Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

The CNIL’s recommendation of 12 March 2026, which was published on 14 April 2026 and applicable from that date, provides detailed guidance on the legal framework applicable to email tracking pixels. 

While the applicability of ePrivacy rules to tracking pixels had already been recognised at European level, notably through the EDPB’s interpretation of Article 5(3) of the ePrivacy Directive, the recommendation is the first French regulatory instrument dedicated specifically to the use of tracking pixels in emails. It seeks to clarify how Article 82 of the French Data Protection Act should apply in practice across a range of use cases. 

The recommendation has attracted particular attention in recent days due to the expiry, on 14 July 2026, of the three-month transition period that followed its publication. During that period, organisations were required, among other things, to inform individuals whose data had been collected before publication of the recommendation and to give them the opportunity to object to the use of tracking pixels. 

Beyond this transitional mechanism, the recommendation provides important guidance on several issues that had previously generated practical uncertainty, including the circumstances in which consent is required, the scope of the deliverability exemption and the relationship between the rules governing the sending of emails and those governing tracking technologies. 

The CNIL subsequently organised a webinar on 28 May 2026 to explain its approach and answer implementation questions from organisations and technology providers. The explanations provided during that webinar offer useful insight into how the authority is likely to interpret and apply the recommendation in practice. 

The recommendation does not create a new legal regime. Rather, it applies existing ePrivacy principles to email tracking practices and reflects the CNIL’s broader effort to extend to email environments concepts that are already familiar in the context of cookies and other online trackers. 

Qualification as “Trackers”

The CNIL considers that email tracking pixels constitute technologies that access or write information on a user’s terminal device, regardless of their invisibility or limited technical footprint. 

As clarified during the webinar, this qualification is based on the functional effect of the technology, namely its ability to collect information when the email is opened, rather than on its form or visibility. 

This leads to a two-step analysis, with ePrivacy rules which apply at the stage of access to the terminal, and GDPR which applies only where personal data is subsequently processed.

Accordingly, the assessment must be carried out ex ante, by reference to the purpose pursued through the pixel, rather than only to the data effectively collected. 

This distinction is important in practice. Even where the information collected through a pixel is limited, the initial access to the terminal may still trigger Article 82 unless the operation falls within one of the recognised exemptions. 

The CNIL indicates that prior consent is required in most situations, in particular where pixels are used to: 

  • measure campaign performance;
  • analyse user behaviour;
  • personalise content or sending frequency;
  • build or enrich user profiles;
  • enable targeting across channels.

The recommendation adopts a purpose-based approach. The relevant question is not merely what information is collected, but why the technology is used and whether the operation can be regarded as strictly necessary for a service requested by the user. 

During the webinar, the CNIL emphasised that organisations should assess whether the use of a pixel is strictly necessary for a specific purpose and should be able to document that assessment. 

A Narrow Deliverability Exemption

One of the most significant practical aspects of the recommendation is the recognition of a limited exemption for deliverability-related tracking. 

The CNIL accepts that certain pixels may be used without consent where they are deployed solely to manage mailing lists and identify inactive recipients, provided the organisation can demonstrate that the tracking is strictly limited to adjusting sending frequency or discontinuing communications to inactive users. 

The recommendation also expects data collection to remain minimal. During the webinar, the CNIL indicated that organisations should limit collection and retention to what is strictly necessary for the relevant purpose and referred favourably to approaches relying only on limited information relating to the most recent opening event. 

However, the webinar also clarified that this exemption only applies where the email has been expressly requested by the recipient or is linked to a service expressly requested by the recipient. The CNIL therefore considers that the exemption may apply, for example, to subscribed newsletters or transactional communications, but not to B2B prospecting emails or emails sent solely on the basis of a marketing soft opt-in. 

In practice, this distinction may have significant consequences for many existing email marketing practices. 

Organisations relying on the exemption should also ensure that data collected for deliverability purposes is not subsequently reused for marketing analytics, profiling, personalisation or other purposes requiring consent. 

One of the most important clarifications provided by the CNIL is that the legal regime applicable to the sending of an email and the legal regime applicable to tracking pixels are independent. 

As clarified during the webinar, the fact that an organisation may lawfully send an email does not automatically legitimise the use of a tracking pixel within that email. 

As a result, an organisation may be permitted to send a marketing email on the basis of a soft opt-in while still requiring consent for the tracking technology embedded in that message. 

For many organisations, this may be one of the most significant compliance implications arising from the recommendation. 

Transparency Obligations

The CNIL requires users to be clearly informed about the presence of tracking pixels, their purposes, the data collected, any recipients, including service providers involved in the processing.

Given the invisible nature of pixels, the webinar stressed the importance of clear and explicit information enabling individuals to understand that their interaction with an email may be tracked. 

Where consent is required, this information must be provided before consent is collected and in a sufficiently granular manner. 

More generally, any subsequent processing of personal data generated through the use of tracking pixels remains subject to the GDPR, including its transparency and accountability requirements. 

The recommendation should be viewed in the broader context of the CNIL’s long-standing approach to cookies and other trackers. 

Over recent years, the CNIL has developed a detailed compliance framework for tracking technologies, supported by guidance, investigations and enforcement actions. The recommendation extends many of the same concepts to email tracking practices: purpose-based analysis, a restrictive interpretation of exemptions, transparency obligations, consent management and accountability requirements. 

Practical Implications

The recommendation has immediate operational implications for organisations using email marketing, CRM or customer engagement tools. 

In practice, organisations should consider: 

  • reviewing the default tracking settings of their email tools;
  • identifying the precise purposes pursued through each tracking functionality;
  • assessing whether those purposes require consent or may benefit from an exemption;
  • updating privacy notices and related documentation;
  • documenting any reliance on the deliverability exemption;
  • reviewing relationships with email service providers and marketing platforms.

Particular attention should be paid to tools combining multiple purposes, such as deliverability monitoring, campaign analytics and personalisation, as these mixed-use scenarios are often the most difficult to analyse. 

Looking Ahead

The CNIL’s recommendation confirms that email tracking pixels should now be analysed as part of the broader regulatory framework governing tracking technologies. 

Its main contribution is not to establish the applicability of ePrivacy rules from scratch, but to provide a dedicated French framework explaining how those rules should be applied to common email tracking practices. 

While the recommendation and the webinar provide valuable guidance, certain practical questions remain, particularly regarding the implementation of consent mechanisms in email environments and the treatment of technical solutions combining several purposes. 

Against that backdrop, organisations would be well advised to adopt a structured and well-documented approach, ensuring that each use of tracking pixels is assessed in light of its purpose, necessity and technical implementation. 

Baker McKenzie’s France Data & Cyber team, including Floriane Cruchet, Juliette Olliveaud, Marlyse Lissan, Juliette Leportois, Antoine Preux and Raphaëlle Mauret contributed to the preparation of this client alert.

Author

Magalie Dansac Le Clerc is a partner in Baker McKenzie's Paris office. A member of the Firm's Information Technology and Communications Practice Group, she is a Certified Information Privacy Professional (CIPP).