<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Is email open tracking illegal in France now?",
"acceptedAnswer": {
"@type": "Answer",
"text": "No — it's legal with consent. CNIL's April 2026 recommendation requires prior consent for email open tracking pixels used for marketing analytics for recipients based in France. Narrow exemptions exist for authentication security and strict deliverability management."
}
},
{
"@type": "Question",
"name": "When did CNIL enforcement of email pixel tracking rules begin?",
"acceptedAnswer": {
"@type": "Answer",
"text": "CNIL published its recommendation on April 14, 2026 and gave a three-month transition period to inform existing recipients. Enforcement is expected to begin after July 14, 2026."
}
},
{
"@type": "Question",
"name": "What is an email tracking pixel?",
"acceptedAnswer": {
"@type": "Answer",
"text": "A transparent 1x1 image embedded in an email's HTML. When the recipient loads images, the pixel pings a server and records data such as timestamp, device type, email client, and IP address — this is how platforms measure email opens."
}
},
{
"@type": "Question",
"name": "How do I make Marketo Engage compliant with CNIL's pixel tracking guidance?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Adobe recommends creating a custom boolean consent field (Email Pixel Tracking), building two email variants (open tracking enabled and disabled), and using a Smart Campaign choice step to send the untracked variant to anyone whose consent field is false."
}
},
{
"@type": "Question",
"name": "What are the penalties for violating CNIL tracking rules?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Violations fall under Article 82 of the French Data Protection Act — the same provision CNIL used to fine Google €150 million and Facebook €60 million for cookie consent failures. Sanctions scale with severity and company size."
}
},
{
"@type": "Question",
"name": "Does CNIL's email tracking guidance affect senders outside France?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Yes — it applies to any entity sending emails to recipients based in France, regardless of where the sender is located. Italy's Garante has issued similar guidance, and the same ePrivacy principles apply across the EU."
}
}
]
}
</script>If you send marketing emails to anyone in France, your open rates just became a legal question.
Here’s the short answer up front: on April 14, 2026, France’s data protection authority (CNIL) published a formal recommendation requiring prior consent for email open tracking pixels used for marketing analytics. The transition period ended July 14, 2026 — enforcement can begin any time now. If your ESP tracks opens by default (almost all of them do) and you have French subscribers, you need consent, an opt-out path, or tracking turned off for that audience.
Open tracking has been the default in email marketing for two decades. Nobody asked permission because nobody thought they had to. That era is over — at least for France, and probably soon for the rest of the EU. Here’s everything you need to know.
What Did CNIL Actually Announce?
CNIL published a recommendation (adopted March 12, 2026, published April 14, 2026) clarifying that under Article 82 of the French Data Protection Act, email tracking pixels require the recipient’s prior consent unless the tracking is strictly necessary to deliver the email or a service the recipient requested.
This isn’t a new law. It’s the regulator spelling out how existing French ePrivacy rules — the same legal basis behind cookie consent banners — apply to the invisible 1×1 pixel your email platform drops into every send. Cookies needed consent; now the pixel in your newsletter does too.
The recommendation applies to any entity sending emails to subscribers based in France. Not just French companies — anyone with French recipients on their list.
What Is an Email Tracking Pixel?
An email tracking pixel is a tiny transparent image (1×1 pixel) embedded in an email’s HTML. When the recipient’s email client loads images, the pixel pings a server and logs a timestamp, device type, email client, and often an IP address — which is how your platform knows the email was “opened.”
Every open rate you’ve ever reported came from one of these. So did most of your automation triggers: re-engagement flows, “opened but didn’t click” segments, send-time optimization, engagement scoring. That’s why this guidance matters — it’s not about one metric, it’s about the data layer under half your lifecycle marketing.
When Do You Need Consent (and When Don’t You)?
Consent is required when pixels are used for marketing analytics — measuring campaign performance, optimizing open rates, building recipient profiles, or targeting people across other channels. Consent is NOT required when tracking is strictly limited to deliverability hygiene or authentication security.
Consent required:
- Analyzing open rates to measure and optimize campaign performance
- Building recipient profiles based on preferences and interests
- Targeting recipients outside email (websites, apps, other channels) based on open behavior
- Fraud detection and analytics that go beyond strict necessity
No consent needed (narrow exemptions):
- Pixels that help secure user authentication
- Individual open tracking strictly limited to deliverability — adjusting send frequency or cleaning inactive recipients from your database
Read that second list carefully. The deliverability exemption is narrow. If the same open data feeds your engagement scoring or campaign reports, you’re back in consent territory. You can’t label marketing analytics “deliverability” and call it a day — regulators have seen that movie.
What Counts as Valid Consent?
Consent must be prior, specific, separate from your general email opt-in, granular by purpose, easy to withdraw, and provable. A line buried in your privacy policy doesn’t count. Silence doesn’t count either — CNIL says recipient inactivity should be treated as refusal.
