Email tracking pixels need consent in France, even if you are not based there
Open your email provider's dashboard and look at the open rate on the last onboarding email you sent. To produce that number, the provider put an invisible image in every copy of the email, each with a web address unique to its recipient, and logged who loaded it and when, often with the IP address and email client as well. France's data protection regulator, the CNIL, published a recommendation on 14 April 2026 saying that this image needs the recipient's prior consent 1 4. There are two exceptions: securing a sign-in, and checking deliverability. Both apply only in emails the recipient asked for, and only if the pixel records little more than the date of the last open. Postmark, for one, records the IP address and a location with every open. The grace period for existing contacts ended on 14 July 2026 2, and when it published the recommendation in April the CNIL said its future inspections would check compliance 4.
This is not only a question for French companies. The CNIL's FAQ says it can act against a sender established anywhere when the recipients are in France, and that the EU's usual rule, under which a company deals only with the regulator of the member state where it is established, does not apply here 2. I read the recommendation and its FAQ side by side, and this post is my map of which of your emails can keep a pixel and what to change for the rest.
Why does an invisible image in an email need consent?
Because it is covered by the same law that makes you run a cookie banner, and that decides whether your analytics needs consent. Article 5(3) of the ePrivacy Directive requires consent before anything is stored on or read from someone's phone or laptop, unless it only carries a communication or is strictly necessary for a service they asked for 3. Loading the image and sending back its identifier is exactly that kind of reading. The European Data Protection Board (EDPB), where the EU's national regulators agree common positions, named the email case in its 2024 guidelines: "the sender may include a tracking pixel to detect when the receiver reads the email" 3. That part is EU-wide.
The list of exemptions and the data limits are French. The recommendation is guidance rather than a new law: it is the CNIL's reading of the existing rule, and it says so itself 1. I have not found an equivalent from another regulator, so for recipients in Germany or the Netherlands you have the EDPB's position that the pixel is covered, and no national list of exemptions yet.
On who is responsible, the recommendation is clear: the company that decides to send the email is the controller for the pixels in it, the party that answers for them in law, even when an email service provider runs the tracking on its behalf 1. Where the provider also uses the data for its own purposes, the two can be joint controllers 2. Provider defaults differ: Mailchimp's help centre says open tracking is enabled by default, while Postmark's API docs leave it off unless you ask for it. In my reading, leaving a default on is still a choice you made.
Does your legal documentation match what you ship?
Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.
Get startedWhich emails can keep a tracking pixel without consent?
Only emails the recipient asked for, and only for two purposes 1:
- Securing a sign-in. A pixel whose sole job is to check that the email carrying a one-time code was opened on a device known to belong to the user. The FAQ extends this to password resets, which are a target for interception 2.
- Deliverability. Recording whether each recipient still opens your email, so you can send less often, stop, or switch to another channel. It may also help show that you delivered information the law required you to send 1.
For both, the CNIL says the pixel should in principle keep only the date of the last open, to the day and without the time, overwritten at each new open 1 2. Collecting the IP address or the user agent (the string that names the email client) puts the pixel outside the deliverability exemption, even if you anonymise or delete them shortly afterwards, unless you can document why deliverability needs them 2. Provider tracking collects far more than a date: Postmark's open webhook reports the email client, the IP address, a postcode and map coordinates for each open.
An email counts as asked for when it is transactional or when the recipient consented to receiving it 1. The CNIL's list of transactional email includes welcome emails, account alerts, order confirmations and invoices, password resets, shipping notices and support replies 1. One condition catches software products: an email that carries promotional content, an upsell in a receipt for instance, loses its transactional status 2.
Here is how I sort the email a typical software product sends:
| Pixel without consent | |
|---|---|
| Sign-in code | Security only, minimal data |
| Password reset | Security only, minimal data |
| Welcome email | Minimal data only |
| Invoice with no upsell | Minimal data only |
| Terms or privacy policy update | In principle, minimal data |
| Newsletter they signed up for | In principle, minimal data |
| Onboarding nudge to upgrade | No |
| Cart recovery | No |
| Marketing without an opt-in | No |
"Minimal data" means the last-open date and nothing else, and no row allows the provider's standard open tracking. Of the three providers I checked, Mailchimp, Postmark and Customer.io, each documents open tracking as on or off, per message or per recipient, and none documents a mode that keeps only a last-open date. With those three, the exemption means switching the provider's tracking off and, if you want the date, recording it with your own pixel on a server that does not log or store the IP address or user agent. Most web servers log both by default, so that is a configuration change too. The security rows work the same way: the exemption covers a pixel used only to secure the sign-in, not general open tracking left on in a sign-in email.
Two rows carry conditions from the FAQ. A terms or privacy policy email qualifies when informing users of the change is its only purpose. A newsletter qualifies when the person asked to receive it, and not when you send it to customers who never opted in 2. So the onboarding email from the opening depends on what it is. The welcome email can keep a minimal pixel, and the CNIL accepts an aggregate open rate built from exempt pixels once the data is anonymised 2. The day-three email that pushes an upgrade is promotional, and its pixel needs consent.
The last row needs explaining. French law, like the rest of the EU, lets you email existing customers about similar products without asking first. The CNIL says that permission covers sending the email, not the pixel in it: such an email is not one the customer asked for, so even the deliverability pixel needs consent 2.
My own conclusion is that per-person open tracking beyond that last-open date is over for recipients in France unless you collect consent, and for most products it is not worth collecting. For a B2B product I would switch the provider's open tracking off, record my own last-open date on transactional email if I needed one (with IP and user-agent logging off), and judge campaigns by replies and by what recipients go on to do in the product.
