Following a recommendation adopted on March 12 and published on April 14, the CNIL has mandated that online services obtain user consent before deploying tracking pixels in email marketing. This regulatory shift mirrors existing cookie guidelines, treating tracking pixels as tools that require explicit permission.

While retroactive consent was not required, the CNIL gave companies a three-month grace period to notify their users and update their practices. This led to a surge of notifications from various sectors—including banks, e-commerce, media, and transport services—ahead of the July 14 compliance deadline.

Tracking pixels are single-pixel invisible images hosted on remote servers. When a recipient opens an email, the image is requested from the server, allowing the sender to track open rates and build marketing profiles via server logs. Users can protect their privacy by configuring their email clients to block the automatic display of remote images.