For years, the tracking pixel embedded in marketing emails operated in a regulatory grey area. While cookie banners governed tracking technologies on websites, the invisible pixel inside an email largely escaped scrutiny. That is now changing.
France’s CNIL has now issued specific guidance on tracking pixels in emails, following a public consultation in 2025. For organisations using Salesforce Marketing Cloud or similar platforms, this has direct implications for how email tracking should be configured going forward.
This article provides an overview of the latest guidance on email open tracking and consent in Europe. For a deeper dive, download our eBook, which translates the regulatory requirements into practical actions for marketing
What has changed?
France’s CNIL and Italy’s Garante now classify email open-tracking pixels as cookie-equivalent technologies.
Using these pixels for marketing, profiling, or campaign performance measurement requires the recipient’s prior consent.
Who is affected?
Any organisation emailing recipients located in France or Italy is affected, regardless of where the organisation itself is headquartered.
The obligation follows the recipient’s location, not the sender’s. Recipients in France fall within CNIL’s guidance, while recipients in Italy fall within the Garante’s provisions. Recipients elsewhere are not currently covered by these two specific rules.
What should organisations do?
Continue sending transactional and marketing emails as normal. Consent governs tracking, not delivery.
Enable the tracking pixel only for recipients who have provided consent. Organisations may still have a valid basis to send an email while needing separate, distinct consent to track it.
CNIL’s recommendation gives organisations a limited window to inform existing subscribers and put a compliant opt-out in place before enforcement expectations tighten.
The regulatory basis for the change
A tracking pixel is a small, invisible image embedded in the body of an email. When a recipient opens the message, that image loads from a remote server, registering the open event.
Click tracking operates on a similar principle by routing links through a redirect that logs the interaction before forwarding the recipient to the destination URL.
CNIL’s position, aligned with European Data Protection Board guidance, is that loading a pixel means reading information from the recipient’s device. This triggers the same consent standard traditionally associated with cookies.
Sending and tracking are governed separately
The key point is that the guidance regulates tracking, not email delivery.
Transactional messages, service notifications, and marketing emails to properly opted-in subscribers can continue uninterrupted. What changes is whether the tracking pixel fires on that send.
A valid basis to send an email does not automatically provide a valid basis to track it.
Scope and practical implementation challenges
The rules apply based on the recipient’s location. However, an email address alone does not reliably indicate where a recipient is located.
This makes selective, geography-based tracking rules difficult to implement and maintain at scale. In practice, many organisations may find it more manageable to adopt a single, audience-wide consent policy for email tracking.
What this means for engagement reporting
Once tracking is limited to a consented subset of the audience, open and click rates will be calculated against a smaller pool of tracked sends.
This is an expected consequence of the change, not necessarily an indication of declining engagement.
Reporting should compare tracked sends against tracked sends over time, rather than assuming continuity with historical rates based on universal tracking.
Open rate has already become less reliable because of mechanisms such as Apple Mail Privacy Protection. This reinforces the case for prioritising click-through rate, conversions, and downstream engagement metrics.
Getting compliance right
Knowing that this change is coming is only the first step. The harder part is determining which current tracking uses require consent, which may be exempt, and how consent should be collected without disrupting existing sign-up flows.
For Salesforce Marketing Cloud, consent should be modelled in a way that can be enforced automatically at send time.
A detailed compliance guide and marketing team checklist can help teams audit their current setup, handle existing subscribers under CNIL’s transition rules, and update their tracking practices.
Quick checklist
| Action | Why it matters |
| Confirm audience location exposure | Identify whether your database includes recipients in France or Italy. |
| Separate send consent from tracking consent | Keep delivery permissions distinct from tracking permissions. |
| Review open and click tracking configuration | Ensure pixels and redirects only apply where consent exists. |
| Update engagement reporting logic | Compare tracked sends with tracked sends over time. |
| Model consent in Salesforce | Use a contact or subscriber attribute that can be enforced at send time. |
Download the full compliance guide and marketing team checklist here.
How Stellaxius Can Help
Understanding the regulatory change is only the first step. The real challenge lies in translating compliance requirements into scalable marketing operations without disrupting customer experience, reporting, or campaign execution.
At Stellaxius, we help organisations assess the impact of evolving privacy and consent requirements across their Salesforce Marketing Cloud ecosystem and customer data models. Our team can support you in:
- Assessing your current email tracking practices against the latest guidance from CNIL and Garante.
- Designing consent management models that separate marketing permissions from tracking permissions.
- Implementing consent-based tracking controls in Salesforce Marketing Cloud.
- Reviewing reporting frameworks and KPIs to ensure performance measurement remains meaningful as tracking becomes more restricted.
- Creating scalable governance processes that support both compliance and marketing effectiveness.
Ready to Review Your Setup?
Whether you’re evaluating the impact of these changes or looking to update your Salesforce marketing architecture, our team can help you identify risks, define a compliant approach, and implement it effectively.
Contact Stellaxius to discuss your email tracking and consent strategy.
This article provides a general overview of current regulatory guidance and should not be construed as legal advice. Organisations should consult qualified legal counsel to assess their specific compliance obligations.

I'm a Marketing Automation Consultant specialising in Salesforce Marketing Cloud Engagement and Data Cloud. I help organisations design and optimise data-driven customer journeys, marketing operations, and engagement strategies across multiple channels.