Email Tracking Compliance Just Got Harder. What Do UK Marketers Need To Know?
Stay informed about the latest developments in email tracking. Compliance in the EU and UK is more complex than ever for businesses.
Oops! We could not locate your form.
Stay informed about the latest developments in email tracking. Compliance in the EU and UK is more complex than ever for businesses.
This post is for general informational purposes and doesn’t constitute legal advice. Email tracking compliance depends on your specific data flows, contact bases, and legal bases for processing, talk to your DPO or legal counsel before changing your consent mechanisms or compliance timelines.
If your company sends marketing or sales emails to contacts in France or Italy, or anywhere else in the EU, the rules around that innocuous little tracking pixel that tracks recipients’ interactions with your emails, just shifted. If you’re a UK business, you’re not off the hook either, the UK’s own regulator moved on the same issue, on the same day.
Three separate developments landed within weeks of each other in spring 2026, and together they signal that ‘everyone tracks opens, it’s fine’ is no longer a safe assumption anywhere in Europe.
On 17 April 2026, Italy’s data protection authority adopted new guidelines specifically targeting tracking pixels in email (Provvedimento n. 284/2026). The Garante’s position is that dropping a pixel into someone’s inbox counts as accessing their device under Article 122 of Italy’s Privacy Code (the local implementation of the EU’s e-Privacy rules).
That means it’s prohibited by default unless you have consent, the message itself requires it to be sent, or it’s strictly necessary for a service the recipient asked for. The guidelines were formally published in the Gazzetta Ufficiale on 29 April 2026, and businesses have six months from that date (so effectively until around 29 October 2026, but you should confirm this) to comply. Notably, the Italian guidelines go slightly further than France’s. Recipients must be offered a genuine three-way choice of, tracked emails, untracked emails, or no emails at all, not just a binary consent/unsubscribe toggle.
A couple of weeks earlier, the French regulator adopted its own recommendation on email tracking pixels (Délibération n° 2026-042 du 12 mars 2026), publishing it on 14 April 2026. It treats pixels the same way it treats cookies under Article 82 of the French Data Protection Act.
The CNIL sets out concrete examples of when consent is and isn’t needed, and lays out what it considers good consent-management practice, including that unsubscribe-style withdrawal links should be available for tracking specifically, not just for the marketing emails themselves.
Two details matter more than they might look. First, pixel consent is treated as legally distinct from consent to receive the email itself, even where you can lawfully email an existing customer without fresh consent (the ‘soft opt-in’), you still need separate, specific consent to track whether they open it. Second, where pixels are used only for list-hygiene purposes (removing inactive contacts), the CNIL expects genuine data minimisation, for example, retaining just the date of last open rather than a precise timestamp.
The UK’s ICO
Here’s the part many UK marketers have missed. On 29 April 2026, the same day Garante’s Italian guidance hit Italy’s Official Gazette, the UK’s Information Commissioner’s Office finalised its own updated guidance on storage and access technologies.
It explicitly folds tracking pixels, alongside cookies and device fingerprinting, into Regulation 6 of PECR (the UK’s Privacy and Electronic Communications Regulations). The message is nearly identical to the Continental one. Pixels used for anything beyond the strictly necessary require freely given, specific, informed consent, and refusing must be exactly as easy as accepting.
One caveat here is that the ICO has flagged that its separate review of Regulation 6 as applied to online advertising and ‘consent or pay’ models is still ongoing, with recommendations to government expected in the coming weeks, so UK guidance in this space may still move.
So this isn’t really ‘Europe tightens the rules and the UK watches from the sidelines.’ It’s three regulators converging on the same conclusion within a fortnight, and the UK is very much inside the tent.
Despite different legal texts, the Garante, the CNIL and the ICO are pointing in the same direction on the specifics:
It’s tempting to read the Garante and CNIL guidance as a France and Italy problem. It isn’t, for two reasons.
First, EU data protection law generally applies based on where the recipient is, not where the sender is registered. If your sales team is prospecting into French or Italian accounts, or your customer base includes contacts there, you’re potentially within scope of local enforcement regardless of your UK incorporation.
Second, the ICO’s own guidance means the same underlying question ‘Do we have proper consent for this pixel?’ now has to be answered for your UK-domestic email activity too. Businesses that assumed PECR was mostly a website-cookie-banner problem are discovering it now explicitly covers the tracking pixel sitting inside every marketing and sales email they send.
Most sales and marketing tools, HubSpot’s sales tracking being a common example, embed an invisible tracking pixel by default the moment you send a one-to-one or marketing email, and offer GDPR-linked settings that limit tracking to contacts with an assigned lawful basis for processing. That’s a reasonable technical mechanism, but it doesn’t itself constitute consent.
If your CRM lets you flip tracking off for contacts without a valid legal basis, that’s a helpful control, but someone still has to have actually decided what that legal basis is, documented it, and be prepared to demonstrate it. A default toggle isn’t a compliance programme.
None of this requires panic, but it does require action, and reasonably soon. Italy’s six-month clock runs out around 29 October 2026, and the CNIL expects businesses to have informed existing contacts about pixel use, and given them a way to object, by mid July 2026. For any new email flows, both regulators expect compliance now, not at the deadline.
Individually, none of these three developments is dramatic. Together, they represent European and UK regulators arriving at a shared, more literal reading of decades old ePrivacy law. A tracking pixel accesses your device, therefore it needs the same consent as a cookie, full stop. For UK companies doing business with European customers and prospects, the safe assumption going forward is that ‘everyone does open tracking’ is a description of common practice, not a legal defence.
This post is for general informational purposes and doesn’t constitute legal advice. Email tracking compliance depends on your specific data flows, contact bases, and legal bases for processing, talk to your DPO or legal counsel before changing your consent mechanisms or compliance timelines.
Discover the key factors in a successful domain migration. Understand the risks before making this crucial change.
Vikki Baker
This post is designed to help marketing teams and professionals without an SEO background, who have access to their company's Search Console account, and are daunted by the Page Indexing report.
Vikki Baker
If you received an email from Microsoft, Google, or your CMP in early 2026 warning you about TCF v2.3, you ...
Vikki Baker