Compliance guide: tracking pixels
This guide is intended for all Ediware customers who send email campaigns with open tracking. It describes what the platform handles automatically for you, the actions that remain on your side and the concrete impact on your statistics.
What the CNIL says: the essentials in three points
On 12 March 2026, the CNIL (the French data protection authority) adopted a recommendation on tracking pixels in emails (deliberation no. 2026-042, published in the French Official Journal on 14 April 2026). A tracking pixel is the invisible image loaded when an email is opened. It makes it possible to measure opens, timestamp them and approximately locate the recipient. This mechanism falls within the scope of article 82 of the French Data Protection Act (ePrivacy directive).
What changes: individual performance measurement (identified openers, opening time, device used) now requires the recipient’s explicit consent.
What does not change: you keep sending your campaigns as usual. The sending of the email itself is not affected, and the overall open rate of your campaigns remains fully available.
The B2B point to remember: the B2B prospecting exception (article L.34-5 of the French Postal and Electronic Communications Code, CPCE) does not exempt you from pixel consent. These are two distinct legal regimes. You can keep prospecting without prior consent to the sending, but fine-grained open measurement, which identifies the recipient, requires separate consent.
What the platform does for you, with no configuration on your side
The automatic branching at every send
The branching starts at sending time: the platform adapts each recipient’s pixel to their status in your consent register. When the email is opened, the recording follows that choice.
granted, consent given: full measurement is recorded. Precise time, IP address, email client, recipient identifier. All nominative statistics remain available.- Any other status: by default, the inserted pixel is a simple audience pixel, identical for all these recipients and stripped of any identifier. From the moment of sending, nothing makes it possible to link an open to a person. Only a strictly aggregated and anonymous count is kept, without any identifying data, not even the address. The overall open rate of the campaign is maintained, but no individual or unique opens. Anonymity is therefore not obtained by after-the-fact cleaning, it is guaranteed by the design of the pixel itself. A dedicated option (see action 2) additionally lets you keep, for deliverability or list hygiene purposes, only the last-open date per address.
The non-consenting statuses are the following:
| Status | Meaning | How it is assigned |
|---|---|---|
refused | Explicit refusal of measurement | Click on “Refuse” on the consent page, or CSV import |
withdrawn | Withdrawal of a previous consent | Click on the link in the email footer, or CSV import |
unknown | No decision expressed | Default status of a record without a decision. This is notably the status set by “Import from a campaign” for informed contacts (§7, informed_at filled in) who have neither granted nor refused: silence is not a refusal under this regime |
| (absent) | Not present in the register | Treated as non-consenting, aggregated measurement only |
This branching applies to campaigns falling under the consent regime. Three per-campaign settings, mutually exclusive, come into play: fully disabling the pixel (no measurement), declaring the campaign out of scope (full measurement without consulting the register, under your responsibility) and hygiene measurement (keeping the last-open date of non-consenting recipients to identify inactive addresses). See action 2 below, and in particular the default setting applicable until 14 July 2026.
Robot detection and filtering
For your consenting contacts, automated opens (antivirus, preloading email clients, security scanners) are identified and excluded from your statistics by the robot filtering option.
For non-consenting recipients, the audience pixel keeps neither IP address, nor identifier, nor precise timestamp. These are precisely the elements that make it possible to spot a robot. Filtering is therefore less reliable there: the aggregated count may include a share of automated opens. This is the accepted trade-off of maximum anonymization, and it does not affect the reading of your main indicator, the overall open rate compared from one campaign to the next.
The withdrawal link in every email
In accordance with §5 of the recommendation, every email automatically includes a consent management link in the footer, distinct from the unsubscribe link. This link leads to a dedicated page where the recipient explicitly confirms their withdrawal with a button. This confirmation protects against unintended withdrawals triggered by pre-fetchers and antivirus software. The effect is immediate, including on emails already sent: any subsequent open by this recipient switches to aggregated measurement.
This link can be disabled campaign by campaign in the Monitoring & consent portlet of the campaign settings. It is not inserted in campaigns declared out of the scope of consent (see action 2): a link to manage a consent that does not apply would serve no purpose.
A consent register isolated per account
Each account has a physically separate register. A consent given to another sender has no value in your account, even for the same address. Conversely, a consent collected in your account is valid for all your lists and all your campaigns: the recipient does not have to re-consent at every send.
Your three actions, step by step
Three actions remain on your side. They are presented in order of priority.
