Smartphone with a newsletter sign-up form

Are You Tracking Newsletter Conversions? This Concerns You

For years, the open rate of email communications has been treated as one of the most important numbers in marketing. Every mainstream email platform reports it, teams optimize around it, and almost nobody stops to ask how it is measured. The answer is a tracking pixel: a tiny, usually invisible image loaded from a remote server the moment a recipient opens a message, quietly reporting back that the email was read, when, and often on what device. These tools are so ubiquitous that, if you run a newsletter, I would bet, without having seen it, that it has one.

Your own company may have already gotten a preview of what comes next. Over the past weeks, several email service providers have started sending their customers notices about "changes to email tracking." If one of those notices landed in your inbox and you were not quite sure why, here is the short version: two European regulators have turned the magnifying glass on this.

Two Regulators, Same Direction

The push has come from two authorities working through their own national processes and arriving at similar conclusions. In France, the CNIL adopted a Recommendation on tracking pixels in emails (Délibération n° 2026-042). In Italy, the Garante adopted its Guidelines by decision n. 284 of 17 April 2026.

Both authorities reach the same position: inserting a tracking pixel into an email is a reading or writing operation on the recipient's device, so it requires the recipient's prior consent unless a narrow exemption applies. Purely technical or security uses, and aggregate, anonymized open-counts that do not single out an individual, can fall outside the consent requirement. Measuring individual opens and clicks to optimize campaigns, build profiles, or target people across other channels does not.

In simpler words, if a user is ticking a box that says “I consent to receiving email communications”, that does not necessarily authorize the use of tracking pixels to measure conversions or insert any other marketing tracking technology, because those are separate purposes requiring separate, specific wording.

Moreover, a user should be able to withdraw consent for tracking without this automatically meaning withdrawal of consent to receive the newsletter itself. That means the link that usually sits in the footer of a newsletter, which today typically just unsubscribes the reader, now needs to offer both options: stop receiving the emails, or keep receiving them without the tracking. 

The two authorities differ in the fine detail of how consent should be presented, and those differences matter to specialists advising in each market. For a general audience the more useful takeaway is the convergence: both require that recipients be informed, that consent be genuine and specific rather than buried, and that people be able to withdraw it easily and selectively. 

This Is Not Only a French and Italian Problem

It would be a mistake to read this as two national quirks. The requirement these authorities are enforcing does not originate in French or Italian law. It comes from the ePrivacy Directive (Article 5 para. 3), which every EU and EEA country has transposed into its own national law. The GDPR then applies on top, to any personal data the pixel actually collects. In other words, the underlying obligation already exists across the bloc. The French and Italian authorities are simply the first to spell out how it applies to email pixels and to explicitly announce that they will enforce it with specific grace periods, but nothing prevents another authority from publishing similar guidance, and a business operating across several European markets could consider taking a unified approach rather than by treating this as a country-by-country fire drill.

The Transition Period

Both authorities recognize that existing programs cannot be rebuilt overnight, so both build in a grace period rather than demanding an immediate stop.

In practice, both follows the same logic: existing tracking may continue for now regarding recipients already on file but must be told about it as soon as possible with a clear message, and they must be given a real, working way to opt out of the tracking specifically, going forward. The details between the authorities vary, but that is the shared idea.

That leniency, however, is reserved for people already on your list. Anyone added after the guidance took effect falls outside the grace period entirely: for new sign-ups, both authorities expect consent to be collected upfront, ideally at the moment the email address is gathered, with no transitional runway at all.

The dates, however, differ. The CNIL's Recommendation provides that, for email addresses already on file, tracking without consent should not continue for more than three months from publication. Since the Recommendation was published on 14 April 2026, that puts the deadline at 14 July 2026. The Garante's Guidelines were published in the Official Journal on 29 April 2026 and allow six months from that date for general compliance, landing on 29 October 2026.

Where This Leaves You

The deadlines are close. If your company sends email communications to recipients in France or Italy, the first and most pressing task is to send a compliant information notice to your existing subscribers, explaining the tracking and their options before the respective deadline passes.

At the same time, start rethinking the consent journey itself, and everything that comes with it, to make sure that new subscribers are engaged compliantly since the beginning. Handled with care, this can be brought into compliance while sacrificing the smallest possible amount of conversions.

If you would like a clear read on how these requirements apply to your own email program, and a practical plan to bring it into line, we are happy to help.



No comments


« Previous post Next post »