Click tracking needs its own analysis. With it switched on, the provider rewrites every link to pass through its server with an identifier for the recipient, and the EDPB treats tracking links like pixels 3. The CNIL's FAQ says links fall under the same law but are not directly covered by the recommendation, so each one has to be strictly necessary for the service or consented to. The only exempt link it names is the per-recipient link used to give or withdraw consent 2. In practice, I would not rely on the pixel exemptions for click tracking at all: switch off the provider's link rewriting on every email where you do not have consent, transactional ones included. Links that carry a per-person token because the feature needs one, such as a password reset or an unsubscribe link, are a different case 1.
How do you ask for consent to a tracking pixel?
This section is for you if you decide per-person tracking is worth keeping. Ask at the moment you collect the email address. The CNIL recommends it there: on the sign-up or newsletter form, with a short line naming each purpose and a link to the detail 1. The recommendation includes worded examples you can adapt 1.
The rest of what it asks for:
- A separate choice for the pixel. On a sign-up form, "send me product news" and "track whether I open it" are two choices. One tick can cover both only when the purposes are linked. The CNIL's example is marketing sold as personalised, where the pixel is what personalises it 1.
- Silence is a no. If you ask later by email, that email must not itself carry a pixel that needs consent. The choice has to be an active click on a page. No answer counts as a refusal 1.
- Easy withdrawal. The law requires withdrawing to be as easy as agreeing. The CNIL recommends a link in every footer that works in one step, and says the pixels in emails already sent must stop being used too 1 2.
- Proof per person. You must be able to show when and how each recipient agreed 1.
For addresses collected before 14 April 2026, the CNIL allowed a lighter route: tell existing recipients about the pixels and let them object, by 14 July 2026. If you did, you can keep relying on their not objecting as long as the way you email them stays the same and you do not need a fresh consent for those addresses. If you did not, the full rules now apply to those addresses, unless you documented why you needed longer 2.
What should you change in your email setup?
If you send email to people in France with open or click tracking switched on, you need to switch it off on every email you cannot tie to consent, to an exemption, or to a pre-April contact who was told and did not object. Otherwise each of those emails places a tracker without consent under Article 82 of France's Data Protection Act, the provision the CNIL has already enforced against website publishers over cookies 1.
- List your email streams and sort them against the table above.
- Turn open and click tracking off where nothing fits, starting with cart recovery, upgrade nudges and marketing sent without an opt-in.
- Replace the provider's pixel where you rely on an exemption. Unless your provider can keep only the last-open date, switch its tracking off and record the date yourself, without logging the IP address or user agent.
- If you keep per-person tracking, add the consent line to your sign-up form, and record who agreed, when, and to what. Customer.io's consent setting is one way to act on it per recipient.
- Update your privacy policy. An exempt pixel is exempt from consent, not from the GDPR. The data it collects still needs a lawful basis and has to be disclosed, with a way to object if that basis is legitimate interest 2.
Lawcel is a compliance tool that reads your team's pull requests and tickets and flags which published legal documents a change affects. When tracking arrives through code, in a pull request that adds an email provider or turns on click tracking, it can flag the privacy policy and sub-processor list that change touches. It does not see a toggle flipped in a provider dashboard, or a default like Mailchimp's that was never touched.
Tags
FAQ
References
- CNIL, Recommendation on tracking pixels in emails (Deliberation 2026-042 of 12 March 2026), English courtesy translation - accessed 26 Sep 2026
- CNIL, FAQ sur la recommandation relative aux pixels de suivi dans les courriers électroniques (22 July 2026) - accessed 26 Sep 2026
- EDPB Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive (Version 2.0, adopted 7 October 2024) - accessed 26 Sep 2026
- CNIL, Pixels de suivi dans les courriers électroniques : la CNIL publie ses recommandations (14 April 2026) - accessed 26 Sep 2026
About the author
Ulf Aslak Lai
Co-founder, Chief Technology Officer
Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.
- Platform architecture
- Data governance
- ML/AI systems
Related articles
Is legitimate interest enough for product analytics? Check what your tool stores on the device first.
Not on its own. Two rules apply to analytics, in order. Article 5(3) of the ePrivacy Directive, the rule behind cookie banners, governs storing or reading anything on the visitor's device and offers consent or one of two narrow exemptions, never legitimate interest. GDPR Article 6 governs the analysis you run afterwards, and there legitimate interest is available if you can pass the balancing test.
GDPROnly 17% of Product Hunt launches ask when they set tracking cookies
I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU location with an empty cookie jar. 292 stored tracking cookies, but only 50 of those (17%) did that after obtaining my consent. Filtering for EU based startups didn't improve this static significantly (26%).
GDPRKeep your cookie banner. The Digital Omnibus cookie reform is still a proposal.
The EU's Digital Omnibus proposes fewer cookie banners, but it is not law. In August 2026 Parliament had not voted and the member states had no agreed position, and no deal had been reported by 2 October. Once agreed, the new rules would apply six months to two years later, depending on which draft wins. Until then today's rules apply, so refusing cookies must be as easy as accepting them.
GDPRAn unsubscribe must stop marketing email from every tool you use, under EU and UK law
Under EU and UK law, every marketing email must offer a free, easy way out, and an opt-out has to take effect in every tool that sends the marketing it covers: the newsletter, CRM sequences and product email. Withdrawing consent must be as easy as giving it, so if one tick put someone on several lists, one step should take them off all of them.