logo

WordPress Design Agency

020 3355 8747

Message Us
  • Home
  • About Impact®
    Learn More About Impact Media®
    • Meet The Team
       
    • Why WordPress
       
    • Careers
       
    • Giving Back
       
    • 100K Tree Challenge
       
    James Coates
    Schedule a discovery call with UX Specialist James
    Book A Call
  • WordPress Services
    Learn More About Our Services
    • WordPress Web Design
       
    • UX Design
       
    • WordPress Development
       
    • WordPress Support & Maintenance
       
    • WordPress Evolve Retainer
       
    • WordPress Multisite Development
       
    • WooCommerce
       
    • Replatform To WordPress
       
    • WordPress Consultancy
       
    • Integrations & Plugins
       
    • WordPress Managed Hosting
       
    • WordPress Health Check
       
    James Coates
    Schedule a discovery call with UX Specialist James
    Book A Call
  • Our Process
  • Case Studies
  • Insights
  • Contact Us
WordPress Design Agency
020 3355 8747
logo logo
Book A Call
Back
Menu
  • Home
     
  •  
    About Impact Media
    Learn More About The Impacters
    • Meet The Team
       
    • Why WordPress
       
    • Careers
       
    • Giving Back
       
    • 100K Tree Challenge
       
  •  
    Our Services
    Discover How We Can Help
    • WordPress Web Design
       
    • UX Design
       
    • WordPress Development
       
    • WordPress Support & Maintenance
       
    • WordPress Evolve Retainer
       
    • WordPress Multisite Development
       
    • WooCommerce
       
    • Replatform To WordPress
       
    • WordPress Consultancy
       
    • Integrations & Plugins
       
    • WordPress Managed Hosting
       
    • WordPress Health Check
       
  • Our Process
     
  • Case Studies
     
  • Insights
     
  • Contact Us
     
020 3355 8747
Mon - Fri • 9am - 5pm
Close

Oops! We could not locate your form.

Home / Insights / Email Tracking Compliance Just Got Harder. What Do UK Marketers Need To Know?
Home / Insights / Email Tracking Compliance Just Got Harder. What Do UK Marketers Need To Know?
Back

Email Tracking Compliance Just Got Harder. What Do UK Marketers Need To Know?

Published 03.07.26
3rd July 2026
Last Updated 10.07.26
10th July 2026
Newer
8 Min Read
Vikki Baker
Vikki Baker
Marketing
Older
8 Min Read
 
Vikki Baker
Vikki Baker
 
Marketing

Stay informed about the latest developments in email tracking. Compliance in the EU and UK is more complex than ever for businesses.

An email inbox open on a laptop screen.

This post is for general informational purposes and doesn’t constitute legal advice. Email tracking compliance depends on your specific data flows, contact bases, and legal bases for processing, talk to your DPO or legal counsel before changing your consent mechanisms or compliance timelines.

If your company sends marketing or sales emails to contacts in France or Italy, or anywhere else in the EU, the rules around that innocuous little tracking pixel that tracks recipients’ interactions with your emails, just shifted. If you’re a UK business, you’re not off the hook either, the UK’s own regulator moved on the same issue, on the same day.

Three separate developments landed within weeks of each other in spring 2026, and together they signal that ‘everyone tracks opens, it’s fine’ is no longer a safe assumption anywhere in Europe.

What’s Actually Changed?

Italy’s Garante

On 17 April 2026, Italy’s data protection authority adopted new guidelines specifically targeting tracking pixels in email (Provvedimento n. 284/2026). The Garante’s position is that dropping a pixel into someone’s inbox counts as accessing their device under Article 122 of Italy’s Privacy Code (the local implementation of the EU’s e-Privacy rules).

That means it’s prohibited by default unless you have consent, the message itself requires it to be sent, or it’s strictly necessary for a service the recipient asked for. The guidelines were formally published in the Gazzetta Ufficiale on 29 April 2026, and businesses have six months from that date (so effectively until around 29 October 2026, but you should confirm this) to comply. Notably, the Italian guidelines go slightly further than France’s. Recipients must be offered a genuine three-way choice of, tracked emails, untracked emails, or no emails at all, not just a binary consent/unsubscribe toggle.

France’s CNIL

A couple of weeks earlier, the French regulator adopted its own recommendation on email tracking pixels (Délibération n° 2026-042 du 12 mars 2026), publishing it on 14 April 2026. It treats pixels the same way it treats cookies under Article 82 of the French Data Protection Act.

The CNIL sets out concrete examples of when consent is and isn’t needed, and lays out what it considers good consent-management practice, including that unsubscribe-style withdrawal links should be available for tracking specifically, not just for the marketing emails themselves.

