Portolano Cavallo reports that organizations have until October 29, 2026, to comply with the Italian Data Protection Authority’s (the “Garante”) guidelines on the use of tracking pixels in email communications (the “Guidelines”). The Garante adopted the Guidelines on April 17, 2026, and provided organizations six months from their publication to comply.
Tracking pixels have become a widespread tool for monitoring user behavior online. They are one-pixel images not directly embedded in an email but hosted on remote servers. Each time a recipient opens the email (whether for the first time or on a subsequent occasion), HTML code embedded in the message automatically triggers a request to the sender’s server, causing the image to be downloaded by the recipient’s email client and stored on their device.
This process allows the sender, or one of its partners, to obtain information about whether a specific user has opened and read the email and may also yield additional data derivable from the recipient’s IP address, such as the type of device used, the time of consultation and the number of subsequent openings of the same email.
Following a series of inspections conducted between October 2025 and February 2026, the Garante found that tracking pixels are used in virtually all cases, serving multiple purposes: ensuring correct email delivery (deliverability), countering spam, measuring audience engagement and campaign performance, personalizing communications, detecting phishing activity and addressing formatting requirements.
Legal Framework and Applicable Rules—Disclosure Obligations
The Garante confirms that the use of tracking pixels involves the storage of information on, and access to information already stored on, a recipient’s terminal device, within the meaning of Article 122 of the Italian Privacy Code (the “Code”), which implements the e-Privacy Directive in Italy.
Tracking pixels are described as particularly invasive tracking tools, primarily because of their hidden nature. Accordingly, the Guidelines emphasize that, in order to be lawful, the use of tracking pixels in emails must be disclosed in advance to recipients, regardless of the purpose of communication or the nature of the sender.
Consistently with the approach taken for cookies, the Garante favors a simplified, layered approach to disclosure. According to the Guidelines, this may be provided in concise form within a data collection form, with a link to more detailed information (including within a cookie policy where relevant), or through multiple channels and formats.
Legal Basis for Processing
Article 122 of the Code imposes a general prohibition on the use of tracking pixels in emails, subject to three exceptions: (a) the recipient’s prior, informed, free, specific and unambiguous consent; (b) cases where the processing is necessary for, or facilitates, the transmission of an electronic communication; or (c) cases where the operations are necessary to provide an online communication service requested by the user.
The Garante indicates that controllers may rely on an exemption from the consent requirement in certain cases, including where tracking pixels are used solely for aggregate statistical counting of email open rates, provided the data is anonymized. According to the Guidelines, this may be achieved by using non-individualized pixels identical for all recipients of the same campaign, and by anonymizing associated technical data such as IP addresses.
Additional exemptions apply where tracking pixels are used to implement security measures relating to user authentication, and in the case of institutional or service messages that the controller is legally obliged to send and for which actual receipt by the addressee is relevant, such as communications concerning phishing threats, contractual changes, data breach notifications or reminders of contractual or regulatory deadlines.
In all other cases, in particular where individual-level measurement of email open rates is used to evaluate and optimize promotional campaigns, adapt content or frequency on the basis of observed behavior or build commercial profiles, prior consent is required.
Where new processing operations commence after the Guidelines enter into force, consent should preferably be collected at the time the email address is obtained, following appropriate disclosure. Where tracking pixels are already in use, data controllers may fulfill their disclosure obligations by including the relevant information in the first available communication or at the first point of discontinuity in the existing relationship with the data subject.
To avoid overlapping consent requests, the Garante accepts that consent to tracking pixels may, in principle, be incorporated into a single consent to receive promotional communications—provided the request is formulated in a neutral manner, free from any element of pressure. Users who have given consent must subsequently be able to withdraw it easily and in a granular manner, either by revoking their consent in full, thereby stopping all future communications, or by withdrawing it solely with respect to tracking pixels while continuing to receive emails without such markers. According to the Guidelines, this may be achieved by including a standardized icon or footer link in each email, directing the user to a dedicated area where they can exercise their rights.
Controllers whose processing operations are already under way at the date the Guidelines enter into force must fulfill their disclosure obligations and implement a granular withdrawal mechanism. In no circumstances may a user who refuses tracking be subjected to any limitation of the service they receive.
Privacy by Design and by Default
The Guidelines call on controllers to adopt privacy by design and by default measures under Article 25 of the General Data Protection Regulation. In particular, the Garante recommends that senders generate a non-sequential, unintelligible identifier for each tracking pixel and associate it with the recipient’s email address in a separate, internal layer of the platform. This would allow open-event counting to occur through the identifier without the email address being included in the technical request generated when the pixel loads, thereby reducing re-identification risk.
The Guidelines follow similar developments elsewhere in Europe. In particular, the French Data Protection Authority (“CNIL”) adopted a recommendation on tracking pixels in emails on March 12, 2026, and later published frequently asked questions (“FAQs”) on July 22, 2026, clarifying how its recommendation applies in practice. Read our blog on the CNIL’s FAQs and Recommendation here.
Read the Garante’s Press Release and the Guidelines, both in Italian.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- California Privacy Protection Agency
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- Digital Services Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- FTC
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Hacker
- Hawaii
- Health Data
- Health Privacy
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code