+33 1 75 43 77 01info@ediware.netFree account: 1,000 emails per month FrançaisFR
Talk to an expert

HomeDeliverability & technicalTracking pixel

Tracking pixel and the CNIL recommendation: what changes for your email campaigns

In brief: On 12 March 2026, the CNIL, the French data protection authority, adopted its recommendation on tracking pixels in emails (deliberation no. 2026-042), published on 14 April. The three-month transition period ends on 14 July 2026. Your sends are not called into question. It is the named measurement of opens that moves under consent.

Illustration: Tracking pixel and the CNIL recommendation: what changes for your email campaigns

Let us clear up the misunderstanding straight away, because it has been doing the rounds since the spring. The CNIL does not ban the tracking pixel. Nor does it stop you prospecting in B-to-B. What it regulates is your ability to know that Paul Martin opened your campaign at 2:32 pm from an iPhone.

The nuance looks thin. Yet it changes everything about how to approach the subject. Here is what the text says, what you concretely lose in your statistics, and the three things to do before 14 July.

The pixel is a tracker, and it already was

The recommendation starts from a simple legal observation. The tracking pixel, that invisible one-pixel-by-one-pixel image inserted in the body of an email, is a tracker within the meaning of article 82 of the loi Informatique et Libertés (the French Data Protection Act). The same article that governs cookies. It requires free, specific, informed and unambiguous consent before any access to or storage of information on the user’s terminal.

So this is not a new text. The CNIL is applying to email a framework that already existed, taking its specificities into account. It clarifies, it does not invent. Which also explains why the transition period is so short: nobody is discovering the principle, only its application.

The scope is broad. All organisations, private and public alike, companies, associations, public authorities, as well as their service providers. Your router is concerned just as much as you are.

This is the practical heart of the text, and the part that most articles published in recent months skimmed over.

Purpose Regime
Measuring and optimising campaign performance (analysis of opens) Consent required
Personalising content or sending frequency according to opening behaviour Consent required
Adapting the communication channel according to the recipient’s engagement Consent required
Measuring deliverability individually to remove inactive addresses Exempt
Transactional emails: order confirmation, account alert, shipping notification, password reset Exempt
Security measures contributing to user authentication Exempt

The deliverability exemption deserves a pause. It did not exist in the draft submitted to public consultation; it was introduced in the final version. It allows you to keep an individual record of the last open, for the sole purpose of identifying dead addresses and removing them from your lists. A hygiene measure, not a performance measure. The line is thin and that is precisely where your analysis will need to be documented.

And then there is the point almost everyone misses: click tracking is not concerned. A click is a voluntary action by the recipient, not information stored without their knowledge. Your click rates, your redirect links, your conversion attribution, none of that changes. Keep that sentence in mind; it will be useful further on.

The B-to-B exception exempts you from nothing

Here is the mistake that is going to cost many companies dearly.

Article L.34-5 of the Code des postes et des communications électroniques (the French Postal and Electronic Communications Code) allows email prospecting to a professional address without prior opt-in, provided the message relates to the position of the person being solicited. It is the foundation of B-to-B prospecting in France. It remains valid; it has not moved a millimetre.

Except that this exception concerns the send. It says strictly nothing about the tracker. The CNIL confirmed the distinction in its recommendation, and it must be taken seriously: being allowed to write to a prospect gives you no right to measure their opening by name.

Operational translation. On a cold prospecting file, you keep sending exactly as before. But you measure only in anonymous aggregate. Same logic for files purchased from third parties, which default to non-consenting.

What you really lose in your statistics

The question everyone is asking. Here is the answer, without dramatising.

What does not change: volumes sent, the aggregate open rate, invalid addresses and bounces, the click rate, the conversion rate, unsubscribes.

What becomes reserved for consenting contacts: the named list of openers, hour-by-hour opening curves, the breakdown by device and by email client, follow-up segmentation of openers versus non-openers, and lead scoring based on opens.

What remains for non-consenting contacts: an anonymous aggregate count, with no identifier whatsoever.

Now, the real question. Is it that serious?

Frankly, no. And for a reason we have been repeating for years at Ediware: the open rate was already largely fictitious. Apple Mail Privacy Protection has been preloading images since 2021 and triggers phantom opens en masse. The security robots of corporate email systems open and click before the recipient has even seen the message. We devoted an entire article to this subject, because the phenomenon distorts everyone’s statistics and few advertisers measure its extent. You can read it again here: robot clickers and false opens.

The CNIL recommendation does not break a reliable metric. It speeds up the exit of a metric that was becoming less and less so. Teams that were already steering by click and conversion will lose almost nothing. The others will have to learn, and that is rather good news disguised as a constraint.

