Email Open Tracking Pixels Now Need Consent in France and Italy: What Marketers Need to Know
TL;DR
France’s CNIL and Italy’s Garante have both ruled that including an open tracking pixel in emails for marketing purposes requires explicit, separate consent from the recipient, the same standard already applied to website cookies.
This applies to any brand sending emails to recipients located in France or Italy, regardless of where the sending company is based.
France’s transitional window closed on July 14, 2026. Italy’s runs until October 28, 2026. If you send to either market and haven’t acted, the time to move is now.
MoEngage has built a native solution that handles consent-based pixel suppression automatically, so your teams stay compliant without rebuilding your email program from scratch.
What Changed, and Why It Isn’t a Surprise
France and Italy haven’t passed new laws; that’s the part that often gets misread. The CNIL and Italy’s Garante are clarifying that the consent obligation was already embedded in existing EU law, specifically the ePrivacy Directive, which each country has implemented through its own national legislation. But adherence to this obligation for email tracking pixels had been patchy across the industry, much like cookie consent in its early years, before enforcement brought it into mainstream practice.
So what exactly changed? For years, tracking email opens via invisible 1×1 image pixels has been standard practice across CRM and email marketing platforms. These pixels fetch a tiny image from a remote server the moment an email is opened, registering data like the time of open, the device used, and the recipient’s approximate location. It’s the mechanism behind every open rate, engagement score, and send-time optimization model in your email program.
Both authorities have now published formal guidance making their position explicit: including a tracking pixel in an email is legally equivalent to what a cookie does on a website. And just like a cookie, it now needs prior consent for most marketing purposes.
In plain terms: the fact that someone opted into your mailing list does not permit you to track whether they open your emails.
That requires a separate, specific consent.
The Regulatory Breakdown
France: CNIL
France’s Commission Nationale de l’Informatique et des Libertés adopted its recommendation on March 12, 2026, and published it on April 14, 2026. The CNIL is explicit on three points that marketers need to internalize:
Consent must be separate. Marketing email consent and open tracking pixel consent are two distinct consents. A recipient can continue to receive your emails while opting out of being tracked. These are independent choices, and your platform and consent flows need to reflect that.
Inactivity counts as refusal. If a recipient doesn’t respond to a consent request, that silence cannot be treated as agreement. The absence of a positive signal is non-consent.
Pre-ticked opt-ins are invalid. You cannot default recipients into tracking consent. The consent must be actively given.
Italy: Garante
Italy’s Garante per la Protezione dei Dati Personali adopted Provision No. 284 on April 17, 2026, and published it in the Official Gazette on April 29, 2026. The rules closely mirror France’s, with one key practical difference: the Garante allows tracking consent to be collected alongside marketing email consent in a single request, provided the language is neutral and non-coercive.
There’s a critical caveat, though. Withdrawal must be granular. A recipient must be able to opt out of open tracking while
continuing to receive emails. The two must stay separable.
Who Is In Scope
Both regulations apply based on where the recipient is located when the email is opened. Nationality and company headquarters don’t matter. A brand based in Singapore sending to a recipient located in Paris is in scope. A French brand sending to a recipient located in New York is not.
Key Deadlines at a Glance
|
Regulation |
Published |
Scope |
Transitional deadline |
New contacts |
|---|---|---|---|---|
| CNIL (France) | April 14, 2026 | Recipients located in France | July 14, 2026. Existing contacts must have been informed and allowed to object. | Compliant consent required immediately from April 14, 2026 |
| Garante (Italy) | April 29, 2026 (Official Gazette) | Recipients located in Italy | October 28, 2026. Existing contacts must be informed and allowed to object. | Compliant consent required immediately from April 29, 2026 |
If you missed the French deadline: the pragmatic path is to suppress email open tracking for all French contacts who have not actively consented, and begin notifying them of your tracking practices so they have a clear opportunity to opt in going forward. Taking action now, even after the deadline, demonstrates good faith and is a substantially better position than continuing to track without a lawful basis.
