France and Italy Tighten Email Tracking Rules: How to Adapt Your Compliance Program
Sales and marketing teams rely on email open and click-through rates to gauge the efficacy of their efforts. Use of tiny tracking pixels and customized tracking links give marketers a host of valuable info like when a message was opened and whether the recipient used the message to access additional web content. Such feedback helps teams measure campaign performance, prioritize follow-ups, personalize future communications, and gauge overall customer engagement.
Now European privacy regulators are taking a harder look at the actual mechanics behind these routine metrics. This past spring, authorities in France and Italy issued new guidance to clarify when email tracking requires explicit recipient consent. The changes create compliance challenges that extend well beyond the marketing department.
Organizations that do business in either country need to review not only their email campaigns, but also the tracking capabilities embedded in their CRM platforms, sales tools, customer-service systems, and other applications that routinely send tracked messages.
What's changed in France and Italy?
France's data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), published its final recommendation on email tracking pixels in April of this year. Rather than crafting new privacy law, the CNIL opted to clarify how existing French rules implementing the EU ePrivacy Directive (often called the "Cookie Law") apply when organizations place tracking technology in their email.
The CNIL now insists that invisible email tracking can't be treated as an automatic feature of an email platform. User consent is required before the use of email pixels for measuring individual engagement, personalization, or marketing performance unless a specific exemption applies. For email addresses collected before April 14, 2026, the CNIL allowed a three-month transition period in which organizations could provide clear notice and an opportunity to object. That period expired in July.
Meanwhile, Italy's Garante per la Protezione dei Dati Personali issued similar guidance in April, ruling that tracking pixels subject to Article 122 of Italy's Privacy Code require prior, free, specific, and informed consent. Organizations have until October to fully adapt their practices.
Bottom line: France and Italy now treat tracking pixels the same way they treat cookies; if it can be used to identify a person, it requires their permission. Both nations clarified that consent to receive marketing emails and consent to track whether that email had been opened are now two distinct actions that need to be managed separately. Users must also have an easy way to opt-out of pixel-based tracking without unsubscribing from emails completely. In response, organizations need to understand where and why such tracking is being used, provide appropriate transparency, solicit appropriate user consent, and be able to demonstrate that their tracking practices comply with the new rules.
Do these requirements apply only to marketing emails?
No, and this might be the most important compliance point for organizations to grasp.
France's CNIL explicitly states that the rules apply regardless of the sender or the recipient. That can include customers, prospects, employees, partners, etc. The focus is squarely on the use of the tracker rather than on the categorization or source of the message.
Italy takes a similarly broad stance. Its guidelines identify newsletters and direct marketing emails, as well as transactional, automated, and service-related messages. The Garante says recipients must be informed about tracking pixels regardless of the purpose of the communication or the type of sender.
That means organizations need to keep a sharp lookout beyond Marketing. Sales reps may be tracking one-to-one outreach. Customer-success teams may monitor whether clients open messages. Support systems may send automated emails containing tracking technology. HR or other departments may also be using tools with tracking enabled. The existence of tracking capabilities as well as the purpose of the tracker and the circumstances surrounding the message are what matter most under the new guidelines.
Bottom line: Email-tracking compliance can't be treated solely as a marketing issue under the latest rule changes. Sales, customer support, customer success, HR, and other lines of business may use platforms that track opens or interactions. To stay compliant, organizations need to inventory email tracking across the whole business rather than assuming that removing pixels from newsletters and promotional campaigns solves the problem.
When is consent required? Are there legitimate exemptions?
Both French and Italian regulators recognize circumstances in which tracking may be permissible without consent, but those exemptions are narrower than the traditional excuse of simply dubbing an email as "transactional." If tracking features are to be used to measure engagement, optimize marketing, personalize communications, or build behavioral profiles, prior consent is a must.
The CNIL, for its part, recognizes limited exemptions to the rules related to deliverability and security. When the email relates to a service explicitly requested by the recipient and the tracking is strictly limited to the delivery of that service, the messaging is generally exempt. Examples include order confirmations, account alerts, shipping notifications, password resets, invoices, and security notifications. But be warned, adding promotional content to these transactional messages puts them back in the consent-required camp.
Italy identifies similar exceptions, including some security uses, tech functions integral to a requested service, certain legally required communications, and the use of messages to aggregate statistical measurements in a way that does not permit individualized tracking. Individual measurement of opens for campaign optimization, behavioral analysis, or profiling, however, all require consent.
The key here is that consent to receive an email and permission to track interaction with that email are distinctly separate compliance questions. Organizations must document why tracking is necessary and which legal basis or exemption they believe applies in order to be compliant with either country's new rules.
