This article summarises publicly reported details and does not constitute legal advice. Sources are listed at the end of the piece.
For twenty years the open rate has been the most-quoted number in email marketing. It is also, as of this spring, a compliance liability in the European Union.
On 17 April 2026 Italy’s data protection authority — the Garante per la Protezione dei Dati Personali — adopted its first dedicated guidelines on email tracking pixels (Provision no. 284), published in the Official Gazette on 29 April. The move looks technical and is anything but: it drops the email open-tracking pixel into the same legal bucket as the cookie. The moment a pixel loads on open and tells you which named recipient did the opening, you now need prior opt-in consent — the identical basis regulators have long demanded for cookies.
If you send marketing email to anyone in Italy, your open-rate reporting is now a consent question. Here is what the ruling actually says, and what to do about it.
What the ruling actually changes
The mechanism is worth understanding because it explains why the exemptions fall where they do. An open-tracking pixel is a tiny, usually invisible image embedded in an HTML email. When the recipient’s client loads that image, it calls back to a server — and because the URL is unique per recipient, the sender learns this specific person opened this specific message at this specific time.
The Garante grounded its decision in Article 122 of the Italian Privacy Code, which implements Article 5(3) of the EU ePrivacy Directive — the same provision behind cookie consent — and aligned it with the European Data Protection Board’s Guidelines 2/2023. The logic is that storing or accessing information on a user’s device (loading that pixel) to identify them is exactly the activity ePrivacy governs. It was never really about cookies as a technology; it was about tracking. The pixel just wasn’t being enforced against. Now it is.
So the headline is not “open tracking is banned.” It is: open tracking that identifies an individual now requires the same opt-in consent as a marketing cookie.
The timeline you’re working against
- 17 April 2026 — Garante adopts Provision no. 284
- 29 April 2026 — published in the Official Gazette; the six-month clock starts
- 14 July 2026 — France’s CNIL date for informing existing contacts
- 28 October 2026 — Garante compliance deadline
During the transition, senders may keep tracking mail to existing lists, but only if those recipients are told what’s happening and given a genuine chance to opt out at the first reasonable opportunity. Once 28 October passes, the full opt-in standard bites.
France’s CNIL published its own recommendation on the same topic and lands stricter in two places. It won’t let you fold pixel-tracking consent into a general marketing opt-in the way the Garante does — CNIL wants consent that is, in principle, specific to each purpose. And it flatly declines to recognise the anonymised-aggregate statistics exemption that Italy allows. The practical upshot: if you send into both markets, you’re building to the stricter CNIL bar and the Garante’s Italy-specific duties, against the earlier July date.
The exemptions — narrower than you’d hope
Under the Garante’s guidelines, consent is not required in a short list of cases:
- Anonymised aggregate statistics — but only if you use a single, non-individualised pixel for the whole campaign and anonymise IP and client data before storing anything, so no one recipient can be picked out of the crowd.
- Security and service messages where awareness is legally relevant — password resets, security notifications, changes to terms, and comparable institutional communications.
Two things worth underlining. First, France’s CNIL does not accept the anonymised-aggregate carve-out at all — but it does permit pixels used purely to measure individual deliverability so you can adjust frequency or stop mailing inactive recipients, an exemption the Garante frames differently. Second, everything a marketer actually reaches for — per-recipient opens, engagement segmentation, “opened but didn’t click” re-send flows, send-time optimisation — sits outside every one of these exemptions and needs consent.
”But my ESP handles this” — no, you’re the controller
This is the line that catches teams out. The Garante is explicit: the sender is the data controller, even when pixel management is fully outsourced. Routing everything through Mailchimp, SendGrid, Brevo, or any other platform does not move the legal responsibility onto them.
A contract clause stating that your ESP collects consent is not sufficient on its own. What regulators want to see is the underlying evidence: an immutable, per-address consent log with timestamps and proof of any revocation. If you can’t produce, for a given recipient, “here is when they opted in and here is the record,” a provider’s terms of service won’t save you.
A practical compliance checklist
If you send into the EU, here’s the shape of what “compliant” looks like under the ruling:
Consent & disclosure
- Add pixel-specific disclosure to your sign-up forms, with unchecked opt-in boxes (no pre-ticking).
- Identify the controller — and any joint controllers — clearly.
- Update your privacy policy to document exactly what the pixel collects, how long you keep it, and which third parties receive it.
Preferences & withdrawal
- Build a two-level withdrawal mechanism: let people disable tracking without unsubscribing. These are different choices and must be logged separately.