Two details matter more than they might look. First, pixel consent is treated as legally distinct from consent to receive the email itself, even where you can lawfully email an existing customer without fresh consent (the ‘soft opt-in’), you still need separate, specific consent to track whether they open it. Second, where pixels are used only for list-hygiene purposes (removing inactive contacts), the CNIL expects genuine data minimisation, for example, retaining just the date of last open rather than a precise timestamp.

The UK’s ICO

Here’s the part many UK marketers have missed. On 29 April 2026, the same day Garante’s Italian guidance hit Italy’s Official Gazette, the UK’s Information Commissioner’s Office finalised its own updated guidance on storage and access technologies.

It explicitly folds tracking pixels, alongside cookies and device fingerprinting, into Regulation 6 of PECR (the UK’s Privacy and Electronic Communications Regulations). The message is nearly identical to the Continental one. Pixels used for anything beyond the strictly necessary require freely given, specific, informed consent, and refusing must be exactly as easy as accepting.

One caveat here is that the ICO has flagged that its separate review of Regulation 6 as applied to online advertising and ‘consent or pay’ models is still ongoing, with recommendations to government expected in the coming weeks, so UK guidance in this space may still move.

So this isn’t really ‘Europe tightens the rules and the UK watches from the sidelines.’ It’s three regulators converging on the same conclusion within a fortnight, and the UK is very much inside the tent.

The Common Thread Across All Three

Despite different legal texts, the Garante, the CNIL and the ICO are pointing in the same direction on the specifics:

  • A pixel is treated like a cookie – All three regulators now explicitly classify tracking pixels as a form of accessing information on someone’s device, which pulls them into e-Privacy-style consent rules rather than leaving them as a vague ‘legitimate interest’ grey area.
  • Consent is the default, not the exception – Marketing-related open tracking, measuring campaign performance, adjusting send frequency based on behaviour, building engagement profiles, needs prior, specific, opt-in consent in essentially all three jurisdictions.
  • There are narrow carve-outs – Purely anonymised, aggregate open-rate counting (not tied to an individual), security-related uses like confirming account activation, and legally mandated service messages tend to be exempt. Ordinary sales and marketing tracking does not fall into these categories.
  • Withdrawal has to be as easy as consent – Regulators are explicit that recipients need a straightforward way to opt out of tracking specifically, separate from unsubscribing from the emails altogether, and that a ‘no response’ should be read as a refusal, not a green light.
  • Bundling consent is allowed, but carefully – The CNIL, in particular, accepts that tracking consent can be folded into general marketing consent to avoid overwhelming people with pop-ups, provided the request is framed neutrally rather than nudging people toward ‘yes.’
  • We can already email them doesn’t mean we can already track them – This is the nuance most likely to catch UK marketing teams out. Being lawfully able to send someone an email, because they’re an existing customer under the soft opt-in exception, for instance, is a separate question from whether you’re allowed to put a tracking pixel in it. The French guidance is explicit that the two need separate legal bases.
  • The tooling isn’t quite there yet – Consent management platforms are built for website cookie banners. None are purpose-built for the email environment in the way the new guidance now expects. That’s a genuine practical gap, not just a legal one, and it’s worth raising with whichever vendor manages your consent infrastructure.

Why This Matters Even If You’re Only UK-based

It’s tempting to read the Garante and CNIL guidance as a France and Italy problem. It isn’t, for two reasons.

First, EU data protection law generally applies based on where the recipient is, not where the sender is registered. If your sales team is prospecting into French or Italian accounts, or your customer base includes contacts there, you’re potentially within scope of local enforcement regardless of your UK incorporation.

Second, the ICO’s own guidance means the same underlying question ‘Do we have proper consent for this pixel?’ now has to be answered for your UK-domestic email activity too. Businesses that assumed PECR was mostly a website-cookie-banner problem are discovering it now explicitly covers the tracking pixel sitting inside every marketing and sales email they send.

The Tool Issue

Most sales and marketing tools, HubSpot’s sales tracking being a common example, embed an invisible tracking pixel by default the moment you send a one-to-one or marketing email, and offer GDPR-linked settings that limit tracking to contacts with an assigned lawful basis for processing. That’s a reasonable technical mechanism, but it doesn’t itself constitute consent.

If your CRM lets you flip tracking off for contacts without a valid legal basis, that’s a helpful control, but someone still has to have actually decided what that legal basis is, documented it, and be prepared to demonstrate it. A default toggle isn’t a compliance programme.

What To Actually Do About It

None of this requires panic, but it does require action, and reasonably soon. Italy’s six-month clock runs out around 29 October 2026, and the CNIL expects businesses to have informed existing contacts about pixel use, and given them a way to object, by mid July 2026. For any new email flows, both regulators expect compliance now, not at the deadline.

