Privacy & compliance

CNIL Email Tracking Pixel Rules: What Marketers Need to Change in 2026

France’s data protection authority has clarified how its email-pixel recommendation applies to tracked links, older contact databases and marketers that missed the July transition deadline.

This analysis explains public regulatory guidance and product documentation. It is not legal advice.

What the CNIL clarified on July 22

The French data protection authority, the CNIL, published a detailed question-and-answer document on July 22, 2026 to clarify how organizations should implement its April recommendation on tracking pixels in email. The update matters because email platforms often treat open tracking as a default reporting feature, while the CNIL separates permission to receive a message from permission to measure an identifiable recipient’s behavior.

The clarification is not a new Europe-wide email law. It is guidance from the French supervisory authority on the application of French data-protection and tracking rules. Businesses should therefore avoid turning it into a universal claim that every email open pixel everywhere in Europe is automatically unlawful. The practical scope depends on the recipient, the sender, the purpose of the tracking and the applicable law.

For marketers with contacts in France, however, the document is operationally important. It explains the transition for pre-existing databases, distinguishes pixels from tracked links and confirms that organizations cannot rely indefinitely on silence when the required information was never provided.

The July 14 transition deadline for older databases

The CNIL allowed a progressive transition for email addresses collected before the recommendation was published on April 14, 2026. Organizations could continue inserting pixels if they clearly informed recipients within a period that should generally not exceed three months and gave them an easy opportunity to object.

That period ended on July 14, 2026 in the ordinary case. The FAQ states that if the information was not sent by the deadline, the recommendation’s normal rules apply. Where consent is required, the sender should collect it; otherwise, the sender should stop the pixel use that requires consent.

The CNIL recognizes that unusually large databases or deliverability concerns may justify a reasonable extension, but the difficulties must be objectively justified and documented. This is not a blanket extension for teams that simply postponed the work.

A practical action plan for email teams

The right response is not necessarily to disable every measurement overnight. It is to identify which recipients and use cases fall within scope, separate exempt aggregate measurement from individual marketing profiling and document the choices made.

  • Identify contacts based in France and document how location is determined.
  • Inventory open pixels, tracked links, engagement scores, send-time optimization and open-based automations.
  • Separate consent to receive marketing from consent to individual-level tracking where required.
  • Review signup forms, preference centers and email footers for a clear tracking choice and an easy revocation mechanism.
  • Audit promotional messages sent through transactional APIs or automation channels.
  • Decide how contacts with unknown tracking status should be handled and document the default.
  • Preserve evidence of notices, consent timestamps, sources and changes to tracking preferences.
  • Ask qualified privacy counsel to review the implementation when the organization has material French exposure.

What Brevo users can do now

Brevo has introduced per-contact pixel-tracking consent. The feature stores whether a contact has accepted, declined or not answered, together with consent date and source attributes. Users can add a dedicated checkbox to forms, segment contacts by tracking status and place a revocation link in email footers.

Brevo recommends setting unknown contacts to no tracking after the transition point. The platform also provides an API field for transactional sends so consent can be set for recipients programmatically. These controls are useful, but enabling them does not by itself make an organization compliant. The consent language, location logic, record keeping and treatment of mixed-purpose messages still require a business decision.

The development strengthens Brevo’s position for teams that need granular French-contact controls. It also adds setup work: forms, existing contacts, automations, transactional flows and templates all need review.

Read the Brevo review

What this means for other email platforms

The CNIL clarification is not a Brevo-only issue. Mailchimp, MailerLite, Kit, beehiiv, Omnisend, Klaviyo and other platforms commonly use open pixels or engagement events. Buyers should now ask whether a platform can manage tracking permission per contact, disable individual tracking without losing essential delivery data and provide a clear preference-revocation workflow.

Platforms that only offer an account-wide on/off switch may be harder to operate when a business has mixed geographic audiences. MailScouter will treat per-contact tracking controls and documentation quality as a more important comparison factor in future reviews.

The bottom line

The July FAQ removes several convenient assumptions. Tracked links are not simply the same as pixels, B2B permission to send is not permission to track, and organizations that missed the transition communication cannot rely indefinitely on recipient silence.

For businesses marketing to people in France, the immediate task is to map tracking purposes and consent records—not merely update a privacy-policy paragraph. Teams with uncertain exposure should seek legal advice before deciding which measurements can remain active.

Primary sources

Documents checked for this analysis