Summary
- Introduction
- What is an email tracking pixel?
- What do the CNIL and Garante guidelines say?
- When is consent generally required?
- When may an exemption apply?
- Transactional, service, and B2B emails
- Collecting and demonstrating consent
- Withdrawing tracking consent
- Your responsibilities and Mailjet’s role
- Managing tracking in Mailjet
- Recommended actions
- Frequently asked questions
- Learn more
Introduction
Email tracking helps you understand how recipients interact with the emails you send through Mailjet. This includes measuring whether an email was opened and whether recipients clicked links included in the message.
Open tracking is usually performed through a small, invisible image known as a tracking pixel. Because loading this image may access information from the recipient’s device and generate information about their activity, its use may be subject to privacy and consent requirements.
In April 2026, the French data protection authority, Commission Nationale de l'Informatique et des Libertés (CNIL), and the Italian data protection authority, Garante per la protezione dei dati personali (Garante), published guidance specifically addressing tracking pixels in emails.
These publications do not introduce new statutory rules. They clarify how existing rules, primarily the ePrivacy Directive together with the GDPR and the corresponding French and Italian national laws, apply to email tracking.
What is an email tracking pixel?
A tracking pixel is a small, usually invisible image included in an email. The image is hosted on a remote server rather than being stored directly inside the message.
When the recipient opens the email and their email client loads external images, it sends a request to the server hosting the pixel. This request can allow the sender or its email service provider to register that the email was opened.
Depending on the implementation, the request may involve information such as:
- An identifier associated with the email or recipient.
- The date and time at which the pixel was loaded.
- The IP address used for the request.
- Information about the email client or device.
- Whether the message was opened more than once.
Open tracking can help senders measure performance, investigate deliverability, identify inactive contacts, and understand engagement. However, because the tracking mechanism is usually invisible, regulators emphasize transparency and recipient control.
What do the CNIL and Garante guidelines say?
What both authorities agree on
Both authorities consider that loading a tracking pixel may access information from a recipient’s device. The operation therefore falls within rules derived from the ePrivacy Directive, in addition to any GDPR requirements applicable to the subsequent processing of personal data.
Both authorities emphasize that:
- Prior consent is generally required unless a specific exemption applies.
- Recipients must be clearly informed that tracking pixels are being used.
- The purpose of the tracking must be clearly defined and explained.
- Only information necessary for the stated purpose should be collected.
- Consent must be free, specific, informed, unambiguous, and demonstrable.
- Recipients must be able to withdraw consent easily.
- The requirements applicable to the tracking pixel are separate from those applicable to sending the email.
Where France and Italy differ
The CNIL and Garante follow the same general consent principle, but they describe some exemptions differently.
| Topic | France: CNIL | Italy: Garante |
|---|---|---|
| Deliverability measurement | Individual open tracking may qualify for a limited exemption when it is used exclusively for actions strictly necessary for deliverability, such as adjusting sending frequency or stopping sends to inactive recipients. | The exemption is generally described in terms of global, non-personalized open-rate statistics using effectively anonymized information. |
| Data minimization | The CNIL recommends retaining only the date of the last known open, without the precise time, and replacing the previous value after a new open. | The Garante recommends using the same pixel for all recipients of a campaign and anonymizing associated technical information, such as IP address and email-client data. |
| Individual analytics | Consent is generally required when individual open information is used outside the limited deliverability exemption. | Individual-level open tracking generally requires consent unless another specific exception applies. |
| Withdrawal | The CNIL recommends a personalized link in each email footer and effective withdrawal for future emails and, where technically necessary, previously sent emails. | The Garante requires an easy and granular withdrawal mechanism, allowing recipients to stop tracking while continuing to receive emails. |
| Transition | For previously collected addresses, the CNIL provided a transitional period that should generally not exceed three months from publication of the recommendation (April 14, 2026). | The Garante provides six months from publication (April 29, 2026) of its guidelines in the Italian Official Gazette for affected organizations to adapt. |
When is consent generally required?
Whether consent is required depends primarily on the purpose for which open information is collected and used.
Consent may generally be required when individual open information is used for:
- Measuring and optimizing marketing campaign performance.
- Personalizing email content based on observed engagement.
- Adapting sending frequency or send time for individual recipients.
- Creating segments based on opens or non-opens.
- Triggering promotional Automation workflows.
- Building recipient profiles or engagement scores.
- Targeting recipients through other channels.
- Sending reminders or reactivation campaigns to non-openers.
- Investigating fraud or automated activity outside a narrowly defined security exception.
- Measuring individual deliverability outside the conditions of a recognized exemption.