For Italy: you still have a runway, but October 28 is closer than it looks. The steps below apply now.
What Requires Consent vs. What Doesn’t
Not every use of a tracking pixel requires consent. But the exempt uses are narrow, and most of what email marketers rely on day-to-day falls squarely into the consent-required category.
Requires Consent
- Measuring open rates for campaign performance reporting
- Behavioral triggers based on opens, such as abandoned cart sequences, win-back campaigns, and re-engagement flows
- Open-based segmentation, or grouping contacts by whether they opened specific campaigns
- Personalization based on open behavior, such as send-time optimization and content adaptation
Exempt (Narrow)
- Basic deliverability monitoring: confirming that emails reach inboxes at a technical level, with no data stored against individual contacts
- Identifying completely inactive contacts for database hygiene, provided the data used is minimal and not retained for any other purpose
MoEngage’s solution takes a straightforward approach: when a recipient hasn’t consented, the tracking pixel is suppressed entirely. This keeps implementation clean and compliance clear.
The Upside: Why This Could Improve Your Email Program
Compliance requirements can feel like a net loss: fewer contacts tracked, lower open rates on paper. But there’s a genuine upside worth considering.
Recipients who actively consent to being tracked are self-selecting as engaged. They’ve explicitly indicated they’re comfortable with you monitoring their opens, which by definition makes them a more invested audience. The open data you collect from consented contacts is therefore a cleaner, more reliable signal. You’re measuring people who want to hear from you, not an inflated baseline that blends engaged and disengaged contacts together.
Over time, consent-based open rates are likely to be more meaningful and more useful than what most programs report today. And brands that handle this transparently, giving recipients genuine control over whether they’re tracked, build a small but real trust advantage at a time when inbox privacy is only becoming more important to consumers.
What This Means for Your Email Strategy
What to move away from
- Treating marketing consent as blanket permission to track opens
- Defaulting all contacts to tracked status without an explicit opt-in
- Using open data to trigger automated sequences for contacts who haven’t consented to tracking
- Assuming recipients located outside your company’s home country are out of scope
What to move toward
- Collecting open tracking consent as a separate, explicit preference at the point of sign-up for new contacts located in France and Italy
- Running a re-permission campaign to your existing French and Italian audiences to gather consent retroactively
- Suppressing the tracking pixel for all contacts who have not consented, which means stopping the pixel from firing, not just disabling analytics
- Giving every recipient a clear, easy way to withdraw tracking consent without affecting their email subscription
- Keeping an auditable record of consent state changes at the individual contact level
- Recalculating open rate metrics against your consented audience only, so the numbers your team reports reflect real, lawful signal
How MoEngage Handles This For You
Compliance requirements like these create a real operational challenge: how do you manage consent at scale, across a large and changing audience, without breaking your existing email workflows?
MoEngage has built a native solution that handles this automatically, so your team doesn’t need to rebuild your email program or manage consent suppression manually.
Here’s how it works at a high level:
Country-scoped consent enforcement. You configure which countries the consent requirement applies to: France, Italy, or any market that regulates pixel tracking. For recipients outside those countries, tracking continues as today. You don’t lose open data for your entire global audience; enforcement is scoped precisely to where it’s legally required.
Per-recipient consent attribute. MoEngage introduces a dedicated open tracking consent attribute on each contact profile. This is separate from email subscription status. A contact can be opted out of tracking and still receive your emails normally. The attribute can be updated via data import, SDK, your server-to-server data pipeline, or directly through the consent management page.
Automatic pixel suppression. When a recipient’s consent attribute is set to opted out, or when no consent has been recorded, MoEngage suppresses the tracking pixel before the email is sent. No pixel fires, no open event is recorded. For previously sent emails that a contact re-opens after withdrawing consent, those pixel fires are also dropped.
Consent management link in every email footer. When the feature is turned on, MoEngage automatically adds an open tracking preferences link to every email footer, separate from and in addition to the unsubscribe link. Recipients can use it to opt out of tracking or opt back in at any time. If you manage your own preference center, you can use the link token anywhere in your email template and the auto-injection is suppressed.