- Provide granular preference management, linked from the email footer.
Technical implementation
- Use opaque, non-sequential pixel IDs — never the email address or anything derivable from it.
- Serve a pixel-free HTML variant whenever consent is absent or has been withdrawn.
- Keep immutable per-address consent logs with timestamps and revocation proof.
What this means for how you measure email
The uncomfortable truth underneath this ruling is that the open rate was always a fragile metric. Apple’s Mail Privacy Protection already inflated it years ago by pre-loading images for many users. The Garante decision is the point where the industry has to stop treating “opens” as a reliable, free signal and start treating it as consented, documented data — or stop relying on it.
The teams that will barely feel this are the ones already measuring what actually correlates with revenue: clicks on tracked links, replies, conversions, unsubscribe and complaint rates, and list health. Clicks are a first-party action the recipient deliberately takes (though note CNIL treats link-tracking as its own consent question), and they map to intent far better than a silently-loaded pixel ever did.
At Score, our position is that deliverability and engagement should be measured on signals you can stand behind — per-provider delivery, bounce and complaint data, and consented engagement — rather than a pixel that regulators are now, correctly, treating as tracking. If the open rate has been carrying your reporting, the next four months are a good moment to rebalance toward metrics that are both more honest and more defensible.
Sources
- Garante per la Protezione dei Dati Personali — Provvedimento del 17 aprile 2026: Linee guida in materia di utilizzo di tracking pixel nelle comunicazioni di posta elettronica (official text, Italian)
- Covington — Italian DPA Publishes Guidelines on Email Tracking Pixels
- Lewis Silkin — Tracking Pixels in Emails: A Comparative Analysis of the CNIL and Garante Guidance
- Covington (Inside Privacy) — CNIL Publishes Recommendation on Email Tracking Pixels
- iubenda — Garante email tracking pixel rules: deadline 28 October 2026
This article summarises publicly reported details of the Garante guidelines and the parallel CNIL recommendation. It is not legal advice. Confirm your own obligations with qualified counsel — especially if you send into both Italy and France, where the stricter, earlier CNIL requirements apply.
Frequently asked questions
Does the Garante ruling ban email open tracking?
No — it reclassifies them rather than outlawing them. Once a pixel loads on open and lets you identify who opened the message, the Garante treats that as the same kind of terminal access already covered by the cookie rules, so it needs the same prior opt-in consent. The legal hook is Article 122 of the Italian Privacy Code, which transposes Article 5(3) of the ePrivacy Directive. You can keep tracking opens for recipients who have said yes; for everyone else you send a version of the email with no pixel in it.
Who does this apply to and when?
It reaches any sender whose recipients are in Italy, wherever the sender itself is based. The guidelines (Provision no. 284) were adopted on 17 April 2026 and published in the Official Gazette on 29 April, starting a six-month clock that runs out on 28 October 2026. France's CNIL published its own recommendation on the same subject, with a 14 July 2026 date for existing contacts — so if you mail into both countries, plan against whichever obligation is stricter and lands first.
What kinds of email are exempt from consent?
The carve-outs are narrow. Under the Garante's guidelines, consent isn't needed for genuinely anonymised aggregate stats — a single non-individualised pixel per campaign, with IP and client data anonymised before storage — nor for security and service messages where the recipient's awareness is legally relevant (think password resets, security alerts, or terms-of-service changes). France's CNIL declines to recognise the anonymised-aggregate exemption at all, but does allow pixels used purely to gauge individual deliverability so you can throttle or stop sending to inactive recipients. Anything that identifies a person for marketing analytics falls outside all of these and needs opt-in.
If I use an ESP like Mailchimp or SendGrid, am I covered?
No. The Garante is explicit that the sender is the data controller even when pixel management is fully outsourced. A contract clause saying your ESP collects consent is not enough on its own — you need the underlying per-recipient evidence records: who consented, when, and proof of any revocation. The responsibility to hold that evidence stays with you.
How do I keep measuring engagement without breaking the rules?
Three practical paths: collect explicit opt-in for open tracking at sign-up and log it per address; send a pixel-free HTML variant to anyone who hasn't consented or has withdrawn; and lean on consent-independent signals — clicks on tracked links (a separate consent question under CNIL), replies, conversions, and list hygiene — instead of treating the open rate as your north-star metric.
Send email you can measure and defend
Score routes across your SMTP providers with per-provider deliverability, bounce, and complaint analytics — engagement signals you can actually stand behind.