On July 22, 2026, the French Data Protection Authority (CNIL) took an important step in data protection by publishing frequently asked questions (FAQs) about its Recommendation concerning tracking pixels in emails. This Recommendation elucidates the application of Article 82 of the French Data Protection Act to these tracking mechanisms and aims to provide clarity to organizations that utilize tracking pixels for various analytical purposes.
The Recommendation Overview
Originally adopted on March 12, 2026, and later published in the French Official Journal on April 14, this Recommendation lays the groundwork for understanding how consent must be handled when deploying tracking pixels in email communications. Tracking pixels, small, often invisible images embedded in emails, can collect information about user interactions, which raises significant privacy considerations.
Consent: A Core Requirement
One of the critical takeaways from the Recommendation is the clear message regarding consent. Generally, tracking pixels in emails necessitate prior consent from the recipient. The CNIL specifies instances where this consent may be required, such as for measuring campaign performance, personalized targeting, and detecting potentially fraudulent activity. Notably, even if an email itself does not require consent, the associated tracking pixel might; it highlights the separate implications of the email content and tracking mechanism.
Collecting Consent Effectively
In practical terms, the CNIL advises organizations to collect consent during the initial collection of email addresses. This consent collection should come with explicit information about what the tracking pixels will be used for, ensuring the recipient fully understands their choices. To promote transparency, the CNIL encourages that withdrawing consent should be just as easy as giving it—ideally facilitated via a link in the footer of each email. If initial consent collection isn’t possible, organizations can later seek consent through an email that does not include any tracking mechanisms that would necessitate prior consent.
Understanding the FAQs
The FAQs released alongside the Recommendation provide invaluable insights into its practical application. For instance, the CNIL clarifies that deliverability-only pixels, which monitor whether emails have been opened, are exempt from consent—but only if they are used strictly as necessary. Specifically, the only essential data for this purpose is the last opening date, barring justification for additional data needs, such as collecting Internet Protocol (IP) addresses or user-agent information.
Exempt vs. Non-Exempt Purposes
The CNIL FAQs also elucidate the distinctions between exempt and non-exempt purposes for using tracking pixels. A single pixel can be employed for both purposes, but any non-exempt use demands that consent has been obtained beforehand. Importantly, there needs to be a clear and defined purpose for deploying a tracking pixel; organizations cannot deploy these mechanisms in anticipation of potential user consent later.
Broad Applicability of the Recommendation
This Recommendation isn’t limited by the type of sender or recipient; it broadly applies to all forms of email communications. However, the requirement for consent hinges on the specific circumstances, including the intended purposes and the categories of emails being sent. For instance, whether an email can benefit from exemption for deliverability depends on whether it was expressly requested by the user.
Handling Pre-Existing Email Addresses
Addressing concerns regarding email addresses collected before the Recommendation’s publication, the CNIL allows organizations to continue using tracking pixels during a transition period. This period expires three months post-publication, requiring organizations to inform recipients of their right to object to future emails. Organizations facing challenges complying with the timeline may request a reasonable extension, contingent upon providing documented justification.
Status of Non-Compliance
If organizations did not comply with the July 14, 2026, deadline for sending required notices and no justification exists for an extension, they must either adhere to the Recommendation’s full requirements—including obtaining consent—or cease the use of tracking pixels that necessitate consent. Meanwhile, if prior notifications were successfully sent to users about their right to object prior to this date, the organizations can continue to rely on an absence of objection, provided conditions remain unchanged.
Further Resources
To dive deeper into this important subject, organizations and stakeholders can review the original Recommendation in French or English. Additionally, for official communications, interested parties can access the CNIL’s press release and relevant FAQs.