Bottom line: Consent is now necessary when tracking is used to measure an individual's engagement, optimize marketing, personalize communications, or build behavioral profiles. Limited exemptions may apply when tracking is strictly necessary for security, deliverability, or requested services, but organizations need to evaluate and document those exceptions specifically rather than applying them broadly.
What about links for tracking clicks?
Tracking pixels are primarily used to identify when an email has been opened. Click tracking works a little differently, usually by replacing a normal hyperlink with a trackable intermediary link that records the recipient's interaction before redirecting them to the destination. The compliance rules that cover each differ.
The CNIL issued additional guidance in July saying tracking links are not directly covered by its latest email-pixel rules. That does not, however, mean click tracking falls outside privacy rules altogether. The CNIL says tracked links can involve reading or writing information on a user's device, which would fall under Article 82 of France's Data Protection Act. Whether consent is required depends on the tracking link's purpose and whether such tracking is necessary to provide a requested service. For compliance teams, the best approach is to examine both pixel and link-based tracking rather than treating "email tracking" as a single issue.
Bottom line: Message open and click-thru tracking use different technologies and aren't automatically treated the same way under the law. France's pixel recommendation directly addresses open-tracking pixels, while tracked links require their own compliance analysis. Organizations should identify both types of tracking and determine the purpose, data collected, and consent requirements for each.
What should compliance teams do now?
The first step to addressing the new French and Italian rules is figuring out all of the places where tracking actually occurs in your organization. That starts with identifying every system capable of sending external emails, things like marketing automation platforms, CRM systems, sales-engagement apps, help-desk platforms, customer-success tools, and employee email extensions. Compliance teams need to figure out whether open and click tracking are enabled by default, who can activate them, what data they collect, and how that data is ultimately used.
The next step typically involves classifying common email use cases into buckets that include marketing campaigns, prospecting emails, order confirmations, account notifications, support correspondence, security alerts, and one-to-one sales messages. Each of these will likely require subtly different treatment under the rules.
Throughout this exercise, it's important to remember that consent mechanisms need to be connected to technical controls. Recording that a recipient declined tracking on one platform doesn't accomplish much if another department can still send that user a tracked message through a different app.
Finally, policies need owners. You need clear responsibility for email-tracking compliance across the organization. Marketing alone won't solve the compliance issue if sales, support, HR, and other lines of business continue to use separate platforms or plug-ins that independently track recipient activity.
In this context, establishing policy ownership means defining who's responsible for:
- Identifying systems using email tracking
- Deciding when tracking is permitted or requires consent
- Configuring systems appropriately
- Maintaining consent and exemption records
- Training sales, marketing, support, HR and other LOB users
- Periodically checking that teams have not introduced new "rogue" tools or changed system settings
Bottom line: Organizations should inventory email systems, map tracking to specific business purposes, classify email types, document applicable exemptions, and connect consent records to technical controls. Responsibility should also extend across the organization so tracking cannot be unintentionally re-enabled through separate tools or workflows.
How can tech tools ease compliance with the new mandates?
In anticipation of rulings like the most recent in France and Italy (and likely more to come elsewhere), email platform vendors are starting to provide more granular privacy controls focused around tracking. Cloud platform provider HubSpot, for example, now lets recipients disable open and click tracking for individual marketing emails even when tracking remains enabled at the account level. Turning tracking off also removes the tracking pixel from that message.
HubSpot also provides admin controls for one-to-one email tracking. Admins can disable tracking across emails sent through the CRM, conversations inbox, sequences, and supported Gmail and Outlook integrations, preventing users from seeing recipients' open and click information.
Such technical settings are only one part of the compliance picture, however. Organizations still need repeatable governance for identifying privacy requirements, assigning responsibility, recording decisions, documenting evidence, and periodically reviewing whether controls remain effective.
A purpose-built GRC platform such as SimpleRisk brings those compliance pieces together. With it, organizations can translate regulatory requirements into documented controls, assign responsible owners, track remediation activities, retain supporting evidence, test whether controls are working, and monitor identified compliance gaps through resolution.
This turns email-platform settings into what they really should be: manageable compliance requirements.
Bottom line: Technology can disable or limit email tracking, while GRC processes help ensure those settings are applied consistently and remain connected to documented compliance requirements, owners, evidence, and reviews across the entire organization. As authorities worldwide move toward tighter privacy scrutiny and stricter tracking restrictions, combining platform-level controls with structured governance gives organizations a more defensible way to adapt.
Want to learn more? Check out these related posts: