Documentation for your DPO
This page gathers the elements your DPO (or your legal counsel) needs to complete your record of processing activities, update your privacy policy and prepare for a possible request from the CNIL (the French data protection authority).
The legal qualification of the parties
Depending on the purpose of the processing, Ediware acts under two distinct qualifications.
Ediware is a processor (art. 28 GDPR) for §3.1 performance measurement, carried out on your behalf on consenting contacts. This relationship is covered by your existing data processing agreement with Ediware.
Ediware is a joint controller (art. 26 GDPR) for the operations specific to platform deliverability under §3.2 (sending IP reputation, detection of failing lists at infrastructure level), where Ediware processes data for purposes of its own.
The wording to add to your privacy policy
Your privacy policy must be completed with the following elements.
On purposes and legal basis: state the use of tracking pixels in your emails, with the two distinct purposes. On one side deliverability and list hygiene (§3.2, exempt from consent), on the other individual performance measurement (§3.1, requiring consent). Specify that the legal basis for performance measurement is consent within the meaning of article 82 of the French Data Protection Act.
On its optional nature: specify that consent to performance measurement is optional, that refusing or withdrawing it does not affect the receipt of the emails, and that some statistical features (identified openers, engagement-based follow-up) are not available without consent.
On withdrawal: mention the ability to withdraw consent at any time via the link in the footer of every email, with immediate effect on future emails.
On Ediware’s qualification: processor for §3.1 performance measurement, joint controller for §3.2 deliverability.
A template clause is available on request from Ediware support.
The evidence available in the event of a CNIL audit
Four elements to rely on, in the order of priority of an audit.
1. The exportable consent register.
From Account management → Pixel consents → Export CSV. The export includes for each contact: email address, status (granted / refused / withdrawn / unknown), source of the consent, date, §7 information date (informed_at), last update date. The proof of collection (IP, user agent, timestamp) is kept in the database and can be extracted on request.
2. The proof of the §7 transitional information.
The informed_at field is recorded per recipient when sending via the dedicated module, and included in the export. If you carried out the §7 information by your own means (in-house template, another channel), import informed_at via CSV to complete the register.
3. The Ediware reference architecture document. Ediware maintains a technical document (current version 1.20) detailing the anonymization guarantees, the data flows, the design choices and the security measures. It is sent on simple request to your DPO or to the CNIL within a reasonable time.
4. Your documented analysis of the applied regimes. This is the document you must produce and keep. It justifies the choices made list by list and campaign by campaign: cautious §3.2 position on such and such cold B2B databases, activation of the §7 opt-out on such and such lists, collection of explicit §3.1 consents via such and such form, activation of the §3.2 hygiene measurement (retention of only the last-open date of non-consenting recipients) on such and such campaigns, campaigns declared out of the scope of consent (recipients outside the scope of the applicable regulations) with the legal qualification adopted. This document is to be kept in your own record of processing activities. It cannot be produced by Ediware on your behalf, because it reflects your capacity as data controller.
Sharing the register between accounts of the same controller
If your organization uses several Ediware accounts (a main account and sub-accounts), the consent register of the main account can be shared with its sub-accounts. This option only makes sense, and is only lawful, if the sub-accounts belong to the same data controller as the main account, for example departments or brands of the same legal entity. It must never be used to share consents between distinct entities: a consent given to one entity is not valid for another.
How it works. When the option is enabled, sub-accounts no longer keep a register of their own. The tracking of their campaigns and their consent collection links read from and write to the register of the main account, which becomes the single source of truth. A refusal or withdrawal expressed from any account of the group is thus honored by all. The Pixel consents page of the sub-accounts then indicates that the register is managed by the main account.
Traceability. Activation is reserved to the main account and subject to an explicit attestation, “my sub-accounts belong to the same data controller”, recorded and timestamped with its author. The option is disabled by default and reversible at any time; upon deactivation, each sub-account resumes its own register. When a consent decision is recorded from a sub-account into the shared register, the proof keeps track of the account the action originated from.
B2B and the L.34-5 exception: two distinct regimes
The B2B prospecting exception (article L.34-5 of the French Postal and Electronic Communications Code, CPCE) does not exempt you from pixel consent. These are two distinct legal regimes:
| Regime | Text | B2B case |
|---|---|---|
| Sending the prospecting email | art. L.34-5 CPCE | Exempt under conditions |
| Setting and reading the pixel | art. 82 of the French Data Protection Act | No B2B exception: consent required for individual performance measurement |
The CNIL recommendation of 12 March 2026 states this explicitly in its “Point of attention” box: pixel consent may be required for emails that do not require consent to the sending itself (order confirmation, B2B prospecting related to the profession, etc.). The CNIL clarified during the webinar of 28 May 2026 (in French) that lawful B2B prospecting (to a professional in connection with their role, allowed without opt-in by art. L.34-5 CPCE) could not benefit from the deliverability exemption.
For operational implementation, refer to the compliance guide and the checklist.
This content is intended to be educational. It does not constitute legal advice.