For years, consent management has lived almost entirely in the browser. A banner when you land on a website, a categorised list of cookies, a record of what each visitor accepted. That has been familiar ground for any consent management platform (CMP).
In spring 2026, that ground has widened. Within a matter of weeks, two of Europe’s most active data protection regulators (the CNIL in France and the Garante in Italy) independently reached the same conclusion: a tracking pixel in an email is not legally different from a cookie on a website. It is a technology that accesses the recipient’s device to identify them and record their behaviour, and it is therefore subject to the same standard of freely given, specific, informed and unambiguous consent.
The reasoning is not a new law. It is the application of a framework that already existed: Article 5(3) of the ePrivacy Directive (the same legal basis behind cookie banners for more than a decade), reinforced by 2023 guidelines from the European Data Protection Board (EDPB) that had already clarified the technical scope of that rule for any tracking technology, not just web cookies. France and Italy are simply the first authorities to apply that framework explicitly to email.
What exactly has changed
France (CNIL): recommendation adopted on 12 March 2026 and published on 14 April. It establishes that consent to receive a marketing email and consent to be tracked within that email are two separate permissions. The deadline to bring existing contacts into line passed on 14 July 2026. For contacts acquired from 14 April onwards, there is no grace period: compliance must be in place from the first send.
Italy (Garante): Provvedimento no. 284, adopted on 17 April 2026 and published in the Gazzetta Ufficiale on 29 April. It grants a six-month adaptation window, with a deadline of 28 October 2026. Unlike France, it allows marketing and tracking consent to be combined in a single flow, as long as the information is clear and a separate option is offered to decline tracking only.
Both frameworks agree on the essentials. They distinguish between purely operational tracking (list hygiene, send frequency management, with no identification of the recipient), which does not require consent, and tracking that measures opens to evaluate campaigns, profile behaviour or feed lead scoring, which does.
How the rules could affect you
No other member state has yet published its own guidance on email pixels. However, the legal basis invoked by France and Italy is identical across all 27 EU countries, with each having transposed it into national law, and European data protection authorities routinely coordinate their positions. It is therefore best not to treat this as a peculiarity of these two countries. It is reasonable to expect the rest of Europe’s authorities to publish their own decisions gradually over the coming months, and it makes sense to prepare before that happens.
For any organisation managing consent at European scale, the question is no longer “does this apply in my market?” but “is my consent data model ready for this to apply in any market, the moment it does?”
The blind spot in current tools
Here is the practical problem: existing CMPs (Cookiebot, Usercentrics, OneTrust and similar) are designed to block scripts that load in a browser when someone visits a website. The email pixel fires from the recipient’s email client (Gmail, Outlook), completely outside the reach of any web banner. With today’s tools, there is no possible integration between the two worlds.
Email marketing providers are reacting unevenly. Klaviyo already offers tracking controls per recipient and at account level, and is building native consent capture into forms and preference centres. Adobe has published specific guidance for Journey Optimizer, with per-message toggles. Salesforce Marketing Cloud, Mailchimp and HubSpot still send with the pixel switched on by default in their templates, without such granular control for the time being.
This leaves a clear gap. The problem a CMP solves for cookies (consent that is managed centrally, verifiable and revocable) does not yet have a mature equivalent for email. Until the market solves it, the responsibility for building that logic falls, for now, on each organisation.
The roadmap: from regulation to practice
These are the phases for getting from the regulation to a consent control that works for email too.
Phase 0. Inventory of sending platforms
List every tool that sends emails with tracking: your main email service provider (ESP), social-to-email tools, sales engagement, transactional email and any automation. For each one, check whether it natively supports pixel suppression per recipient or whether that has to be built.
Phase 1. Consent data model
One central record per contact, not a boolean per platform: a field for marketing consent and another for tracking consent, each with the date, the capture method and the version of the privacy notice in force at that moment. It lives in the CRM/CDP and syncs via API to each ESP.
Unlike cookies, whose consent is tied to the browser or device it was given on, email has the advantage of being sent to a known address: consent can be natively anchored to that person, without depending on syncing state across devices.
Phase 2. Consent capture
Two unticked checkboxes, at sign-up and in the preference centre. Separate, specific wording for each purpose. Italy allows a single flow with a clear option to decline tracking only, while France requires a more explicit separation.
Phase 3. Retroactive revocation where the deadline has passed
In cases like France, where the deadline has already passed, the safest position for contacts without documented tracking consent is a fail-safe of “do not track” by default, until they actively give consent. This means marking tracking consent as not granted for that group and enabling the corresponding suppression in the ESP.
Phase 4. Per-user blocking and unblocking mechanism
This is the central technical point, and the one that varies most depending on the sending platform. Some platforms can disable the pixel per contact automatically, while others only allow it at campaign or account level. Where there is no native support, the alternative is to segment the send (with or without tracking) or to use a proprietary pixel proxy that works the same way on any platform.
Phase 5. Dependent systems
Identify the automations, lead scoring and sales alerts that depend on opens. For the segment that has not consented, define an alternative signal (for example, link clicks that do not individually identify the recipient, covered by marketing consent).
Phase 6. Audit and quality control
An immutable, auditable record of every consent. Periodic technical audits (sending test emails to non-consenting contacts and confirming that the pixel is not served). A review of contracts with each ESP and sub-processor. Extending the same criterion to other channels (SMS, WhatsApp) if they introduce similar tracking in future.
The wider opportunity
What France and Italy have done, in practice, is extend the perimeter of consent management beyond the web. Any organisation that already solves this problem for cookies has the foundation to solve it for email too. Only the point of technical application changes: from a script in the browser to a setting in the sending platform.
The advantage of acting now, before the rest of the EU publishes its own guidance, is building the data model once instead of having to redo it country by country.
Do you have questions about how to apply this to your specific case, or about managing consent across different European markets? Check our internationalisation FAQs or get in touch and we will solve it together.