The practical requirements:
- Collect consent when you collect the email address — a checkbox or preference in your signup form, separate from the subscribe consent itself
- Explain each tracking purpose in plain language, with a short first layer and detailed second layer
- Let people consent to purposes separately (or grouped logically)
- Include an easy withdrawal link in every email, just like your unsubscribe link
- Keep proof of consent — a contract clause saying a third party collected it for you is not sufficient on its own
- If someone ignores your consent request, that’s a no. Good practice per CNIL: don’t re-ask for six months
What Was the July 14, 2026 Deadline?
For contacts collected before April 14, 2026, CNIL gave a three-month transition window: senders had until July 14, 2026 to inform existing recipients about pixel tracking, its purposes, and their right to object. For new contacts added after April 14, there was no grace period — compliant consent from day one.
That window is closed. CNIL is expected to begin enforcement after July 14, 2026 — which means as of now, “we didn’t know” is not a position you want to be in. CNIL has history here: it fined Google €150 million and Facebook €60 million under the same Article 82 for cookie consent violations. Tracking pixels sit on identical legal footing.
Does This Affect You If You’re Not in France?
Yes, if anyone on your list is based in France. And even if nobody is, this is the direction of travel for the entire EU.
EU data protection authorities operate as a network and routinely borrow each other’s reasoning. Italy’s Garante has already issued similar guidance on email tracking pixels. The underlying ePrivacy and GDPR principles are the same in Germany, the Netherlands, Spain, and every other member state — CNIL just moved first with specifics. Building consent-based tracking now means you’re done when the next regulator follows.
The smarter takeaway for marketers: open rates were already dying. Apple Mail Privacy Protection has been inflating opens since 2021. CNIL is one more reason to shift your success metrics to clicks, conversions, and revenue — signals that are both more reliable and less regulated.
How Do You Comply in Marketo Engage? (Step-by-Step)
Adobe’s recommended pattern: store consent in a custom boolean field, build two variants of each email (tracking on / tracking off), and use a Smart Campaign choice step to route each person to the right variant.
Adobe published an official implementation guide. Here’s the build:
Step 1 — Create a consent field. Admin → Field Management → New Custom Field. Object: Person. Type: Boolean. Name it “Email Pixel Tracking.”
Step 2 — Populate it. Load consent status via API sync or CSV import. Going forward, capture it directly on your forms so people opt in or out of open tracking at signup.
Step 3 — Build two email variants. Email One: standard, open tracking enabled (the default). Email Two: a clone with open tracking disabled — in Email Designer, the “Disable open tracking” checkbox lives in the Details tab of the Summary pane; in the legacy editor, it’s under Email Settings.
Step 4 — Route with a Smart Campaign. Add a Send Email flow step with a choice: if Email Pixel Tracking is false, send Email Two (untracked). Default choice: Email One (tracked).
Result: consented recipients get the tracked email, everyone else gets the pixel-free version, and your reporting stays intact for the audience that said yes.
Not on Marketo? The pattern translates to any platform: a consent field, a tracking-disabled send path, and logic that routes on consent. Brevo, HubSpot, and other ESPs have shipped their own CNIL controls — check your platform’s docs.
What Should You Do This Week?
Audit, segment, and ship a consent flow. In that order.
- Find your French subscribers (country field, IP data, .fr domains — whatever you have)
- Check whether your ESP tracks opens by default on those sends (it does)
- Add pixel-tracking consent to your signup forms as a separate, unticked choice
- Build the untracked email path for non-consenting recipients
- Add a tracking opt-out link to your email footer alongside unsubscribe
- Document your consent records — you need to prove it, not just claim it
- Start migrating your KPIs from opens to clicks and conversions regardless
FAQ: CNIL Email Tracking Rules
Is email open tracking illegal in France now? No — it’s legal with consent. What’s no longer allowed is tracking opens for marketing analytics without prior consent from recipients based in France.
When did CNIL enforcement start? The transition period for informing existing contacts ended July 14, 2026. CNIL is expected to conduct enforcement activities after that date.
Do I need consent for click tracking too? The recommendation targets open tracking pixels specifically. Click tracking raises its own ePrivacy questions, but clicks are an intentional user action — most compliance teams treat them differently. Ask your counsel; don’t assume.
What are the penalties for non-compliance? Article 82 violations have real teeth: CNIL fined Google €150M and Facebook €60M under the same provision for cookie consent failures. Sanctions scale with severity and company size.
Can I just disable open tracking for my whole list? Yes, and for some senders that’s the simplest fix — no pixel, no consent problem. You lose open data but keep clicks and conversions, which are better metrics anyway.
Does this apply to B2B emails? CNIL’s recommendation covers email recipients in France; it doesn’t carve out B2B. Assume it applies unless your counsel says otherwise.
What about existing subscribers who never consented? You were required to inform them about pixel tracking and their right to object by July 14, 2026. If you haven’t, either get consent now or send them untracked emails.


Leave a Reply