Legal & Compliance

The CNIL’s pixel deadline has passed. Here is where senders now stand

France’s transitional window for email tracking pixels closed on 14 July 2026. Under the CNIL’s recommendation, adopted in March and published on 14 April, senders had three months to inform contacts collected before that date that their email opens were being tracked, and to offer a simple way to object. That window has now expired, and the regulator has said it will verify compliance with the information obligation through its inspection activity, with French legal commentary reporting controls beginning from mid-July. We set out the full framework, and the Italian regime running alongside it, in our analysis of the spring’s pixel rules. This is the follow-up: what the expiry of the deadline actually changes.

Three populations, three positions

Every sender with French recipients now sits in one of three positions, and the difference between them is the whole compliance picture.

Contacts who were informed before 14 July and did not object may continue to be tracked on the opt-out basis the transitional regime provides. The obligation from here is operational: the objection mechanism must keep working, separately from the unsubscribe link, and objections must actually switch the pixel off for that recipient.

Contacts who objected must be suppressed from tracking while continuing to receive mail if they remain subscribed. A combined control that forces a full unsubscribe to escape the pixel does not satisfy the recommendation.

The third position is the uncomfortable one. Senders who did not send the information notice in time cannot rely on the transitional regime at all, because the opt-out arrangement was conditional on informing recipients within the three-month window. For those databases, prior consent is the remaining lawful path for non-exempt tracking. The practical sequence for a sender in this position is to switch off non-exempt pixels first, then notify properly and rebuild on a consent basis. Late but documented is likely a defensible posture. Silent continuation is probably not.

The exemption fine print

The exemptions are narrower than many programmes assume, and the detail matters now that inspections are live. Transactional messages, such as order confirmations and password resets, sit outside the consent requirement. Individual deliverability measurement is also permitted without consent, but only at the strict minimum: the recommendation allows retention of the date of the last open only, without the time, overwritten at each new open. A “deliverability” pixel that feeds open timestamps into engagement scoring, send-time optimisation, or sales alerts is not within the exemption. It is marketing measurement wearing an operational label, and the classification is judged by what the data does, not what the field is called.

For new addresses collected since 14 April, none of the transitional questions arise. Consent is required at the point of collection, and silence counts as refusal.

Platforms have moved. The Garante is next

The major platforms have not waited for enforcement. Klaviyo published guidance in mid-July describing what it has built for the French and Italian rules, and HubSpot wrote to account administrators about the guidance at the start of the month. Senders should confirm what their own ESP has shipped, and in particular whether per-recipient tracking suppression is available and how the objection signal reaches it, because the controller’s obligation is not discharged by a platform feature the sender never configured.

The next date on the wall is Italy’s. The Garante’s Provision 284 gives senders until late October to comply with its own regime, which is more permissive on consent bundling and aggregate statistics but strict on granular withdrawal. Senders who treated 14 July as the finish line should likely treat it instead as the halfway point. Those that haven’t addressed it yet, you are already overdue.

This article is for general informational purposes only and does not constitute legal advice. Regulatory requirements may apply differently depending on your organisation, processing activities, technology and recipients. Senders should review the CNIL and Garante guidance directly and obtain advice from qualified legal counsel before making compliance decisions.

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory