Exempt vs. consent-based pixels
Not every pixel needs consent. Where the line sits between security/deliverability measures and marketing analytics.
Article 5(3) of ePrivacy — and Article 82 in France — requires consent for accessing a device, but it carves out exemptions for things that are strictly necessary. Applied to email, this splits tracking into two buckets.
The exemption test
A technique is exempt from consent only if it is strictly necessary either:
- to carry out the transmission of a communication, or
- to provide a service that the user has explicitly requested.
“Strictly necessary” is read narrowly. Convenient, useful, or commercially valuable is not the same as necessary.
Broadly exempt
- Security and authentication. Measures that protect the message or confirm it reached the right person. The per-recipient link in the footer is the clearest example: because it limits an action (like unsubscribing) to the holder of that address, it functions as a security measure and does not itself need prior consent.
- Strictly-scoped deliverability measurement. A minimal, aggregate check that messages are being delivered and rendered — used purely to keep lists clean and maintain sender reputation — can fall under necessity, provided it is not repurposed for marketing analytics or profiling and is limited to what deliverability actually requires.
Requires consent
- Marketing open-tracking. Measuring who opened, when, how often, and feeding that into engagement scores or send-time optimisation.
- Profiling and segmentation. Combining opens and clicks with other data to build a picture of your interests.
- Cross-campaign or cross-brand tracking. Following behaviour across many mailings or properties.
- Individual-level analytics that go beyond what deliverability strictly needs.
The grey zone: individual deliverability measurement
The hardest case is per-recipient open measurement justified as “deliverability”. The direction of travel in the CNIL’s 2026 recommendation is that this can only stay exempt if it is genuinely limited to deliverability and list hygiene — for example, detecting persistently unreachable addresses — and is not quietly reused to measure engagement. The moment the same signal feeds marketing decisions, it needs consent.
A quick comparison
| Purpose | Consent needed? |
|---|---|
| Per-recipient security link (footer) | No — security measure |
| Minimal, aggregate deliverability check | Generally no, if strictly scoped |
| Individual open-tracking for engagement | Yes |
| Click-tracking for marketing analytics | Yes |
| Profiling / segmentation | Yes |
| Cross-campaign behavioural tracking | Yes |
Why the distinction matters to you
When you use a preference centre like this one, the exempt measures (the security link) keep working because they protect you, while the consent-based ones (marketing analytics) are what you can switch off. Understanding the split tells you what withdrawing consent actually changes — and what, legitimately, it does not.