On July 22, 2026, the French Data Protection Authority (“CNIL”) published frequently asked questions (“FAQs”) on its recommendation regarding the use of tracking pixels in emails (the “Recommendation”). The Recommendation explains how Article 82 of the French Data Protection Act applies to tracking pixels in emails and aims to help organizations that use tracking pixels in emails to analyze and understand their role and obligations.
Key Takeaways from the Recommendation
The Recommendation was adopted on March 12, 2026, and became applicable once published in the French Official Journal on April 14, 2026.
In the Recommendation, the CNIL clarifies that tracking pixels in emails generally require the recipient’s prior consent unless they fall within a limited exemption, including where they are used exclusively for security measures linked to user authentication or, in certain cases, for deliverability purposes. The CNIL states that consent is required for uses such as measuring and optimizing campaign performance through personalization or frequency adjustment, creating recipient profiles for targeting in other contexts, detecting suspected fraud and deliverability measurement that does not satisfy the conditions of the exemption.
The Recommendation also makes clear that the consent regime for tracking pixels is separate from the rules governing the sending of the email itself. As a result, a tracking pixel may require consent even where the underlying email does not.
In practical terms, the CNIL recommends collecting consent when the relevant email address is collected, with clear information about the purposes of the pixels and the scope of the choice. The CNIL also recommends that refusal be as easy as acceptance and that users be able to withdraw consent at any time, including through a link in the footer of each email. If consent cannot be collected when the email address is collected, the Recommendation contemplates requesting it later through an email that does not itself contain a consent-requiring tracking device.
Key Takeaways from the FAQs
The FAQs provide additional guidance on how the Recommendation applies in practice. Among other points, the CNIL explains that deliverability-only pixels are exempt only if they are limited to what is strictly necessary and, in principle, the only data needed for that purpose is the date of the last opening (unless the sender can document a need for more). The FAQs also state that collecting additional data, such as an Internet Protocol address or user-agent, beyond what is strictly necessary for deliverability prevents reliance on the exemption, even if that data is later anonymized or deleted.
The FAQs further clarify that a single pixel may pursue both exempt and non-exempt purposes, but the non-exempt purposes may be pursued only after valid consent has been obtained. They also emphasize that pixels cannot be placed without a defined purpose and cannot be deployed merely in anticipation of possible future consent.
In addition, the FAQs confirm that the Recommendation applies broadly to the use of trackers in emails regardless of the type of sender or recipient, although whether consent is required depends on the circumstances, including the purposes pursued and the category of email involved. The FAQs also note that for deliverability purposes, whether an email can benefit from the exemption depends in part on whether it was expressly requested by the user or is tied to a requested service.
Timing
The FAQs are particularly notable because they address timing for email addresses collected before the Recommendation was published. For those email addresses, the Recommendation allowed organizations to continue using pixels during a transition period provided they sent clear and accessible information to recipients within a period that should not, in principle, exceed three months from publication and gave recipients the ability to object for future emails. That period expired on July 14, 2026.
The FAQs indicate, however, that a reasonable extension may be possible where the volume of the database or deliverability issues made compliance within that period impracticable, provided those difficulties are objectively justified and documented. The FAQs also state that if the required notice was not sent by July 14, 2026, and no justified extension applies, organizations must apply the Recommendation in full, including obtaining consent where required, or stop using pixels that require consent.
The FAQs further clarify that where users whose email addresses were collected before April 14, 2026, were informed of their right to object in accordance with the Recommendation, organizations may continue to rely on the absence of an objection for later emails, so long as the conditions under which those emails are sent remain unchanged and no new consent is otherwise required.
Review the Recommendation in French and in English and the CNIL’s Press Release here. Read the FAQs.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code