Skip to content

Frequently asked questions about pixel compliance

By Loïc Bresler 6 min read

I do B2B prospecting without prior consent. Do I have to stop?

No. You keep prospecting as before. The recommendation affects the measurement of individual opens, not the sending of the emails. Your overall open rate remains available. Only nominative statistics (who opened, when, with which email client) are restricted to consenting contacts.

I buy B2B prospect files. How does that work?

These contacts are recorded with a non-consenting status by default. §7 of the recommendation explicitly excludes databases acquired from a third party from the transitional opt-out regime, even if they were collected before the publication of the recommendation (14 April 2026) by their original source. You therefore prospect on raw aggregated measurement (overall open rate). If prospects show interest, they can consent via your tracked collection link and switch to fine-grained measurement on their next emails.

I send to recipients outside France. Does the recommendation apply?

The CNIL recommendation falls within the scope of article 82 of the French Data Protection Act, whose reach is territorial. If the recipients of a campaign are not covered by any regulation requiring prior consent to the pixel, you can declare that campaign “out of scope” in the Monitoring & consent portlet: full open measurement then applies to all its recipients, without consulting the register. Be careful, this qualification is yours to make and engages your responsibility: within the European Union, most member states have equivalent rules (transposition of the ePrivacy directive), even if their doctrine on pixels is more or less developed. Have your analysis validated by your DPO. Until 14 July 2026, this setting is enabled by default on new campaigns (transitional period); it then flips.

A contact refused or withdrew their consent. Can I switch them back to granted via an import?

No. A refused or withdrawn status is never overwritten by an import (CSV or “Import from a campaign”, already available; API coming soon): these rows are flagged as “protected” in the import summary. This is a compliance guarantee: the proof of the refusal is kept, and only the recipient themselves can reverse their decision, by re-consenting via the tracked collection link. Their status then switches back to granted with a new timestamped proof.

What about click tracking, is it also affected?

No. The recommendation specifically targets tracking pixels, that is, an image loaded automatically at open time, without any action by the recipient. Click tracking is technically distinct: the redirect happens server-side, on a voluntary and explicit action by the recipient, without reading from or writing to their device within the meaning of article 82 of the French Data Protection Act. The current click tracking logic is maintained without modification.

A contact withdrew their consent. Can they give it again later?

Yes. Withdrawal (withdrawn) is not final. If the contact re-consents via a tracked link, their status switches back to granted and fine-grained measurement is restored immediately on their next opens. The recommendation nevertheless suggests not re-soliciting a contact who has refused or withdrawn their consent for at least 6 months.

If a prospect does not reply to my §7 information email, what happens?

The absence of a reply is not a refusal under the §7 regime, unlike the positive consent collection of §4.2. On the lists you have placed under the opt-out regime (step 2 of action 3 in the compliance guide), you keep full measurement for contacts who have not objected. Only those who have explicitly exercised their objection (status withdrawn) switch to aggregated measurement.

How do I know how many of my recipients have consented?

From Account managementPixel consents, the list displays your full register with filters by status. Filter on granted to know your base of active consenting contacts. The CSV export lets you cross-check against your campaign lists.

Is the engagement-based follow-up module (openers / non-openers) still available?

It is, for your consenting contacts. This module relies on the individual identification of openers, which falls under §3.1 performance measurement and therefore requires consent. For non-consenting contacts, it is not available. The active / inactive segmentation for list cleaning and frequency adjustment remains available for your consenting contacts; for non-consenting contacts, it requires the basic hygiene measurement to be enabled on the campaign (§3.2 deliverability purpose, exempted). Otherwise, only the anonymous aggregated count is kept for these contacts.

How do I prove my compliance in the event of a CNIL audit?

Four elements to rely on: your consent register exported from the platform, the proof of the §7 information (informed_at field per recipient), the Ediware reference architecture document (on simple request) and your own documented analysis of the regimes applied list by list. The details are in the documentation for your DPO.

How long are consent proofs kept?

For the entire time the consent is active, plus 3 years after its withdrawal. This period is aligned with the CNIL doctrine on marketing prospecting and with the standard limitation period for civil liability actions. The identifying data of the opens (tracking table) is kept for 13 months.

Does the platform really anonymize the data, or is it a usage convention?

Anonymity is guaranteed at the technical level, by design, not by after-the-fact cleaning. For a non-consenting recipient, the inserted pixel is by default a simple audience pixel (with the mention “anonymous” in place of the recipient reference), identical for all and stripped of any identifier: from the moment of sending, nothing makes it possible to know who opened. No IP address, no recipient identifier, no email client or precise time, not even the address, is stored. It is not a masking or a restricted access to existing data: the data is simply not collected. If you enable the hygiene measurement on a campaign, only the last-open date per address (to the day) is additionally kept, under the conditions of §3.2.

I have a main account and sub-accounts. How is consent shared?

By default, each account keeps its own register. If your sub-accounts belong to the same data controller as your main account (brands or departments of the same entity), you can, from Account managementPixel consents of the main account, enable register sharing. The sub-accounts then rely on the register of the main account, both reading and writing: a refusal or withdrawal expressed on one is respected by all. Activation requires an explicit, timestamped attestation that the accounts belong to the same data controller. It does not allow sharing consents between distinct legal entities.

This content is intended to be educational. It does not constitute legal advice.

Last updated on