These activities use open information to make decisions about an identifiable recipient rather than merely producing limited technical or anonymous statistics.
When may an exemption apply?
Both regulators recognize limited situations in which prior consent may not be required. An exemption should be interpreted narrowly, documented, and regularly reassessed.
Authentication security
Tracking may potentially qualify for an exemption when it is strictly necessary for a security measure related to user authentication.
For example, a pixel may be used exclusively to help verify that an email containing an authentication code or password-reset instruction was opened on a device known to belong to the intended recipient.
Deliverability and inactive-contact management under the CNIL recommendation
The CNIL describes a limited exemption for individual open tracking used exclusively for deliverability purposes.
To rely on this exemption, the sender must be able to demonstrate that the information is limited to what is strictly necessary to:
- Identify inactive recipients.
- Adjust sending frequency.
- Stop sending to inactive recipients.
- Clean the mailing list by reducing or stopping sends to inactive contacts.
The information must not be reused for marketing analytics, profiling, personalization, engagement scoring, or unrelated purposes.
Anonymous global statistics under the Garante guidelines
The Garante describes a possible exemption where pixels are used to calculate the overall percentage of recipients who opened a campaign, provided that the resulting information does not allow personalized measurement.
The Garante recommends measures such as:
- Using the same pixel for all recipients of the campaign.
- Not associating the event with an individual recipient.
- Anonymizing IP addresses and other technical information.
- Preventing the information from being used for recipient profiling.
Legally required, institutional, or essential service communications
The Garante also identifies possible exemptions for certain messages that the sender is legally required to provide or that protect the recipient.
Examples may include:
- Security-incident notifications.
- Warnings about current phishing or fraud threats.
- Legally required contractual notices.
- Important changes to scheduled services or events.
- Certain public-service or institutional communications.
Transactional, service, and B2B emails
The sending channel does not determine the email’s purpose
Sending an email through the Mailjet SMTP relay, Send API, Automation, or a transactional template does not by itself determine whether the email is transactional for privacy purposes.
For example, an abandoned-cart, reactivation, product recommendation, or price-drop message may remain promotional even when it is triggered automatically or sent through the transactional API.
Transactional emails are not automatically exempt
A genuinely transactional email is normally triggered by a recipient’s action and provides information required for a requested account, service, or transaction.
Examples may include:
- Order confirmations and invoices.
- Shipping and payment notifications.
- Password resets and account-security alerts.
- Appointment or reservation confirmations.
- Responses to customer-support requests.
Even when the email itself can be sent without marketing consent, using individual open information for personalization, profiling, or campaign optimization may still require tracking consent.
B2B communications
Certain B2B emails may, depending on the applicable law and circumstances, be sent without the same consent requirements that apply to consumer marketing. This does not automatically authorize individual open tracking.
The legal basis for sending the email and the requirements applicable to the tracking pixel should be assessed separately.
Collecting and demonstrating consent
When consent is required, it should generally be collected before the tracking pixel is used.
Consent should be:
- Informed: The recipient should understand that tracking pixels will be used and for which purposes.
- Specific: Separate purposes should be clearly identified.
- Freely given: Refusing tracking should not create an unnecessary disadvantage or prevent access to the requested service.
- Unambiguous: Consent should result from a clear positive action.
- Demonstrable: The sender must be able to prove when, how, and under which conditions it was obtained.
Collect consent when collecting the email address
Both authorities recommend informing recipients about tracking when their email address is collected, such as through a registration, checkout, or newsletter sign-up form.
The notice should explain:
- That tracking pixels may be included in emails.
- The purposes for which they will be used.
- The types of information that may be collected.
- Which parties may process the information.
- How consent can be withdrawn.
A short notice can be displayed directly on the form, with a link to more detailed information in your privacy or tracking policy.
Collect consent later
When tracking consent was not collected together with the email address, the CNIL indicates that the sender may request it later through an email linking to a consent interface.
The consent-request email should not itself contain a tracking pixel that requires consent. Clicking the link should also not automatically register consent, because email clients and security tools may preload links.
The linked page should require a clear positive action, such as selecting an option or clicking a confirmation button.
Contacts obtained from third parties
Mailjet prohibits the use of purchased, rented, scraped, or other third-party mailing lists.
For contacts collected through partners, affiliates, or co-registration processes, confirm that the collection method complies with Mailjet’s policies and that you can provide individualized evidence of the recipient’s permission where required.
A contract stating that another party collected consent may form part of your compliance documentation, but it may not be sufficient by itself. You should be able to produce evidence that each relevant recipient gave informed consent to the tracking purposes concerned.
