Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.Currently taking on only 1 new client in Q4 2026.

Do Email Tracking Pixels Require Consent? 2026 Rules by Country

The EU, UK, California and Canada, and what changes in the CRM built on open-rate data.

In the EU and UK, tracking whether an individual opened your email generally requires prior consent, because the pixel reads their device. Each regulator allows narrow exceptions for deliverability, security and aggregate-only analytics, and those exceptions differ by country. California is opt-out rather than consent: you can track unless the data is sold or shared. Canada has no settled pixel-specific rule. The pixel still works everywhere; what changed is that your individually usable open data now fragments by country and purpose instead of disappearing.

12 min read Updated Jul 2026

Can you still use opens for a given workflow?

Whether tracking is legal is the wrong starting question. Start from the workflow: can you still use an open for this specific job? The answer splits two ways, by purpose and by country. Individual scoring and profiling need consent almost everywhere in the EU and UK. Aggregate measurement and pure deliverability suppression are where the national regulators diverge.

Open-data use by purpose across France, Italy and the UK
Open-data use France (CNIL) Italy (Garante) UK (ICO / PECR)
Aggregate campaign open rate, no individual ID Allowed as a reuse of lawfully collected data; anonymising the collection by itself is not an exemption Exempt if the pixel is identical for all recipients and the technical data is anonymised May fit the statistical-purposes exception: aggregate only, with clear information and a free way to object, and no individual retention
Individual engagement scoring or segmentation Consent Consent Consent
Profiling or personalisation Consent Consent Consent
Last-open sunset or suppression Potentially exempt: last-open date only, on an email the user asked for Consent Consent, as individual monitoring rather than aggregate
Send-time optimisation Consent Consent Consent
Security or service (authentication, transactional) Exempt, narrowly Exempt, narrowly Strictly necessary, narrowly

Sources for the table: the CNIL pixel FAQ (questions 6 to 8 and 18), the Garante's Provvedimento n. 284 (sections 5 and 6), and the ICO's exceptions guidance.

The row that surprises people is sunset and suppression. France's CNIL now says a pixel used only for deliverability may keep the recipient's last-open date to reduce frequency or stop mailing inactive contacts, with no consent, as long as it collects nothing more (no open time, no IP address, no user agent, even if that extra data is deleted soon after) and the email is one the user asked for. Italy's Garante treats the same "adapt frequency or stop sending" logic as needing consent, so the same open event gets opposite answers one border apart.

California and Canada do not fit this grid. California is opt-out of sale and sharing, so a first-party open pixel that is not used for cross-context advertising is not subject to a general opt-out, whatever the use. Honour opt-out signals, including Global Privacy Control, only where the data is sold, shared or fed into ad targeting. Canada has no settled pixel-specific rule. CASL governs sending the message, while PIPEDA and Quebec's Law 25 govern the data you collect. Applying CASL's software-installation rule to an ordinary open pixel is a commentator's reading that the CRTC's own guidance cuts against.

What changed, and by when

The EU baseline is that email tracking pixels fall under the ePrivacy device-access rule, Article 5(3), the same rule that covers cookies, so they need consent unless a narrow exemption applies. The European Data Protection Board settled that point in its Guidelines 2/2023, finalised on 7 October 2024. France and Italy are the first national regulators to publish pixel-specific guidance on top of it, and other member states can follow.

France's CNIL adopted its recommendation on 12 March 2026 under Article 82 of the French Data Protection Act, published on 14 April 2026. Italy's Garante adopted Provvedimento n. 284 on 17 April 2026 under Article 122 of the Privacy Code, published in the Gazzetta Ufficiale on 29 April 2026. Germany has no pixel-specific text yet. Its data-protection conference (the DSK) has said guidance is coming, and for now pixels sit under existing device-access law (the TDDDG) and email-marketing law (the UWG). The EU's Digital Omnibus reform, tabled in November 2025, has not changed any of this.

On deadlines: in France, the 14 July 2026 transition for addresses collected before the recommendation has passed in principle, but the CNIL allows a reasonable, documented extension where the size of the list or its deliverability makes one necessary, and it lets you keep relying on non-objection for older addresses that you informed properly during the window. In Italy, the deadline is 29 October 2026, six months after publication. Germany's guidance is pending, and the Digital Omnibus is not adopted.

Why this is a CRM problem, not a legal one

The legal question has a clear answer; the operational one is harder, and two things were already true before any regulator acted. Open does not equal read: Apple's Mail Privacy Protection loads remote images in the background whether or not the person engages, so a share of your "opens" were never reads. And the pixel is how your CRM knows an email was opened, so as consent rules, deliverability carve-outs and opt-outs bite unevenly, that signal fragments rather than vanishing. Your individually usable open data shrinks to a consented subset that varies by country, and also by device, mail client and preference.

