On April 14, 2026, following a public consultation, the French data protection authority (Commission Nationale de l'Informatique et des Libertés, or CNIL) published its recommendation on tracking pixels in emails, as part of its announced priorities for 2026, alongside cross-device consent and consent traceability.
To bring clarity and context, we teamed up with fifty-five for a webinar on the topic, during which we explained the reasoning behind this new recommendation, the potential impacts on business operations, and practical guidance on the actions to take to ensure compliance.
This article covers the key points of the recommendation, including a detailed action plan to help you achieve compliance, as well as a downloadable practical guide, which you can access (no email required) at the end of the article.
What does the CNIL say about tracking pixels in emails?
A tracking pixel is an invisible one-pixel image embedded in an email. When the recipient opens the message, the pixel loads and transmits information to the sender's server (whether the email was opened, at what time, on what type of device, and so on). All of this happens without any action from the recipient.
For the CNIL, this operation amounts to reading information on the recipient's device. As such, it falls under Article 82 of the French Data Protection Act (loi Informatique et Libertés), just like cookies.
Any processing of personal data produced or collected via a tracker (hereinafter 'subsequent processing') must comply with the provisions of the General Data Protection Regulation (GDPR) and the relevant provisions of the French Data Protection Act.
- CNIL, Recommendation on tracking pixels in emails (source: CNIL)
Except in strictly defined cases, the use of tracking pixels in emails therefore requires the recipient's prior consent.
What are the exceptions?
The exceptions recognized by the recommendation cover a few specific cases:
- Security and authentication
- Individual deliverability measurement for emails linked to a service requested by the recipient
- Evidence of compliance with a legal obligation, for transactional emails
Common marketing uses, such as open rate analysis or campaign optimization, are not among them.
The recommendation also clarifies how responsibilities are distributed across the email chain, starting with the sender, who remains the data controller. A contractual clause is not enough to transfer this responsibility.
What is the marketing impact of the CNIL's recommendation on tracking pixels and emails?
During the webinar, Thomas Adhumeau and Guillaume Tollet highlighted three concrete operational consequences:
- For new data collection, consent to the pixel must be obtained at the very moment the user provides their email address, directly in the form, with clear information about the purposes.
- For existing CRM databases, a three-month window is granted to inform existing contacts and offer them the right to object.
- For proof of consent, a Consent Management Platform (CMP) will not be enough for this use case. The reason is that, outside authenticated environments, it is difficult to match a pixel consent obtained through a CMP with a marketing consent tied to an email address. Companies will need a Preference Management Platform (PMP), capable of keeping a timestamped, individualized record of pixel consent linked to the email identifier, and of allowing users to withdraw it as easily as they gave it.
These three impacts define the roadmap ahead. Let's look at how to put them into practice.
Action plan for complying with the CNIL's recommendation
Before taking action, one prerequisite is to map your current usage: which tools in your email stack embed pixels? For what purposes? Some of these uses may be exempt, while others require consent.
This assessment will shape the two steps that follow.
Step one: Update your existing database
The CNIL's recommendation provides a transitional regime for addresses collected before its publication. Ongoing tracking operations may continue temporarily, provided that recipients are clearly informed within a period not exceeding three months from the publication of the recommendation.
Under these conditions, with regard to email addresses already collected, reading or writing operations may continue to be carried out, subject to the sending of clear and accessible information to recipients within a period which should not, in principle, exceed 3 months from the publication of the recommendation.
This information must enable these recipients, in cases where their consent has not been obtained in accordance with the methods set out in this recommendation, to be given the ability to object to such operations for future emails.
- CNIL, Recommendation on tracking pixels in emails (source: CNIL)
Since the recommendation was published on April 14, 2026, this window closed in mid-July. If you have not yet fulfilled this information obligation, it should be treated as your top priority. The goal is to be transparent with your contacts by letting them know that tracking pixels may be used in your emails, reminding them that they can object to this for future sends, and giving them an easy way to do so.
In practice, this can take the form of a dedicated email or a notice within a regular communication. The message must clearly explain the use of pixels and link to a space where recipients can manage their choices. A Preference Center makes it possible to centralize this space and keep a timestamped record, which is useful in the event of an audit.
Step two: Secure consent for new contacts
For all new contacts, consent to tracking must be obtained before the first tracked email is sent. This means integrating this step directly into the existing sign-up journey, whether through a newsletter form, account creation, or any other entry point into the email relationship.
This is where a traditional CMP reaches its limits, as it collects consent tied to a browsing session, without a named identifier. It cannot link that consent to a specific email address.
This is precisely what Didomi's Preference Management Platform (PMP) makes possible: collecting, storing, and retrieving consent at the individual level, purpose by purpose, and making it usable by downstream sending tools. The PMP can be integrated directly into the existing user journey, via a widget or an API, without requiring a redesign of the sign-up flow:

How Didomi can help you comply with the CNIL's requirements
The CNIL's recommendation sets a clear framework, but its technical implementation requires the right tools.
Didomi supports marketing and data teams in setting up a consent collection and management system tailored to email, with full traceability and integration into existing user journeys.
To go further, watch our webinar (in French) and check out our downloadable guide (no email required):
















