pixel and its purpose. A “take it or leave it” bundle with the newsletter subscription will not meet the standard.
- An anonymous-aggregate exemption. Consent is not required where the pixel serves only an anonymised statistical count of the overall open rate, provided standardised pixels are used and related technical data are anonymised. Authentication-related security measures and legally required service messages are also exempt.
- A compliance deadline. The guidelines opened a six-month window expiring 28 October 2026. Fines reach the GDPR ceiling of €20 million or 4% of worldwide annual turnover.
Germany and the wider bloc
Germany transposes Article 5(3) through §25 of the TDDDG (the renamed TTDSG). The German Data Protection Conference’s guidance, supplementing EDPB Guidelines 2/2023, treats email pixel tracking as requiring consent on the same basis. France and Italy are simply the authorities that have published the most explicit email-specific guidance; the underlying obligation exists in every member state, where the Dutch, Spanish and other DPAs apply the same logic. Treat the French and Italian texts as the clearest statement of a rule that holds bloc-wide, not as two national quirks.
The same split, across the channels
The email pixel is one instance of a rule that is not about email. On any channel, measurement tied to an identifiable person is processing of personal data under the GDPR and its analogues. Wherever such a law applies, the permission to reach someone and the permission to measure them are separate grants, device or not. Article 5(3) is the added requirement, applying wherever the measurement stores information on the recipient’s device or reads information already there. EDPB Guidelines 2/2023 read that as technology-neutral: the terminal equipment it protects is the smartphone, laptop or connected TV, not the inbox. So where the measurement touches the device, ePrivacy requires consent for the access as well as the GDPR obligations; where it does not, only the GDPR applies. The channels differ mainly in how much of the measurement touches the device.
- Web and onsite. Cookies, local storage and browser fingerprinting are the original case of Article 5(3), for which the consent banner is where that access is asked for. Not all web measurement is that: server-side analytics and first-party server logs that record a page view or an on-site click without reading or writing the visitor’s device raise no Article 5(3) question, only the GDPR one, the same split the email click follows. Where the device is read and consent is refused, the visitor cannot be profiled, a legal cap on what website personalisation can do rather than a technical one. It is the same grant the email pixel needs, asked at a different surface.
- Mobile app, push and in-app. An app SDK that reads a device identifier or writes to local storage falls squarely within Article 5(3). Platform rules add a gate of their own: Apple’s App Tracking Transparency requires a prompt before an app may access the IDFA to track across apps. Android has been moving to restrict its advertising identifier on a similar path. Event tracking the app reports server-side against a signed-in account, without reading device storage, may not engage Article 5(3), but the GDPR governs it as it governs any behavioural data. The OS permission to send a push is a separate grant again, distinct from the right to track and from the analytics the SDK records inside in-app.
- SMS and RCS. There is no open pixel. A tracking link records the click on the redirect server as it resolves, which stores and reads nothing on the device and so does not necessarily engage Article 5(3) the way a pixel does. The GDPR is: because the click tied to a number is personal data, click measurement still needs a lawful basis and clear disclosure even where ePrivacy requires no consent for it.
- Wallet and point of sale. A scanned barcode and pass analytics are first-party and tied to an identity the customer presented, a lighter position than third-party device tracking, but the data is still processed under the GDPR even where Article 5(3) is not engaged. See wallet passes and point of sale.
- Direct mail. No device, no Article 5(3): the match-back and the per-recipient code are ordinary personal-data processing under the GDPR and nothing more. See direct mail.
Across all of them, the right to reach someone on a channel never includes the right to measure what they did there. Where the GDPR or an equivalent data protection law applies, it governs the measurement data on every channel. On the device-based channels Article 5(3) adds a consent requirement for the device access, with a platform gate, the tracking prompt, the advertising-identifier phase-out or the push opt-in, as a further condition again; on the channels that never touch the device, only the GDPR’s processing rules apply.
What this means for measurement
The split also changes how to read your numbers. The bundle already warns that open rate is corrupted by Mail Privacy Protection and is directional at best; see metrics are directional and core metrics. Tracking consent adds a second, structural source of missingness: in strict-consent jurisdictions a non-random slice of your EU audience may never be measured at all. EU open and click rates therefore understate true engagement and can skew segment and cohort comparisons. The sound response is the one the measurement layer already argues for. Rather than the open as a primary metric, lean on outcomes you can observe without the pixel: clicks to first-party destinations; on-site and in-app conversion; incrementality via holdouts. See deliverability for how the open signal degrades on the delivery side too.
The practical minimum
- Treat tracking consent as a distinct grant from sending consent, captured and recorded separately at the point the address is collected; see the form mechanics in consent and preferences.
- Do not bundle pixel consent into the newsletter opt-in or the terms.
- Keep a strictly-necessary tier (deliverability, security) separate from the analytics tier that needs consent. Where you rely on Italy’s exemption, ensure the aggregate count is genuinely anonymised.
- Suppress tracking, not sending, for EU recipients who consent to mail but not to measurement. Design reporting that tolerates an unmeasured EU slice.
- Operate to the strictest regime your list touches, exactly as for sending consent.