Email Tracking Laws Changed in Europe: What Marketers Need to Know
European regulators have turned their attention to one of the oldest tools in email marketing: the tracking pixel.
In recent guidance, France's data protection authority, the CNIL, and Italy's Garante per la Protezione dei Dati Personali, have clarified that tracking pixels collect personal data. That means the way marketers collect, justify and disclose email engagement data now matters more than ever.
This is not a ban on email tracking. It is a reminder that the rules around data collection are tightening.
For marketers, the practical impact is clear. Campaign reporting must become less dependent on invisible pixels. Consent notices must become more specific. And the metrics that matter most need to be the ones that reflect real business outcomes, not just whether an image loaded.
What's Actually Changing?
The change is not a new law. It is updated guidance from two of Europe's most influential data protection authorities on how existing laws already apply to email tracking.
The CNIL and the Garante have both emphasised that tracking pixels are subject to the same data protection rules as other online tracking technologies. In practice, this means organisations cannot treat email engagement tracking as a background technical process that falls outside privacy law.
Under the GDPR and the ePrivacy Directive, organisations must have a legal basis for processing personal data and, in many cases, must obtain consent before storing or accessing information on a user's device. Email tracking pixels do both. They access the recipient's device to load an image, and they generate personal data about that recipient's behaviour.
The guidance from France and Italy reinforces that:
- Tracking pixels are not invisible to the law. The data they collect is personal data.
- Generic privacy policies may no longer be enough. Recipients should understand that email opens are being tracked.
- Consent or legitimate interest must be assessed carefully, especially where pixels reveal location, device or behaviour over time.
- Marketers should document what they collect, why they collect it, how long they keep it, and who can access it.
The exact interpretation may differ by country and by legal advice. But the direction is consistent across Europe: tracking must be transparent, justified, and proportionate.
Key insight: The regulators are not banning pixels. They are requiring marketers to treat the data they produce as personal data and act accordingly.
What Is an Email Tracking Pixel?
An email tracking pixel is a tiny, transparent image embedded in an email message. When the email is opened and the image loads, the server that hosts the image records the request. That request can reveal:
- Whether the email was opened
- When it was opened
- The type of device used
- The email client or app
- The IP address, which may indicate approximate location
- Whether the same recipient opened the email multiple times
This information has been central to email reporting for more than two decades. Most marketers use it through platforms such as Mailchimp, Klaviyo, HubSpot, Brevo or SendGrid without thinking about the data protection implications.
But from a privacy perspective, the process is straightforward: a device is accessed, information is sent back to the sender, and a record is created about an individual's behaviour. That is personal data processing.
Email Tracking Methods: Pixels vs Link Tracking
Not all email tracking works the same way. Marketers should understand the difference between pixel-based tracking and link-based tracking.
| Method | How It Works | What It Reveals | Regulatory Consideration |
|---|---|---|---|
| Tracking pixel | A transparent image loads when the email is opened | Open event, device, client, IP address, location | Usually requires consent under ePrivacy; personal data under GDPR |
| Link tracking | Unique parameters added to clicked links | Click event, destination, conversion path, browsing behaviour | Personal data under GDPR; must be disclosed in privacy notice |
| UTM parameters | Campaign tags appended to URLs | Source, medium, campaign, content | Should be disclosed; less intrusive but still trackable |
Tracking pixels attract more regulatory attention because they operate without the recipient taking any action. The email client loads the image automatically. Link tracking requires a click, which is a clearer expression of intent. Both are personal data processing, but the legal analysis can differ.
Why European Regulators Care
Opening an email feels like a private act. Many recipients do not realise that the simple act of opening a message can transmit information back to the sender, sometimes including their location and device details.
European regulators increasingly view this as a transparency problem. Recipients have a right to know what data is collected about them, why it is collected, how long it is kept, and what legal basis allows the processing.
