What the CNIL's 2026 recommendation says
A plain-language summary of the French regulator's guidance on tracking pixels in email, and the law it rests on.
In May 2026 the French data-protection authority, the CNIL, issued a recommendation on the use of tracking pixels in email. It does not create new law; it explains how existing law applies to a practice that had been operating in a grey area for years.
This page is an educational summary, not legal advice. Where precision matters, read the recommendation and the underlying texts directly.
The legal chain it rests on
- Article 5(3) of the ePrivacy Directive (2002/58/EC) requires consent before storing information on, or gaining access to information already stored in, a user’s terminal equipment — unless a narrow exemption applies.
- Article 82 of the French Loi Informatique et Libertés transposes that rule into French law and is what the CNIL enforces.
- EDPB Guidelines 2/2023 clarified that Article 5(3) is technology-neutral: it applies not just to cookies but to any technique that reads from or writes to a device — explicitly including email tracking pixels and the caching of remote resources.
Reading a pixel involves your device fetching and caching a remote resource, so it falls squarely within Article 5(3).
What the recommendation asks of senders
- Consent before insertion. As a rule, a tracking pixel may only be inserted into an email if the recipient has given prior, specific, informed and freely-given consent for that purpose — except where a recognised exemption applies (see exempt vs. consent-based pixels).
- Purpose granularity. Consent for one purpose (say, measuring deliverability) does not authorise another (say, building a marketing profile). Each purpose must be presented clearly.
- Withdrawal as easy as consent. Recipients must be able to withdraw consent at any time, and doing so must be as simple as giving it was — no friction, no re-authentication hurdles.
- Effective withdrawal. Once consent is withdrawn, tracking must actually stop — including for emails already sent. A pixel sitting in an old message must no longer register opens.
- The per-recipient link. A unique unsubscribe/preference link in the email footer, tied to a single recipient, is treated as a security measure (it limits action to the address holder). That link itself is exempt from prior consent.
What it means for you as a recipient
- You have the right to be asked before a brand tracks your opens, and the right to say no.
- If you consented, you can change your mind, and the change should take effect immediately — even on messages already in your inbox.
- You should never have to type your email address into a form to opt out; the personal link already identifies you securely. See your rights.
Where TrackingCompliant fits
TrackingCompliant is the preference-management surface a sender operates to meet points 3–5 in practice: a one-click withdrawal from the footer link, effective across already-sent mail. It is run by the sender, not by an independent auditor — we state that plainly because honesty about who operates the tool is part of doing this correctly.