On April 14, 2026, France's data protection authority, the CNIL, published the final version of its recommendation on tracking pixels in emails, formally adopted by Deliberation No. 2026-042 of March 12, 2026. The recommendation treats the invisible 1x1 pixel images embedded in marketing emails the same way French and EU law already treat cookies: most uses now require prior, informed consent under Article 82 of France's Data Protection Act, the domestic implementation of the ePrivacy Directive.

The deadline that makes this urgent for anyone running an email list is July 14, 2026, three months after publication. For contacts collected before April 14, the CNIL is not demanding retroactive opt-in consent outright. Instead, it required organizations to clearly inform those existing subscribers that pixels are tracking their opens, and give them an easy way to object, by that July date. Contacts added after April 14 get no such grace period: a valid opt-in has been required for them from day one.

CNIL webpage announcing its final recommendation on tracking pixels in emails, published April 14, 2026

Source: CNIL, "Pixels de suivi dans les courriers électroniques", captured August 4, 2026.

CNIL gave email marketers a 3 month window to fix tracking pixel consent 3 months CNIL's window to inform existingsubscribers before the July 14 deadline

Figure: The CNIL gave organizations a three month runway from publication to inform existing subscribers about email pixel tracking before the July 14, 2026 deadline. Source: CNIL Deliberation No. 2026-042.

Why the CNIL bothered with email specifically

Tracking pixels in email are not new. Marketing platforms have used them for years to record open rates, personalize follow-up sequences, and clean stale addresses off a list. What changed is the volume of complaints the CNIL says it has received about the practice, and the fact that an inbox is a more personal space than a website: opening an email is not the same kind of voluntary browsing action as clicking around a site, so the regulator concluded the same consent logic used for web cookies needed an email-specific version rather than a blanket carryover.

The recommendation builds directly on the CNIL's existing cookie framework and on the European Data Protection Board's guidelines on the technical scope of Article 5(3) of the ePrivacy Directive, applying it to the specific mechanics of email delivery and open tracking.

The CNIL drew a narrower line than "every pixel needs a checkbox." Two categories of pixel remain exempt from prior consent, provided they are tied to a service the recipient actually requested:

Pixel useConsent required?Example
Marketing personalization, audience measurement, cross-channel profilingYesSegmenting subscribers by what they open, retargeting ads based on email engagement
Individual open-rate tracking for deliverability, limited to removing inactive recipientsNo, if data is minimizedDropping addresses that have not opened in 6 months from a newsletter send
Security and authentication pixelsNoVerifying account activity linked to a login
Transactional email pixels (order confirmations, shipping alerts, password resets, security notices)No, for the pixel tied to that transactional purposeConfirming a shipping notification rendered correctly

The CNIL's July 22, 2026 FAQ sharpened that line further: the deliverability exemption only covers pixels that collect the minimum needed to flag inactivity, and adding extra data like IP address or user-agent strings disqualifies a pixel from the exemption even if that data is later anonymized. A newsletter someone actively subscribed to still counts as a "requested service" for that narrow exemption, but a cold marketing blast to a purchased list does not.

What this means practically if you run an email list

For most businesses sending marketing or newsletter email that reaches subscribers in France, the practical checklist looks like this. Any pixel used to personalize content, build a marketing profile, or feed ad retargeting needs prior opt-in consent, collected separately from a general newsletter signup and just as easy to decline as to accept. Any list built before April 14, 2026 needed a clear notice about pixel tracking, with a working opt-out, sent to those subscribers by July 14. Any address added after April 14 needed that consent flow in place from the first send, with no transition window. Pixels limited to inactivity cleanup or transactional confirmations can keep running without consent, as long as the data collected stays limited to that narrow purpose.

The July 14 deadline itself has already passed relative to today's date. If your organization has not sent that notice yet, the CNIL's own framing treats the transitional opt-out window as closed: continuing to track those legacy contacts without either the required notice already sent or a fresh, compliant opt-in now sits outside the recommendation's grace period, and the CNIL has said it will move into its "control" phase, meaning inspections and enforcement, in the months following.

This is guidance from a single national regulator, not a binding EU-wide regulation, but it reads existing law (Article 5(3) ePrivacy Directive, transposed as Article 82 of the French Data Protection Act) rather than creating new obligations, so the underlying legal requirement is not unique to France. Other EU data protection authorities have historically converged on CNIL positions over time, cookie consent enforcement being the clearest precedent.

Bottom line

The consent framework the CNIL just spelled out for email pixels is the same disclosure logic that already governs cookies on your website: name what you are tracking, say why, and make refusal as easy as acceptance. A cookie policy that only covers your website's own cookie banner and says nothing about tracking pixels embedded in your marketing emails is missing half of what a regulator now expects an organization's disclosures to cover.

Our Cookie Policy Generator lets you document tracking technologies beyond just browser cookies, including the pixels and tracking mechanisms your email marketing platform embeds, so your published policy actually matches what a subscriber's inbox is doing when they open your emails.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.