Law firms own what the regulator said. ESPs own the off switch. Neither owns what happens to a lifecycle programme built on open-rate data once that data stops being one uniform thing.

What specifically changes

The open still fires. What changes is which flows can legally use it, and for whom. At least six CRM jobs are affected. Some need consent, some can run on a minimal deliverability basis, and all become uneven across jurisdictions.

  • Engagement segmentation and scoring. Individual "engaged" and "dormant" tiers built on opens need consent in the EU and UK. Without it, unconsented but active readers look dormant.
  • Sunset and suppression. In France a minimal last-open signal can keep pruning inactive contacts without consent. In Italy the same individual suppression needs consent. In the UK it counts as individual monitoring, so consent. One flow, three legal bases.
  • Re-engagement triggers. A "no open in 90 days" win-back inherits that split: runnable on a deliverability basis in France, consent-gated in Italy.
  • Send-time optimisation. Optimising send time on individual open behaviour is a performance use, so it needs consent across the EU and UK.
  • Lead and account scoring. Open-based points now rise or fall with consent state rather than intent, which biases the score rather than merely thinning the data.
  • Deliverability monitoring. Aggregate open rate as an inbox-placement proxy is the most survivable use, because aggregate exemptions exist, though it is noisier now that Apple loads images by default.

The harder problem is that the remaining data is uneven as well as thinner. Your remaining individually usable opens over-represent the consented and the non-Apple users, and they mean different things in Paris, Milan and London.

Take a 90-day sunset flow. In France it can continue with no consent if you rebuild it around a single retained field, the last-open date, used only to slow or stop sends to inactive contacts on mail they opted into. Cross into Italy and the same flow needs consent, because stopping sends based on a recipient's manifested interest is treated as a consent-requiring use. The flow's legal basis changes by country rather than the flow breaking. The part that goes dark without consent is individual scoring, the segment that reads opens to rank engagement.

How to rebuild scoring without opens

Where consent is missing, replace individual open-scoring with a blend of consent-permitted signals, and keep opens only for the uses that survive: aggregate measurement, and minimal deliverability suppression where your country allows it. None of these matches the breadth of opens; each trades coverage for a stronger signal.

  • Clicks. Stronger intent, lower coverage, and not a free pass. A uniquely identified tracking link is itself device access and personal-data processing. The CNIL says links are not covered by the pixel recommendation but need the same analysis. Use consent-permitted click events, not clicks as a way around the rule.
  • Site and product events. Often the best signal for SaaS, because they capture real downstream intent, but they need identity stitching to the emailed person, which is its own consent surface.
  • Reply rate. The highest-intent signal, especially in B2B and sales-assisted flows, but sparse. Good for alerts, weak for segmentation.
  • Purchase and activity recency. Strong for commerce and product-led growth, though it lags and is blind to upper-funnel interest.
  • Declared preferences. A preference centre does not by itself count as pixel consent, because choosing topics is not the same as consenting to tracking. It is the right place to host the tracking-consent control, though, and it produces first-party signals you own outright. Build an explicit tracking-consent control rather than treating topic preferences as consent.

Two moves make the transition manageable. First, rebuild suppression on whatever your jurisdiction permits: the last-open date in France, or consented tracking plus click, visit, reply and purchase recency elsewhere, so list hygiene survives. Second, rebuild individual scoring as a weighted blend of the signals above, and expect smaller, more honest "engaged" segments than the open-inflated ones you had.

Turning open tracking off in your ESP

The four platforms below offer different levels of control over open tracking, and the toggle is only half the job. Being compliant also means capturing consent, or documenting an exemption, storing it against the contact, and honouring it on every send. The CNIL is explicit that a platform's standard terms are not proof of consent. The record is yours, and you have to be able to demonstrate it, by audit if asked.

  • Customer.io lets you disable tracking at workspace level, per message, or run a consent-gated mode through a per-contact attribute (cio_email_tracking_consent). See its open-tracking consent docs; it has also published a 2026 EU explainer.
  • Klaviyo lets you turn tracking off at account level and per recipient, and treats open-tracking consent as separate from marketing consent. Confirm current message-level options in its open-tracking settings docs.
  • Braze disables tracking per user profile through the email_open_tracking_disabled attribute, currently documented for SparkPost and SendGrid in its user attributes docs.
  • HubSpot lets you turn marketing-email tracking off at account level and per marketing email, with separate controls for one-to-one sales email. See its email tracking settings docs.

Vendor settings change often, so confirm the current option before you rely on it.

