Italian Garante Guidelines on Tracking Pixels in Emails are Effective October 29
Time 6 Minute Read

Portolano Cavallo reports that organizations have until October 29, 2026, to comply with the Italian Data Protection Authority’s (the “Garante”) guidelines on the use of tracking pixels in email communications (the “Guidelines”). The Garante adopted the Guidelines on April 17, 2026, and provided organizations six months from their publication to comply.

Tracking pixels have become a widespread tool for monitoring user behavior online. They are one-pixel images not directly embedded in an email but hosted on remote servers. Each time a recipient opens the email (whether for the first time or on a subsequent occasion), HTML code embedded in the message automatically triggers a request to the sender’s server, causing the image to be downloaded by the recipient’s email client and stored on their device.

This process allows the sender, or one of its partners, to obtain information about whether a specific user has opened and read the email and may also yield additional data derivable from the recipient’s IP address, such as the type of device used, the time of consultation and the number of subsequent openings of the same email.

Following a series of inspections conducted between October 2025 and February 2026, the Garante found that tracking pixels are used in virtually all cases, serving multiple purposes: ensuring correct email delivery (deliverability), countering spam, measuring audience engagement and campaign performance, personalizing communications, detecting phishing activity and addressing formatting requirements.

Legal Framework and Applicable Rules—Disclosure Obligations

The Garante confirms that the use of tracking pixels involves the storage of information on, and access to information already stored on, a recipient’s terminal device, within the meaning of Article 122 of the Italian Privacy Code (the “Code”), which implements the e-Privacy Directive in Italy.

Tracking pixels are described as particularly invasive tracking tools, primarily because of their hidden nature. Accordingly, the Guidelines emphasize that, in order to be lawful, the use of tracking pixels in emails must be disclosed in advance to recipients, regardless of the purpose of communication or the nature of the sender.

Consistently with the approach taken for cookies, the Garante favors a simplified, layered approach to disclosure. According to the Guidelines, this may be provided in concise form within a data collection form, with a link to more detailed information (including within a cookie policy where relevant), or through multiple channels and formats.

Legal Basis for Processing

Article 122 of the Code imposes a general prohibition on the use of tracking pixels in emails, subject to three exceptions: (a) the recipient’s prior, informed, free, specific and unambiguous consent; (b) cases where the processing is necessary for, or facilitates, the transmission of an electronic communication; or (c) cases where the operations are necessary to provide an online communication service requested by the user.

The Garante indicates that controllers may rely on an exemption from the consent requirement in certain cases, including where tracking pixels are used solely for aggregate statistical counting of email open rates, provided the data is anonymized. According to the Guidelines, this may be achieved by using non-individualized pixels identical for all recipients of the same campaign, and by anonymizing associated technical data such as IP addresses.

Additional exemptions apply where tracking pixels are used to implement security measures relating to user authentication, and in the case of institutional or service messages that the controller is legally obliged to send and for which actual receipt by the addressee is relevant, such as communications concerning phishing threats, contractual changes, data breach notifications or reminders of contractual or regulatory deadlines.

In all other cases, in particular where individual-level measurement of email open rates is used to evaluate and optimize promotional campaigns, adapt content or frequency on the basis of observed behavior or build commercial profiles, prior consent is required.

Where new processing operations commence after the Guidelines enter into force, consent should preferably be collected at the time the email address is obtained, following appropriate disclosure. Where tracking pixels are already in use, data controllers may fulfill their disclosure obligations by including the relevant information in the first available communication or at the first point of discontinuity in the existing relationship with the data subject.

To avoid overlapping consent requests, the Garante accepts that consent to tracking pixels may, in principle, be incorporated into a single consent to receive promotional communications—provided the request is formulated in a neutral manner, free from any element of pressure. Users who have given consent must subsequently be able to withdraw it easily and in a granular manner, either by revoking their consent in full, thereby stopping all future communications, or by withdrawing it solely with respect to tracking pixels while continuing to receive emails without such markers. According to the Guidelines, this may be achieved by including a standardized icon or footer link in each email, directing the user to a dedicated area where they can exercise their rights.

Controllers whose processing operations are already under way at the date the Guidelines enter into force must fulfill their disclosure obligations and implement a granular withdrawal mechanism. In no circumstances may a user who refuses tracking be subjected to any limitation of the service they receive.

Privacy by Design and by Default

The Guidelines call on controllers to adopt privacy by design and by default measures under Article 25 of the General Data Protection Regulation. In particular, the Garante recommends that senders generate a non-sequential, unintelligible identifier for each tracking pixel and associate it with the recipient’s email address in a separate, internal layer of the platform. This would allow open-event counting to occur through the identifier without the email address being included in the technical request generated when the pixel loads, thereby reducing re-identification risk.

The Guidelines follow similar developments elsewhere in Europe. In particular, the French Data Protection Authority (“CNIL”) adopted a recommendation on tracking pixels in emails on March 12, 2026, and later published frequently asked questions (“FAQs”) on July 22, 2026, clarifying how its recommendation applies in practice. Read our blog on the CNIL’s FAQs and Recommendation here.

Read the Garante’s Press Release and the Guidelines, both in Italian.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page