Keep evidence of consent
Your consent records should allow you to demonstrate:
- Who consented or refused.
- The date and time of the choice.
- The email address covered by the choice.
- The purposes presented to the recipient.
- The wording and version of the consent notice.
- The source through which the choice was collected.
- Any subsequent withdrawal or change.
Withdrawing tracking consent
Recipients who consented to tracking must be able to withdraw that consent at any time. Withdrawing consent should be as easy as giving it.
Where required by the applicable regulatory framework, the withdrawal mechanism should allow recipients to choose between:
- Unsubscribing from future emails entirely.
- Continuing to receive emails while refusing the use of tracking pixels.
The CNIL recommends providing a personalized tracking-consent withdrawal link in the footer of each email. The Garante similarly recommends a clearly visible link or standardized icon leading to an area where the recipient can manage their choices.
Previously sent emails
Mailjet applies tracking changes when an email is generated. Switching tracking to Anonymous or Disabled therefore affects future sends only.
Emails sent before the change keep their original tracking configuration, so opens or clicks from those messages may still be recorded.
Your responsibilities and Mailjet’s role
In the usual Mailjet sending relationship, you decide why emails are sent and how the resulting tracking information is used. You therefore act as the data controller for those purposes.
Mailjet provides the technical email-sending and tracking functionality and processes the corresponding information on your instructions.
As the sender, you are responsible for:
- Determining whether tracking is necessary.
- Identifying the purposes for which tracking information is used.
- Determining whether consent or an exemption applies.
- Informing recipients about the tracking.
- Collecting and recording any required consent.
- Applying refusals and withdrawals.
- Being able to demonstrate compliance.
Managing tracking in Mailjet
You can manage open and click tracking from your Mailjet account settings.
- Log in to your Mailjet account.
- Go to Account → Tracking .
- Under Email tracking settings, select the options you want to apply.
The Track openers - transactional and campaigns setting controls how Mailjet tracks email opens.
Depending on your account configuration, you may see the following options:
| Option | Description |
|---|---|
| Enabled | Mailjet tracks email opens at recipient level when the tracking pixel is loaded. |
| Disabled | Mailjet does not track email opens. Open statistics and open-based activity will not be available. No open tracking pixel will be added to the email. |
| Anonymous | Mailjet tracks opens in an anonymous way, helping you measure overall open activity while reducing the amount of recipient-level tracking data collected. |
The Track clicks - transactional and campaigns setting controls whether Mailjet tracks clicks on links included in your emails.
Depending on your account configuration, you may see the following options:
| Option | Description |
|---|---|
| Enabled | Mailjet tracks clicks on links included in your emails at recipient level. |
| Disabled | Mailjet does not rewrite links for click tracking, and click statistics and click-based activity will not be available. |
| Anonymous | Mailjet tracks clicks anonymously. This allows you to measure overall click activity while reducing the amount of recipient-level tracking data collected. |
Using Anonymous tracking
Availability
This feature is included in the following plans.
- Free
- Starter
- Essential
- Premium
- Custom
The Anonymous option allows you to continue measuring overall email engagement while reducing the amount of recipient-level information collected.
It is a useful choice when you want to monitor general open and click activity but do not need to identify which individual contacts interacted with a specific email. This can help you maintain visibility into campaign performance while adopting a more privacy-conscious approach to engagement tracking.
Anonymous tracking can therefore form an important part of your privacy and compliance strategy, particularly when aggregated performance insights are sufficient for your needs.
However, no single technical setting can address every legal requirement. Whether consent is required may still depend on factors such as the purpose of the tracking, the applicable jurisdiction, how the information is processed, and whether the resulting data meets the relevant legal standard for anonymization.
Recipient-level consent management
The Mailjet settings described in this article apply at account level. They do not create or manage a separate tracking-consent status for each recipient.
Through these settings, you cannot automatically:
- Enable tracking only for contacts who consented.
- Disable tracking only for contacts who refused or withdrew consent.
- Apply a different setting to each recipient within the same account.
- Maintain proof of each recipient’s consent.
What happens when tracking is anonymized or disabled?
Changing your tracking settings may affect the engagement information available in Mailjet and any features that rely on recipient-level activity.
When Anonymous tracking is selected, Mailjet continues to measure overall open or click activity while reducing the amount of recipient-level information collected.
This allows you to retain a general view of email performance, but individual engagement events may no longer be available for features or processes that need to identify which specific contact opened or clicked an email.
Anonymous tracking may affect:
- Recipient-level activity history.
- Segments based on individual opens or clicks.
- Engagement scoring based on recipient activity.
- Automation conditions or workflows that rely on individual open or click events.