Legal regime at a glance

Legal regime for email tracking pixels by jurisdiction
Jurisdiction Opt-in or opt-out Pixel specifically in scope? Primary enforcement Headline penalty
EU (all 27) Opt-in Confirmed at EU technical-scope level (EDPB, Article 5(3)); pixel-specific guidance so far in France and Italy National data-protection authorities such as the CNIL and Garante, on the EDPB reading GDPR fines apply; the ceiling varies by member state
UK Opt-in Confirmed; the ICO lists tracking pixels under PECR device-access rules, separate from the marketing-message rules ICO under PECR, with powers enhanced by the Data (Use and Access) Act Up to £17.5M or 4% of global turnover, which is PECR's higher maximum rather than an automatic figure for every breach
California Opt-out Inferred; no CCPA text names email pixels, so general tracking rules apply The CPPA or Attorney General for the CCPA; private class actions for CIPA CCPA per-violation penalties, and CIPA statutory damages, though email-pixel CIPA claims have largely failed (Ramos v. Gap (2025) was dismissed)
Canada Unsettled; CASL governs the message, Quebec is strictest on the data Inferred; the CASL software-install reading of a pixel is not an established CRTC position and arguably cuts the other way CRTC for CASL, the OPC for PIPEDA, the CAI for Quebec's Law 25 CASL and Quebec Law 25 penalties apply to the underlying conduct

Germany is left out on purpose. Its device-access fine is unsettled across the sources reviewed, and there is no pixel-specific German ruling yet. Exact ceilings differ between sources and are not the deciding factor for a CRM decision, so confirm them before you rely on a figure.

FAQ

Do I need consent to track email opens?

In the EU and UK, yes for individual open tracking. The pixel reads the device and needs prior consent, unless a narrow exception applies for deliverability, security or aggregate-only analytics, and those exceptions differ by country. California is opt-out, so no prior consent, but you must honour sale and sharing opt-outs where they apply. Canada has no settled pixel rule. For a list that spans several markets, treat individual open tracking as consent-required by default.

Does this apply to transactional emails?

Often you can put a pixel in a transactional or service email without consent, but only for a narrow purpose. A pixel limited to deliverability or security on a message the user requested, such as an order confirmation or a password reset, can be exempt. It loses the exemption the moment it also measures campaign performance, profiles the recipient, or collects more than the last-open date. Cart-abandonment and promotional emails that look transactional are treated as marketing and need consent.

Does this apply to B2B?

Yes, for the pixel. B2B rules and carve-outs, such as Canada's conspicuous-publication basis or Germany's existing-customer exception, govern whether you may send the message, not whether you may read the device. The CNIL's FAQ is explicit that the recommendation applies regardless of sender or recipient, whether the address belongs to a client, a prospect or an employee, and whether it is a personal or a generic mailbox. The consent test is the same as for B2C.

Can I still track opens in the US?

In California, yes, without prior consent, because the CCPA is an opt-out regime. If the tracking feeds cross-context advertising, or the data is sold or shared, honour opt-out signals, including Global Privacy Control, and follow the rules on consent interfaces. A separate wiretap-litigation risk exists under CIPA, but it has mostly affected website trackers, and the leading email-pixel case, Ramos v. Gap (2025), was dismissed. There is no federal opt-in requirement in the sources reviewed here.

Can I still run a sunset flow on opens?

It depends where the recipient is. In France, a pixel that keeps only the last-open date, used purely to slow or stop sends to inactive contacts on an email they asked for, can run without consent. In Italy the same individual suppression needs consent, and in the UK it counts as individual monitoring, so consent. The version that travels across borders is to rebuild suppression on consented signals, or on clicks, visits, replies and purchase recency, so the flow survives wherever your recipients are.

What about Germany specifically?

Germany has no dedicated 2026 pixel guidance yet, but open tracking is not free. The pixel sits under the TDDDG's device-access rule, which requires consent unless the access is strictly necessary, and the email itself sits under the UWG, which requires prior consent with a narrow existing-customer exception. German courts accept double opt-in as the way to prove consent. The sharper risk is enforcement: Germany's Abmahnung system lets competitors and industry associations send cease-and-desist letters directly, so exposure is not limited to the regulator.

If you would rather have your lifecycle setup audited for this than only read about it, so you know which flows read opens, where the consent gap bites, and what to rebuild first for each market, that is the kind of work I do.

Related reading: CRM Implementation Checklist 2026, for the steps that matter once you decide which lifecycle flows to rebuild without open data.

Sources and method

Primary sources this article relies on:

This article checks its load-bearing claims against that primary regulator and vendor text rather than secondary summaries. Regulator and statute text is treated as settled; practitioner readings are flagged in the prose as interpretation. I am a growth and CRM practitioner, not a lawyer, and none of this is legal advice. Confirm your own position with counsel before you change how you email. The rules are still moving: the EU's Digital Omnibus is in negotiation, Germany's guidance is pending, and the California and Canada details, especially CIPA and the CASL software-installation argument, are the ones most worth re-checking against primary sources.

Last reviewed: 25 July 2026

Audit my lifecycle setup →