Skip to content
TrackingCompliant
All guides
Law 7 min read Updated 2026-07-10

What the CNIL's 2026 recommendation says

A plain-language summary of the French regulator's guidance on tracking pixels in email, and the law it rests on.

In May 2026 the French data-protection authority, the CNIL, issued a recommendation on the use of tracking pixels in email. It does not create new law; it explains how existing law applies to a practice that had been operating in a grey area for years.

This page is an educational summary, not legal advice. Where precision matters, read the recommendation and the underlying texts directly.

  • Article 5(3) of the ePrivacy Directive (2002/58/EC) requires consent before storing information on, or gaining access to information already stored in, a user’s terminal equipment — unless a narrow exemption applies.
  • Article 82 of the French Loi Informatique et Libertés transposes that rule into French law and is what the CNIL enforces.
  • EDPB Guidelines 2/2023 clarified that Article 5(3) is technology-neutral: it applies not just to cookies but to any technique that reads from or writes to a device — explicitly including email tracking pixels and the caching of remote resources.

Reading a pixel involves your device fetching and caching a remote resource, so it falls squarely within Article 5(3).

What the recommendation asks of senders

  1. Consent before insertion. As a rule, a tracking pixel may only be inserted into an email if the recipient has given prior, specific, informed and freely-given consent for that purpose — except where a recognised exemption applies (see exempt vs. consent-based pixels).
  2. Purpose granularity. Consent for one purpose (say, measuring deliverability) does not authorise another (say, building a marketing profile). Each purpose must be presented clearly.
  3. Withdrawal as easy as consent. Recipients must be able to withdraw consent at any time, and doing so must be as simple as giving it was — no friction, no re-authentication hurdles.
  4. Effective withdrawal. Once consent is withdrawn, tracking must actually stop — including for emails already sent. A pixel sitting in an old message must no longer register opens.
  5. The per-recipient link. A unique unsubscribe/preference link in the email footer, tied to a single recipient, is treated as a security measure (it limits action to the address holder). That link itself is exempt from prior consent.

What it means for you as a recipient

  • You have the right to be asked before a brand tracks your opens, and the right to say no.
  • If you consented, you can change your mind, and the change should take effect immediately — even on messages already in your inbox.
  • You should never have to type your email address into a form to opt out; the personal link already identifies you securely. See your rights.

Where TrackingCompliant fits

TrackingCompliant is the preference-management surface a sender operates to meet points 3–5 in practice: a one-click withdrawal from the footer link, effective across already-sent mail. It is run by the sender, not by an independent auditor — we state that plainly because honesty about who operates the tool is part of doing this correctly.

Related guides