Full consent audit trail. Every change to a contact’s open tracking consent, including the new state, the previous state, when it changed, and what triggered it, is logged as a system event on the contact’s profile. If you ever need to demonstrate compliance, the record is there.
For a step-by-step guide to setting this up in your workspace, see Help Doc here.
Your 4-Step Compliance Checklist
Step 1 – Identify your in-scope audience. Pull a list of all contacts located in France and Italy. Remember: location at time of email open, not nationality, is what matters.
Step 2 – Turn on open tracking consent in your workspace. Turn on the MoEngage open tracking consent feature in your email settings and configure it for France and Italy. Set your fallback behavior for contacts with no country data. Full setup instructions at Help Doc here.
Step 3 – Run a re-permission campaign. For existing French and Italian contacts who haven’t been informed yet, send a one-time re-permission email explaining that you use open tracking and giving them an easy way to opt in. Contacts who do not respond will remain opted out by default, and the platform will suppress tracking for them without any additional action needed on your part. This applies to all future opens, including opens of previously sent emails. If a contact opts out, open events from any email they re-open will not be recorded or attributed to them, regardless of when that email was originally sent.
Step 4 – Update your new contact flows. Ensure that any sign-up form, landing page, or CRM integration that adds French or Italian contacts to your MoEngage workspace also captures their open tracking consent preference from day one. Once collected, pass that consent value into MoEngage using any of the standard data ingestion mechanisms, such as the MoEngage SDK, the Server-to-Server Data API, or User Import, so the platform can act on it immediately. This ensures no new contacts are added without a consent record in place.
What Doesn’t Change, and What to Expect
Here’s what turning on this feature does and doesn’t affect, so your teams know what to watch for and what to leave alone.
Your existing sends keep working. Your existing campaigns, flows, and event-triggered journeys will continue to send normally. Turning on open tracking consent does not cause any sending failures or errors. For non-consented recipients in regulated countries, the email is delivered as usual. The only difference is that the tracking pixel is not included. Recipients still get the email; you just don’t get the open signal.
What you should expect to change:
Open rates will likely drop. This is expected and correct, not a bug. The open rate you see in campaign analytics will now reflect only the consented portion of your audience. How much it drops depends on what share of your audience is in regulated countries and how many of those contacts have actively opted in to tracking. Over time, as more contacts go through your re-permission campaign and new sign-up flows capture consent, this number should recover.
Fewer contacts may enter open-triggered flows. If you have flows or event-triggered campaigns where “Email Opened” is used as an entry condition or trigger, non-consented recipients will not generate open events and therefore will not enter those flows. You may want to review any journeys that rely heavily on email open as a trigger and consider whether an alternative, such as email clicked, is a more reliable condition for your audience going forward.
The Bigger Picture
France and Italy are the first two European regulators to issue formal, explicit guidance on how existing law applies specifically to email open tracking pixels, but the direction of travel across Europe is clear. The legal framework behind them, the ePrivacy Directive and GDPR, applies in every EU member state. It is reasonable to expect similar guidance and enforcement to emerge in other markets in the future.
Brands that build consent-aware infrastructure now will be significantly better positioned when that happens. Rather than treating each new regulatory development as a one-off project, building a consent management capability into your email program today means you’re ready to extend it to new markets when required, without starting from scratch each time.
MoEngage’s solution has been built with exactly this in mind. It’s built to adapt, so as the regulatory landscape evolves, your program can keep pace through configuration rather than rebuilding.
Open tracking isn’t going away. But the era of tracking every recipient without asking is giving way to a more transparent, consent-based model, and the brands that move early will be better placed commercially, not just legally.
The good news is that setting this up correctly in MoEngage takes a matter of hours, not weeks. Get started at Help Doc here, and reach out to your Customer Success Manager if you need help mapping this to your specific program.
MoEngage is not a law firm, and this post does not constitute legal advice. Consult your data protection officer or legal counsel to assess how these requirements apply to your specific program and audience.