The issue is not that tracking is inherently harmful. It is that many organisations have never clearly explained it. As privacy expectations rise, regulators are looking for evidence that organisations have thought through:
- What data is collected by tracking pixels
- Whether the tracking is necessary for the service
- Whether the recipient has been informed
- Whether the legal basis is valid
- How long the data is retained
- Whether the recipient can opt out
This is part of a wider European trend toward privacy-by-default and transparency-by-design.
The Legal Framework: GDPR and ePrivacy
Two laws are usually relevant.
The ePrivacy Directive, often implemented through national laws, focuses on storing or accessing information on a user's device. For email tracking pixels, this typically means consent is required before the pixel can access the recipient's device.
The GDPR governs the processing of personal data. It requires a legal basis, which is usually either consent or legitimate interest. Legitimate interest is not a free pass. It requires a balancing test that weighs the marketer's interest against the recipient's privacy rights.
| Requirement | What It Means for Email Tracking |
|---|---|
| Transparency | Recipients must be told clearly that email opens and engagement are tracked |
| Legal basis | There must be a valid GDPR basis for processing the data |
| Consent | The ePrivacy Directive generally requires consent to access or store information on a device |
| Data minimisation | Only collect the data you genuinely need |
| Purpose limitation | Use the data only for the purposes you disclosed |
| Storage limitation | Keep data only as long as necessary |
| Security | Protect the data from unauthorised access |
| Recipient rights | Allow recipients to access, correct, delete or object to processing |
Different EU member states have slightly different interpretations. France and Italy have taken a stricter position than some other countries. Germany has long taken a privacy-heavy approach. The Netherlands and Ireland have also published guidance on tracking and consent.
Consent vs Legitimate Interest: A Practical Guide
Choosing the right legal basis is one of the most important decisions a marketing team can make.
Consent means the recipient has given clear, informed, specific and unambiguous permission. For email tracking, this usually means the subscriber knows that opens, clicks and engagement are being measured and has agreed to it.
Legitimate interest means the organisation has a genuine business reason for the processing and that reason does not override the individual's rights. This requires a documented balancing test.
| Factor | Consent | Legitimate Interest |
|---|---|---|
| Standard of proof | Higher. Must be freely given, specific, informed and unambiguous | Lower, but must be documented and defensible |
| Withdrawal | Must be as easy as giving consent | Recipients can object at any time |
| Best suited for | Tracking pixels, behavioural profiling, third-party sharing | Internal analytics, fraud prevention, service delivery |
| Risk level | Lower if obtained correctly | Higher if challenged by a regulator |
Most legal teams advise that email tracking pixels fall under the ePrivacy consent requirement because they access the recipient's device. Legitimate interest is harder to justify for invisible tracking, though some organisations may rely on it for aggregated analytics with strong safeguards.
B2B vs B2C Email Tracking
Business-to-business email marketing raises slightly different questions. In B2B, the recipient is often contacted in a professional capacity, and the email address may belong to the employer rather than the individual.
However, the GDPR still protects the individual's personal data. An email address like firstname.lastname@company.com is personal data. The fact that the recipient works for a company does not remove the need for a legal basis or transparency.
B2B marketers should consider:
- Whether the contact is a sole trader or a corporate employee. In some jurisdictions, sole traders receive stronger protection.
- Whether the email address is personal or generic. Generic addresses like
info@company.comare not personal data, but most business contacts are identifiable individuals. - Whether the tracking is necessary for the business relationship. Service emails, such as order confirmations or account notifications, may have a stronger basis than marketing newsletters.
- Whether the recipient can object easily. Even in B2B, individuals have the right to object to processing.
The safest approach for B2B marketers is to apply the same transparency and consent standards as for B2C, unless a specific legal exemption clearly applies.