  1. Map where your tracking actually happens – Marketing automation platforms, sales engagement tools, browser plugins individual reps may have installed, all of it. Many organisations are surprised by how much tracking exists outside centrally managed systems.
  2. Work out your legal basis for each flow – For most commercial email marketing and sales prospecting, that basis is going to be consent, not legitimate interest, and not ‘they didn’t complain.’
  3. Separate tracking consent from marketing consent where you can – Regulators want people to be able to say ‘keep emailing me, just don’t track me’ as a genuine option, not a hidden one.
  4. Build in a real opt-out for tracking, not just unsubscribe– Recipients who withdraw consent should stop being tracked, including, per the French guidance, retroactively on messages they might reopen later.
  5. Check your consent records – If you can’t show when, how, and for what purpose someone agreed to be tracked, you don’t currently have usable consent, you have a plan.
  6. Loop in whoever owns GDPR/PECR compliance early – Email infrastructure and CRM changes take longer to implement than the compliance deadlines suggest, and DPOs and email service providers both need runway.

The Bigger Picture

Individually, none of these three developments is dramatic. Together, they represent European and UK regulators arriving at a shared, more literal reading of decades old ePrivacy law. A tracking pixel accesses your device, therefore it needs the same consent as a cookie, full stop. For UK companies doing business with European customers and prospects, the safe assumption going forward is that ‘everyone does open tracking’ is a description of common practice, not a legal defence.

This post is for general informational purposes and doesn’t constitute legal advice. Email tracking compliance depends on your specific data flows, contact bases, and legal bases for processing, talk to your DPO or legal counsel before changing your consent mechanisms or compliance timelines.

Share Socially
Vikki Baker
Vikki Baker
Digital Marketing Manager, Cat Lady & Former Female Indiana Jones
Vikki has over 15 years of experience in Digital Marketing for WordPress specialist agencies. She loves WordPress for its simplicity of use, huge flexibility, and how great it is for SEO.
View Team Profile
See More Articles
Vikki Baker
Vikki Baker
Digital Marketing Manager, Cat Lady & Former Female Indiana Jones
Vikki has over 15 years of experience in Digital Marketing for WordPress specialist agencies. She loves WordPress for its simplicity of use, huge flexibility, and how great it is for SEO.
See More Articles
View Team Profile

If You Liked This, You Might Like These

Marketing
August 18th, 2026
13 min read

The Risks Of Domain Migrations & How To Manage Them

Discover the key factors in a successful domain migration. Understand the risks before making this crucial change.

Vikki BakerVikki Baker
 
Marketing
May 29th, 2026
13 min read

A Guide To The Page Indexing Report In Google Search Cons...

This post is designed to help marketing teams and professionals without an SEO background, who have access to their company's Search Console account, and are daunted by the Page Indexing report.

Vikki BakerVikki Baker
 
Marketing
May 22nd, 2026
10 min read

What Is IAB TCF v2.3 And Does Your Website Actually Need It?

If you received an email from Microsoft, Google, or your CMP in early 2026 warning you about TCF v2.3, you ...

Vikki BakerVikki Baker
 
Looking For Support For
Your WordPress Website?
Let Us Take The Stress Of Website Maintenance & Support Off Your Plate
Let's Talk
studio@impactmedia.co.uk
020 3355 8747
Impact Media's LinkedIn
Impact Media's Twitter
Impact Media's Facebook
Impact Media's Instagram
Impact Media's Youtube
wordpress.org

About Impact

  • About Impact Media®
  • Meet The Impact Team
  • Why WordPress?
  • Our Web Development Process
  • Careers
  • Awards
  • Partners
  • Giving Back
  • 100K Tree Challenge

WordPress Services

  • WordPress Web Design
  • UX Design
  • WordPress Development
  • WordPress Evolve Retainers
  • WooCommerce Development
  • Multisite WordPress
  • Migrate To WordPress
  • Custom Integrations & Plugins
  • WordPress Consultancy

WordPress Support

  • WordPress Support & Maintenance
  • WordPress Managed Hosting
  • Case Studies
  • Insights
  • Contact Us

Addresses

London Address:

50 Liverpool Street,

London, EC2M 7PY, UK

+44 (0) 20 3355 8747

 

Registered Address:

Woodland Place, Hurricane Way

Wickford, SS11 8YB, UK

  • Privacy Policy
  • Cookie Policy
Impact Media logo
© Impact Media® 2003 - 2026
Impact Media is a trading name of IMDMS LTD. Company Reg. 05970261
Impact® & Impact Media®
are registered trademarks of IMDMS LTD