- Processes that identify inactive contacts using recipient-level engagement.
When open or click tracking is Disabled, Mailjet no longer collects the corresponding engagement information.
This may affect:
- Open or click rates in campaign statistics.
- Recipient-level activity history.
- Segments based on opens or clicks.
- Engagement scoring based on email activity.
- Automation conditions or workflows based on opens or clicks.
- Processes used to identify inactive contacts.
Before changing your tracking settings, review any active segments, Automation workflows, reports, exports, or operational processes that depend on open or click data.
How Anonymous tracking works
When Anonymous tracking is enabled, Mailjet continues to record overall campaign activity while limiting the recipient-level information displayed for anonymous opens and clicks.
In the Activity tab:
- Delivered always shows the contacts who received the email.
- Opened does not show contacts whose opens were recorded anonymously.
- Clicked does not show contacts whose clicks were recorded anonymously.
- Unsubscribed always shows the contacts who unsubscribed.
- Spam always shows the contacts who marked the email as spam.
For reporting purposes, Mailjet may associate certain identifiable actions with an open event. Therefore:
- If an identifiable click, unsubscribe, or spam event is recorded, the contact may also appear under Opened, even when open tracking is Anonymous.
- If open tracking is Anonymous but click tracking is Enabled, a contact who clicks a link appears under both Clicked and Opened. This is because clicking a link confirms that the recipient interacted with the opened email.
Recommended actions
Review your email tracking practices with your legal, privacy, deliverability, marketing, and engineering teams.
Audit your use of open data
Map every place where open information is used, including:
- Statistics and dashboards.
- Segments and contact scoring.
- Automation triggers and workflow conditions.
- Personalization and send-time optimization.
- Re-engagement and inactivity processes.
- Deliverability and database-cleaning decisions.
- Exports or third-party integrations.
Review your consent flows
- Check whether sign-up forms clearly mention tracking pixels.
- Explain each tracking purpose in clear and neutral language.
- Avoid preselected options.
- Do not interpret inactivity as consent.
- Record consent, refusal, and withdrawal.
- Make withdrawal easy and visible.
Review the origin of your contacts
- Identify which contacts came through your own forms.
- Review imported, partner-provided, rented, or co-registered contacts.
- Confirm whether individualized proof of consent is available.
- Verify that the use of the contacts complies with Mailjet’s policies.
Assess your geographic exposure
- Determine whether you send to recipients in France or Italy.
- Identify which national requirements apply.
- Consider whether applying a stricter standard across your EU audience would reduce operational complexity.
- Monitor guidance from other national data protection authorities.
Review your engagement strategy
- Avoid relying on opens as your only engagement signal.
- Prioritize clicks, replies, purchases, and conversions.
- Review workflows that depend heavily on open or non-open events.
- Determine what would happen if open information became more limited or less reliable.
Frequently asked questions
Does consent to receive marketing emails include consent to tracking pixels?
Not automatically. The requirements for sending an email and the requirements for tracking its opening should be assessed separately. In some circumstances, sending and tracking consent may be presented together when the purposes are closely connected and clearly explained. Consult your legal or compliance team before using a combined consent.
Are transactional emails exempt?
Not automatically. A limited exemption may apply where the email concerns a requested service and the tracking is strictly necessary for security, deliverability, a legal obligation, or another recognized exempt purpose. Using individual opens for marketing, profiling, personalization, or campaign optimization may still require consent.
Can I track B2B recipients without consent?
The fact that a B2B email may be sent without marketing consent does not automatically authorize individual open tracking. Assess the sending and tracking activities separately.
Can I use open data to target contacts who did not open a campaign?
Using individual non-open information for reminders, reactivation campaigns, personalization, or other commercial targeting may require prior tracking consent.
Does Anonymous tracking mean consent is no longer required?
Not necessarily. Its legal treatment depends on the technical implementation, the information initially collected, the tracking purpose, and whether the resulting information is effectively anonymized.
Can Mailjet manage tracking consent separately for each contact?
The account-level tracking settings do not provide per-contact tracking-consent management. You must manage and retain recipient choices through your own consent-management process.
Can recipients refuse tracking without unsubscribing?
Both the CNIL and Garante support allowing recipients to refuse tracking while continuing to receive emails. However, Mailjet’s current account-level tracking settings cannot disable tracking for only one recipient. Review this technical limitation when designing your consent and withdrawal process.
Do the CNIL and Garante guidelines apply throughout the EU?
The CNIL recommendation applies within the French legal framework, while the Garante guidelines apply within the Italian legal framework. Both are based on European ePrivacy and GDPR principles, but other national authorities may interpret or implement these requirements differently.