GDPR compliance - tracking pixels
The CNIL recommendation of 12 March 2026 (in French) regulates the use of tracking pixels in emails. It requires senders to inform recipients of the presence of a pixel and to collect their consent before inserting it, with some exceptions.
This section documents the platform features that help you comply with these requirements.
What the recommendation says
A tracking pixel is an invisible 1×1 pixel image loaded when an email is opened. This loading lets the sender know that the message has been opened, along with the date, the time and, often, the approximate location of the recipient.
The CNIL qualifies the pixel as a tracker within the meaning of the ePrivacy directive. As such:
- Prior consent is required for most commercial and marketing emails.
- Informing recipients of the presence of the pixel is mandatory, whether consent is required or not.
- Some emails are exempt from consent (strictly necessary service communications), but the information duty still applies.
The cases exempt from consent (section 3.2 of the recommendation)
The CNIL provides for two categories of pixels that can be used without prior consent, provided their use is strictly limited to the declared purpose.
Deliverability and list hygiene. A pixel can be inserted without consent if its sole purpose is to identify deliverability problems: adjusting the sending frequency or stopping sends to inactive recipients (list cleaning). The recommendation nevertheless imposes a strong constraint on data retention: only the date of the last opened email (to the day, without the time) should be kept, and replaced at each new open. As soon as the pixel is used to measure campaign performance, personalize content or build a profile, the exemption no longer applies and consent becomes mandatory.
Authentication and security. A pixel can also be used to verify that an email containing an authentication code has actually been opened on a device known to the recipient. This case is rare in commercial emailing.
The CNIL sets a condition: the deliverability exemption only covers emails “requested by the recipient or related to a service requested by the recipient”.1 It cites as examples transactional emails and lists for which consent has been collected. This list is not exhaustive. However, the CNIL clarified during the webinar of 28 May 2026 (in French) that lawful B2B prospecting (to a professional in connection with their role, allowed without opt-in by art. L.34-5 of the French Postal and Electronic Communications Code, CPCE) could not benefit from it.
For B2C prospecting without prior consent to receiving the emails, the exemption does not apply: no pixel should be inserted, including for deliverability purposes. B2C lists for which consent to receive the emails has been collected do benefit from the exemption, in the same way as transactional emails.
What the platform lets you do
Default behavior. For every send, the platform inserts an audience pixel. For recipients who have not given their consent to tracking, this pixel is by default identical for everyone and stripped of any identifier: from the moment of sending, nothing makes it possible to know who opened. No identifying data is recorded when it loads, no IP address, no recipient identifier, no opening time. Only a strictly aggregated and anonymous open count is kept, without any address. It is not a tracking pixel but an audience pixel, since the recipient identification parameter is not transmitted.
Send an information email to your contacts. To inform your contacts about the use of the pixel and collect their consent, you can send a standard campaign with the pixel disabled and a link to the consent collection page.
Disable the pixel for a campaign. For B2C sends without prior consent, for consent collection campaigns themselves, or if your company policy requires removing the pixel, the platform lets you completely disable the pixel at campaign level.
Apply the exemption for deliverability and list hygiene. By default, non-consenting recipients only generate an anonymous aggregated count. If you consider you can rely on the deliverability and basic hygiene exemption (§3.2), you can enable, campaign by campaign, the retention of only the last-open date per address, in order to identify and remove inactive addresses. This decision is yours: have it validated by your DPO. It does not apply, in particular, to B2B contacts collected on an opt-out basis after 12 March 2026, which must remain under the anonymous aggregated regime. When this option is enabled, consenting contacts are, for their part, fully recorded and usable in campaign statistics.
The features documented in this section operate at campaign level. They are not a substitute for a consent management policy, but they let you manage open tracking consistently with your contacts’ choices and the requirements of the recommendation.
CNIL recommendation, section 3.2, p. 5 (in French, our translation): “Insofar as article 82 of the law refers to an ’express request’ by the user, these exemptions can only concern emails requested by the recipient or related to a service requested by the recipient. These are, for example, so-called ’transactional’ emails […] or emails for which the recipients have given their consent.” ↩︎