Country-by-Country Snapshot
Privacy enforcement is not identical across Europe. The GDPR provides a common floor, but national regulators interpret it differently.
| Country | Regulator | General Position on Email Tracking |
|---|---|---|
| France | CNIL | Tracking technologies generally require consent; transparency must be specific |
| Italy | Garante | Email tracking pixels are subject to consent and disclosure rules |
| Germany | BfDI and state DPA | Strict approach; consent is usually expected for tracking |
| Netherlands | AP | Consent generally required for storing or accessing information on devices |
| Ireland | DPC | Follows GDPR and ePrivacy; emphasises clear notice and lawful basis |
| Spain | AEPD | Consent-oriented approach to tracking technologies |
This means a one-size-fits-all privacy notice may not be enough for organisations marketing across Europe. Local legal advice is valuable, especially for high-volume senders.
This Is Not Happening in Isolation
Email marketers have already lived through several major privacy shifts.
| Year | Development | Impact on Email Tracking |
|---|---|---|
| 2018 | GDPR introduced across the EU | Raised the legal standard for consent and personal data processing |
| 2021 | Apple Mail Privacy Protection launched | Preloaded tracking pixels, inflating open rates and masking real behaviour |
| 2024–2025 | AI inbox features expanded | Messages summarised before full engagement, changing how opens relate to attention |
| 2025–2026 | French and Italian guidance on tracking pixels | Increased scrutiny of how engagement data is collected and justified |
Each step has reduced the reliability of open-based metrics. The pattern is clear.
Key insight: The value of the open rate has been declining for years. The latest guidance simply gives marketers another reason to move beyond it.
Why Open Rates Were Already Becoming Less Reliable
Even before the recent guidance, open rates were an increasingly weak signal.
Apple Mail Privacy Protection preloads images for many users, including tracking pixels. That means an email can be recorded as opened even if the recipient never sees it. Other email providers have introduced similar privacy features. AI-powered inbox assistants summarise messages before users fully open them, making it harder to connect an open with genuine engagement.
As a result, two campaigns can report similar open rates while producing completely different business results.
Many experienced marketers already treat open rate as a health indicator rather than a success metric. It can signal deliverability problems, subject line issues, or audience fatigue. It should not be used alone to judge the effectiveness of a campaign.
What Marketers Should Measure Instead
If open rates are less reliable and more regulated, the answer is not to stop measuring. It is to measure better.
| Traditional Metric | Stronger Alternative | Why It Matters |
|---|---|---|
| Open Rate | Click Rate | Shows active engagement, not just image loading |
| Unique Opens | Revenue Per Recipient | Ties email to business value |
| Total Opens | Conversion Rate | Measures whether the email achieved its objective |
| Pixel Loads | Inbox Placement | Reflects deliverability and sender reputation |
| Device Opens | Customer Lifetime Value | Shows long-term relationship impact |
| Opens by Country | Engagement Over Time | Tracks subscriber health and interest |
These metrics are harder to manipulate and more closely tied to what the business actually cares about.
A Practical Compliance Checklist
There is no need to panic or remove tracking overnight. But there is a clear case for reviewing your practices.
A sensible checklist includes:
- Review your privacy policy and ensure it specifically mentions email tracking, including pixels and link tracking.
- Check how your email platform collects engagement data and whether it can be disabled for non-consenting subscribers.
- Ensure consent and marketing preference wording reflects your actual tracking activities.
- Document your legal basis for tracking different subscriber groups.
- Avoid relying on open rate as the primary measure of campaign success.
- Educate stakeholders and clients about why open rates are less reliable.
- Build reporting around business outcomes such as clicks, conversions, revenue, retention and deliverability.
- Put a retention policy in place for engagement data.
- Make it easy for subscribers to withdraw consent or object to tracking.
- Segment subscribers by consent status so tracking can be disabled for those who opt out.
Many organisations have already started this transition. The latest guidance reinforces that it is worth completing sooner rather than later.
How to Write a Compliant Privacy Notice
A privacy notice does not need to be a long legal document. It needs to be clear, accurate and specific. For email tracking, it should answer the questions a recipient would reasonably ask.
