What’s changed for email marketers?
Note that this article was originally published on July 23, 2026. It has been updated to reflect new information and product functionality.
France’s data protection authority (CNIL) and Italy’s data protection authority (Garante) each issued updated guidance this year on tracking pixels in email. These pixels are invisible 1×1 images that report opens, timestamps, device, and approximate location, and they’re now treated the way regulators already treat cookies. Prior, informed, freely-given consent is required unless a narrow exemption applies. Both authorities root this in Article 5(3) of the ePrivacy Directive and the GDPR.
This affects any sender emailing recipients in France or Italy, including B2B sends to a named work address.
Consent to receive an email and consent to be open-tracked are two different things. Keep reading to dig into why that distinction matters.
The problem with an on/off switch
Until recently, most senders had exactly two options. Neither was good.
- Option #1: Leave open tracking on for everyone, and accept the compliance exposure for recipients who declined.
- Option #2: Shut the open beacon off account-wide, which protects you in France and Italy… but simultaneously blinds you everywhere else. Engagement scoring, sunset policies, re-engagement segments, last-open-date list hygiene – all of it runs on open data for the rest of your list.
That’s a bad trade, and it’s not the one regulators asked for. CNIL and Garante ruled on individual consent. The fix needed to work at the individual level too. So MessageGears built one.
How per-recipient pixel suppression works
MessageGears reads a reserved recipient field called TrackingConsent. You pass a consent value for each recipient alongside their email address, and at render time, we simply leave the open pixel out of that person’s message.
A few things worth being explicit about:
- The email still sends. Suppressing the pixel never blocks delivery and doesn’t unsubscribe anyone.
- Nothing is emitted at all. When suppressed, the pixel is absent from the rendered email. Not broken. Not a blank request. Absent.
- It’s resolved per recipient, per send. Two people in the same campaign can get different treatment.
Matching is case-insensitive and ignores stray whitespace.
Read that last row twice. The default is fail-open. Silence in your data means tracked. That’s deliberate. An unreadable consent value should never stop an email from going out – but it means suppression has to be stated explicitly. Leaving the field off protects no one.
TL;DR: the per-recipient TrackingConsent field lets you honor a recipient’s refusal of open tracking without turning the pixel off for your entire program.
Where to put the recipient tracking flag
If you build audiences in the MessageGears platform, you can alias a column as TrackingConsent in your audience query the same way you already alias EmailAddress or RecipientId. If you send through the API, include a TrackingConsent field in the recipient payload for transactional or bulk submissions. Use the exact field name – that’s the whole integration on our side.
What email marketers actually need to do
The new field is the easy half. The plumbing that feeds it is the real project.
And unfortunately, your ESP can’t handle this for you. No vendor can decide on your behalf who consented. You are the data controller for tracking in your campaigns, so capturing, storing, and proving consent is your responsibility. Your ESP (e.g. MessageGears) then acts on the flag you hand over. Here’s how you can get started:
- Find out who this applies to. Estimate how much of your list sits in France and Italy using the location data you already have. This scopes everything else.
- Add the ask where you collect addresses. Open-tracking consent needs its own checkbox – unbundled from your email opt-in, never pre-ticked, and as easy to withdraw as to give – on every signup source, not just the main one.
- Notice your existing list. For addresses already on file, send a clear notice with an easy way to decline. France’s window has already closed (July 14, 2026). Italy’s runs through October 28, 2026.
- Treat silence as a no. Anyone who doesn’t respond should be recorded as having refused. A null in your database feels like “unknown,” but regulators read it as “no.”
- Get the value into the send. Map the consent field from your preference center or CMP through to the audience query or API payload. Remember the fail-open default: your query needs to emit an explicit false, not an empty string.
- Keep timestamped proof. Of both consent and withdrawal. CNIL has signaled it will audit on this topic.
- Update your privacy notice. Name the pixel, the controller, each purpose, and any third-party recipients.
What this does to your email reporting
Be ready for this internally. Suppressed recipients emit no open events, so they won’t appear in open rates, engagement scores, or anything else derived from opens. That’s the feature working correctly, not a data problem to escalate. If a meaningful share of your list is in France or Italy, your reported open rate will move – and the honest framing for stakeholders is that the old number was counting people who hadn’t agreed to be counted.
Two things this does not touch: click and link tracking, which is a separate mechanism, and delivery, which is always unaffected.
One more note if you’ve already flipped the account-wide switch. The account-level suppress open beacon setting turns off the automatic beacon for everything. The per-recipient field is narrower, and for flagged recipients, also suppresses beacons placed manually in templates – both HTML and AMP, marketing and transactional alike.
Compliance work rarely gives you a clean answer, but this one comes close. Honor the people who declined, keep the visibility you need everywhere else, and stop making a global decision about a per-person right.
FAQs
Disclaimer:
This article is intended to be informational only and is not legal advice. It reflects public regulatory sources and MessageGears product functionality as of September 2026 and may not reflect the most current guidance. Regulations, deadlines, and interpretations can change. Consult qualified legal counsel before making compliance decisions.
Sources:
- CNIL, “Pixels de suivi dans les courriers électroniques” (April 14, 2026)
- Iubenda, “Garante email tracking pixel rules: what to do before 28 October 2026” (June 3, 2026)
- Lewis Silkin, “Tracking Pixels in Emails: A Comparative Analysis of the CNIL and Garante Guidance” (June 23, 2026)
- MessageGears Documentation Hub: “Open-tracking consent” (2026)
Mathew Hodges Director of Deliverability
With more than a decade of email deliverability expertise, Mathew helps enterprise senders navigate the technical and regulatory complexities of inbox placement. Before joining MessageGears, he led deliverability teams at Healthcasts Media and OutboundEngine. Prior to that, he spent six years at Mailchimp – first as a Deliverability Advisor, then as a Deliverability Engineer – where he managed sending infrastructure, IP and domain reputation, and receiver-side anti-abuse processes at scale.