Action 1: populate your consent register
The register is the centerpiece of your compliance. It records the consent status of each of your recipients and keeps the associated proofs.
Access: Account management menu → Pixel consents.
Three ways to populate it are available.
CSV import, for your existing databases
If you have already collected consents by your own means (web form, CRM, event, documented agreement), import them in bulk.
CSV file format:
| Column | Required | Accepted values |
|---|---|---|
email | Yes | Valid email address |
consent_pixel | Yes | granted: consent givenrefused: explicit refusalwithdrawn: withdrawal of a previous consent |
consent_date | No | ISO 8601 date (2026-04-15), date on which the consent was collected |
informed_at | No | ISO 8601 date, date on which you informed this contact (§7) if this was done outside the platform |
The procedure takes three steps:
- Prepare your CSV file. The separator (
;,,, tab or|) is detected automatically. - In Pixel consents, click Import a CSV.
- Select your file and confirm. The platform indicates the number of contacts imported, updated, protected and ignored.
A later import on an email address already present updates the existing status without creating a duplicate, with one exception: an existing refusal (refused) or withdrawal (withdrawn) is never overwritten by an import, whatever status your file contains. These rows are counted as “protected” in the import summary. This is a compliance guarantee: a recipient’s negative decision (and its original proof) cannot be cancelled by a file; only the recipient themselves can re-consent, via the tracked link.
The tracked collection link, for your information campaigns
The footer of every email carries the consent management link (withdrawal, see above). For collection, the link can be placed anywhere in the body of the message via the %consentement_pixel% variable. This is particularly useful for §7 information campaigns where you want to highlight it. When the recipient clicks and confirms on the dedicated page, their consent (granted) is recorded automatically, with a timestamp and proof.
The /consents API, for CRM integrations
The public /consents API (available soon) will let you push consents in real time from your CRM or any external tool. The documentation will be published in the developer area when it opens.
You can export your register at any time in CSV format from Pixel consents → Export CSV (status, source, date, informed_at, last update date).
Action 2: configure the pixel campaign by campaign
The Monitoring & consent portlet on each campaign page groups the pixel settings. Three structuring options are available there; they are mutually exclusive (at most one active at a time), and all the portlet settings are locked once the campaign has been sent (they then remain viewable as they were, read-only).
Fully disable the pixel
Access: campaign page → Monitoring & consent portlet → Disable the open tracking pixel. The detailed procedure is described in Disable the tracking pixel for a campaign.
Typical use cases:
- Pixel consent collection campaign: it would be circular to insert a measurement pixel in an email that asks precisely for permission to use that pixel.
- Transactional or service email: order confirmation, notification, password reset.
- Send to a cold B2B file for which you have decided to stay on raw aggregated measurement: the option formalizes this choice at campaign level.
When the option is enabled, no pixel is inserted in the email: no open measurement, not even aggregated.
Declare a campaign out of the scope of consent
Access: campaign page → Monitoring & consent portlet → Campaign not subject to pixel consent (recipients outside the scope of the applicable regulations).
Some of your campaigns may target recipients who are not covered by any regulation requiring prior consent to the tracking pixel, for example sends to countries without an equivalent obligation. For these campaigns, you can enable this declaration:
- Full open measurement applies to all recipients of the campaign (precise time, email client, identified openers), without consulting the consent register.
- The consent management link is not inserted in the email footer: there is no point in a link to manage a consent that does not apply. The unsubscribe link, for its part, is still handled normally (a distinct obligation).
This qualification is yours to make. The platform neither defines nor verifies any geographical criteria: it is you, as data controller, who declare that your recipients are outside the scope of a pixel regulation, and who take responsibility for it. Have this qualification validated by your DPO or legal counsel, and document it in your analysis of the applied regimes (see documentation for your DPO).
Keep a hygiene measurement (last open of non-consenting recipients)
Access: campaign page → Monitoring & consent portlet → Identify inactive addresses amongst recipients without consent.
By default, for recipients who have not consented to the pixel, the platform only keeps a strictly aggregated and anonymous open count, without any address or individual data. By enabling this option, you additionally keep, for each of these addresses, only the date of its last open, without ever linking it to a campaign or keeping a history. This lets you identify and remove durably inactive addresses (list hygiene, deliverability).
- It is then minimized personal data: an address and a single date, overwritten at each new open. No individual tracking per campaign, no unique opens.