One case deserves your immediate attention: if your lead scoring awards points for opens, it needs to be rebased on clicks. Otherwise your scores will mechanically collapse across the entire non-consenting part of your database, and your sales reps will receive lists of “cold” prospects that are not.

The three actions to take, and the 14 July deadline

The recommendation was published on 14 April 2026. The transition period runs for three months. Do the maths: 14 July 2026.

1. Build your consent register. By CSV import of consents already obtained, by collection via a tracked link in your emails, or by API. One rule to know: a refusal or a withdrawal can never be overwritten by an import. Only the recipient can reverse their decision, of their own accord.

2. Set the pixel campaign by campaign. Three possible choices. Complete deactivation, for your transactional emails and above all for the campaign that asks for consent, because inserting a pixel in an email that requests permission to track would be contradictory to say the least. Declaring it out of scope, for recipients located outside the territory concerned, under a responsibility you document with your DPO. Or activating the hygiene measure only, which keeps the last opening date of non-consenting contacts under the deliverability exemption.

3. Inform your historical database before 14 July. This is the transitional obligation, and it is the one that is pressing. For addresses collected before the recommendation was published, the CNIL asks you to inform clearly about the use of the pixel and to allow easy objection. In practice: a dedicated campaign, pixel deactivated, with a tracked consent link. Nothing complicated, but it has to go out.

What your platform must handle without you

A technical point that is going to separate the tools in the coming months.

Branching by consent status must be native. A full measurement pixel for consenting contacts, an anonymous aggregate pixel with no identifier for everyone else, and this within a single campaign. If your router forces you to choose between “pixel for everyone” and “pixel for no one”, you are stuck: either you are outside the rules, or you lose all measurement. There is no third option.

The rest follows the same principle. A withdrawal link in every email. An exportable register, which will be your first piece of evidence in the event of an inspection. Bot filtering maintained for consenting contacts. At Ediware, this switch was built ahead of the deadline, with anonymisation by design for non-consenting contacts, because GDPR compliance has been part of the architecture from the start and not a layer added afterwards. The details of our approach can be found on the data security and GDPR compliance page.

The file you must be able to present

If the CNIL comes knocking at your door, four elements can be called upon.

The exportable consent register, with each contact’s status, source and dates. Timestamped proof of information, recipient by recipient. The technical documentation of your router’s architecture, which the router must be able to provide you with. And your documented analysis, list by list and campaign by campaign, of the applicable regime.

This last point is the only one nobody can produce on your behalf. It is also the one everyone is going to forget.

On the privacy policy side, a few mentions to add: the two distinct purposes of the pixel, deliverability on one side and individual measurement on the other, the legal basis resting on consent within the meaning of article 82, the optional nature of that consent, the withdrawal arrangements via the link in the email footer, and the retention periods. Proof is kept for the entire period the consent is active, then three years after any withdrawal.

Frequently asked questions

Can I still do cold B-to-B prospecting? Yes. Article L.34-5 CPCE remains applicable and your sends are not called into question. Only the named measurement of opens requires consent.

Is click tracking concerned? No. A click is a voluntary action by the recipient. Your click rates and conversions remain measurable as normal, across your entire database.

What happens if I have done nothing by 14 July? You leave the transitional regime. The named measurement of opens on your historical database then finds itself without a legal basis, which exposes you in the event of an inspection. Catching up remains possible, but it will have to be documented.

Can a contact who refused give their consent again? Yes, but only of their own accord, via a tracked link. You cannot reinstate them through an import. It is prudent to wait at least six months before any new solicitation on this point.

Are my transactional emails concerned? No. Order confirmations, account alerts, shipping notifications and password resets are exempt.

What about my recipients located outside France? The campaign can be declared out of scope if no local regulation requires consent to the pixel. That analysis is your responsibility and is documented with your DPO.

A regulatory constraint that sets the counters straight

The tracking pixel had lived on an unexamined assumption for twenty years. An invisible image, placed without a word, that sent back to the advertiser the recipient’s opening time, IP address and email client. That the CNIL should eventually take an interest in it is hardly surprising.

The real subject of the coming months is not legal, it is methodological. Companies that steered their campaigns by open rate will have to start again from clicks, conversions and revenue generated. It is more demanding. It is also distinctly more honest.

To go further, the full recommendation can be consulted on the CNIL website. We also devoted a webinar to the subject on 8 July, with Flore Chatelet, DPO of the company Aporia, whose replay remains available, along with a detailed compliance guide for our users.