For years, the humble tracking pixel powered one of email's most quoted numbers: the open rate. A tiny transparent image, loaded when the recipient opens the email, tells you who opened and when.
That mechanism is now under pressure from two directions. Privacy protections such as Apple's Mail Privacy Protection already inflated open counts to the point of unreliability. Now a European regulator has moved on the legal side. In April 2026, France's CNIL published final recommendations on email tracking pixels, tightening the conditions under which individual open tracking is lawful.
This guide explains what CNIL said, why it matters beyond France, and how to rebuild your reporting without the pixel as your foundation.
What you will learn:
- What CNIL actually said about tracking pixels
- The difference between individual and aggregate tracking
- Why open rate was already unreliable
- How the ruling interacts with GDPR and ePrivacy
- What to measure instead
The Short Version
- CNIL published final recommendations on email tracking pixels in April 2026.
- Individual open tracking generally requires consent under ePrivacy rules.
- Aggregated, non-identifying measurement is treated more favourably.
- Open rate was already distorted by Apple MPP and bot activity.
- The fix is to shift primary reporting to clicks, conversions and replies.
What CNIL Said
CNIL's recommendation focuses on the tracking pixel — the embedded image used to detect whether, when and how an email is opened. Its position follows the pattern set for cookies and web tracking:
- Individual open tracking — recording that a specific, identifiable person opened a specific email — is generally subject to consent under ePrivacy rules.
- Consent must be freely given, specific, informed and unambiguous.
- Aggregated measurement that does not identify individual recipients is treated more favourably, because it poses lower privacy risk.
This is not a ban on measuring performance. It is a boundary between measuring campaigns and individuals. If you use open data to trigger flows, segment audiences or retarget specific people, you are on the individual-tracking side of the line and need a proper basis.
| Use of open data |
CNIL treatment |
| Campaign-level open rate (aggregated, non-identifying) |
Lower risk |
| Individual "who opened this email" record |
Generally requires consent |
| Open-triggered automation for a specific person |
Requires consent / lawful basis |
| Retargeting or profiling based on opens |
Requires consent |
Why This Matters Beyond France
CNIL is France's data protection authority, and the recommendation is binding guidance in France. Its wider importance is persuasive: it reflects how the ePrivacy Directive and GDPR are interpreted across the EU, and it signals the direction regulators are heading.
If you send to European recipients — or aspire to — you should treat this as the emerging standard. National rules such as the UK's PECR and other member states' ePrivacy implementations are heading in a similar direction. The practical principle is simple: do not track individuals without consent, and prefer aggregated measurement where possible.
For a wider view of the rules that govern consent and tracking in email, see email tracking laws in Europe and the GDPR compliance checker.
Open Rate Was Already Unreliable
Even before CNIL, open rate had been quietly degrading as a metric. Three forces combined:
- Apple Mail Privacy Protection pre-fetches content and loads pixels in the background, so a large share of reported opens are not real reads. See the open rate problem in detail.
- Security scanners and bot activity generate opens without human intent, adding noise.
- Privacy law now adds a legal question to the technical one: may you even collect this data?
The result is that open rate, already the least trustworthy headline metric, now carries legal risk on top of technical distortion. That is a strong argument to move it from your primary KPI to a secondary, directional signal.
What to Measure Instead
Shifting away from opens does not mean you are blind. It means you measure things that reflect real behaviour and are defensible under privacy rules.
- Click-through rate — do people act on your content?
- Click-to-open rate (CTOR) — of those who engaged, how many clicked?
- Conversion events — the outcomes you actually care about.
- Reply rate — especially valuable in B2B, and a strong engagement signal for the inbox.
These metrics also align better with what mailbox providers reward. The click-to-open rate guide and reply rate guide cover how to use them. And because clicks are the most reliable engagement signal, they are the right basis for engagement-based list pruning.
The honest replacement for the open rate is not another metric. It is a measure of what people do, not what pixels report.
A Practical Path Forward
- Audit your tracking. List every place you use open data and classify it as individual or aggregate.
- Add consent where needed. Update your privacy notice and, where you track individuals, put consent in place.
- Prefer aggregate reporting. Use campaign-level stats that do not identify individual recipients.
- Shift primary KPIs to clicks and conversions. Keep open rate as a directional signal, not a trigger.
- Rebuild automation triggers. Replace open-based triggers with click- or action-based ones where you cannot justify consent.
- Document your position. Record your lawful basis so you can defend it if asked.
Building an Aggregated Tracking Approach
The simplest way to stay compliant without losing performance insight is to measure campaigns rather than individuals. Concretely:
- Count opens at the campaign level, not per recipient. A total open count and rate is aggregate data; a list of which individual opened is individual tracking.
- Remove open-based personal triggers. Replace "opened but did not convert" automations with click- or action-based ones.
- Use hashed, non-identifying identifiers where you need to link activity, so the data cannot be traced back to a person.
- Keep your privacy notice accurate. If you say "we count campaign opens for aggregate reporting", do not quietly build per-person profiles.
| Approach |
Individual tracking? |
CNIL risk |
| Campaign open rate only |
No |
Low |
| "Who opened" per recipient |
Yes |
High — needs consent |
| Open-triggered automation per person |
Yes |
High — needs consent |
| Click and conversion tracking |
Depends on linkage |
Medium — document basis |
Aggregated measurement answers the same business questions — did the campaign perform? — while respecting the boundary CNIL drew.
A Consent Notice That Works
If you do track opens at an individual level, your notice must be specific. A generic footer line is not enough. A clearer model:
We use a tracking pixel to see whether you open our marketing emails, so we can tailor future content and measure campaign performance. We only use this where you have agreed, and you can change your choice or withdraw consent at any time in your email preferences.
Three requirements to check against any notice you write:
- Freely given — consent is a choice, not a precondition of the newsletter.
- Specific — it names open tracking as the purpose.
- Informed — it says what data is collected and how to withdraw.
The GDPR compliance checker walks through consent, notice and record-keeping requirements in a single pass, and the privacy notice link reference covers how to surface it in the footer.
Key Takeaways
- CNIL's April 2026 recommendations restrict individual open tracking without consent.
- Aggregated, non-identifying measurement is treated more favourably.
- Open rate was already unreliable due to Apple MPP and bots.
- The guidance is persuasive across the EU and reflects wider privacy trends.
- Shift primary reporting to clicks, conversions and replies.
- Audit your tracking and document your lawful basis.
Sources and Further Reading
Related Articles
Related tools: Review your compliance position with the GDPR compliance checker, measure genuine engagement with the email click-to-convert rate calculator, and monitor your open rate calculator without relying on it as a primary KPI.
This article summarises public regulatory guidance for informational purposes and is not legal advice. Data protection rules vary by jurisdiction and change over time; consult qualified counsel for your own programme.