A good notice should explain:
- That you track email engagement, including opens and clicks
- What data you collect, such as timestamps, device type, email client and IP address
- Why you collect it, such as to improve content, measure performance or maintain deliverability
- How long you keep it
- Who you share it with, including analytics tools, email platforms or data warehouses
- The legal basis, such as consent or legitimate interest
- How the recipient can opt out or object
Weak notices use vague language like "we may collect information about your interactions." Strong notices say "We use a small transparent image to record when you open our emails and which links you click. This helps us understand what content is useful."
The notice should be available at the point of signup, in a privacy policy, and linked from every marketing email. Consent management platforms can help record and manage these preferences at scale.
How to Audit Your Tracking Setup
A tracking audit does not need to be complex. It should answer a few straightforward questions.
Identify what is being tracked. Look at your email platform settings. Are open tracking, click tracking and link rewriting enabled? Are third-party analytics tools connected?
Map the data flow. Where does the engagement data go? Does it stay in the email service provider, or is it sent to a customer data platform, data warehouse, advertising network or analytics tool?
Check your legal basis. Is tracking based on consent or legitimate interest? Is the basis documented? Does it differ by country or audience?
Review disclosures. Does your privacy policy specifically mention email tracking? Does your signup form explain what will be measured?
Test opt-out mechanisms. Can subscribers easily withdraw consent? Does the platform actually stop tracking when they do?
Set retention limits. Decide how long engagement data is useful and delete or anonymise it after that point. Review your email data retention policy regularly.
What Email Platforms Are Doing
Most major email platforms have started to respond to privacy changes. The features vary, but common developments include:
- More granular tracking controls, allowing senders to disable open tracking for specific audiences
- Consent segmentation, so tracking can be suppressed for subscribers who have not consented
- Improved privacy notice templates
- Reporting that highlights clicks, conversions and revenue alongside opens
- Integration with consent management platforms
Marketers should not assume that their platform handles compliance automatically. The legal responsibility sits with the data controller, which is usually the organisation sending the email, not the software provider.
What This Means for Reporting
One of the biggest changes over the next few years will not be how emails are sent. It will be how they are measured.
Privacy protections, AI inboxes, browser restrictions and evolving regulation all point in the same direction. Marketing teams need reporting that looks beyond opens.
Instead of asking:
"Did someone open my email?"
The better question is:
"Did this email achieve its objective?"
That means measuring:
- Clicks
- Conversions
- Revenue
- Customer retention
- Deliverability
- Long-term engagement
- List health
Those metrics are harder to game, more resilient to privacy changes, and ultimately more valuable to the business.
Privacy and Performance Can Coexist
Privacy does not have to be the enemy of analytics. The strongest marketing teams are adapting by becoming more transparent, collecting only the data they genuinely need, and focusing on measurements that reflect real customer behaviour.
As regulations continue to evolve across Europe, organisations that build privacy into their reporting strategy today will be better prepared for whatever comes next.
The future of email analytics is not about collecting more data. It is about making better decisions with the right data.
Related Articles
- The Email Metrics That Actually Matter
- Why Email Open Rate Is a Misleading Metric
- Email Marketing Attribution Is Mostly Guesswork
- How AI Is Changing What Gets Opened, Clicked, and Ignored
- The Hidden Cost of Bad Email Data
Frequently Asked Questions
No. Email tracking pixels have not been banned. Regulators have clarified that collecting engagement data through pixels is personal data processing and must be transparent, justified by a legal basis, and disclosed to recipients.
Yes. If your emails reach recipients in France, Italy or any EU country, the GDPR and ePrivacy rules apply to that data processing regardless of where your business is based.
It depends on the jurisdiction and the type of tracking. For storing or accessing information on a recipient's device, the ePrivacy Directive generally requires consent. For processing the resulting personal data, GDPR allows consent or legitimate interest, subject to a balancing test.
No. Open tracking remains technically possible, but open rates have become less reliable due to Apple Mail Privacy Protection and AI inbox features. Marketers should use broader metrics such as click rate, conversion rate, revenue per recipient, engagement trends and deliverability.
Successful teams are shifting toward click rate, conversion rate, revenue per recipient, engagement over time, list health, deliverability and business outcomes rather than relying primarily on open rates.