- This decision is yours. By enabling the option, you declare that you are relying on the deliverability and basic hygiene exemption, under your responsibility as data controller; have it validated by your DPO. It does not cover every situation: in particular, it does not apply to B2B contacts collected on an opt-out basis after 12 March 2026, for which you keep the default regime, aggregated and anonymous.
Action 3: inform your contacts collected before 14 April 2026
The recommendation provides in §7 for a transitional period for addresses collected before its publication (14 April 2026): their holders must be informed of the use of the pixel and given the ability to object, within a baseline period of 3 months after publication, i.e. until 14 July 2026. If you have not yet carried out this step, do it without delay. Beyond the deadline, a voluntary and documented approach is recommended.
Who does this regime apply to?
The recommendation is written for cases where consent has been collected, but without all the arrangements it introduces. Its exact scope depending on the type of database remains a matter of legal interpretation. The table below reflects a common practical reading, to be validated by your DPO or legal counsel according to your situation.
| Type of database | Practical reading |
|---|---|
| Prior B2C opt-in (even imperfect) | Appears to fall within the scope of §7 |
| B2B with an established relationship (customers, prospects who have interacted, contacts collected at events) | May be covered, to be documented and validated |
| Pure cold B2B (purchased or scraped lists, never activated) | Uncertain. A cautious position (raw aggregated measurement) is often adopted |
| Contacts purchased from a third party | §7 explicitly excludes transfers between data controllers |
The platform is conservative by default: all contacts without an explicit status stay on raw aggregated measurement. You decide contact by contact via the consent management module, under your responsibility as data controller.
The two-step procedure
Step 1: send the information via a standard campaign to the list or lists concerned.
- Create a campaign dedicated to the §7 information, with the pixel disabled. Sending a measurement pixel in an email that asks for permission to use that very pixel would be contradictory.
- Write your information message and insert the consent collection link via the
%consentement_pixel%variable to highlight it in the body of the message. - Send the campaign to the list concerned.
The absence of a reply is not a refusal under this regime. Recipients who click “Refuse” or withdraw their consent are automatically recorded as withdrawn.
Step 2: record the information in the register, from the Pixel consents module.
- Simplified route: the Import from a campaign function lets you directly select the campaign sent in step 1. All its delivered recipients are automatically recorded with
informed_atdated at the send. You choose the default status:unknown(cautious position, contacts stay on raw aggregated measurement) orgranted(you activate the §7 opt-out regime, individual measurement applies in the absence of objection). An already recorded refusal or withdrawal is never overwritten, and an existing consent is never downgraded. - CSV alternative: if you activate the §7 opt-out (status
granted), you can also export the list of recipients of your campaign and import it via Import a CSV (action 1), settingconsent_pixeltograntedandinformed_atto the send date. Here again, contacts who have refused or withdrawn their consent are automatically protected (these rows appear as “protected” in the summary). If you adopt the cautious position, no import is needed: your contacts stay on raw aggregated measurement by default.
Contacts who have exercised their objection (status withdrawn) are already recorded; neither the CSV import nor the “Import from a campaign” function will ever overwrite them.
If you stay on the cautious position for pure cold B2B, no action is required: these contacts are already on raw aggregated measurement by default.
The impact on your statistics
What stays unchanged
| Indicator | Availability |
|---|---|
| Number of sends | Unchanged |
| Raw open rate | Unchanged, this is your main KPI |
| Bounce and unsubscribe rates | Unchanged |
| Click rate | Unchanged (click tracking is not covered by the recommendation) |
| Active / inactive segmentation (list cleaning, frequency adjustment) | Consenting contacts, and non-consenting contacts only if hygiene measurement is enabled on the campaign (§3.2 deliverability purpose) |
What is restricted to consenting contacts
| Indicator | Restriction |
|---|---|
| Identified unique openers | Consenting contacts only |
| Hourly open curve | Consenting contacts only |
| Email client / device breakdown | Consenting contacts only |
| Nominative list of openers | Consenting contacts only |
| Engagement-based follow-up module (openers / non-openers) | Consenting contacts only |
The engagement-based follow-up module relies on the individual identification of openers (§3.1 performance measurement): it is only available for consenting contacts. The active / inactive segmentation for list cleaning remains available for consenting contacts; for non-consenting contacts, it requires the hygiene measurement to be enabled on the campaign (§3.2 deliverability purpose, exempted). Otherwise, only the anonymous aggregated count is kept for these contacts, with no per-address distinction.
To go further
This guide is intended to be educational and operational. It does not constitute legal advice.